spyware help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by geegonzo, May 3, 2005.

  1. geegonzo

    geegonzo Private E-2

    I am having trouble getting rid of loadingwebsite.com and others, here is my hijackthis log if that helps. Thanks in advance.

    Edit by chaslang: Unrequested log removed
     
    Last edited by a moderator: May 3, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the Announcement at the top of everypage in the Spyware Forum. Also please read and follow the sticky thread guidelines.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. geegonzo

    geegonzo Private E-2

    Ok, I followed step by step the read me before asking for support page, and through all of the sections I was able to remove some of the spyware, however there are still some out there. That loadingwebsite.com keeps coming back. I did take some notes along the way if that will help. Thanks again for the help and the support pages.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just complete the steps I gave you so we can get to the root of your problems.
     
  5. geegonzo

    geegonzo Private E-2

    Sorry chaslang, kinda of a newbie to this, anyway here it is. Thanks again. :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not extract HijackThis from the ZIP file as I requested. You are running it directly from the ZIP file as show by your log:
    C:\DOCUME~1\TOMMYM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You must extract the HijackThis.exe file from the ZIP file and put it into the folder suggested.

    Download LSP - Fix

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If the file is already in the Remove section, just click finish.


    Now download the following tool: L2MeFix Tool

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Get a new HijackThis log.
    Now come back here and post the l2mfix log and the new HJT log as attachments.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  7. geegonzo

    geegonzo Private E-2

    I think I finally got it chaslang , here are the log files. thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the below two lines and then click Fix:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log.

    Again, don't run any other files in the L2MFix folder.
     
  9. geegonzo

    geegonzo Private E-2

    Here is the l2mfix log file. My computer did go bazonkers (lol) like you said. Thanks for the help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Okay that fixed some problems. Please post a new HJT log. How are things running right now?
     
  11. geegonzo

    geegonzo Private E-2

    so far no popup adds like before, have not tried to reset homepage yet. Here is the hijackthis file.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That looks clean! I would just do two more things:

    1) Please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    2) Complete all the steps in the below thread to help keep you clean:
    How to Protect yourself from malware!
     
  13. geegonzo

    geegonzo Private E-2

    You guys are the greatest! Is there anything I can do to support this service you provide? Thanks for being patient with a newbie geek like me. Thanks again!!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You can buy a Majorgeeks teashirt or sweatshirt. Also, an email of appreciation to the owners (see there names and email addresses here: http://www.majorgeeks.com/page.php?id=2 ) is always appreciated. Also send your friends here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds