Where to begin?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by spacedustM, Dec 13, 2004.

  1. spacedustM

    spacedustM Private E-2

    I've briefly read through the pined posts how to protect yourself from malware and How to:Spyware, Trojan and virus Removal. My concern is where to begin.

    What steps apply to me in the How to: Spyware, Trojan and Virus removal. I ask this because I'm running a decrept version of windows 98SE and have not been updating when prompted, I have a internet explorer version 6.0 and I'm ready to delete it once I find something I can use to replace it. (firefox or oprea I guess)Also the fact that I am getting about blank hijacking as well as a home search hijacking. I cannot seem to find the tools at the top of my Windows explorer for C:/ on my version of windows. I also have a Virus that the dec 10th 2004 virus definitions from Norton can recognize as a virus but not how to deal with it. The ad-aware software I updated very early yesterday and have run it multiple times yet many of the worms and miners seemed to resist all my limited efforts and knowledge on my attempt to irradicate them. My system is slowing down considerably and my ping time on one of my favorite games is about 3 times normal. Random virus, worm, etc prevention web pages are poping up when I surf and it's quite annoying. I don't want to apply to any of them because thier method of delivery is straight out blackmail in my opnion.

    I hope you see my problem of not knowing where to start and what to do about steps 2 and 3 on the how to:spyware,Trojan, and Virus Removal

    I also was wondering exactly which of the tools in the Downloading tools (4)would be best suited for use on Windows98SE for the destruction and removal of my current problems. If anyone is expert enough a helping hand could be welcome if I'm just not using my ad-aware program properly. I should mention that my Norton is Norton Antivirus 2002 with the most recent definitions and some features like Norton protected recycle bin.

    If I have left out any pertinate information to my problem please let me know.

    I realize that this will likely be a fairly major overhaul of an older system. I am however not in a position to get a newer computer or system and would genuinely like to learn how to fix and prevent these effects on my computer so that I can apply the knoledge to future computers and prevent the unwanted use and abuse of my computer.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME was written for all Windows OS. Just run the all the steps accept one's that say optional or that say they are only for a particular OS that you do not have. For example, in the section titled Getting Prepared; Steps to be sure your system is ready to be scanned: steps 1 & 2 do not apply to you. But steps 3 & 4 do. The in the next section: Scanning And Cleaning Steps: (note steps 1 thru 4 are NOT optional!) all the steps apply up to and including step 4. But again notice at the end of step 4 it tells you not to run HSremove since you have Win98.
     
  3. spacedustM

    spacedustM Private E-2

    Sorry, I missed the two words "top of" in section 3 from reading too quickly and for section 4 I spent too much time looking at the file names and not enough on the paragraph before them. So much for my skim-reading skills.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So run all the steps. Make sure you run the online scanners too (obviously not in safe mode for Win98).

    If still having a problem after that, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  5. spacedustM

    spacedustM Private E-2

    Just finished the fourth download and It will likely will take me some time. I'll likely begin the how to protect yourself from malware once this gets taken care of. I hope that this prosess fixes it but If not I'll carefully read (and likely print like I did the malware and Major attitudes don't not post until post) and do what you just suggested in the bottom 3/4ths of your post.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It's best to wait until we get current problems fix before going on to the How to Protect thread.
     
  7. spacedustM

    spacedustM Private E-2

    Housecall found a trojan in the boot sector and removed it. It might be worthwhile to note when doing that online scan that housecall (Trend micro's free online virus scan) may seem to freeze for about 5-10 minutes while messing with the boot sector. I was beginning to wonder if the program had frozen and post such a question about what to do about it. I had the arrow and an hourglass when my mouse was over the application and scaned stayed at 0 for some time.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So what about the rest of the steps!
     
  9. spacedustM

    spacedustM Private E-2

    It's (Trend micro's) scanning my whole comp apparently it's found 10 non-cleanable trojan files so far and it's only done 65k files so far. I'm hoping that the next step will get them I guess I believe I have about 125k more files on my computer. So I might just leave it running and pick back up tomorrow.
     
  10. spacedustM

    spacedustM Private E-2

    humm thought I'd check it just before I went to bed. It just finished all of the files are in the windows directory the program is unable to clean them, should I use its delete option or hold off for one reason or another?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What filenames and what virus problems were detected?
     
  12. spacedustM

    spacedustM Private E-2

    ALL of the following agents are in Trojans and the c:\windows\ directory

    Troj Agent .aap c:\windows\sdkdj32.exe cannotaccess
    Troj Agent .abq c:\windows\ieme32.exe noncleanable
    Troj Agent .aap c:\windows\istl.exe cannotaccess
    Troj Agent .abq c:\windows\altky.exe noncleanable
    Troj Agent .ae c:\windows\rundll32.exe.$$$ noncleanable
    Troj Agent .ae c:\windows\nsxcv.exe noncleanable
    Troj Agent .aap c:\windows\javaul32.exe cannot access
    Troj Agent .abq c:windows\mfcxd.exe noncleanable
    Troj Agent .aap c:\windows\d3gy32.exe cannotaccess
    Troj Agent .abq c:\windows\crun32.exe noncleanable

    I don't know many key filenames but altky, javaul32, and crun32 sound like ones that may cause problems if deleted.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you have HSA hijacker problems. Have you run About:Buster? If not, shutdown all browsers and disconnect from the internet. Run it once in normal boot mode then immediately reboot into safe mode and run it again. Now reboot in normal mode and follow the steps I gave you in message #4 and post a HJT log (as an attachment).
     
  14. spacedustM

    spacedustM Private E-2

    I have not since I am on step 1 first part should I skip ahead then to step 4 (about:buster) then continue with step 1 part 2? I'll do it w/in 5 minutes if not given a reply
     
  15. spacedustM

    spacedustM Private E-2

    I should re-mention that I was asking if I should use the delet option in the housecall scan. I was unsure if I should just ignore the results and continue or do something to deal with them at that point in the list part 1 first bullet.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I meant in my last message. Use About:Buster now as I indicated. Don't do anything else with HouseCall yet.
     
  17. spacedustM

    spacedustM Private E-2

    I ran the (about:blaster) in normal mode. I then tried to reboot to safe mode and was unable to get to in I tried 3 times and one shutoff/turnon.

    After these attempts I ran blaster again and got this on my first scan. (very similar to the first scan in normal mode.)

    ADS not scanned System(FAT)
    Attempted Clean Of Temp folder.
    Removed Uninstall Key (HSA)
    Removed Uninstall Key (SE)
    Removed Uninstall Key (SW)
    Pages Reset... Done!

    I can reset to MS-Dos mode but, I'm unsure why taping the F8 key will not work for me in my efforts.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now run Hsremove! Then complete anything else you have not done from the READ ME. Afterwards post your HJT log if still having a problem.
     
  19. spacedustM

    spacedustM Private E-2

    Hsremove requires windows xp or windows 2000 :/
     
  20. spacedustM

    spacedustM Private E-2

    I wonder if this will work anyway since I cannot seem to achieve safe mode. Like I've said I can restart to msdos but the f8 key is giving me no joy in trying to reach safe mode.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! Forgot you had Win98.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stop getting side tracked! Complete the procedure and post your HJT log.
     
  23. spacedustM

    spacedustM Private E-2

    I was thinking about the upcoming bullet 3 under step 1 I'll just ignore any do safe mode 1st instructions then
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  25. spacedustM

    spacedustM Private E-2

    I actually managed to get it to work using the f8 method about 3 minutes after I asked, I ran the stinger and about:buster then foolishly restarted my computer thank you for the link. I'm sorry if I was short or didn't read well enough somone really angered me just before my post. (not you) and interupted a previous attempt at posting earlier.

    When attempting ccleaner in normal mode the progess bar kept getting full and restarting. It eventually came up with a windows illegal function window on the process. I also was unable to find the optional delete index.dat checkbox. I'll see if there are any downloads for it but if you know offhand what tab it's supposed to be under please let me know. I'm tempted just to start over from the beginning of step one due to the multiple restarts since that point, can you tell me if that's what I should do or not? It takes ages to scan but, I think it may be worth it to spare you and I more frustration, although those scans take quite some time.

    Once again I appoligize if I've "done your head in"(agrivated) you.
     
  26. spacedustM

    spacedustM Private E-2

    found the index option nevermind about that
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Skip CCleaner for now and don't worry about index.dat also it is normal for the progress bar to do what you describe as it works thru the different areas that it is cleaning. The crash is not normal.

    Let's skip the rest of the READ ME steps for now. Go to message #4 in this thread and get me that HJT log now.
     
  28. spacedustM

    spacedustM Private E-2

    Some of these I recognize but I fear it's alot to go through. my home page is google, Norton is my antivirus service, and I do have a dling utility through fileplanet. I do recognize several that I'd be more than happy to kill however. edit-bet i need to make it a txt :/
     

    Attached Files:

  29. spacedustM

    spacedustM Private E-2

    the txt version >.<
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you require this proxy setting for something:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.2

    You have a load of problems! I'll post things to do in following messages.
     
  31. spacedustM

    spacedustM Private E-2

    I'm unsure I'm hooked upto a local network that is connected to the internet. However this computer has been connected many times to networks connected to the web so I may have some left over settings I need to clear any Idea about the best way to check?

    btw:the computer I'm hooked upto likely has more problems if I learn what to do well enough on this one I might attempt fixing his >.<
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not completely sure where you got to in the READ ME FIRST process since I told you to post a HijackThis log now. So bare with me. We need to fix this in a few stages. Put please do the following:

    First look in Add/Remove Programs for anything like:
    - WINDOWS CONTROLAD
    - CSBB or Clearsearch
    - SURFSIDEKICK
    - FastSeeker or FastSeekerToolbar

    If found, uninstall them.

    Now from the READ ME, make sure you have Ad-Aware SE 1.05 and update it (new refs just came out). The run it and have it fix everything it finds.

    Do the same with SpyBot S&D.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\IETL.EXE
    C:\WINDOWS\JAVAUL32.EXE
    C:\WINDOWS\SYSTEM\SDKDJ32.EXE
    C:\WINDOWS\D3GY32.EXE
    C:\PROGRAM FILES\WINDOWS CONTROLAD\WINCTLAD.EXE
    C:\PROGRAM FILES\CSBB\CSV7P070.EXE
    C:\PROGRAM FILES\AUTOUPDATE\AUTOUPDATE.EXE
    C:\PROGRAM FILES\WINDOWS CONTROLAD\WINCTLADALT.EXE
    C:\PROGRAM FILES\COMMON FILES\TSA\TSM2.EXE
    C:\WINDOWS\SYSTEM\KSUBG.EXE
    C:\PROGRAM FILES\COMMON FILES\TSA\TS2.EXE
    C:\WINDOWS\SYSTEM\WINUPDT.EXE

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\umdgo.dll/sp.html#28129
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\umdgo.dll/sp.html#28129
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\umdgo.dll/sp.html#28129
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: Class - {EFF77B34-BB10-6259-D56C-2FE1758999B5} - C:\WINDOWS\MFCEV.DLL
    O4 - HKLM\..\Run: [Windows ControlAd] C:\PROGRAM FILES\WINDOWS CONTROLAD\WINCTLAD.EXE
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\SYSTEM\winupdtl.exe
    O4 - HKLM\..\Run: [CSV7P70] \Progra~1\CSBB\CSV7P070.EXE
    O4 - HKLM\..\Run: [hfelvjbjdpc] C:\WINDOWS\SYSTEM\cjkwox.exe
    O4 - HKLM\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
    O4 - HKLM\..\Run: [ptfvgc] C:\WINDOWS\SYSTEM\ptfvgc.exe
    O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
    O4 - HKLM\..\Run: [AutoUpdater] "c:\Program Files\AutoUpdate\AutoUpdate.exe"
    O4 - HKLM\..\Run: [pt5P36X] NETRM.EXE
    O4 - HKLM\..\RunServices: [IETL.EXE] C:\WINDOWS\IETL.EXE
    O4 - HKLM\..\RunServices: [JAVAUL32.EXE] C:\WINDOWS\JAVAUL32.EXE
    O4 - HKLM\..\RunServices: [SDKDJ32.EXE] C:\WINDOWS\SYSTEM\SDKDJ32.EXE
    O4 - HKLM\..\RunServices: [D3GY32.EXE] C:\WINDOWS\D3GY32.EXE
    O4 - HKCU\..\Run: [Tsa2] C:\PROGRAM FILES\COMMON FILES\TSA\TSM2.EXE
    O4 - HKCU\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
    O4 - HKCU\..\Run: [YAuFRWbme] KSUBG.EXE
    O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar011203.dll/cmsearch.html
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted Zone: *.msn.com
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.scoobidoo.com
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.static.topconverting.com
    O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://stream10k.redhotnetworks.com/cabs/videox.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=fab19f64c271dfd5b772fcfb344ed4d5f8217f7b03e9b7145eeb15c7b73869070b857bc819ac1ca41787ff055d83fcb743482bfaec:0a002003c3f6d5950937c6314a45eb37
    O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://c:eek:exist.mht!http://crdrcr.com/chm.chm::/a.exe

    Boot into safe mode and use Windows Explorer to delete (if you cannot boot in safe mode try to delet in normal mode. Keep track of what you can and cannot delete or find):
    C:\WINDOWS\MFCEV.DLL
    C:\WINDOWS\umdgo.dll
    C:\WINDOWS\IETL.EXE
    C:\WINDOWS\JAVAUL32.EXE
    C:\WINDOWS\SYSTEM\SDKDJ32.EXE
    C:\WINDOWS\D3GY32.EXE
    C:\PROGRAM FILES\WINDOWS CONTROLAD <--- delete the whole directory
    C:\PROGRAM FILES\CSBB <--- delete the whole directory
    C:\PROGRAM FILES\AUTOUPDATE <--- delete the whole directory
    C:\PROGRAM FILES\COMMON FILES\TSA <--- delete the whole directory
    C:\PROGRAM FILES\SURFSIDEKICK 2 <--- delete the whole directory
    C:\PROGRAM FILES\VBOUNCER <--- delete the whole directory
    C:\Program Files\FastSeeker <--- delete the whole directory
    C:\WINDOWS\SYSTEM\WINUPDT.EXE
    C:\WINDOWS\SYSTEM\winupdtl.exe
    C:\WINDOWS\SYSTEM\cjkwox.exe
    C:\WINDOWS\SYSTEM\ptfvgc.exe
    C:\WINDOWS\SYSTEM\NETRM.EXE
    C:\WINDOWS\SYSTEM\KSUBG.EXE

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  33. spacedustM

    spacedustM Private E-2

    I killed controlad by add/remove
    however my ad-aware se has clunked out 2 times now when trying to quarentene(2nd) or delete(1st) the 385(1st) or 377 of 381(2nd) items checked. I'll attempt to run it once more and let it run for the rest of the night.
    Things don't look to good at this point but, perhaps tomorrow will bring more luck. going to attempt it in safe mode
     
  34. spacedustM

    spacedustM Private E-2

    I've been working hard. So much for sleep and such. I had too dificult of a time trying to get ad-aware and splyblast to work in safe mode (no mouse ps2 thing and the shading is horrible + enter wont start them) I managed to get ccleaner to work in there so i did it 2x deleted what I could w/o a mouse (the controlad dir and fastseeker dir could not locate other dirs) checked the processes to end somewhere in here and sometimes in the midst of all this as compared and removing things from highjack I'm having trouble remembering exactly when;

    Then restarted to normal then did ccleaner 3x, did advertblaster, did ccleaner again 2x :p, then ad-aware se(nothing noted, perhaps I did it twice remember 4 objects taken care of sometime) then search ad destroy, then imunize then CWShredder then kill2me, then about:buster (ignored HSRemove due to win version) then deleted (Ksubg.exe from win/sys, only one I found from the list left) ran hijackthis with as much as I could think to turn off at 540am rechecked list only found the trusted *frame crazywinnings one told it to fix it with everything I could think of off reran it it poped up again in my list. I'm attaching my hijacktxt now.

    Please tell me what I should do next, and how I can make SURE that these things don't return to plague me.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that's a lot cleaner now, isn't it?

    I would still like to know what this line is about:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.2

    Do you need that setting for some reason?

    For CrazyWinnings, simply fixing with HJT will not work. Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file move.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.

    Now run HJT and fix the O1 - Hosts lines and the O15 - Trusted Zone: http://*.frame.crazywinnings.com line if still there. Then reboot your computer and get a new HJT log to post here.
     
  36. spacedustM

    spacedustM Private E-2

    I happened to wake up a couple minutes ago and caught your post, I don't trust my faculties enough yet to try those or that step. Once again any suggestions on testing that IP in a way that is safe? Also I would really like to be sure system restore will not undo all my work by reseting, any way to doublecheck? sorry if not making sense and take your time in replying if you need. (spacedustM mumbles incoherently and stumbles back to his bed)
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are hooked up to your own network (do you have a router? I assume so.), the IP address is probably within your local network's range defind by your router. Do the following:
    - click Start, Run, and enter ipconfig /all > c:\ipinfo.txt

    This will create a file in your root directory of drive C named ipinfo.txt that has info about your IP configuration. Upload it back here.

    As far as System Restore, I assume it is still off.
     
  38. spacedustM

    spacedustM Private E-2

    Well here is how my fighting with this comp is going,
    I copied and pasted ipconfig /all > c:\ipinfo.txt into a start, run box and a msdos window briefly shows up (too quick for me to tell what it's doing) I've looked in the c:\ directory and done a find but it cannot find a ipinfo.txt anywhere

    As for the merge I coppied to my notpad saved as move.reg then proceeded to double click on it's location. It ask id I want to ADD it I said yes and it gave me window box Cannot Import C:\mydocu~1\move.reg: The specified file is not a registry script You can import only registry files.

    Yes I did do all files, and typed move.reg into the upper box.

    I also had a brown out before I did this so I cleaned and checked and couldn't access the internet so I reset wondering if I mangled my ability to connect before I remembered the router needed to be unplugged for about a minute then repluged to regain access to the net. The cleaning didn't come up with much. I'm about to try both again (crosses fingers)
     
  39. spacedustM

    spacedustM Private E-2

    No luck I checked the properties of my move.reg and it said it was Registration Entries
    and an arcive file the ending was a .reg
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn! You have Win98. Forgot about that. Use this version, to overwrite the old one. Or just edit the first line to say REGEDIT4 instead of Windows Registry Editor Version 5.00



    Double-click on the move.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
    [/QUOTE]
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This should have worked

    ipconfig /all > c:\ipinfo.txt

    Try it from a command prompt. Are you sure it is not there? By any chance do you have a Hide extensions for known file types checked in Windows Explorer, Tools, Folder Options, View.
     
  42. spacedustM

    spacedustM Private E-2

    Running it from msdos prompt worked it created a file visable in dos prompt and through the browse option to attach files. Here is that file Still unsure about that reg file, this is what I copied and pasted to my notepad humm the info from you post looks different somehow I think the opening line has changed going to recopy and paste, it worked this time.
     

    Attached Files:

  43. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So is CrazyWinnings gone. Check your HJT log.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the output from ipconfig, your network is not using 192.168.0.2. Have HJT fix this line:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.2

    Let me know how things are working.
     
  45. spacedustM

    spacedustM Private E-2

    Crazy is gone, your new post came in while I was doing it, I'll go back to kill that line. I expect I'll be taking the next while after this working on the making your computer safe and secure section of the sticky (I don't expect anywhere near the amout of difficulties I had previously) Thank you once again.

    I do have one remaining question about spywareblaster, does it conflict with nortons auto-protect and should I fire it up anytime I'm doing activities online. I'd ask about a firewall as well but I'm vitually positive I saw the info in a sticky that I glanced over and will end up sitting down to most carefully read and follow.

    edit (that line killed)
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know of any conflicts between spywareblaster and nortons auto-protect.

    I don't know what you mean by this "should I fire it up anytime I'm doing activities online".
    Are you referring to SpywareBlaster? Once installed, you just enable the protections. That's it. You will not see any processes running because there aren't any.

    You should look at: How to Protect yourself from malware!
     
  47. spacedustM

    spacedustM Private E-2

    I have already done most of the steps in the malware thread however I wanted to ask about this one:
    7) Adjust Active X security settings
    - In Internet Explorer, click Tools/Internet Options/Security. Click on the Internet globe. Then select 'Default Level', then click OK. Now select 'Custom Level' and scroll down to the ActiveX controls and plug-ins section:
    - Set 'Download signed Active X controls' to Prompt
    - Set 'Download unsigned Active X controls' to Disable
    - Set 'Initialize and Script ActiveX controls not marked as safe' to Disable
    Click OK and OK again.

    It was already set like that in my internet explorer, however I've downloaded firefox and was wondering if it has a similar feature I need to find and enable should I begin to use it as my default browser. (firefox is set as default atm)

    Btw:I did the windows updates one of them (something)-wdt required linking out or somesuch I was unsure of it so I put it off for later. I removed the microsoft java and installed the sun java (java web start) and got and installed zonealert
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FireFox does not use Active X.

    You'll need to be more specific than (something)-wdt
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds