Red ! - PC infected by Spyware button

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Katzenjammer, Oct 10, 2004.

  1. Katzenjammer

    Katzenjammer Private E-2

    Greetings!

    I have followed all the instruction from your http://forums.majorgeeks.com/showthread.php?t=35407 tutorial and have gotten nowhere getting rid of this insidious thing.

    I've run AdAware SE, Spybot S&D, CCleaner, Spywareblaster, Kill2Me, Stinger, CW Shredder, etc from the above thread. Followed all of the instructions carefully. Not once, but three times and gotten nowhere. I'm now 6 hours into this and it's still there.

    I was playing a web game and suddenly I started getting popups all over the place and the red exclamation point in the white circle suddenly appeared. Which I didn't click, but it was already in my taskbar and in my IE bar.

    Initially I ran Spybot and Adaware which came up with over 800 problems to fix. (I ran these only two weeks ago with only 20 items to fix.) Each time I re-run Adaware it comes up with 20'ish Ezula tracking items which I tell it to delete.

    So I came to your website and started to follow through the tutorial. :p (I had done this a month ago because my main computer was infected with ads123 which your information helped me get rid of... thank you!)

    My hijack log keeps showing the 09 Extra button: Your PC is infected with spyware - click here to fix your PC

    When I tell it to fix checked and scan again, it's already back.

    SO... now that I'm done rambling, now what? :)
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Show me a log file. I hope you online virus scanned as well?
     
  3. Katzenjammer

    Katzenjammer Private E-2

    You bet!

    I did do an online virus scan after I ran my Norton Anti-virus which came up with nothing.

    Trend Micro came up with 8 items it could clean. 6 of them were joke files I'd forgotten I even owned from 8 years ago, and two were viruses:
    Troj Lalus.A
    Troj Istbar.X
    Both of which I hit the delete button for.

    Hmm.. I see the begin2search just popped up on my Hijack log. *sighs* That wasn't there yesterday. If I rip my hair out and scream, don't mind me. This computer is old, but I use it for all my college and work related research so I don't infect my main computer with too much nonsense.

    Okay, for my Hijack log:
     

    Attached Files:

    • hjt.txt
      File size:
      5.4 KB
      Views:
      3
    Last edited by a moderator: Oct 13, 2004
  4. Katzenjammer

    Katzenjammer Private E-2

    Fixed!!!

    I have managed to fix this (and quite a lot of other spyware I didn't even know I had!) myself. :) Thank you guys for the attempt.

    I'll tell you what I did... I found a program called Spyware Nuker 2004. I couldn't afford to buy it, but I downloaded it to see what it'd do. Boy oh boy... it found a ton of spyware that I thought my other spyware items had found and gotten rid of, and some things I didn't even know I had!

    Anyway, because I couldn't purchase it, it didn't fix any of the problems it found. But (and this is a big but!) it does allow you to hit the expand button so you can find all the files these programs are hidden in... including all the registry information!! **ding, ding, ding**

    Two hours after finding this little program and discovering the 80 files it found, I am now spyware free of all it could find. :)

    Oh, and the red exclamation point thingy? It's called spyware deleter, one of the files is sd.exe if anyone finds it in their stuff. There's other files associated with it you'll want to find and delete out. *grins and thumbs up*

    Good luck all you folks with spyware problems!!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Fixed!!!

    The SpyDeleter problem has been fixed in this forum a bunch of times already.

    You may want to post a new HJT log (as a .txt file attachment this time). You had a bunch of issues in your last log (trojans too) which I doubt were fixed by SpyNuker 2004.

    You should also uninstall SpyKiller . It is on the below link of rogue/suspect spyware removal tools:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm
     
  6. Katzenjammer

    Katzenjammer Private E-2

    *nods avidly*

    Picture me doing a bobble head dance nodding in agreement on the Spyware Killer response. I didn't install it, so out it went! :)

    Apologies on the not making the last HJT a .txt, didn't realize you wanted it that way. I must not have researched your site as thoroughly as I thought I had. :(

    The Spyware Nuker 2004 program... lol :p Adaware considers it to be Malware. *grins* Oh well, it helped me get rid of the worst of the problems I was having, so it can consider it that all it wishes. :p

    Okay... I DL'd BHO Daemon, that seems to be helping a bit, too.
    I also DL'd Zone Alarm so I'd have a firewall. ;) Those are the only new additions since I last posted.

    I went to the website in your guide for the items listed in HJT to see if the 04's were okay. I wasn't sure how to tell which were okay or not. ;( IE: that NeroCheck.exe... no idea if it's the OK one or nay. I dont' remember if I installed Nero or not on this computer to start with. :(

    I hope this one meets a little more with your approval. :) I await your response avidly. :)
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: *nods avidly*

    Internet Explorer (and any other browsers) MUST always be shutdown before using HJT especially when fixing items with it. You had it running when you scanned. Make sure you shut it down from now on.

    Spyware Nuker (older versions pre-2004 version) were considered malware. The 2004 version is not supposedly on that list anymore. But who needs it?

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Some trojans are still on your PC. But first a question, did you put the O1 entry into your hosts file? Do yo recognize this: O1 - Hosts: 64.24.234.120 swirve.com

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [hoadgbw] C:\WINDOWS\kjberup.exe
    O4 - HKCU\..\Run: [cBo2RXH4h] wtsntcreate.exe

    Now boot in safe mode and delete:
    C:\WINDOWS\kjberup.exe
    C:\WINDOWS\system32\wtsntcreate.exe if not here look for it the path below
    C:\Documents and Settings\Name\Local Settings\temp\wtsntcreate.exe

    Now reboot in normal mode and post a new log.

    You need to go to Windows Update and get your PC updated. You are way out of date.
     
  8. Katzenjammer

    Katzenjammer Private E-2

    Shutting down before running HJT:
    Whoops! I'm a fluffhead. Apologies.

    Spyware Nuker comment:
    *grins* Oh well, "supposedly" and "actually" can be considered separate things in this instance. :p

    I have restore disabled and viewing hidden files enabled.

    Do yo recognize this: O1 - Hosts: 64.24.234.120 swirve.com
    Yes, that's the Utopia game I play where I think I'm getting this spyware, although the owner swears up and down it's not coming from him because then he'd have a lot of angry players.

    Followed all instructions to get rid of kjberup.exe (which was also under system32) and wtsntcreate.exe.

    Windows Update comment:
    GMTA - Great minds think alike. I just went to Windows Update last evening and hit the install, then set it up to do auto update and install when I'm not awake. :p

    Here's the latest HJT. -Gee, just think... this is only one of four of my computers I need to go over for spyware. :p I guess when I'm ready to hit the next one I'll be back here. :p :p :p
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you got the Windows updates, why does your system still show:
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Those are old.
     
  10. Katzenjammer

    Katzenjammer Private E-2

    Hmmm

    No clue? Cause I went and did installs and set it up to auto install in my absence.

    I never said I was a computer genius. :p I do my best and hope.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Hmmm

    If it still indicates those numbers in your log, you have not installed the updates. You still need to do this.
     
  12. Katzenjammer

    Katzenjammer Private E-2

    ah well

    Is the rest of my HJT clear for this comp, hon? :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: ah well

    Yes, it's clean!
     
  14. Katzenjammer

    Katzenjammer Private E-2

    Whoot!

    You're a doll! Thank you :) I'm giving myself a break before I tackle my main computer. :p I spent way too long on this for my secondary. I don't know how you do it all day! *hugs*

    Have a wonderful weekend and you are the best!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Whoot!

    You're welcome! Thanks for the hugs! :) You have a nice weekend too!
    How is the weather down there? I'll be in Ft Myers in November.


    If you have problems on your other computer, start a new thread for it when ready. So we avoid any confusion with this one.
     
  16. Katzenjammer

    Katzenjammer Private E-2

    Weather is beautiful now that all the hurricanes have gone through. :)
    Was a little rainy today, but that was good, we had a fire nearby. :(
    I'm only a couple hours north of Ft. Myers (in Tampa area).

    If you wish to speak privately on this rather than digging up this old post when you've fixed my problems :p :p, feel free to private message me. :) I hate taking up people's forum space and digging of old posts more than necessary. :) It just feels rude to do. *blushes*

    Yes, I'll start a new thread when the time comes to tackle that one. :p I haven't had any serious issues beyond ads123, which seems to be gone since I followed your instructions under "Read me first before asking for support" to start with (which was when I found this forum 2 weeks ago.) Of course, after that success, I had to send you new business!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for the new business!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds