Help me remove this stuff

Discussion in 'Malware Help (A Specialist Will Reply)' started by syrk, Jul 2, 2006.

  1. syrk

    syrk Private First Class

    The Free Zone Alarm Online Spyware Free Scanner has found the following stuff on my pc:

    Game Spy Arcade - Adware
    Registry key - HKEY_CURRENT_USER\Software\Game Spy\3D
    Registry key - HKEY_CLASSES_ROOT\gsarcade\


    The CA eTrust Pest Patrol Anti Spyware Free Online Scan has found the following stuff on my pc:

    Actual Spy 2.8
    key: hkey_local_machine\software\microsoft\windows\current version\policies\explore\run


    Should I get rid of this stuff?/How should I get rid of this stuff. syrk
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you put this stuff on your PC yourself? Many gamers appear to use this site. Do you need it? Look in Add/Remove programs for anything related to this and uninstall if you don't need or want it.

    It all depends on what is under the policies key.

    Run the below procedure and attach the runkeys.txt log to your next message.
     
  3. syrk

    syrk Private First Class

    Chaslang,

    About Game Spy Arcade - Adware: Come to think of it, it did come with one of the games which I installed on my computer years ago. But I don't remember the source of the download. It could have been a game I bought or a downloaded trial game from a web site. If this adware is not a danger to my security I'll keep it. Is it a potential threat?

    About Actual Spy 2.8: I attach the runkeys.text file you requested.

    Thanx. syrk
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would not worry about it!

    It does not show in the registry key you said eTrust mentioned. It is a kelogger but it is normally one that the end user installs themselves. Did you install it at point in time? Unless you purchase the program, it was only a 40 minute trial.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  5. syrk

    syrk Private First Class

    Ok Chaslang,

    Attached is the uninstall_list.txt you asked for.

    Thanx again. syrk
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my previous question about Actual Spy. I said:
    Click Start, Run, and then paste the below into the box and click OK.

    regedit /E %systemdrive%\xlmpol.txt "HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Policies"

    Now attach the below file to your next message. I'm assuming that C is your boot drive.

    C:\xlmpol.txt
     
  7. syrk

    syrk Private First Class

    Chaslang,

    I did not willfully install the keylogger. I have no idea how it got in.

    I attach the xlmpol.txt file.

    Thanks. syrk
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message number 1 you said:
    If you look at the log you just posted you will notice there is no such registry key. There is one with explorer\run But even it has no Actual Spy under it. It is empty.

    I seem to remember having problems with you posting incorrect registry keys once before. You must learn to be EXACT in your postings.
     
  9. syrk

    syrk Private First Class

    Chaslang,

    Guilty as charged! It is indeed "explorer\run" and not "explore\run". I'm sorry. So what's the verdict about Actual Spy? The CA eTrust Pest Patrol Anti Spyware Free Online Scan is still picking it up. Is this what is commonly known as a false positive? Thanx. syrk
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It will probably go away if you just delete the empty key. The below key is what I'm referring to:


    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\run]
     
  11. syrk

    syrk Private First Class

    Chaslang,

    How do I delete this empty key? Thanx. syrk
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  13. syrk

    syrk Private First Class

    Chaslang,

    I followed your latest instructions but Pest Patrol still picks it up. What's next? syrk
     
  14. syrk

    syrk Private First Class

    Chaslang,

    Can this help? It's Ad-Aware SE Professional's Ad Watch Event Log taken right after I merged the fixme.reg file with my computer's registry:

    08/07/2006 18:43:13 - Registry modification detected
    Root:HKEY_CURRENT_USER
    Key:Software\Microsoft\Windows\CurrentVersion\Run
    Value:LDM
    Data:
    New Data:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    thanx. syrk
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This has nothing to do with your first problem of Actual Spy! And it is not really malware. It is just Logitech Desktop Messenger. If you don't use it, uninstall it. It is just a waste of system resources for most people.
     
  16. syrk

    syrk Private First Class

    Chaslang,

    Any other thoughts about Actual Spy?

    thanx. syrk
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a complete log from Pest Patrol. DO NOT HAND TYPE. Post a real log. My first suggestion though would be to stop using Pest Patrol unless you are going to buy it.
     
  18. syrk

    syrk Private First Class

    Chaslang,

    Here's the Pest Patrol log. Does your first suggestion still stand? thanx. syrk
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It probably will! But first, do you still have Registrar Lite installed from the last time you were here with a problem.

    If not, reinstall it.

    Download and install Registrar Lite make sure to download it from one of the Majorgeeks links and not the Author site.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\run

    Then click the Security pull down on the top menu and choose Take Ownership. Click OK in the next window to approve it.

    Now right click on the above key and select delete. Make sure it deleted the key. Refresh and check to make sure it is gone. Tell me whether it deleted or not.

    Now exit Registrar Lite

    Does PestPatrol still detect it? Did you get any error messages while doing any of the above?
     
  20. syrk

    syrk Private First Class

    Chaslang,

    I ran RegistrarLite and PestPatrol no longer detects Actual Spy 2.8. No error messages appeared during the process. Should I stop using the PestPatrol freebie? thanx. syrk
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you are going to buy it, why do you want it. It does not fix anything! Do you like having all these false positives or detections of things that are not really problems? You did not have a keylogger but it told you you did simply because a registry key existed. All the detections in zonemap\domains were wrong too. They were things put into your Restricted Zone by Spybot or similar and are there to protect you.
     
  22. syrk

    syrk Private First Class

    Chaslang,

    Thanx. I will follow your advice. syrk
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds