Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Halbibabe, Jan 23, 2006.

  1. Halbibabe

    Halbibabe Private E-2

    I was running my weekly scans to make sure that my laptop was free of all the ware out there. I ran avg,spysweeper,spybot,ad-aware SE,ewido,Panda,bitdefender,A2, smartfix,and everything was clean except Panda. It came up with "Cookies\owner@2o7[2].txt"I did a google search and it said that this has to do with popups.I went ahead and deleted this file.
    Does anyone know much about this spyware,and was deleting the file good enough.Panda activescan submitted.
     
    Last edited: May 14, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's just a cookie which is no big deal. I'm surprised that Panda still found it after you ran Ewido. Or did you run Ewido after running Panda.
     
  3. Halbibabe

    Halbibabe Private E-2

    Yes I already ran ewido first, the online scans were last.Thanks for looking at the scan.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You should look at your Ewido log if you have it because I'm sure I have seen Ewido remove this cookie during scans. The log from Ewido normally would have a line similar to below:

    C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
     
  5. Halbibabe

    Halbibabe Private E-2

    When I ran Ewido it came back wth no infected objects//I'm not sure why Panda found the cookie and ewido didn't. Thanks again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Is your version of Ewido current and does it have the current reference list?
     
  7. Halbibabe

    Halbibabe Private E-2

    Yes ewido is up to date, I just checked again and it came back that I was updated.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Strange! That line I gave in message # 4 was right out of a real Ewido log which showed that it found this cookie and removed it.
     
  9. Halbibabe

    Halbibabe Private E-2

    I don't know what to say.I ran another scan with spysweeper and it found the trojan MSblast.I don't go on any bad sites and yet things are showing up:eek: I ran an ewido scan,spybot,ad-aware SE,and they came up clean.I really like the spysweeper program.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spy Sweeper is at the top of our list of programs to use but you must pay for it to keep it updated. This is recommended. Don't drive yourself crazy with miscellaneous components of malware being found. There are probably 20 to 30 different valids tools you can run and each will more than likely pickup items not found by the others. In many cases, items that are being found can just be stray benign registry keys or some files that relate to the malware but are actually not really a problem since they are not the ones that cause the malware to become active or allow it to spread.
     
  11. Halbibabe

    Halbibabe Private E-2

    Your right,I purchased spysweeper a few months back and have it set for auto update.I did a google search on the trojan MSblast and found out that even with the windows patch it can still slip past and infect your system.All my updates are good so it must of been a freak thing.
    Thanks for your time.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Surf safely!
     
  13. Halbibabe

    Halbibabe Private E-2

    Chaslang,

    Can you look at my hyjackthis log, I have things in there I don't remember seeing in the past, mostly the 017 area. I keep getting pesky little trojans when I get on the internet. I know a lot of the 017's could be for domain I've just never noticed them before. Thanks
     
    Last edited: May 14, 2008
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are due to a Wareout infection! Follow the steps below.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3E6E6310-FACE-4AA8-96E3-A4ECE40F6D5E}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{89774BE4-D37E-49AF-8042-5FE607DBED65}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{975B6B0C-30AC-4A42-B7CA-444E5A5D9048}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CACE4C17-FB25-4A5F-8C1E-6A9A84C37CFF}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CC038B97-C0E0-4F98-AD6A-363B8BF5AD36}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D9017B64-E093-4BD5-B700-A95D1EFA9923}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DA9FC384-05D9-47EA-AFB5-D6A4847560B6}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DAE0B26D-39EE-4FD9-8D1F-0FF2F9348B3D}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DE3D5E22-4671-442F-8D0C-EE0DD81CD406}: NameServer = 85.255.116.101,85.255.112.168
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F7B4FC76-0249-43BF-AB67-9017E7E5327C}: NameServer = 85.255.116.101,85.255.112.168

    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  15. Halbibabe

    Halbibabe Private E-2

    Hi Chaslang

    There was no UnSpyPC in Add/Remove programs.Also found no files UnSpy PC with windows explorer in safe mode.Thanks again.
     
    Last edited: May 14, 2008
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your clean now. Is everything working OK!

    If so, make sure you have completed the steps in the below:

    How to Protect yourself from malware!
     
  17. Halbibabe

    Halbibabe Private E-2

    Yes, everything is fine, I wasn't having any problems that I noticed. I noticed that I didn't update ewido the last scan that I did,so I updated and ran a scan and ewido found 22 infected objects. I thought wow this is crazy and thats when I ran a hyjackthis scan and found all those weird 017's, and fiqured this had to be my problem with all the strange stuff that keeps showing up on the scans.
    Anyway thanks a lot I have learned a lot of things off this forum,you guys are by far the best. Thanks again Chaslang.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds