Member Panel


Sponsors and Ads

Live Tag Cloud

Spyware / AdWare - Tons of malware posted in the Security & Safety forums; Hello, I'm trying to clean up my sister's computer and just realized how much spyware and adware there is on her computer. Before you tell me this, the computer has ...

JOIN US NOW to remove these Ads

pc help forum number one in the search engines
Post New Thread  Reply
  #1  
Old 10-22-2005
bmsfn1's Avatar
New Poster
 
Join Date: Oct 2005
Posts: 1
bmsfn1 - See this Members User comments on their Profile page
Default Tons of malware

Hello, I'm trying to clean up my sister's computer and just realized how much spyware and adware there is on her computer.


Before you tell me this, the computer has TONS of spy/ad/malware.
Attached Files
File Type: txt log.txt (17.4 KB, 3 views)



Last edited by Hengis; 10-22-2005 at 02:03 PM.
  #2  
Old 10-22-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Welcome to PCHF , bmsfn1.



Before using HijackThis Please Do the Following:


Please download Ccleaner

uninstall Logitech Desktop Messenger in "add and remove programs" and then please disable Spybot's TeaTimer to make sure it doesn't interfere with the fixing process.

Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.

Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Download Ewido Security Suite

  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.

Now boot in safe mode (hit f8 when booting up)

Click Start>Run and type in: services.msc
Click OK
In the Services window find:

hkigeat

Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past:

hkigeat

Click OK.

and then fix these with hjt:

O4 - HKLM\..\Run: [0FrP32V] strmtpdr.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\system32\wintask.exe
O4 - HKLM\..\Run: [guarnset] C:\WINDOWS\system32\guarnset.exe
O4 - HKLM\..\Run: [VEL_] c:\windows\mrjj.exe
O4 - HKLM\..\Run: [noC=] C:\windows\mrjj.exe
O4 - HKLM\..\Run: [F ma] C:\windows\mrjj.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
ALL 018 "Logitech Desktop" entry's
O18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: hkigeat - Unknown owner - C:\WINDOWS\system32\hkigeat.exe (file missing)
O16 - DPF: {47CD99DF-8BCF-4B9B-94EF-02E51B2F79DA} - http://www.alwaysupdatednews.com/install/aun_0032.exe
O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0006.exe
Delete the files in bold and then run ccleaner.




Dont fix these yet but do you reqognize them?

OrgName: Level 3 Communications Inc.
OrgID: LVLT
Address: 1025 Eldorado Blvd.
City: Broomfield

O17 - HKLM\System\CCS\Services\Tcpip\..\{3E7D563B-541B-4B81-9CE3-7519AD1CA306}: NameServer = 4.2.2.0,4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{434A8B4B-8BCC-457D-BB84-15A04090624C}: NameServer = 4.2.2.0,4.2.2.1

And can you upload this file to the site below to check it out:

O20 - Winlogon Notify: UNIMODEM - C:\WINDOWS\system32\s4pule791h.dll

http://virusscan.jotti.org/

Now please post a new hjt log plus the Ewido log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[FIXED] Library of Spyware and Adware on my PC Tigereye1786 [Fixed] Hijackthis! Logs 61 11-12-2005 06:20 PM
Malware turns PSP into expensive brick. joe5 Security Watch 0 10-17-2005 04:47 AM
[FIXED] Yet more malware.... Anyone have time to help delete it? conversee [Fixed] Hijackthis! Logs 26 09-26-2005 12:35 AM
[FIXED] Problems with Safe Mode, System Restore, and malware marielle [Fixed] Hijackthis! Logs 11 09-20-2005 01:20 AM
Spyware and Adware and Malware, Oh My! Spaceman3750 Security Tutorials 1 09-17-2005 04:47 AM


All times are GMT +1. The time now is 02:42 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top