found this,now trying to lose it!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by kookla647, Jan 6, 2006.

  1. kookla647

    kookla647 Private E-2

    Hello people, I dont know if this is a new trojan or what, but its called Raze spyware hunter. it high jacks your desktop and does all sorts of bad things! i did a google search on it to remove it and was told only half the way to remove it,,,i did a high jack this log and wanna know if i can post it and maybe get some help? i removed the logo that appears on the desk top but when i did what i was told, to do a panda activesearch, it stoped and now every time my mouse pointer touches the display on desktop ((backround)) it blinks and changes colors for a split sec.
    when you see the log you'll get what i mean. Thank you and keep up the great work!!! CHEERS
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com, please follow the steps below:

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. kookla647

    kookla647 Private E-2

    Thank you for replying so fast! I did all you mentioned and its still there, am running XP home edtion if you need to know and what it is doing is, wont let me change backrounds and popups some times comes up, computer running slow and homepage changed to msn. my log of hjt and panda are below!
    if you need more info. let me know ok?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the BitDefender log for BJ too.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    1. Download and Install CCleaner
      • Note that, when asked to run CCleaner, you should run ONLY the default scan (Windows Tab). Do Not “Scan For Issues”!

    2. Download FixWareout by Lonny and save it to your Desktop.


    3. Download & Install Ewido Security Suite
      • Be sure to uncheck Install background guard and Install scan via context menu when you Install Ewido.
      • After installing EWIDO, please update it’s definitions by Clicking the Update Button > Start.
      • Just leave it for now. You'll be running it shortly ;)

    4. Please locate your download of FixWareout and INSTALL it.
      • Be sure that Run fixit is checked.
      • Click Finish to begin the fix.
      • Follow the prompts and Reboot when asked to do so.
      • Upon Reboot, follow the prompts and HijackThis should open.

    5. After HJT opens, Click Scan and then Check the boxes for the following, if they should remain:

      O17 - HKLM\System\CCS\Services\Tcpip\..\{3CF67694-A0BF-4306-BF51-C01C4D3E0788}: NameServer = 85.255.116.174,85.255.112.181
      O17 - HKLM\System\CCS\Services\Tcpip\..\{3DF66BC9-BCDB-4945-90FD-A05D8E96A7A5}: NameServer = 85.255.116.174,85.255.112.181
      O17 - HKLM\System\CCS\Services\Tcpip\..\{4A91B805-0CAF-49FC-9861-B13A7CC5F807}: NameServer = 85.255.116.174,85.255.112.181
      O17 - HKLM\System\CCS\Services\Tcpip\..\{A962B389-5517-4A7A-B5A7-ABDBA173FC1A}: NameServer = 85.255.116.174,85.255.112.181


    6. Now, run CCleaner, Be sure you only run the Default Scan (Windows Tab) and select Run Cleaner. Do not run any other options from other tabs.


    7. Please Boot to Safe Mode!
      • Open Ewido and Select Scanner. Click Settings, make sure ALL boxes are checked under How to Scan & Unwanted Software and that Scan Every File has been selected.
      • When EWIDO has been configured correctly, click OK.
      • Click Complete System Scan to begin the scan. Allow EWIDO to clean all that it finds and then save the log to where you can find it easily.


    8. After ALL of the above has been completed, please REBOOT to normal Windows, scan with HijackThis and ATTACH that log. Please save and attach the logs the EWIDO scan, and the log found at C:\fixwareout\report.txt as well.
    Let me know of any problems you may have encountered with the above instructions and how your computer is running now.
     
  6. kookla647

    kookla647 Private E-2

    Thanks bjarrick,, my hats off to ya! I removed that nasty spyware with what you told me to do,,,,But now it left a blank spot in my display (were the wallpaper shows) from the missing window! is there any way to fix this? i tried to do a system restore but cant, because i used system mechanic6 to try and fix the display and it clean out the regis.
    Thanks for all your help! CHEERS
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You missed part of step 8 and BJ will need this:
     
  8. kookla647

    kookla647 Private E-2

    sorry about missing parts, guess i need to pay attention alittle more!
    the scans are listed below,,i hope we can get ride of this infestation for my enjoyment and also am sure others out there will get this one!!!
    Thank you
     

    Attached Files:

  9. kookla647

    kookla647 Private E-2

    here is another one you asked for,,,,,if you need any more info please let me know. Cheers
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Now a fresh HJT log from normal mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds