Spyware won't go away after following your instructions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bper, Nov 5, 2004.

  1. bper

    bper Corporal

    Hi all,

    I'd like to send a Hijackthis log file because although system restore is turned off, online scans turn up nothing in safe mode or normal mode, spyware returns on reboot after they have been cleaned with spybot s&d 1.3 and adaware se.

    cashback comes back, dso-exploit comes back everytime. Running adaware and spybot reports to have cleaned them but they return everytime I reboot.

    Can I send the log file? Should I send it from normal mode or safe mode? Show all files has been turned on by the way, and this is Win XP Home.

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For the DSO Exploit problem with Spybot, get this: Spybot - Search and Destroy DSO Exploit Fix

    Did you run all the steps in the Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If so, and you still have a problem, follow the guidelines below.

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. bper

    bper Corporal

    Hi,

    Thanks for your reply. I have followed the steps in sticky thread. I still have the problem. BTW, I don't know if it's related, but windows update also is not working. It just hangs when I attempt to access windows update.

    Here is my log...


    Edit by chaslang: Inline log changed to an attachment
     

    Attached Files:

    • hjt.txt
      File size:
      10.4 KB
      Views:
      1
    Last edited by a moderator: Nov 5, 2004
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post inline logs. Post them as requested, as an attachment to your message.
    I will change it for you this time. But the typical process (unless we are not busy) is to delete inline logs.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Nov 5, 2004
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to fix a broken LSP chain.

    Download LSP-Fix from here first: http://www.majorgeeks.com/download4180.html
    And run it. Check the "I know what I am doing" box Click on problem dll on the left window (in your case that dll is osmim.dll) and click on the arrow pointing to the right. Click Finish and follow the prompts.

    Now post a new HJT log attachment.

    Questions:
    1) Is this next line something you install and know about:
    O4 - HKLM\..\Run: [Create A Monster] "C:\Program Files\Kudd.com\createAMonster.exe" -run

    2) Do you know what this IEMenuExtension Toolbar is:
    O3 - Toolbar: IEMenuExtension toolbar - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - C:\Program Files\IEMenuExtension\tbextn.dll
    O4 - HKLM\..\Run: [IE Menu Extension toolbar] rundll32.exe "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB
     
  7. bper

    bper Corporal

    Hi,

    Thanks for responding. Regarding the inline log, my apologies - a case of the 'clicker' being faster than the brain. I realized my error after right after I submitted the post. Thanks for your patience.

    I ran Giant, and it apparently worked. After reboot, scans showed no signs of spyware. I have 'attached' the Giant log as well as the HJT log to this message.

    I will follow the broken LSP chain suggestion and let you know. The only odd thing is that after running Giant, I lost my ability to connect to the internet. I have to investigate this. I'm sending this to you from another computer.

    Thanks again.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably lost the ability to connect due to the O10 line I wanted you to repair with LSP-Fix.

    Fix it and see what happens.

    You did not answer my questions.
     
  9. bper

    bper Corporal

    Sorry, missed your questions. No, I don't know about those things. Don't recognize them. Based on the HJT 'Read me first', I guess those should be fixed by HJT?

    Regarding the LSP-Fix, your instructions stated that the problem dll (osmim.dll) would be in the left pane. When I run LSP-Fix, osmim.dll is in the right pane ( the Remove section). Therefore, I didn't proceed. What should I do?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Run LSP-Fix again and with it in the remove pane, click finish or remove.

    For the other items:

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them (if found):
    createAMonster.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: IEMenuExtension toolbar - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - C:\Program Files\IEMenuExtension\tbextn.dll
    O4 - HKLM\..\Run: [Create A Monster] "C:\Program Files\Kudd.com\createAMonster.exe" -run
    O4 - HKLM\..\Run: [IE Menu Extension toolbar] rundll32.exe "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\IEMenuExtension\tbextn.dll
    C:\Program Files\Kudd.com <--- the whole directory

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. bper

    bper Corporal

    Great, I ran the LSP-Fix, was then able to access the Internet, then learned how to fix my windows update problem.

    It just occurred to me that a family member might know what the 03 and/or 04 HJT items are so after asking them, I will proceed with your HJT suggestions and send you a log. Either way, I'll let you know.

    Thanks a lot. Needless to say, you were very helpful. I suppose that I can uninstall Giant at anytime should I not choose to go past the 15 day trial?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Ask other family members before removing items that you may need. Be careful, sometimes things people say they need are actually malware programs. They just don't know it until it is explained to them.

    Yes, you can remove Giant at anytime.
     
  13. bper

    bper Corporal

    OK, fixed 03 & 04s, and deleted the file as you suggested. The Kudd directory didn't exist. All seems to be running well. And, as you requested, attached is the final log.

    If you don't mind, I have an old 98 machine, PIII 450 with 128M RAM that checks out fine as far as viruses, spyware/malware/adware is concerned. However whenever starting AdAware-SE, Opera browser, or making an Internet connection to download updates, system freezes momentarily before continuing.
    Any ideas? If it's not too much trouble.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log looks good now. For your Win98 system it would be better to start a new thread to avoid confusion with other info in the current thread that only relates to you XP SP2 system. As usual, make sure all steps from the READ ME FIRST are run before posting, and when you do post explain "momentary" and what makes you think it is not normal computer delay.
     
  15. bper

    bper Corporal

    OK if need be, I'll start a new thread.

    Again, thanks a lot for being such a great help in resolving this problem.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds