Backdoor.small.eo AND Adware statblaster

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by felines_purple, Oct 25, 2007.

  1. felines_purple

    felines_purple Private E-2

    Hi Folks!

    This is a great site...well done to all.

    Ok, so I ran spyware doctor (free version only) and it picked up the two above bad boys. I have done a search to find any removal tools but no luck finding a successful one Do you guys know any handy programmes that would remove these.

    The tools I have used to try to remove these nasties are (all are the free versions)

    Anti Malware
    AVG
    Spybot
    Adaware
    Windows defender
    Windows One Care (full service scan)
    A squared
    Remove it

    Others
    CCleaner
    Wise Registry Cleaner

    Any others that might help?

    Thank you
    Karen
     
  2. felines_purple

    felines_purple Private E-2

    This is the log file from spydoc if it is any use.....
     

    Attached Files:

    Last edited by a moderator: Oct 25, 2007
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. felines_purple

    felines_purple Private E-2

    Hi,
    Thank you for replying

    HJT, bitdefender and panda are on its way.
    Could not run Counter spy and AVG found no threats (I assume you do not need to see that log file)

    Karen
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your ShowNew log is empty ...please see this thread to fix the problem:
    Using ShowNew.

    I need your HJT log also ...
     
  6. felines_purple

    felines_purple Private E-2

    :eek:

    Ok here are the remaining logs.

    Panda showed no infections and it did not come up with a pop up window with the saving log option. Being a techno idiot I assume I have done something wrong even though I did it twice and I followed the instructions on your web site.
     
  7. felines_purple

    felines_purple Private E-2

    :eek::eek::eek::eek::eek::eek: again
     

    Attached Files:

  8. felines_purple

    felines_purple Private E-2

    Sorry this is not a bump, this is me pressing the wrong button and not knowing how to delete a post.....did I mention I'm techno idiot.
     
    Last edited: Oct 26, 2007
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download SDFix and save it to your Desktop.
    • Run the SDFix.exe by double clicking on it.
    • Allos it to install into the default location which is c:\SDFix
    • Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode )
    • When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Attach the Report.txt file to your next message.
     
  10. felines_purple

    felines_purple Private E-2

    Ok the blue screen went up and I pressed y for all the 'you do that at your own peril do you wish to continue'. and it did its scanning and all looked well and blue screen went. Now all that pc has is the black safe mode screen without icons. There was no prompt for reboot. I this normal? Should I restart manually?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It may still be running ....
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Once you get the finished message ...continue on ....if you don't get that message, reboot.

    When you are back to the desktop, I want you to do this:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then re-run spybot in safe mode.
     
  13. felines_purple

    felines_purple Private E-2

    The message never appeared, spybit is doing its thing now
     
  14. felines_purple

    felines_purple Private E-2

    spybot found no threats
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  16. felines_purple

    felines_purple Private E-2

    Hi Tim,

    Thanks for all your help. Its so reassuring to have such a supportive help forum.

    Spyware doctor was still coming up with the original viruses.

    But I came across a free version of spyware doctor that you can download with google updater (free). I down loaded that and it cleared it up.

    I was also having svchost.exe issues (it was using 80-100% cpu) and that has cleared right up! Which is great cos, looking at the other posts on that subject, clearing it up looks painful! I'm not sure if the Backdoor.small.eo or Adware statblaster caused that problem because I also ran:

    Advanced Spyware Remover
    Advanced WindowsCare V2 and
    one other programme (the programme is not mentioned directly on your site but the company who make it is, I assume that you guys don't want people randomly mentioning software without your approval. If you want details let me know ,

    They found even more nasties on this pc!


    Thank you again sooooooo much!

    Karen
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Glad you got it cleared up ....and you can PM me with the program you are referring to.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds