Some spyware not leaving me alone. (sorry for the other annoying topics)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mickoo, May 2, 2005.

  1. Mickoo

    Mickoo Private E-2

    I have a saved logfile of it if you would like me to post it. All of these are on the new version of hijackthis and are all 023 from aol, McAfee, and some from Wan miniport,intell, NVIDIA, and something from Remote procedure call. I can post the logfile if you want.






    *the annoying topics were from my younger brother, please ignore them. He went crazy when I said Hijackthis is broken* :(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is far from the first step. You should read the announcement and the sticky threads. Please state what your problems are specifically.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Mickoo

    Mickoo Private E-2

    Is this spyware? or somethng else?

    I have done all the steps in the Read Me guide for getting rid of spyware and things. Should I get a firewall? If so, which ones would not interupt aol. I went into safe mode and could not get my aol to work. Here is an attachemnt from hijackthis:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Is this spyware? or somethng else?

    Why do you keep starting new threads for the same problems? You must remain in one thread.

    I'm merging you back to one of your previous threads.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Is this spyware? or somethng else?

    You did not follow directions on where to install HijackThis.

    This does not appear to be a complete HijackThis log. You show no processes at all loading at startup.
    Are you editing this before posting or are you using HijackThis to filter any lines?
    My guess is that you are. We must see a complete unedited and unfiltered HijackThis log.

    You have an HSA hijacker as indicated by the below:
    O23 - Service: Remote Procedure Call (RPC) Helper (?%AF夶À¨) - Unknown owner - C:\WINDOWS\system32\iedi.exe (file missing)

    You should be following the steps in the READ ME FIRST related to this hijacker. Start with step number 2 where you are supposed to stop and disable this service.
     
  6. Mickoo

    Mickoo Private E-2

    Here is the new logfile. I'm not changing anything in it. I'm still having problems with the network services. I deleted it, made a new programs folder for it, and did the steps you told me to in the READ ME.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still do not have HijackThis installed correctly and this cannot be a complete log.

    You should completely delete the version of HijackThis that you have from your Desktop. And then download the ZIP file I gave you in my first post. The extract HijackThis.exe from the ZIP file and put it into a folder that you must create. The suggested name for this folder is
    C:\Program Files\HJT

    Then run hijackthis.exe again and post a new log. I see no problems in your previous log other than the fact that nothing seems to loading on your system at startup. There are many things that normally show in a HijackThis log that you seem to be missing. All you show are some services entries. Something is not right. Did previously use HijackThis and have it fix all items it listed? That would be a bad thing to do!
     
  8. Mickoo

    Mickoo Private E-2

    Okay, I have done everything you said. Deleted hijackthis from desktop. made a new folder. did step two in the read me again. I'm not changing anything, i don't know what could be the problem. I kinda did fix all items on that :( ...
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me make sure I understand this correctly. At some point in time you ran HijackThis and you selected all lines it displayed and you had it Fix all of them? Is this correct?


    How is your PC working right now? Any problems running any programs? You may need to reinstall somethings to get yourself back to a normal condition. I also assume you did disable system restore per the tutorial. If you did not disable it, DO NOT do it now. We may be able to fix you up from an old restore point.
     
  10. Mickoo

    Mickoo Private E-2

    Yes, I have done this all of the time. My uncle said to do that, so i just did it everytime.


    My PC is working okay, I just don't know what could be wrong in my computer that everytime i delete those items in hjt,they come back. My system restore is off, and was off all of the times i had my computer scanned by anything.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not what you should have done and you should tell your Uncle that too. HijackThis merely shows you a list of processes running and a list of various registry keys and their contents. It is not telling you one way or another if they are good or if they are bad. That is up to an experience user to determine. Then the appropriate steps must be taken to fix problems completely. DO NOT use HijackThis by yourself anymore in this fashion. Just follow directions and post your logs and allow us to tell you what should be fixed and how to do it.

    Your log is clean right now but there are many items (good items) that are probably not running properly. You should consider uninstall McAfee and then reboot and reinstall it from scratch. That should get some of its registry keys fixed up.
     
  12. Mickoo

    Mickoo Private E-2

    Do you mean McAfee virus scanner? or the stinger?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    McAfee Virusscan. Stinger is not an installed application. It is just something you run without needing an install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds