CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 934
Comments: 25
block bottom
spacer spacer

malware, or just plain stupidity?

 
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Sun May 18, 2008 10:53 pm    Post subject: malware, or just plain stupidity?
Reply with quote

Hello,

The stupid part is, I had my husband uninstall a bunch of "programs" that were identified by Revo Uninstaller as what looked like registry keys, thinking at the time that they were associated with widgets (don't ask). Hindsight quickly told me I may have made a really big mistake.

Add to this a lot of recently-installed programs some of which were themes, etc.

Plus a history of connectivity problems (which are hopefully resolved at this point).

And one last thing - our default browser is Firefox so we don't really monitor the IE homepage, but we noticed it was set at google-s/alltalkmedia or something like that. Does that sound right to anybody?

Yesterday, we went through the malware removal program you've outlined, and had negligible results (we regularly run AntiVir and until recently, Counterspy). We also made preliminary and post HijackThis scans.

This morning, we decided to restore to a time previous to the uninstall of the registry-looking "programs" (were these maybe hotfixes?), but we are unable to restore to any previous points.

So, are we looking at problems that may have been caused by uninstalling things that shouldn't've been touched? Or, are we looking at maybe a rootkit that is slipping by undetected though normal means?

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5741

MIRT Premium

PostPosted: Mon May 19, 2008 12:07 am    Post subject:
Reply with quote

Do you think your PC may be infected with malware? If so, other than the different homepage in IE, has anything else happend which makes you suspect malware?

Have a look in Add/Remove programs (XP) or Programs and Features (Vista) to check for any programs that you don't want installed or no longer use and un-install them.

Just incase you did un-install any hotfixes visit Windows Update and see if there is anything to install.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Mon May 19, 2008 8:25 pm    Post subject:
Reply with quote

No, nothing much has happened except some erratic behavior. I use a laptop exactly the same at work, and it has been fine. With today's rootkits, I don't know what kind of unusual behavior might be reason to be suspicious. I personally have never seen XP fail to complete a system restore, so for me that's a big red flag. Between that and the strange google homepage setting, I just have to wonder.

I always figure better safe than sorry, so I ran scans and have looked for problems myself. Not finding any, I ask people who know more than me!

We did go to Updates, and SP3 (!) was the only thing available. I chose to delay that until I feel the system is healthy.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5741

MIRT Premium

PostPosted: Mon May 19, 2008 10:49 pm    Post subject:
Reply with quote

If you post a HJT log in CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html someone will help you.

Before posting the log, try changing the IE homepage to something else, rebooting and see if it has been changed again.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer