Spyware Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Longphi, May 7, 2005.

  1. Longphi

    Longphi Private E-2

    I have done everything the basic spyware removal topic suggested, but when I reboot, it all comes back. However, there hasn't been any incidents involved where something unexpected happens. Everytime I login, though, Avast has found the same viruses and when I run Ad-Aware and SpyBot, the same stuff appears. I'm unsure of what to do next.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run all the steps in the READ ME (and did then in safe mode as requested), follow the steps below.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Longphi

    Longphi Private E-2

    Log.
     
    Last edited: Dec 31, 2005
  4. SortYourLifeMate

    SortYourLifeMate Private E-2

    Same problem as Longphi...

    my scan log file is attached
     
    Last edited by a moderator: May 8, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Longphi,

    Run the steps below.

    First we need to fix a bug in Spybot's default configuration.

    Fixing SpyBot's Ignore Products Bug:
    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    Hopefully this will find an fix the NewDotNet stuff.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side.
    Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\Downloaded Program Files\SAHUninstall_.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr51.dll
    O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\system32\psoft1.exe
    O4 - HKLM\..\Run: [cfgmgr51] RunDLL32.EXE C:\WINDOWS\cfgmgr51.dll,DllRun
    O4 - HKLM\..\Run: [G3] C:\WINDOWS\system32\GSMedia3.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O16 - DPF: {2F5B39C5-C6F5-447A-A946-48B382C53985} - http://www.pacimedia.com/install/pcs_0019.exe
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/09e8d69e844ce5f6f017/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\cfgmgr51.dll
    C:\Program Files\NewDotNet <--- the whole folder
    C:\WINDOWS\system32\psoft1.exe
    C:\WINDOWS\system32\GSMedia3.exe

    Additional step to delete SAHUninstall_.exe:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s SAHUninstall_.exe
    del SAHUninstall_.exe
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try
    again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Longphi

    Longphi Private E-2

    Everything seems to be fine now. No viruses or spyware. During the process of deleting New.Net, I couldn't delete two registry entries. Would this pose as a problem? Anyway, thanks for your help. Oh, and here's the log you requested.
     
    Last edited: Dec 31, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Did you mean you could not have HJT fix those two items because they were no longer there?

    At anyrate your log is clean now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds