Please help me romove Spyware Warning in System Tray

Discussion in 'Malware Help (A Specialist Will Reply)' started by jwwaller, Apr 15, 2007.

  1. jwwaller

    jwwaller Private E-2

    My problem started after someone opened a profile in My Space. It restarted the web browser and hijacked the home page to some anti spyware program page. I read through some post here and got rid of that problem but the System tray still has a symbol that switches from a question mark in a circe to a no symbol( a cirle with a diagonal line). It warns me quite often that my system is infected with spyware. I have run the processes on the READ & Run me first page and have all the logs. I think I might know what to do next, but I would prefer some expert advice before proceeding.
     

    Attached Files:

  2. jwwaller

    jwwaller Private E-2

    Here are the rest of the files. It is telling my that my CounterSpy file is too large to upload (over 1 MB).

    Thanks for any help
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    • Why is it so large?
    • Did you forget to run CCleaner on all user accounts as requested?
    • Did you forget to empty quarantine folders as requested?
    • Or is it just showing lots of stuff in System Restore?
    Put the CounterSpy log into a ZIP file and attach the ZIP.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now download the current version of GetRunKey from the link in the READ & RUN ME and use it from now on.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. jwwaller

    jwwaller Private E-2

    I missed the emty quaratine part. Should i run it again?

    It only has 4 issue programs but many problems for each. All 4 programs are casino sites.

    I will run the processes and see if it helps.

    thanx
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not right now! Just complete the other steps I gave to you. But empty your Quarantine now!!
     
  6. jwwaller

    jwwaller Private E-2

    here are the logs.

    Computer is working better than ever.

    How much do I owe you and where do I send it???

    Thanks a ton.
     

    Attached Files:

  7. jwwaller

    jwwaller Private E-2

    Last log file.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to hear it is working better! Now let's make it even better!


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also delete the below folder:
    C:\Documents and Settings\John Waller\Application Data\Viewpoint


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Automatic LiveUpdate Scheduler
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteAutomatic LiveUpdate Scheduler into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab

    After clicking Fix, exit HJT.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new HJT log.

    Make sure you tell me how things are working now!
     
  9. jwwaller

    jwwaller Private E-2

    Here's the HST log.


    Computer is working great. Boots faster than before.

    Thanks again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good! I still see one more LiveUpdate service from Symantec running. Do you have any software from Symantec still installed besides LiveUpdate 3.0 (Symantec Corporation)

    If not, then you should uninstall LiveUpdate3.0.


    Then If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds