Help with spyware please :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kube, Dec 30, 2007.

  1. Kube

    Kube Private E-2

    It seems i have a simular case to this post...
    http://forums.majorgeeks.com/showthread.php?t=146989

    Here's what i have...

    http://i24.photobucket.com/albums/c8/kube01/v.jpg
    The 3 icons installed them self on my DT and i get the other popups when i start my pc and they just come up whenever.


    I also get this popup and all sorts of weird stuff also...
    http://i24.photobucket.com/albums/c8/kube01/v2.jpg

    I try deleting them of course but they just some back up when i restart, i have tried spybot, ad-aware, avg and what not but still nothing.



    Please help :(
     
  2. Kube

    Kube Private E-2

    Here's my smitfruadfix rapport file after trying to clean my pc but still nothing.

    Edit by chaslang: Inline step 1 only log from SmitFraudFix removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Dec 31, 2007
  3. Kube

    Kube Private E-2

    And a highjackthis log if needed...

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Dec 31, 2007
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do not post any logs inline like you have been doing. Logs must be attachments. This is explained in the sticky thread procedures. Also do not attach separate HijackThis logs. We do not need them.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  5. Kube

    Kube Private E-2

    Hey thanks a lot mate, it all seems to be gone now :)
    Sorry for not reading that first.

    Here's the MGlogs zip for ya ;)

    I have now got a lot of spmnoopt.sqm files in my (C) about 19 of them infact and also in other folders i have thumbs.db & desktop.ini files, can i just delete them or do they need top stay?

    Thanks again chaslang, Happy New Year :)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They were always on your PC. You just did not see them because they were hidden before you ran the READ & RUN ME.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1


    You need to delete the below files which were from your infection:
    Code:
    "C:\Documents and Settings\Caleb\Local Settings\Temp\"
    bit1.tmp       1 Jan 2008       85946  "BIT1.tmp"
    bit16.tmp      1 Jan 2008       85946  "BIT16.tmp"
    bit17.tmp      1 Jan 2008       85946  "BIT17.tmp"
    bit2.tmp       1 Jan 2008       85946  "BIT2.tmp"
    bit3.tmp       1 Jan 2008       85946  "BIT3.tmp"
    bit4.tmp       1 Jan 2008       85946  "BIT4.tmp"
    bit5.tmp       1 Jan 2008       85946  "BIT5.tmp"
    bit5f.tmp      1 Jan 2008       85946  "BIT5F.tmp"
    bit6.tmp       1 Jan 2008       85946  "BIT6.tmp"
    bit60.tmp      1 Jan 2008       85946  "BIT60.tmp"
    bit7.tmp       1 Jan 2008       85946  "BIT7.tmp"
    bit8.tmp       1 Jan 2008       85946  "BIT8.tmp"
    bitb.tmp       1 Jan 2008       85946  "BITB.tmp"
    bitc.tmp       1 Jan 2008       85946  "BITC.tmp"
    bitd.tmp       1 Jan 2008       85946  "BITD.tmp"
    bitf.tmp       1 Jan 2008       85946  "BITF.tmp"
    Then run CCleaner to make sure they are remove from your Recycle Bin.


    Other than the above, your logs were clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. Kube

    Kube Private E-2

    Thanks mate all done :) your the man!

    One more Q. should i hide my hidden files again or just leave them as is?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you want them hidden, go ahead and hide them. Just remember that doing so, also allows malware files to hide from you too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds