still have some malevolant infections

Discussion in 'Malware Help (A Specialist Will Reply)' started by tat2d12000, Jun 25, 2006.

  1. tat2d12000

    tat2d12000 Private First Class

    hi- i'm here again seeking help as i've been thru the 7 step program and i'm still not cured. when i click on my search results, i an sneakily redirected randomly it seems to ebay,zapmeta, or something else besides the info i'm seeking . this sux and is the main reason the missus wants to do a format and recovery. problem is she does it as a cure all and i'm tryin to stop that .please help before she does something to make my pc world disappear. the pertinent logs are attached. if other info is needed i can do that.thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run CounterSpy as requested in the READ ME and also attach the log from CounterSpy. Make sure you allow it to fix what it finds. Looks like you may have a WareOut infection.

    Also please read step 7 of the READ ME again. You must install HijackThis correctly. You have it installed exactly where we specify not to install it. Also, you must not use MSconfig to control startups. Please select Normal Startup, reboot and then attach a new HJT log.
     
    Last edited: Jun 26, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After correct what I said in my previous message run the below procedure:

    WarOut Removal
     
  4. tat2d12000

    tat2d12000 Private First Class

    thanks i'm gonna crash and get back on this in the a.m. i'll be hangin' around again tomorrow evening. i think i fixed my hj files and counterspy's on the d/l, so time for some sleep,thanks and cya....
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Don't forget the issue with MSconfig and attach a new HJT log when finished.

    Also attach the log from fixwareout!
     
  6. tat2d12000

    tat2d12000 Private First Class

    hello again. i have run thru this all a second time and now feel i have myself in somewhat order to get some help. i obviously have some trouble still. logs are attached(all 4). i had problems with counterspy ; it won't let me view results. could only enable or disable dns; that must be good ole millenium i suspect. i left it disabled. i am in normal mode no selective startup. we use it to save resources usually. fully loaded i am only 16% free at this point. see what you can do . i am starting to feel like the poster child for anti- virus/ spyware protection.
     

    Attached Files:

    Last edited: Jun 27, 2006
  7. tat2d12000

    tat2d12000 Private First Class

    o.k. so here's the fixwareout.txt to get you all started. when i started it was pretty bad and now it is getting better, just not quite there yet. holla back at me.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the log from FixWareOut before we can continue. It does look like it worked but I need the log to be sure everything is removed.
     
  9. tat2d12000

    tat2d12000 Private First Class

    i tried to get it in there. look in the post right after the first one. didn't know how to post 4 attachments all in one. sorry
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only 3 attachments can be made in a single message!

    You are in serious need of getting your Windows Updates. You are way out of date. You probably have many WinMe updates that are not installed and you are way behing on your Internet Explorer updates. I will give you a procedure that will take care of this and more when we finish all of your cleaning:

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (some of these may not be found, they may already be deleted)
    C:\WINDOWS\SYSTEM\SBUtils <--- delete the whole folder
    C:\WINDOWS\SYSTEM\howiper.exe
    C:\WINDOWS\SYSTEM\CSODB.EXE
    C:\WINDOWS\SYSTEM\unPPC.exe
    C:\WINDOWS\SYSTEM\k404SearchSetup_MS28.exe
    C:\WINDOWS\SYSTEM\SHAgentNew.dll
    C:\WINDOWS\All Users\Favorites\Stop PopUps On Your Computer.url
    C:\WINDOWS\876029.exe


    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. tat2d12000

    tat2d12000 Private First Class

    o.k thanks . now i feel like i 'm getting somewhere. i thought the missus was keeping up with win updates but...i have tried to go to ie6 but it never would work right .i've also had problems with systems works, registry mechanic, and more. oh well, looks like i gots work to do...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just get those files deleted and attach a new HJT log! Then we will start the updating procedure along with a bunch of other security steps and some educational info too! ;)
     
  13. tat2d12000

    tat2d12000 Private First Class

    o.k.now here's a new log . my speed loading pages is getting faster and my search problem looks like it's gone. see what else you can do . i tremendously appreciate this help.
     

    Attached Files:

  14. tat2d12000

    tat2d12000 Private First Class

    chaslang- i am about to pass out from all this it's 1 am and i gotta get back up at 6am so iguess i'm signin' off for the night. i'll try to keep my missus off this til we get it right but i may have to rerun some stuff if she goes online. i don't have anti-virus installed. i have system works 2003 so i thought if i can get it to install correctly it would work for me. but i need to get rid of all this other junk first. anyway cya tomorrow and thanks again.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to Norton System Works 2003?

    It is too old and can you even get updates for it anymore?
    Also Norton is a known resource hog?
    Also what exactly is included in Norton System Works? Is there each of the below:
    - antivirus
    - antispyware
    - firewall

    I would not recommend using this package. Seems too old and the chance of being a resource hog is an issue. Also if you cannot get updates, it is not that valuable. Malware changes everyday (actually ever few hours).

    Are you planning on keeping AOL's Antispyware stuff running? I'm not sure it is very good and also AOL is a resource hog from what I have experienced. Does it also contain an antivirus?


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  16. tat2d12000

    tat2d12000 Private First Class

    hi again. i'm back for day 3 of getting this pc right. you've convinced me to skip the norton systemsworks. i didn't realize how old it was. i usually only use aol dialer but i am planning on changing to suddenlink(cox) high speed digital cable modem in a couple of weeks. that's why i am trying to get this all straightened out. hopefully i'll go to win xp and get rid of me. me is caca. any way , onward to the next link you shared to do more straightenin' up. wish me luck
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cable is good! ;) You'll love it.

    Be careful with changing to WinXP!

    • First what is the speed & type of your processor also how much RAM do you have.
    • Second do not upgrade to WinXP from WinME. Do a complete new install from scratch.
     
  18. tat2d12000

    tat2d12000 Private First Class

    celeron with 667 mhz 383MB ram. it's HP6736 and about the only thing added at this point was some ram and the cd writer. it was my wife's when we met and i basically am on more than she. i would really like to dig into this and make it speed up, maybe overclock. any suggestions would be considered at this point besides" buy a new one!" we's po' folks!
     
  19. tat2d12000

    tat2d12000 Private First Class

    i was wondering if i need to stay running in normal mode. it sucks up my resources.we usually run msconfig and uncheck everything in start up except the aol dialer. any thoughts on this? is it safe to do this if i leave my anti-virus, spyware tools, and firewall checked in startup. also any way to gain my hard drive space back? i'll check back . i'm still doing d/l's.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In my opinion your PC is too slow and has too little RAM for XP. I would recommend using Win 2K fully updated to SP4 level. It would give you a more updated and secure OS that is still supported by Microsoft and that is a lot more stable then WinMe. You just need to make sure you can get all the required drivers for your hardware (Hardware Forum topic).

    There is an Overclocking Forum if you want to discuss that. I don't believe in it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first you should just look into uninstalling anything you don't ever want to run. That is a better approach then partially disabling with MSconfig. Do you really need all the Toolbars from AOL & Yahoo?

    If you are going to keep AOL antispyware, uninstall CounterSpy.

    You never need the below to run, so just have HijackThis fix it permanently:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

    The rest you have decide whether you need or don't need. Just remember if you disable any of your protection software, you put youself at risk for more infections.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds