Unknown Spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by mmcalind, Aug 6, 2005.

  1. mmcalind

    mmcalind Private E-2

    I have copied and completed the 4 steps in the 'How to' removal (35407), the HSA (38772) removal and the HJT tutorial (38752). I deleted a few lines I didn't recognize in HijackThis but nothing seems to help.

    A McAfee update popup appears 3 times on boot, and either the viruscan or firewall is disabled. Outgoing messages are no longer being checked for viruses.

    Quicken files are missing back to 2004 and now the program opens to a new setup screen. I tried to restore from the backup CD but there is a file missing. Other data (NAIC Prospector) also reverted to 2004 data and restore said successful, but the files were dated 2004 and had been updated in July.

    I had a difficult time using the XP backup of files and settings on 7/30 and have not tried to restore these from the CD as the problems had already begun.

    The Word cursor has changed to a much larger bold I beam.

    Please help me, I teach computer classes to the disabled and my system is sick!! Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HSA hijackers can be pretty nasty and destructive.

    Please follow the steps below exactly:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. mmcalind

    mmcalind Private E-2


    Thanks Chaslang. I'm not sure that this is good, but it's the only place I could find an attachment link. Thanks for the help, Mary
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never ran step 1 of the clean up procedure in the READ ME FIRST. Is there a reason why?

    However, I see no signs of an HSA hijacker. However Spybot's Teatimer and SpySweeper could be blocking some items from showing. Do they ever complain about anything?

    If you really believe something is wrong with your antivirus and or firewall, you may want to consider uninstall all of your McAfee stuff (there is a load of it) and then reboot. Then reinstall.
     
    Last edited: Aug 8, 2005
  5. mmcalind

    mmcalind Private E-2

    Hi Chaslang, the first step was to disable System Restore, I did do this, and don't remember enabling it since I don't want to restore to a problem. I will remove and reinstall the McAfee products. I will also run SpySweeper again, and remove Tea Timer for the options list if I can. Should I repost afterwards? Thanks.
     
  6. mmcalind

    mmcalind Private E-2

    Chaslang, Spy Sweeper found nothing, Spybot had two finds of 'Windows Security Center antivirus disability notify' that I deleted. This has appeared and been deleted before. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Disable System Restore is step 1 of the Getting Prepared section. Step 1 of the Cleaning process is:

    1: Virus And Trojan Scanning (do not skip these two scans or you will be asked to run them before continuing)
    a) Win9x (Windows 95, 98, 98SE) users boot normal mode.
    • do an online scan at Bitdefender <-- agree to the license and then select Scan
    • do an online scan at RavAntivirus <-- select Auto Clean then click Scan My PC
    • now boot in safe mode (and remain there) and run McAfee AVERT Stinger. See how to boot in safe mode below.
    b) And Windows XP, 2000, NT, ME, users boot in "safe mode with networking support" (and remain in there). See how to boot in safe mode below.
    • do an online scan at Bitdefender <-- agree to the license and then select Scan
    • do an online scan at RavAntivirus <-- select Auto Clean then click Scan My PC
    • run McAfee AVERT Stinger
    That is what you did not do. You need to make sure you complete steps 1 thru 4 of the cleaning phase too.
     
  8. mmcalind

    mmcalind Private E-2

    Chaslang, system restore was disabled when I checked, I do not have the files listed in step 2, hidden files and folders and extensions was enabled, and I re-downloaded and updated all the tools. I booted to safe mode and scanned with Bitdefender (no problems) and RavAntivirus (0 infected), then ran McAfee Stinger (205309 clean files).

    Still in safe mode, I cleaned the hard drive with ccleaner according to the instructions, ran AdAware SE and Spybot (without TeaTimer). Spybot found 2 examples of 'Windows Security Center antivirusdisabilitynotify' which it removed (again). HSRemove always deletes 8 items when I run it.Then I ran all the others with no findings.

    I also re-ran HijackThis from Programs and saved the log. I ran all the other tools on the list. a-squared found nothing, Avast found 'Micorsoft SQL server\MSSQL $Microsoft FTBCM/Data/Master Ldf and MDF', and Windows\System 32\catroot2\edb log and tmp.edb.

    I couldn't run ADS Spy as I had an error message that it needed NTFS. I believe I am running Sun Java as I have followed the instructions in step 5. Let me know if you want the HiajckThis log.

    Thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes post a new HJT log now.
     
  10. mmcalind

    mmcalind Private E-2

    Chaslang, are PMs Personal Messages? Am I supposed to be posting to the Software Forum? I have attached the log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log is clean! What problems are you having? If they are not malware issues then yes you should post them in the Software Forum.

    PM = Private Message
     
  12. mmcalind

    mmcalind Private E-2

    I am glad that the log is clean, but that does not explain why my Quicken files since November 2004 have disappeared, as did recent Excel files. There may be others I haven't discovered. It's like the firewall or something else has set a date block. I have manually uninstalled and reinstalled the McAfee Firewall and Virusscan, I think I'll call Quicken to see what they say. May I enable restore again and then restore my last backup of files and settings? Thanks for the help.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not know what happened to your files either. Perhaps a virus you had caused your virus program to delete files. I tend to doubt it though. They do not normally attack data files but who know!

    Yes you can enable system restore now.

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds