Help I have spyware and have hijackers attacking my pc

Discussion in 'Malware Help (A Specialist Will Reply)' started by babyturk, Sep 4, 2006.

  1. babyturk

    babyturk Private First Class

    I am using windows 98 SE and did all the steps that I was supposed to do and did the panda scan I will be attaching a panda scan log that shows that I have the said problems.Please can someone help me out, thank you, my computer seems to be running really slow lately and it is really frustrating:(:confused:
     
    Last edited: Dec 6, 2006
  2. matt.chugg

    matt.chugg MajorGeek

    We need the following logs as per the procedure:
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • HijackThis
     
  3. babyturk

    babyturk Private First Class

    Ok I am running windows 98 SE I don't see anything relating to runkeys for this type of computer,as well as the newfiles please help
     
  4. matt.chugg

    matt.chugg MajorGeek

    Its explained in the details.

     
  5. babyturk

    babyturk Private First Class

    here is the newfiles for your review.
     
    Last edited: Dec 6, 2006
  6. matt.chugg

    matt.chugg MajorGeek

    Ok thats the activescan and the new files. Now we just need:
    • runkeys.txt - the log from GetRunKey.bat
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • HijackThis
     
  7. babyturk

    babyturk Private First Class

    here is my counter spy scanSpyware Scan Details
    Start Date: 9/5/06 9:54:56 AM
    End Date: 9/5/06 10:16:58 AM
    Total Time: 22 mins 2 secs

    Detected spyware

    Paltalk Low Risk Adware more information...
    Details: Paltalk is an advertising-supported instant messaging client.
    Status: Ignored

    Infected files detected
    c:\program files\paltalk messenger\receivedfiles\brq.txt
    C:\palsound.txt

    Infected registry entries detected
    HKEY_CLASSES_ROOT\.PalTalk
    HKEY_CLASSES_ROOT\.PalTalk PalTalkFile
    HKEY_CLASSES_ROOT\.PalTalk Content Type text/PalTalk
    HKEY_CLASSES_ROOT\PaltalkFile
    HKEY_CLASSES_ROOT\PaltalkFile\Shell\Open\Command C:\Program Files\Paltalk Messenger\Paltalk.exe "%1"
    HKEY_CLASSES_ROOT\PaltalkFile\DefaultIcon C:\Program Files\Paltalk Messenger\Paltalk.exe,0
     
  8. matt.chugg

    matt.chugg MajorGeek

    Is that the full log? please attach the FULL log

    Ok we are down to 3

    • runkeys.txt - the log from GetRunKey.bat
    • Bitdefender - from step 6
    • HijackThis
     
  9. babyturk

    babyturk Private First Class

    how do I get the full log for counterspy
     
  10. babyturk

    babyturk Private First Class

    Deleted inline log, last time I will copy into a text doc and attach it for you as you have been through this process already!
     
    Last edited: Dec 6, 2006
  11. matt.chugg

    matt.chugg MajorGeek

    PLEASE ATTACH LOGS, do not just paste them. Runkeys even saves its log as a file!, its less effort to attach the file than it is to open it copy it and paste it. There is a reson why we have the procdure, please try and follow it.
     
    Last edited: Sep 5, 2006
  12. babyturk

    babyturk Private First Class

    I am sorry about that but I am having a hard time attaching my logs??
     
  13. babyturk

    babyturk Private First Class

    this all seems too hard maybe I will just forget it sorry for wasting your time:(
     
  14. babyturk

    babyturk Private First Class

    Here is my run key log for your review I hope I did it right and now I am going to try and figure out how to do the rest.
     
    Last edited: Dec 6, 2006
  15. babyturk

    babyturk Private First Class

    my 15 day free trial is up with counter spy? I will wait to here back from you, where do i go now?
     
  16. matt.chugg

    matt.chugg MajorGeek

    Ok lets forget about counterspy. I still need the bitdefender and I can't do anything without a hijack this log.

    Keep persisting! I will try and make the fix as simple as possible.

    Please try and only post when you need to, so lets attach both of logs with the next post, if you have problems with bitdefender post the hjt log AND let me know the problem with bitdefender all in the next post.

    Please keep in mind that I have around 30 open threads in this forum that I am trying to deal with and the other guys probably have far more so we can't dedicate our full time to one user. If I don't respond directly just hold on, Bumping your thread by posting unnecesarily will just move you backwards as we work from oldest to newest. It seems we offer a much in demand service!

    OK Lets get those last 2 logs and get your computer cleaned up!
     
  17. babyturk

    babyturk Private First Class

    The bitdefender page would not comeup it said page not found, here is my HJT log for your review,
     
    Last edited: Dec 6, 2006
  18. matt.chugg

    matt.chugg MajorGeek

    Your panda active scan log is technically clean apart from one regitsry entry which I cannot identify because active scan doens't give me details.

    One is a cookie, it is of no consequence.

    Two of them are items that Counterspy has quarantined so ignore them.

    The last one is a backup of a file that was deleted in your previous fixing post. you can manually delete the folder : c:\!killbox

    Is your ISP Shaw ?

    There is no malware in your HJT log, however you do have quite a few programs running at startup that probably arn't required which would be slowing your computer down,

    Your counterspy log TELLS you what its found:
    so you have at least 3 instant messenger programs on your computer.

    You may have to consider that the slowness of your computer is not malware related and just that it is old or just has too much 'stuff' on it, Uninstall all programs that you don't need, run the disk clean up too Start --> Programs --> Accessories --> System Tools --> Disk Cleanup and have it remove all tempory internet files, recycle bin, temporary files.

    COnsider Defragmenting your drives.Start --> Programs --> Accessories --> System Tools --> Disk Defragmentor.
     
  19. babyturk

    babyturk Private First Class

    Hi I have no idea what you mean when you say maually remove c:/killbox
    how do I do this do I go into windows explorer?
     
  20. matt.chugg

    matt.chugg MajorGeek

    Yes us windows explorer.

    Double CLick on My Computer

    Doublcik on 'c:'

    Right CLick on !killbox and select delete.

    CLick Yes
     
  21. babyturk

    babyturk Private First Class

    Ok I did that, now I am looking at all the installed programs and I am a bit confused there is so much programs on here I don't know what is important to keep on here and which programs are not please can you help me? Thanks again
     
  22. matt.chugg

    matt.chugg MajorGeek

  23. babyturk

    babyturk Private First Class

    It tells me that it is a sharing violation-\temp Unkey.txt
    access denied?
    what can I do?
     
  24. matt.chugg

    matt.chugg MajorGeek

    At what point in the process do you get this error message ?
     
  25. babyturk

    babyturk Private First Class

    ok it worked this time I think:)
     
    Last edited: Dec 6, 2006
  26. matt.chugg

    matt.chugg MajorGeek

    You have both Winrar and Winzip, you don't need both in your current situation. keep winrar and uninstall winzip. winrar handles zips and rars so you won't need winzip.

    You can probably uninstall Adaware as you have counterspy and adaware isn't proving much use to us in the malware world these days.

    Do you actually need the yahoo toolbar and msn toolbar ? If not uninstall them. The same applies to the google toolbar.

    Uninstall java version 7 and keep version 8 there is no need for both of them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds