What next??

Discussion in 'Malware Help (A Specialist Will Reply)' started by cnand, Nov 27, 2005.

  1. cnand

    cnand Private E-2

    I have followed all of the instructions on the "Read and Run me first". I still am unable to access many of my "favorites" sites, although some still work. An example of a few of the sites that won't work are...my online banking website, "My E-bay" page and my msn homepage. I am no computer whiz to say the least, but I think I did a pretty thorough job of following the required steps before posting. I am attaching my logs as directed in the Read and Run instructions. Someone please help! THANKS!!!! :confused:
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You need to update your definitions for SpySweeper then run another full sweep. Your definitions should be version "575".
     
  3. cnand

    cnand Private E-2

    When I try to update some of these programs such as SpySweeper, a-squared, etc., my computer will not let me connect to their servers and I get error messages saying to check my internet connection settings...uggh! How do I handle this?
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click the link below to download the update I uploaded for you. When the page loads, click on "FREE" and on the next page, right click and save target as and save this to your desktop.

    Once you have the file "masters.mst" on your desktop, copy this file into the directory "C:program Files\Webroot\SpySweeper\Masters". Just replace the one you have now.

    Afterwards run a full sweep and attach the new log.

    http://rapidshare.de/files/8267679/masters.mst.html
     
  5. cnand

    cnand Private E-2

    Well, it didn't seem to help...let me know what you think. I sure appreciate your assistance! I have been doing this for over 6 hours...
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Found quite a few more items, please follow the below...

    Download this trial version of Ewido Security Suite

    • First, please download and run CCleaner to clean temp files, cookies, etc; to make the log shorter.
    • Install ewido security suite
    • When installing the program, under "Additonal Options" uncheck..
      • Install background guard
      • Install scan via context menu
    • Launch ewido, there should now be an icon on your desktop, double-click it.
    • You will need to update ewido to the latest definition files:
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    If you are having problems with the updater, you can use this link to manually update ewido. Ewido Manual Updates

    • Once the updates are installed, exit Ewido.
    • Now print the below instructions or save them locally because I want you to have all browsers closed and also have no connection to the internet (unplug your cable) while doing the below:
    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report[/size][/color]
    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    • Reboot into normal mode and reconnect to the internet.
    Once your machine reboots please attach the report from Ewido along with a fresh HJT log from normal mode.
     
  7. cnand

    cnand Private E-2

    OK, here goes...
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Click on the link below and run the online scan...

    Kaspersky Anti-Virus Online Scan

    • Click on "Kaspersky Online Scanner"
    • Click Accept to procede...
    • If this popup displays, Install Kaspersky's ActiveX Control
    • If this popup displays, Install the "kavwebscan_unicode.cab"
    • After all updates are downloaded, click NEXT to continue...
    • Click Scan Settings and select extended and make sure both boxes are checked at the bottom, Click OK to continue.
    • Now click on My Computer and let it run!
    • This scan may take a while but it is very thorough. After the scan is complete save the log as a txt file and attach it to your next post.
     
  9. cnand

    cnand Private E-2

    OK, I am going to do that but will have to check in with you tomorrow as I have to be up in 5 hours...I really appreciate your help! :)
     
  10. cnand

    cnand Private E-2

    I finally am back at trying to fix things. I had to completely uninstall my Norton System to run Kasperski and that was quite the adventure also due to this virus. Here is my log from Kasperski...
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Ewido

    Spy Sweeper


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost

    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After you complete the above, reboot and let me know how things are running.
     
  12. cnand

    cnand Private E-2

    I seem to be all fixed now!! My fingers are crossed!
    I APPRECIATE ALL OF YOUR HELP!! :) :) :)
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds