Help i was infected with over 200 spyware/viruses

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by OCCMIKE, May 4, 2006.

  1. OCCMIKE

    OCCMIKE Private E-2

    Ok well i'm watching the game last night then all of a sudden i log on to my pc and notice a party poker icon which i never downloaded.Ok so i asked my brother what he was doing and he just said chatting on aim (I know aim is bad i have told him this many times but wont listen)Anyway i noticed there is about 10 things starting at the start up so i knew i was in for a long night.I did a scan with spybot it finds 21 traces of spyware crap.If that wasn't bad enough ewido finds 75 but about 70 of those were cookies.Adware also finds 74 and finally microsoftspyware finds 28.Below are the scans below can you tell me if i have any left over traces i'm guessing with this much crap there is gonna be a lot lurking around.



    Btw i'm running kaspersky,Nav,Panda and Mcafee so i'll update you if anymore is found
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. OCCMIKE

    OCCMIKE Private E-2

    Ok i just did a kaspersky from the faqs list it found this ugh i thought after deleting about 200 i was down guess not.Another thing NAV found nothing so now i'm trying bid defender and mcafee:mad:
     

    Attached Files:

  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  5. OCCMIKE

    OCCMIKE Private E-2

    A bit of an update just ran a scan with bitdefender and it found 1 file in the scan.I'm running a panda scan next what steps should i do next.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ok. 1 file is a good start, that can narrow it down for us. Be sure system restore is off, this trojan is trapped there. With system restore on, you wont get rid of it. Be sure you try some of the tools like Mcafee Stinger, they may get it, and again, from safe mode, with system restore off :)
     
  7. OCCMIKE

    OCCMIKE Private E-2

    Ugh this whole time i have been running these scans with system restore on.I just did a scan with windows security and it found 4 traces of imesh crap.I'll run stinger and avast now and again thanks.:)
     
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I think that will do you. System Volume Information is where all restore info is stored. Your programs know it is there, but the restore area is not accessible, so as far as the programs scanning are concerned, it is a virus that can not be removed. You can spot whats stored in system restore by the directory name:

    C:\System Volume Information\
     
  9. OCCMIKE

    OCCMIKE Private E-2

    Problem i downloaded the Mcafee stinger off the FAQs and it said it was outdated do you have an updated program.
     
  10. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Follow the link to the home page and grab it from them. The authors link should have the latest version.
     
  11. OCCMIKE

    OCCMIKE Private E-2

    One more thing i ran a scan with pro removal or whatever its called from majorgeeks it found these

    sys32.msrep32
    sys.smartmenuxp
    sys32.bdoscandel
    win32.tex.b
    win32.adware.viewpoint


    C:\windows\R.com
    c;\windows\regedit.exe
    c;\windows\system32\dllcache\regedit.exe



    It has an option to remove but again no clue if these are false spywares or not.



    Btw how come i can never get trend micro to load on firefox or IE despite having updated java.
     
  12. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    These all sound bad, like Trojan names:

    sys32.msrep32
    sys.smartmenuxp
    sys32.bdoscandel
    win32.tex.b
    win32.adware.viewpoint

    These sound bad, .com in the root of c is a bad thing and regedit is in Windows root, so thats a clone and possibly problematic.

    C:\windows\R.com
    c;\windows\system32\dllcache\regedit.exe

    Not sure on Firefox... yet, could be one of these issues.
     
  13. OCCMIKE

    OCCMIKE Private E-2

    Odd i did go on Mcafee site and got the Stinger from there but it still says its outdated:confused:
     
  14. OCCMIKE

    OCCMIKE Private E-2

    Another thing i ran microsoft update and installed 28 updates i needed with may have been my problem anyway i can also download SP 2 but i have heard good and bad things about it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note: The below are valid files and should be left alone

    c:\windows\regedit.exe
    c:\windows\system32\dllcache\regedit.exe


    These two detections by RemoveIT Pro XT SE are FALSE!

    If you already deleted them, there is still probably a copy in c:\windows\System32 and the one in dllcache may have recreated itself anyway.

    You should attach the two logs from Bitdefender and PandaActiveScan as step 6 in the READ & RUN ME requests. Also it would be best if you only run what we ask you to run.
     
  16. OCCMIKE

    OCCMIKE Private E-2

    I ran those scans again but they came back clean .1 last thing i know you didn't ask for me to run it but i saw a program called microworld spyware remover on majorgeeks and scanned my pc.It found about 20 files but only will remove the crap if you buy it so i'm guessing its fake.:confused:
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is a valid scanning tool but just will not fix anything unless you buy it. We have used it sometimes as an aid to finding hidden problems and then we can make manual steps to fix what it finds. There are many programs that work like this. Even PandaActiveScan only cleans very little (almost nothing) of what it finds unless you buy it. PestPatrol, Spy Sweeper, SpywareDoctor and many others do the same. They let you scan but you must buy it to fix problems.

    On the otherside, there a literally hundreds of crapware tools the work like this too and many of them do lie to you about what they are finding. That is why the below Rogue Tool list exists:

    Rogue/Suspect Anti-Spyware Products & Web Sites

    Are you still having problems?
     
  18. OCCMIKE

    OCCMIKE Private E-2

    So should i ignore it or what anyway pc seems to be fine although i can never get trend micro to load despite having the updated java.Another thing start up is a bit slow should i post another hijack log.:)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before you post HijackThis logs you must run the READ & RUN ME (all steps) and you must attach the two logs from step 6.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds