trojan adlick

Discussion in 'Malware Help (A Specialist Will Reply)' started by gr8nu2000, Jan 8, 2006.

  1. gr8nu2000

    gr8nu2000 Private E-2

    Went trough your steps,but panda wouldnt let me open the window all the way, could only see half of it but here's the log from bit defender. I hope im doing this right.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Work thru step 7 of the READ ME and attach the HJT log too.

    Also please make sure you empty the Norton AV Quarantine. You have a bunch of stuff saved there that should be deleted.
    Also empty your Recycle Bin and if you use Norton Nprotect to protect the Recycle Bin, empty the NProtect stuff too. The below link explains how to empty NProtect

    Emptying the Norton Protected Recycle Bin


    The above three items made your BitDefender log very large.
     
    Last edited: Jan 8, 2006
  3. gr8nu2000

    gr8nu2000 Private E-2

    ok heres the log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HJT per the directions in step 7. You must not run it from the Desktop, a temp folder, or and sub folder of Documents and Settings, or directly from the ZIP file which you are doing. This is covered in the instructions.

    Did you empty all those folders I requested?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove programs and uninstall Spyware Cleaner if found. It is a rogue non-useful tool.
    After getting HJT installed properly (see my previous message) continue with the below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [F2.tmp] C:\DOCUME~1\bryan\LOCALS~1\Temp\F2.tmp.exe
    O4 - HKLM\..\Run: [F3.tmp] C:\DOCUME~1\bryan\LOCALS~1\Temp\F3.tmp.exe
    O4 - HKLM\..\Run: [F2.tmp.exe] C:\DOCUME~1\bryan\LOCALS~1\Temp\F2.tmp.exe
    O4 - HKLM\..\Run: [F3.tmp.exe] C:\DOCUME~1\bryan\LOCALS~1\Temp\F3.tmp.exe
    O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - Trusted Zone: http://service1.symantec.com
    O15 - Trusted Zone: http://www.wifelovers.com

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\Documents and Settings\bryan\Local Settings\Temp <--- delete all files in the Temp folder that it lets you delete. You may need to skip some.
    C:\Program Files\Spyware Cleaner <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try
    again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go
    back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files
    and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel),
    Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like
    www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds