spyware problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by cpfccc, Mar 25, 2005.

  1. cpfccc

    cpfccc Private E-2

    spyware issues

    cannot get into password sights


    have follwed previous instructions before posting this to you. adaware could not update or connect from server not could spybot

    would not allow me to run online virus scan

    other error 'page could not be displayed'

    is it ok to post hijack this log at this stage

    please help

    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Please try to run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal and provide as much detail as possible on any problems you have on running any of them. Also, if any of the scans do run indicated what problems, if any, were found. If you cannot run the online scanners in safe mode, try them in normal boot mode.

    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. cpfccc

    cpfccc Private E-2

    Apologies for the long delay in replying but wanted to take all necessary steps: here's what happened

    Adaware SE - downloaded but would not allow me to connect to server to get updates. Ran anyway and deleted all it came up with

    Spybot - As above

    The 2 online scans at Trend Micro and Symantec, would not let me run in safe or normal mode. No error messages, just wouldn't connect

    Ran the other tools and then tried the online scans again without any luck.

    Have done HJ This log which I have attached.

    Would like to know what to do next!

    Many thanks
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have two AV programs install. You must choose which one you wish to use and uninstall the other.

    You did not install HijackThis as requested:

    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    You are running it directly from the ZIP which we requested you not do.

    You have no major issues in your HJT log the could be causing problems with your password sites. However you can have HJT fix the below 3 lines.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)


    Have you tried a temporary disabling of your firewall before trying to go to the password sites? How are you connecting here if you cannot use password sites?
     
  5. cpfccc

    cpfccc Private E-2

    Apologies for the delay in replying to last post.

    I have unistalled AVG program.

    Have now run HJT as requested and new log posted.

    I can log into some password sites e.g. Majorgeeks but not others such as online banking - this returns "Page cannot be displayed"
    Also, cannot connect to the servers for Adaware and Spybot to retrieve updates.Have re-run the other tools but nothing has changed.
    Lastly, tried to install Word 2000 and was unable to complete as there was an error with Windows Installer.

    Latest HJT log attached.
    Many thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are still no visible problems in your log. Have you tried running the scans from the Alternative Scans section of the READ ME FIRST?

    Also did you try what I suggested and disable your firewall while trying to connect to the sites where you are having problems?

    Also do this:

    Now please download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Now tell me how things are working.
     
  7. cpfccc

    cpfccc Private E-2

    Hi

    Thanks for your reply

    I have tried both your first ideas and checked hoster

    still have the same problems

    any ideas

    thanks for your help
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. cpfccc

    cpfccc Private E-2

    Thanks again

    Have tried to update windows, unable to do so error 0x8DDD0004 comes up

    Tried another browser, downloaded ok, but comes up with 'connection refused when attempting to contact start.mozilla.org' when i attempt to open the browser

    I have tried to investigate the error number but to no avail

    Please can you provide any further suggestions/help

    Thanks for your help
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jun 2, 2005
  11. cpfccc

    cpfccc Private E-2

    Hi

    thanks for reply

    all legal

    checked link, was for a different error, but went through it all anyway and still have the same problem

    any ideas

    cheers
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try disabling your firewall when you go to Windows update and see if that helps.

    Also turn off any popup, web filters etc.


    Try to register these files by entering each of the below lines in a command prompt window. You open a command prompt by clicking Start, Run, and enter cmd and click OK.

    REGSVR32 C:\WINDOWS\system32\wuapi.dll
    REGSVR32 C:\WINDOWS\system32\wuaueng.dll
    REGSVR32 C:\WINDOWS\system32\atl.dll
    REGSVR32 C:\WINDOWS\system32\wucltui.dll
    REGSVR32 C:\WINDOWS\system32\wups.dll


    Also try removing the Windows Update ActiveX controls and re-install
    http://support.microsoft.com/?kbid=319585

    Also see this link: http://forum.aumha.org/viewtopic.php?p=52963


    If these do not work, I would suggest posting this problem in the Software Forum because it does not appear to be a malware related issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds