HELP! User's laptop depriving me of sleep!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MartyR, Oct 12, 2004.

  1. MartyR

    MartyR Private E-2

    I've been working on a user's laptop now for the last week with reoccuring IE problems - mostly begin2search.com redirects along with other annoying items. I have spent the last 7 hours gathering all of the tools and directions to follow to try and rid this laptop of the many annoyances that seem to reoccur :>( I have followed the instructions posted on you website with the following results:

    1. W2K system - SP4
    2. N/A - no strange processes listed
    3. Enabled
    4. Downloaded Tools and installed on laptop

    Scanning and Cleaning Steps:
    1. Booted in Safe Mode - Trend Micro Free Scan - clean
    2. CCleaner - 36 MB of files removed from HD
    3. Ad-Aware SE - 245 entried removed - 5 nonrelative (left alone)
    Spy-bot - DS Exploit - removed
    4. all tools produced clean results

    Didn't go any further with instructions. Still have a red exclamation point in toolbar of IE that states "You PC is infected with Spyware - click here to fix your PC" and it won't go away. It leads me to believe that I have some more things to clean off of this laptop before I can give it back to my user! Any and all information would be greatly appreciated at this point. I'd like to go home and get at least a couple hours sleep before coming back in the morning (oh, yeah it is morning already! :>( ). Thanks in advance.
     
  2. MartyR

    MartyR Private E-2

    Side note: red exclamation note only appears when IE is loaded under ADMIN privledges, when user id is used (Power User), icon does NOT appear in IE toolbar? Time to go home and get some sleep - MORE FUN TOMORROW!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is from a SpyDeleter problem, do the below:

    Click Start, Run, and enter into the box the following without the quotes "Notepad"
    Now copy and paste the contents the next 3 lines (including the blank line) into the notepad window.
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]


    Now save it as file name: "delspy.reg" (without the quotes).
    Use Save as file type: All files (*.*)
    Save it on your Desktop where it is easy to locate.

    Now on your Desktop double-click on delspy.reg.

    At the prompt "Do you wish to merge the information into the registry?"
    Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".
     
  4. MartyR

    MartyR Private E-2

    Chas,

    Thank you!! It seems to have done the trick and the icon is gone now :) I Ran HJT and everything looks clean - at least that which is supposed to be there. Now maybe I can get some sleep tonight :cool: Thanks again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds