Spyware Symptoms?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hellfire500, Mar 28, 2007.

  1. Hellfire500

    Hellfire500 Private E-2

    The other day I was browsing the net when all of a sudden I couldn't access other web pages - a small window would appear stating that the relative website address was not accessible. I then tried to close IE and got the message: Internet Explorer is busy, closing this window may cause problems.
    I scanned my pc with Spyware Doctor (paid version), Spybot & Norton Antivirus - nothing was found (I also use Zone Alarm). I ran a search on xp for all files created during the past 2 days and nothing out of the ordinary was found. There is also nothing additional running in the task manager or msconfig.
    So far it has only occurred once - does this sound like spy/adware to you?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not really!
     
  3. Hellfire500

    Hellfire500 Private E-2

    Well thats a bit of a relief - its just that I did a search on yahoo for that error message (closing IE may cause problems) and came across a few postings in forums where people who had that error were infected with spyware. Can those errors occur by other means?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You could have just had any number of software errors. I would suspect if you had malware that you would still be having problems. Since you say it only happpen once, that is why I did not say to run the READ & RUN ME. ;)
     
  5. Hellfire500

    Hellfire500 Private E-2

    It first occurred last night and has not happened so far today (I have only used my pc for approx 4 hours since)- I'll give it a week and should it reoccur, I'll start running those tests.
    Thx
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But I would still say that if it takes a week to reoccur, it is not malware.
     
  7. Hellfire500

    Hellfire500 Private E-2

    Whilst on Hotmail today IE suddenly froze for about 20 seconds. I didn't receive any messages - just no response when trying to close IE down. I then went to the task manager (there wasn't anything additional listed) and as soon as I did that IE closed.

    Does this sound any more suspicious or more like an Internet Explorer issue (my current install of xp is less than a year old)? The first occurrence was on Yahoo mail, so could this be something trying to obtain passwords etc?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Malware can cause all kinds of strange and unexpected things to happen. However so can non-malware problems. The only real way we can rule out malware is to have you work thru our standard cleaning procedures.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  9. Hellfire500

    Hellfire500 Private E-2

    Ok, I have run all the tests - Spybot, AVG & Bitdefender found nothing, and Panda Activescan just found 1 cookie containing Tribalfusion, which isn't an issue as I have always had this on my pc (Spyware Doctor always deletes it but it makes its way back in). I have attached the Bitdefender, Getrunkey & Shownew logs. I couldn't upload the Activescan log as it was identical to the one I uploaded several months ago.
     

    Attached Files:

  10. Hellfire500

    Hellfire500 Private E-2

    Here are the HijackThis and AVG Logs
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on those logs, you have no malware. I have a couple things for you to do though.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Are your copies of Spyware Doctor 4.0 or AVG Anti-Spyware 7.5 paid versions? Only keep one installed.


    Now have HijackThis fix the below lines which are not needed at startup:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
     
  12. Hellfire500

    Hellfire500 Private E-2

    Thanks for that. I've carried out all changes listed except the last one (O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe")- since updating Java, the final fix now shows as 6.0 instead of 5.0 - do I still go ahead and fix it?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You don't need the jusched.exe process to run all the time. You should get updates manually when they come out. No sense wasting resources all the time.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds