![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) | |
|
Registered User
Join Date: Jul 2007
Posts: 8
OS: Windows XP
|
Need help cleaning a load of spyware + viruses
Hey guys.
I ran through the steps in the stickies as best I could, but it seems like the longer I try to scan and update, the worse things get, so I'm stopping for now and giving you what I've come up with so far. First of all, the problems. First main, most noticeable problem, is the popups. They'll appear in IE, always, even if I'm using Firefox. This is a sample of one of the URLs it tries to load: http://llehs.com/go/?cmp=vm_mg_ff_h&...7678&lid=&url= I've seen this described as OIN? Or something like that. Anyways, I ran through some of the steps on this site. I downloaded all XP and IE updates. I already had SP2. Now the viruses have a harder time loading their popup sites. It tells me the sites can't be found, but they're still very annoying. They appear at will unless the Internet connection is disabled. And then, it tries to dial out... somewhere. McAfee was able to eliminate several of these dialers and trojans. Some of the scarier ones I saw were CIH?, Smitfraud, PurityScan, and Mirar. Mirar keeps coming back. I'm not sure about the others. McAfee continually blocks generic trojans from being run, so these things are trying to replicate. One of the other scary abilities these viruses have is knowing where I am. I'm currently on vacation in Cincinnati, and the popups knew where I was. Adultfriendfinder showed me girls from Cincinnati. Good Lord, what is the world coming to? Now that I've been fighting them, they're fighting back. Almost all of my reserve HDD space is gone. Heeeeeellllp ![]() EDIT: -_- I was about to edit and say that loading Firefox and Windows Explorer will crash "explorer.exe" but, when I tried, this URL took over the window: http://www7.searchresults.zoomtown.c...WUJ1Qy9gNMoAMy So there's a couple more symptoms for you guys to analyze. X_X Here is the log I got from Panda ActiveScan (This was done BEFORE downloading updates from Microsoft): Quote:
Last edited by Luxamar; 07-18-2007 at 07:36 PM. Reason: Changing code tag to a quote tag; heard the code tagged logs were difficult to read |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,474
OS: N/A
|
Re: Need help cleaning a load of spyware + viruses
1. Download & Save this file to Desktop -> http://download.bleepingcomputer.com...a/ComboFix.exe
2. Double click on combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log & a fresh HJT log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) | ||
|
Registered User
Join Date: Jul 2007
Posts: 8
OS: Windows XP
|
Re: Need help cleaning a load of spyware + viruses
Here's combofix:
Quote:
Quote:
|
||
|
|
|
|
#4 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,474
OS: N/A
|
Re: Need help cleaning a load of spyware + viruses
Do a HijackThis scan (not DSS) & place a check next to these items and select "Fix checked":
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O20 - Winlogon Notify: mallocator - C:\WINDOWS\ Select every O18-Logitech entry O18 - Protocol: bw+0 - {8DCE5638-4DDD-45B7-AAF7-55210392B00D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll --------------- Open notepad and copy/paste the text in the quotebox below into it: Code:
File::
C:\WINDOWS\dcqwn0578.exe
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\system32\csmss.exe
C:\WINDOWS\info147.sys
C:\WINDOWS\pss\TFTP2380Common Startup
C:\WINDOWS\pss\TA_Start.lnkStartup
C:\WINDOWS\pss\VirtuaGirl2.lnkStartup
Folder::
C:\temp\brr
C:\temp\0c2
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mallocator]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TFTP2380]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xarius^Start Menu^Programs^Startup^TA_Start.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xarius^Start Menu^Programs^Startup^VirtuaGirl2.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\829E1F6A]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cryptographic Service]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsasss.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWAS7_0001_N91M2703]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sho]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVX Control Service]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Teso]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tpsudyjA]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wcmdmgr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows System Configuration]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsRegKey update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{ZN}]
![]() Refering to the picture above, drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply. --------------- Please perform an online scan using Internet Explorer at http://www.kaspersky.com/virusscanner Answer Yes, when prompted to install an ActiveX component.
* If you're downloading torrents in the background, please disconnect all of them. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. --------------- In your next post, please include fresh logs from:
__________________
Question - what have you done for the community today? |
|
|
|
|
#5 (permalink) | |||
|
Registered User
Join Date: Jul 2007
Posts: 8
OS: Windows XP
|
Re: Need help cleaning a load of spyware + viruses
Alright, haven't been seeing any more popups, but my HDD space is still MIA, and explorer.exe hangs while trying to load Windows Explorer. Other than that, doing good so far.
ok, here's HJT: Quote:
Quote:
Quote:
|
|||
|
|
|
|
#6 (permalink) | |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,474
OS: N/A
|
Re: Need help cleaning a load of spyware + viruses
TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
Download http://www.techsupportforum.com/sect...etTeaTimer.zip Double click ResetTeaTimer.bat to remove all entries set by TeaTimer. --------------- Open notepad and copy/paste the text in the quotebox below: (don't forget to copy and paste REGEDIT4) Quote:
It should look like this: ![]() Double click on fix.reg & allow it to merge into the registry --------------- C:\QooBox\ is ComboFix's quarantine folder. You can safely delete it CLEAR & RESET SYSTEM RESTORE'S CACHE - (System Volume Information folder) Go to Start → Run → type control sysdm.cpl,,4 & press Enter
How much hdd space did you lose?
__________________
Question - what have you done for the community today? |
|
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jul 2007
Posts: 8
OS: Windows XP
|
Re: Need help cleaning a load of spyware + viruses
I lost ~1.5GB from the time I started working with this site until I reported missing space. Part of that process was downloading and installing a lot of updates from Microsoft (including IE 7). But would that munch up that much space?
|
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Jul 2007
Posts: 8
OS: Windows XP
|
Re: Need help cleaning a load of spyware + viruses
After a restart, things are running pretty smoothly now.
I was wondering... OIN, or whatever that thing was that was causing popups, I heard eats a lot of space? Did it get deleted during all this or just disabled? Let me know if you want any more scan logs. Thanks for the excellent support so far! |
|
|
|
|
#9 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,474
OS: N/A
|
Re: Need help cleaning a load of spyware + viruses
1.5 GB is a lot of disk space. Did not reseting System Restore return much of the space?
Delete the C:\Deckard folder. We dont need it anymore. Let's clear up your temp folders. There's probably a lot of rubbish files in there. Please download ATF Cleaner by Atribune.
Let us know how that went
__________________
Question - what have you done for the community today? Last edited by sUBs; 07-21-2007 at 04:23 AM. |
|
|
|
|
#11 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,474
OS: N/A
|
Re: Need help cleaning a load of spyware + viruses
Now that your system is clean, kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein - http://computercops.biz/postlite7736-.html After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|