Spyware Problem !!! / What is this??

Discussion in 'Malware Help (A Specialist Will Reply)' started by geneman, Jan 13, 2005.

  1. geneman

    geneman Private First Class

    Spyware problem !!!

    Hi Guys

    From yesterday i am getting a lot of problem due to adwares. i was downloading something from a website and just after that the problems started. i tried with spybot adaware and symentec, and they detected many problems (including istbar) and deleted them, but still i am getting lots of pop ups. plis help me in cleaning them out.. symentec doesnt get anything when i put scan, but time 2 time keeeps giving message of "delete succeded" of some .exe files of the category "dowloader.trojan".
    here is my hijack this log, kindly help...:

    Logfile of HijackThis v1.97.7
    Scan saved at 9:39:39 AM, on 1/13/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
     
    Last edited by a moderator: Jan 13, 2005
  2. PhilliePhan

    PhilliePhan Guest

    Re: Spyware problem !!!

    Hi Geneman,

    I see a number of issues in your log. However, your HijackThis is waaaay out of date! Also, it would probably be a good idea to run through our Cleanup Tutorial. I will post my standard speech below!

    But first, a question and suggestion. Do you recognize the following as legitimate and needed?
    C:\Documents and Settings\spathak\Application Data\teer.exe
    Looks like a trojan.

    Also, you ought to dump ARES as it invites more of these problems.

    AllRightyThen, here's the speech:

    Please take a spin through the Cleanup Tutorial HERE:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!
    Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’m not around this forum too often these days, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  3. geneman

    geneman Private First Class

    Re: Spyware problem !!!

    hi philip...

    i have done the things u told, but some adwares still there.. i have put the HJT log.. plis see and help me..

    thanks and regards
     

    Attached Files:

  4. geneman

    geneman Private First Class

    Re: Spyware problem !!!

    any1 plis help...
     
  5. PhilliePhan

    PhilliePhan Guest

    Re: Spyware problem !!!

    Will post something for you this evening - Please be patient :)
    I only have so much free time for this forum.

    PP :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Spyware problem !!!

    I'll try to save you & PP some time!

    You need to go back and follow PP's directions and install HJT to the correct directory and you MUST exit browsers before running. You had this:
    C:\Program Files\Internet Explorer\IEXPLORE.EXE <---- must exit first
    C:\Documents and Settings\spathak\My Documents\HijackThis.exe <--- wrong place to put HJT

    You must fix the the above before continuing!!!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\iexplore.exe <--- this is not valid
    C:\Documents and Settings\spathak\Application Data\teer.exe
    C:\WINDOWS\system32\n?svc32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
    O2 - BHO: (no name) - {F07BC763-03DA-2C77-8692-74A2AC876793} - C:\WINDOWS\System32\hflarge.dll
    O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
    O4 - HKCU\..\Run: [Emet] C:\Documents and Settings\spathak\Application Data\teer.exe
    O4 - HKCU\..\Run: [Ulr] C:\WINDOWS\System32\n?svc32.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)
    O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe (file missing)


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\iexplore.exe
    C:\Documents and Settings\spathak\Application Data\teer.exe
    C:\WINDOWS\System32\hflarge.dll

    Now empty your Recycle Bin and c:\windows\prefetch folders.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    You should not be running multiple antivirus applications. Pick one and uninstall the other.
     
  7. PhilliePhan

    PhilliePhan Guest

    Re: Spyware problem !!!

    Thanks, Chas! Bit overextended at the moment . . . :)

    PP
     
  8. geneman

    geneman Private First Class

    What is this??

    When i put norton antivirus scan i see some spywares present in a folder named "system volume information". but i cannt locate this folder anywhere. what to do now? plis help.

    regards
     
  9. geneman

    geneman Private First Class

    Re: Spyware problem !!!

    thanks guys... i will follow the instructions and let u know

    thanks a lot...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: What is this??

    This means that you have not disabled system restore as directed in the READ ME FIRST.
     
  11. geneman

    geneman Private First Class

    Dear Chaslang and Phillie

    yes after i did as u told, everything is fine now...
    thousand thanx for your greaaat help...
    u guys r genius !
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds