Same problem as Posted below but...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Spyglass, Jul 6, 2005.

  1. Spyglass

    Spyglass Private E-2

    I too have recieved a new toolbar (the same one as described by Gstam66 in a post below) when you click on "remove toolbar" it directs you to stopzilla homepage and every once in a while pops-up a porn ad.

    I have done EVERYTHING in the tutorial. Trend Micro came up empty as did Symantec security response. Subsequent scans with the remaining programs were also negative with the exception of adaware which deleted the Acer program.

    I am running in Safe mode w/ networking support.

    There are some programs on the hijackthis log that are sketch to me though. Hope you can help.
     

    Attached Files:

  2. Spyglass

    Spyglass Private E-2

    Can someone please look at my Hijack log?

    (posted above)
     
  3. tblue

    tblue Corporal

    Hi Spyglass,
    Is that HJT log from safe mode? If it is you should attach one from normal mode.
    T.Blue
     
  4. Spyglass

    Spyglass Private E-2

    OK here is the log from normal mode. What do you think?
     

    Attached Files:

  5. Spyglass

    Spyglass Private E-2

    just trying to stay near the top. Any comments about my log?
     
  6. Spyglass

    Spyglass Private E-2

    OK I managed to kill the search toolbar on my own but I am still getting redirection problems to porn sites and stuff. Here is a new Hijack log.
    PLEASE would someone look at it and help me out?
     

    Attached Files:

  7. tblue

    tblue Corporal

    Morning Spyglass,
    Hang in there and BJ or Chas will get to your log as soon as they can. They are kinda busy in here as you can see by the number of posts. :D
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bad idea! Message threads are looked at from oldest to newest and also by looking at which ones are unanswered.

    Bumping or adding a message to your thread puts you to the the end of that queue not the top.
     
    Last edited: Jul 7, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS and IE versions are way out of date and represent a major security risk. After we fix your current problems you must get updated.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [yaemu.exe] C:\WINDOWS\System32\yaemu.exe
    O4 - Startup: Reboot.exe
    O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://195.95.218.84/users/kick/web/axe/x.chm::/update.exe


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\yaemu.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Also while in safe mode look in both locations below for the reboot.exe file and rename it to reboot.xxx if found. Note: replace username by whatever your user account name actually is.

    c:documents and settings\username\start menu\programs\Reboot.exe <--- rename to reboot.xxx
    c:documents and settings\username\start menu\programs\startup\Reboot.exe <--- rename to reboot.xxx


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. Spyglass

    Spyglass Private E-2

    OK no bumping my threads. Sorry Chas.

    Did as you suggested exactly. And yeah I have to update my OS. I already updated my browser. Though I am considering Firefox.

    Here is my new logfile.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your IE browser is still way out of date.

    You can also have HJT fix the two below minor Alexa related issues:

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    Other than that you are clean. Are you having any further problems?
     
  12. Spyglass

    Spyglass Private E-2

    You ROCK !!! No problems anymore that I have seen.

    What can I do to update my browser? I got the Internet Explorer 6 SP1....is there something else?

    Or should this be another question for another thread in a different forum topic.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should perform the steps in the below thread.

    How to Protect yourself from malware!

    The first step in it will take you to Windows Update. At Windows Update you will eventually get to a point where you can use Express Install or Custom Install

    Express will get you up to Win XP SP2 level

    Custom Install allows you to pick what updates to get.

    The better choice is Express but Custom allows you to download in smaller chunks various updates. This can be useful if you have slow connection (like dialup). You can also order a WinXP SP2 CD (all this is assuming you have a valid license for you current software.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds