possible spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by shewolf, Dec 27, 2004.

  1. shewolf

    shewolf Specialist

    There is a problem that I have been having so I ran the steps in the "read me first..." and I have ran the HJT and would like to attach the log so I can get an opinion if my problem is listed in the log or not.
    Now to explain my problem... when I am signed into Yahoo Messenger and I receive an email I used to be able to click on the little white envelope in the system tray and it would automatically sign me in to the Yahoo mail account. Yes I do have it checked to sign me in Automatically when a Yahoo Link is clicked when in messenger but it doesn't sign me in the little white envelope just disappears. Yes I have the newest version of Yahoo Messenger & yes I have uninstalled it and reinstalled it and still the problem persists.
    OS = Win XP Home Edition SP2
    Browser = Mozilla Firefox 1.0
    Yahoo Messenger = 6,0,0,1750

    Thanks for any help anyone can give me on this and I am ready to attach my HJT log file soon as someone gives me the okay for it.
    Hope everyone had a Merry Christmas..
    shewolf
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can attach your HJT log, just follow the guidelines below. Also, note that I doubt the problem you are having is going to show in an HJT log but we will look for anything that does not look correct.

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. shewolf

    shewolf Specialist

    Chaslang thanks here is the HJT..
     
  4. shewolf

    shewolf Specialist

    I redownloaded my HJT because I had it in a sub folder of Docs & Settings now I have it in its own program folder.
    So here is my new HJT log I do have my others saved from when I had my HJT in Docs & Settings if you need to see those..
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I suspected, I do not see any apparent problem causing this in your HJT log.

    You can have HJT fix this line though:
    O3 - Toolbar: (no name) - {CE89D46B-CC43-0F6B-10F6-7494D7D76E18} - (no file)

    When did the problem start? When did it last work correctly? Have you installed anything since it last worked properly?

    I noticed you have Norton's Firewall running. Have you disabled the built-in firewall of XP SP2? It is enabled by default and having more than one software firewall running can cause problems.

    Although I don't believe it to be the problem, you could try temporarily disabling the following:
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\BHODemon 2\BHODemon.exe
    C:\Program Files\SpywareGuard\sgmain.exe
     
  6. shewolf

    shewolf Specialist

    I looked in my Security Center and it shows for firewall that I am using Norton and that when I click on the Windows Firewall that it is shown to be off.

    As for these programs
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe was installed after my problem started
    C:\Program Files\BHODemon 2\BHODemon.exe has been installed way before my problem started
    C:\Program Files\SpywareGuard\sgmain.exe has been installed way before my problem started

    The Spybot S&D teatimer was installed recently as I uninstalled all my spyware apps and reinstalled them as I was going through the Read Me First and it gave me 2 boxes to check so I checked the tea timer as well as the other box not sure what it actually does but thought it couldn't hurt.

    I am really hazy on when it last worked for me but I am going to say the last time it worked was before I switched from Cable ISP to DSL ISP. I am now going through my phone company for DSL ISP and I switched to that in Mid November the DSL name is SBC Yahoo!. I believe that towards the end of November is roughly when I noticed that I could no longer click on the little white envelope and Automatically log in to Yahoo Mail.
    It isn't a problem for us to open up the browser and manually sign in to get my yahoo mail I just don't want there to be a spyware problem or problem with my computer and not do something to fix it.
    Thanks for your time and help on this I really appreciate it.
    shewolf
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay and when did you upgrade to SP2 relative to the above. Where they before or after SP2? Did you problem occur before or after SP2 was installed?

    Maybe you need to talk to SBC and find out if the are conflicting with your original Yahoo Mail some how.

    I see no apparent spyware. That does not mean there isn't any. It just means, if there is any, it is the type that is not visible. If none of they scans are showing anything at all, you are probably pretty safe.
     
  8. shewolf

    shewolf Specialist

    Spybot, Adware,BHODemon, spyguard were used prior to the SP2 upgrade and never had any problems.
    Please note that the tea timer portion of SpyBot was not added until last week when I uninstalled all my spyware programs so I could follow the "Read Me First" step by step and I could officially say yes I have installed the programs per the instructions. :)
    It appears as though my problems started when I changed from cable ISP to DSL ISP. I just wanted to post here to rule out spyware prior to calling SBC because I have this feeling that when I do call SBC its going to be a major hassle and they are not going to understand what is happening (I hope I am wrong).
    See the thing is with SBC Yahoo! I have an SBC Yahoo! Browser and even when I am signed into that Browser I can't click on the little white envelope to be signed in automatically to read Yahoo Mail. So regardless of what browswer I am using (IE, SBC Yahoo!, or Mozilla Firefox) I can not be signed in automatically to my Yahoo Mail account like I could in the past.
    Thanks chas for all your time and help I greatly appreciate it.. Please have a Safe & Happy New Year..
    shewolf
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The only other thing I would suggest would be an uninstall, reboot, reinstall of their software. (make sure you know how to reconfigure everything). Good luck, sorry I cannot be more help. One other suggestion would be to post a question on this in the Software Forum.
     
  10. shewolf

    shewolf Specialist

    You have been more then helpful and I really needed to have my HJT looked at to rule out spyware prior to doing anything else and you did that so I am most thankful for your time and help.
    Have a great day & Happy New Year..
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy New Year!
     
  12. shewolf

    shewolf Specialist

    Chaslang just wanted to let you know some things since my last post.
    I did post about my problem in the software forum only response I got was the suggestion to uninstall and reinstall messenger (which I had already done prior to posting). I still had the problem with Yahoo Messenger plus I discovered after posting here to you that I couldn't even read profiles, change/update my own profile, click on the Messenger Help, or Messenger Home page under the help button.
    I did contact SBC they told me that I needed to contact Yahoo as it was a Yahoo product and they did not have the tools to help me with a product other then SBC. So, I did contact Yahoo and they told me to uninstall and reinstall messenger and make sure that my IE Browser was current version and up to date.
    I finally gave up and did a complete dump of my computer and started fresh so far the problem that I was having with Yahoo Messenger is gone and each time I update something or add a new program I am testing the Yahoo messenger to make sure it still works the way it should. I figured by doing this after each install or update I can hopefully pinpoint what program was causing it.
    Just wanted to let you know the outcome and what was happening incase you ever run across this again with someone else and if by testing the Messenger after each program is installed or updated I find out which program was causing the problem I will post to let you know.
    Many thanks for all that you do as I for one greatly appreciate it..
    Have a great day!!
    shewolf
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the info. In between installing each program and before testing Yahoo, I would reboot once and then check Yahoo. Some programs don't suggest or require a rebbot after install but it would be better to check it that way to be sure. Also don't forget your Windows Updates.
     
  14. shewolf

    shewolf Specialist

    After I dumped my computer I decided to go through the read me first steps because I keep getting a pop up window with the Windows Installer and another one that says Norton Antivirus 2005 does not support the Repair feature please uninstall and reinstall. I uninstalled and reinstalled NAV2005 and I still get that pop up.
    Well when I did the steps everything came out good except for Symantec Security Check it said there is a problem and I need to use a Personal Firewall I do have Norton Personal Firewall 2005 and it is enabled and up to date I am not sure what else to do with the Firewall.
    My HS remove removed 8 items dunno what those were well now I am at a loss as to how to get the pop up from Windows Installer gone and also what to do about my Firewall that symantec says is a problem..
    I know I am supposed to let you ask me first but I will attach my most recent HJT log so you can see what is happening since this is an ongoing problem with my computer acting up.. Thanks so much I really appreciate your time and help..
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can have HijackThis fix the below items:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    Then you should set your home page to what you want.

    Your Norton Firewall Monitor appears to be running but did you enable the firewall itself. Note you have XP SP2 which has its own firewall which is enabled by default. You should not have more than one software firewall enabled. So if you plan to use Norton's, you must disable the one from XP SP2.

    You may want to check this link out for your Windows Installer issues: Windows Installer CleanUp Utility

    Note: Unless you have problems with HSA hijacks and/or about:blank hijacks, you should not be running HSremove or About:Buster. I'm not sure why HSremove is always finding 8 items but it appears to be a bug many people are seeing. Ignore it unless you have a hijack problem.
     
  16. shewolf

    shewolf Specialist

    Thanks for all of your help I really appreciate it..
    I have downloaded the Windows Installer Cleanup Utility now I just need to know what to remove from that box as I do not want to delete something that I shouldn't (I tend to goof things up if I delete too much) :rolleyes: :rolleyes:
    I will delete the NAV 2005 as that is what comes up upon start up of my computer (Windows Installer pop up then NAV 2005 does not support the repair feature.... ).
    As for the firewall I have it disabled in XP sp2 and I just opened up my firewall and looked at things and ran live update (which came up that all was updated) and then I reran the security check and it came up good.
    As for the about blank I did have that when I went to open up IE to run a program that would not work with Firefox so that is why I ran the about blank and HS Remove..
    All is well with computer now except that Windows Installer which I hope will be taken care of once I remove the NAV 2005 from that list..

    Thanks again...
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There is a difference between having a home page set to about blank and a real about:blank hijack. You can set you start page to about:blank to speed up loading of IE (or for whatever reason you like). A hijacker will not let you change it and you will always get about:blank.
     
  18. shewolf

    shewolf Specialist

    Gotcha.. man you are ever so knowledgable.. thanks sooooooooo much for all your help..
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds