Re: "http://rl.webtracer.cc" start page, unable to remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by toadieboy, May 3, 2005.

  1. toadieboy

    toadieboy Private E-2

    In March you solved a problem for a fellow Aussie "Cosmic Pawn". I have had the same problem and used the same method to eliminate the trojan. I had some different entries but the removal seemed to go well.

    The only remnant that has raised its head is when a typed URL is not found by the DNS server, the retrieved page then goes to the same one that the webtracer trojan used as my home page when it was active. Is there some way to clear up this final bit?

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what steps you have run and what you have not run so please follow the steps below. If you have already run ALL the steps in the READ ME just let me know and skip to the steps for the HijackThis log.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. toadieboy

    toadieboy Private E-2

    I had previously read the "read me first" and executed the various steps of the tutorial. No error messages were evident from the various tools nor did I find any viruses with the tools.

    Attached is the Hijack log as requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.

    On the page that opens, scroll down to IP Stack ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    IP Stack

    Let me know if that works okay and you do not get any error messages.
     
  6. toadieboy

    toadieboy Private E-2

    I ran the programs as instructed and everything went fine with no error messages. When I entered an invalid URL in the Explorer address line, it took me to the standard MSN auto.search screen. Appears that problem is solved.

    Many thanks for your help. That's another case of beer if you ever get to Aussie.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but it would be good if you posted a follow up HJT log. There were some other things that needed fixing.
     
  8. toadieboy

    toadieboy Private E-2

    I'll attach a new log file to this message.

    I ran several updates to XP today to try and plug some of the holes. I know that I was lagging in this. Unfortunately, we puchased our computer from a small shop in our little town that sells used computers. I attempted a very lengthy download of XP SP2 today but when I went to install it, it aborted and told me that I did not have a properly licensed copy of XP. So I guess I'm stuck with that until I buy a proper copy of XP.

    If you have any other suggestions, I'd welcome them.

    Thanks again.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O19 - User stylesheet: (file missing)
    After clicking Fix, exit HJT.

    Double check to see if each was actually fixed and let me know.

    My normal suggestion is for people to run all the steps in: How to Protect yourself from malware!

    Sounds like you will not be able to do step 1 (which is going to leave you vulnerable) but make sure you have done the equivalent of all the other steps (for example: one of the steps mentions a firewall. Since you already have one, you can check that off as complete.)
     
  10. toadieboy

    toadieboy Private E-2

    Those entries are fixed. I will do as many of those steps as I can. As you have mentioned, some of them are done.

    Thanks again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Save your money and get a licensed copy of Win XP SP2! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds