spyware/trojan removal help needed.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by noviceseeking.lol, May 28, 2006.

  1. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi i have followed the procedures that you require b4 posting for help.
    (i hope i followed them correctly as i am a bit dumb on pc's)
    i have attached the scan logs but they basically said!

    bit defender detected nothing,
    panda detected (but didnt remove) atlas and double click.
    spybot removed double click(but it came back obviously cuz panda detected it again) even though system restore was turned off.
    ad aware keeps removing various cookies etc so i presume something is filling my pc with junk.

    i have also attached a hijack this log.

    i also ran ewido 3.5 (free trial) nothing detected.

    plus the other scans you require ccleaner cwshredder and kill2me windows defender .

    i am still having problems so assistance would be greatly appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per step 7 of the READ ME, we require HijackThis logs from normal boot mode not safe mode. However at this point, it probably will not matter. Your logs show no signs of malware.

    Are you actually having any malware problems? This does not mean cookies. Cookies are not problems! See step 11 of

    How to Protect yourself from malware!

    For more information about cookies. You will always have cookies anytime you do any surfing. The are typically very useful to you.
     
  3. noviceseeking.lol

    noviceseeking.lol Private E-2

    hi yes i am having problems!

    my internet connection is very slow (is supoosed to be 10mb broadband and is less than 1) i am getting all kinds of ads popping up (despite having a pop up blocker) and everytime i run adaware or spybot i am having to remove stuff (ie.double click on spybot) which constanly seems to be on my system even though i have removed it with system restore turned off!

    and i only started getting these problems a few days ago until then i was fine!

    sorry about the mistake with the hijack this log but is it possible that being in safe mode has somehow masked any problem?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in my previous message! Cookies are not problems. Please read the link that I gave to you.

    It is possible. The only way to know is to see a log from normal boot mode but before doing that please do the below.

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now download and run the below to disable Windows Messenger:

    Disable/Remove Windows Messenger


    How long ago did you install this C:\Program Files\blueyonder\PCguard
    I assume this was provided by your ISP?
    Does it contain an antivirus application?

    I see Authentium's Command Antivirus installed too. Is it part of the above? I doubt it. If it is not part of PCguard then per step 3 of the READ ME, you should not be runnin multiple antivirus applications.

    Is your copy of Ewido a paid or free trial version? If free, uninstall it now!

    Now attach a new HJT log from normal boot mode and let me know if any of the above has changed any of your problems.
     
  5. noviceseeking.lol

    noviceseeking.lol Private E-2

    1) yes i am aware that cookies are not spyware/malware .

    2)yes pc guard is provided by my isp and contains an anti virus product a firewall and an anti spyware product i installed it after my problems began (was using norton internet security 2005 but it was due to expire in 3 weeks anyway and as i was infected i decided to replace it) but i have never heard of authentiums command anti virus so if it isnt part of telewests pc guard i dont know what it is or how it got on my pc!

    3) the ewido i used was a free trial version and i uninstalled it immediately following using it to scan my pc!

    4)since speaking to you last (time zone differences i am in uk) my son has been running different applications from the geeks recommended section and after running remove it pro the situation has improved alot!
    unfortunately as i was in work and he didnt write it down he cant remember what it was he removed exactly but it was remove it pro that removed it!

    5)my system seems to be acting in its normal way now but i have attached a hijack this log and would be grateful if you could look it over as i am still stumped as to what exactly it was on my pc! and i have been able to run housecall online (which wouldnt load b4) and that said all clear!

    6)i know speed isnt always a good indicator of either problems or no problems but my internet speed tests indicate that i am at 10mb+ which is what i would expect it to be normally!

    7) i know i have gained a yahoo toolbar this was loaded in error by my son running 1 of the scanners but i am unconcerned about it so long as it causes no harm??

    thanks for your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below lines are from Authentium's Command AV:

    C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe

    Let's see if it is installed! Get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Too bad you don't have a log of what it removed. However, I do not recommend using this tool. It can be dangerous right now since it has problems with false positives and is now listed on the rogue tool list. See: Rogue/Suspect Anti-Spyware Products & Web Sites

    You can just uninstall it using Add/Remove programs. You probably don't need the excess baggage from it.



    Your log current log is clean but I want to check into Command AV and remove it before giving you final steps.
     
  7. noviceseeking.lol

    noviceseeking.lol Private E-2

    hi chas i dunno wtf is going on here now????

    pc is totally screwed again! i have attached the log u asked 4 and another hijack this log!

    when booting pc the pcguard program tells me it has failed to launch and to re-install it!

    i am unable to run any online scans as they just stall/crash or fail????

    in my program files there is a folder called common files and in that is a program called pest patrol (i didnt know it was there ) but when i try to run it
    it says i have a pest installed deep inside the operating system that cant be removed except to boot into safe mode and run a batch script clean delete at reboot bat.

    problem is it wont run that either!!!!!(unless i am doing it wrong but i think i did it right) tried several times!!! (log attached)

    i am able to run lavasoft ad aware personnel addition and spybot but they are showing everything being fine!
     

    Attached Files:

  8. noviceseeking.lol

    noviceseeking.lol Private E-2

    further to my earlier response see new hijack this log!

    it would appear but i still am not sure that authentiums anti virus may indeed be a part of blueyonder pcguard!

    blue yonders pc gaurd is provided free to blueyonder 10mb customers but none of the paperwork tells you exactly what makes up their package!
    i doubt it is their own work so maybe they purchased some kind of license from authentium???????

    i dunno but when i re installed pc guard (as requested on boot up by program) authentiums stuff re appeared after disapearing???
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well my personal opinion of software like this is.....don't use it. It's too hard to figure out what belongs to what when the pull stunts like this. You should call them and find out exactly what is included in the package so you know for future reference.

    Here is something else that bothers me. In your uninstall list I see:
    NoAdware v4.0
    Windows Defender

    But neither of them show as running in your HJT log. Why?

    Did you install NoAdware or did it also come with PCguard?

    Are you having any malware problems at the present time?
     
  10. noviceseeking.lol

    noviceseeking.lol Private E-2

    i downloaded no adaware to try to solve the current problem it is not a part of pc guard!

    i wasnt aware that windows defender was on my system and it isnt in my add/remove programs!!

    yes i am still having problems!

    i am unable to run several online virus scans (so i suspect something is interfering with them?)

    i have also had a few programs crash/stall fail to install recently which hasnt happened until recently (last few days)

    pest patrol (dunno where that come from either) still reports that i have a pest deep in my operating system that can only be removed in a safe mode reboot scan but i am unable to run 1 of those (still not 100% sure if something is stopping that or wether thats just my lack of knowledge in how to run that?)

    i only installed pc guard AFTER my current problems had begun and only because i was looking for an alternative to norton internet security/anti virus which was installed on my system but the subscription was due for renewal in a few weeks.
    As i had an infection and i have read in several places that internet security can be a bit of an unecessary resource hog i was looking for an alternative!

    PC guard is (free to me) provided by my ISP and i assumed that it might work well with my internet package if they provide it to their customers!
    It is not a free product you have to subscribe unless you buy their 10mb broadband package (which i have) and it provides a susposedly total internet security type package.

    this includes (as i now know) an anti virus,anti spam,firewall,pop up blocker,ad blocker,and parental screening programs all under the name of pc guard!

    i do not know who provides all of this (although it does appear that command software at least provide part of it) i will attempt to find out that info today!

    stumped as to were i go from here as i seem unable to identify a specific virus/trojan/malaware problem but i am having definite symptoms of that type of problem!

    if there is any other information or scan i can run or provide u with please let me know as i am relying on you for a way forward as my limited knowledge has well expired..lol

    for some reason??? when i post on here i get logged out and have to log in again (this has happened a couple of times now) i assume that this isnt how it should work??? could this be a part of the problem??? is this some kind of hacking thing???
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be running anywhere but it is in you uninstall programs list. Did you purchase this??? If not, then uninstall it.

    Well part of it is!: Windows Defender Signatures show in your uninstall list. Try to uninstall them.

    Both of these problems could be due to the software you are running from your ISP. It could be blocking the scanners from running. You need to check how everything is configured in the firewall and antivirus applications to make sure they are not blocking what you want to run.

    Pest Patrol does not appear in your installed programs list so I don't know how you are running it. Also if you did not purchase Pest Patrol, it will not fix anything. Is this part of your ISP's software. And when you say you where not able to run 1 of those what exactly are you referring too. Also if you are getting a report about something, you need to show me the report. Just saying there is a pest deep in your system does not provide me any useful information.


    Again the software from your ISP may be the problem. It could be blocking various cookies and other info which is causing this problem.

    There are good free alternative tools that we have available for download that you can use for the following, antivirus, antispyware, firewall. And using a free browser like Firefox also provides built-in popup protection.


    Also please give me an new Uninstall programs list from HijackThis.
     
    Last edited: May 31, 2006
  12. noviceseeking.lol

    noviceseeking.lol Private E-2

    hi chas!

    yes it would appear pest control is a part of my pc guard package (although trying to find out whats in it is like trying to get blood from a stone)

    i dont have any info more than i have told you when i run it a window box pops up and i quote:

    "youve got a pest installed deep in the operating system and we cant remove it without your help.
    please reboot into safe mode and run this batch script: C:\PPCleanDeleteAtReboot.bat

    For more information see http://research.pestpatrol.com/howto/safemodePPClean.asp"


    thats what it says word for word! doesnt say what type of pest it is or anything!

    i have removed alot of the sh*te off the system like windows defender etc! (at least i hope i have?) i didnt put it there in the first place but as usual ask the kids how it got there and they dont know!!!!

    i have managed to run a scan on panda active scan and it detected (but didnt fix) something it called processor (see attached log!)

    i did run spybot again and it detected smitfraud c (said it fixed it but i know it cant) so i downloaded a smitfraud fix for that and hopefully i have fixed it i used the guide here: http://www.short-media.com/forum/showthread.php?t=32218
    i hope that was the right thing to do??? sorry if it wasnt but i am anxious to get this fixed!! please let me know if it wasnt and feel free to call me names if i have messed up but remember i am a bit dumb on these things!

    i have also attached the uninstall list you requested and also the pest patrol scan log thing!!

    thanks for your continued patience and help!!!!
     

    Attached Files:

  13. noviceseeking.lol

    noviceseeking.lol Private E-2

    hi chas!

    following my smitfraud removal attempt i looked through the geeks site and found super anti spyware free in your downloads.

    i have run that and my system is now clean??????

    here is my latest hijack this log!

    i havent got a clue what should or shouldnt be on hijack this logs but i am a concerned over the iten 20 winlogon things and the rest of it i dunno at all!

    what are my next steps???? is my system now clean????

    many thanks!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's why I personally would not run the stuff from them even though they provide it free. They have no idea exactly what they are providing or how it works and they cannot provide any proper support on it if you have problems since they did not write the software.

    Well did you boot into safe mode and run the .bat file like they requested?

    Windows Defender is part of the READ & RUN ME. So that is where you probably got it from. You don't need it know if you are going to use all this stuff from your ISP.

    Not a problem. It is from SmitRem. Ignore it.

    Normally when Spybot finds this, it is not the real smitfraud infection that SmitRem or SmiFraudFix are use to fix. It is normally just some other stray registry keys in the domains are that need to be fixed.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What winlogon things are you referring too? Did you mean to say the Running processes? They are all valid.

    Since your ISP's package contains an antispyware blocking program and a scanner. You should probably not run SuperAntispyware (it could cause conflicts and it eats up more system resources.


    You log is clean! If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!


    You aleady have steps 2, 3, 4, & 5 covered since your ISP provided 2,3 & 5 for you. And you got 4 from the READ & RUN ME already. And step 8 is already completed since you are already running the current Sun Java version.
     
  16. noviceseeking.lol

    noviceseeking.lol Private E-2

    thanks very much for all your help!
     
  17. noviceseeking.lol

    noviceseeking.lol Private E-2

    me again!

    still having odd things happen?????

    tried doing an online bit defender scan and got a pop up (whilst it was downloading the definitions) saying new bit defender available click here to restart i.e explorer (bit weird) and so i tried avg free and got a pop up on install saying that avg detects an old copy of roxio easy cd/dvd writer which conflicts with avg? problem is easy cd/dvd creator/writer has never been on this sytem?

    and now my driver for my cd/dvd combi writer is showing as a system conflict and currently unusable.

    the pest patrol scan still comes up with the detected pest message ???

    i suspect something still isnt right? any ideas?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running more scans when your system is clean?
    Why are you installing another antivirus application when you already have the stuff from your ISP? Read step 3 of the READ & RUN ME again.

    CD/DVD drives typically do not require any drivers just to work so I'm not sure what you are referring to.

    Either way, none of this is malware related. You should consider posting in the Software Forum (maybe Hardware if you continue to have CD/DVD drive problems).

    Several messages ago I asked the a question about what Pest Patrol was finding but you never answered the question. I repeat:
    And you are incorrect about not having Roxio software on your PC. Look in Add/Remove Programs. The previous logs you posted show:
    Roxio Burn Engine
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds