HELP!!! spylocked will not go.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dragonlady, May 17, 2007.

  1. dragonlady

    dragonlady Private E-2

    I have done all the tasks as instructed and as you guys are brill having helped me out in the past, I would like your help again.

    I first have a question - my firewall seems to let the kids (21 & 16) access porn sites which despite my extreme anger with them they continue to visit. I am using Ashampoo - could you recommend one that is better and I can control by using a password to allow access to certain sites (if such a thing exists)? I am assuming that is where the spyware is coming from.

    Here are the 1st 3 logs:cry
     

    Attached Files:

  2. dragonlady

    dragonlady Private E-2

    HELP!!! spylocked will not go cont.

    here are 3 more logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember to post all messages and logs for a particular problem in one thread. You started a second thread for this one. I merged you back into one thread.

    Try ZoneAlarmPro but you will have to buy it so you can have all the features including a password lock so that only you can make changes to the settings.

    Now for your malware problems, let's begin with the below (you kids have been downloading porn videos). :(



    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. dragonlady

    dragonlady Private E-2

    Here is the first log from SmitfraudFix before reboot.
     
  5. dragonlady

    dragonlady Private E-2

    I think I messed up with the last post, but here are the logs after running SmitfraudFix.
     

    Attached Files:

  6. dragonlady

    dragonlady Private E-2

    Last one! Yet again you have saved the day! I REALLY appreciate your invaluable help.:D
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Uninstall the below software:
    Internet Explorer Secure Bar
    Java(TM) SE Runtime Environment 6
    Messenger Service
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - Startup: PowerReg Scheduler V3.exe
    After clicking Fix, exit HJT.
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    How are things working?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds