spyware problems?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by damageinc, Dec 12, 2004.

  1. damageinc

    damageinc Private E-2

    My computer recently started displaying a warning message at the top of the screen,which reads."To help protect your security,Internet Explorer has restricted this file from showing active content that could access your computer.Click here for options"Basically my computer is disabled by something so I followed every step here http://forums.majorgeeks.com/showthread.php?t=35407
    Im still having these problems and I have a hijack this log file if it will help.Thanks for any assistance.Dont know if it helps butmy home page will not stay set.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have run all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal > and you still have a problem, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    Make sure you have HJT version 1.99.0 and follow the guidelines on where to install it and how to post a log as an attachment.

    Download A FRESH copy of HiJack This 1.99.0

    Also please provide me with general information about your computer, (Ex. Operation System, etc;)
     
  3. damageinc

    damageinc Private E-2

    Thanks for the help.Ive attached the logfile.My comp uses windows xp.Ive got adaware spybot s&d spyware blaster that i use regularly.Ive had the same problems before and I believe it was registry problems but I dont remember where I found the right values.Dunno if it will help by I tried removing the crazywinnings entry but it wouldnt go away.
     

    Attached Files:

  4. PhilliePhan

    PhilliePhan Guest

    Hi Damageinc,

    You have a nasty piece of Malware. You would be well served to follow the Cleanup Tutorial that BJ linked. You should run About:Buster and HSRemove and the Online Scans.

    Also, you should close all browser windows and other nonessential items when scanning with Hijack this.

    Further, HJT needs its own folder - Please do the below:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER
    To Extract HJT:
    Now, RightClick your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder (C:\Program Files\HijackThis)and click Next.

    Please run HJT from there and attach that log.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made, the mistakenly deleted entry can be restored.

    Hang in there :) I Imagine BJ or Chaslang will check back when time permits.

    PP
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Damageinc,

    You have an HSA hijack problem. You should have followed the ALL the steps < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    You did not follow all of them. There are no signs of the online scans being run and also had you followed them, you would have already disable the Network Security Service that the hijacker is using to make it difficult to fix your PC.
    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\javaqv.exe

    Please go back to the READ ME FIRST and start again from the section titled Getting Prepared; Steps to be sure your system is ready to be scanned:

    Run ALL steps and pay particularly close attention to running steps that talk about HSA, Only the Best, or about:Blank hijacks. Please note you MUST remember that no browsers (that includes Internet Explorer) should be running when using HijackThis, HSremove, or About:Buster. In fact for HSremove and About:Buster, I have found that physically disconnecting (unplug cables) from the internet can also be helpful.

    If this does not fix up your problems we may need to run the long procedure: When all else fails - Generic Solution to HSA (Only the Best) & about:Blank hijack
     
    Last edited: Dec 20, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds