I think I have an anti spy spider..please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by enimrac1206, May 28, 2008.

  1. enimrac1206

    enimrac1206 Private E-2

    I am trying to fix my aunt and uncle's cpu..here is what they were\are getting.
    I fixed this issue: "Your privacy settings are compromised. It is highly recommended to instal antyspyware solution".

    I fixed this issue: When I exit out of it, an internet window pops up this this anti virus site。

    I fixed this issue: On the bottom right corner, there are icons that state that my computer is running slowly due to malware activity, and it directs me to the same website。

    I fixed this issue: When i try to enter “ctrl, alt, del“ it states that it is disabled by administrator

    All of these were fixed by using your initial instructions for malware removal but the cpu still isn't running correctly. I am attaching the logs that you should need per your instructions. Please help. Thanks. Also, during the MGtools scan I kept getting a regedit error message saying something about my clb.dll and reinstalling it could fix the problem. Upon startup I also get error loading sockins32.dll..the specified module could not be found. I cannot find the log for superanti spyware but now when I run it there are no issues found. I am attaching a couple of logs. Let me know if you need more info.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where is the log from ComboFix.

    Also you need to re-run the MGTools and make sure you agree to the HJT license and let it run to completion:
    run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  3. enimrac1206

    enimrac1206 Private E-2

    I could not find the log for combo fix. Combo fix was saved to the desktop. Also, I kept getting the regedit error when I was trying to run MGtools. How do I know when it has completed running? I let it go for awhile before stopping it. I will do as you say and repost the other two logs when I have. Thanks.
     
  4. enimrac1206

    enimrac1206 Private E-2

    Here are the logs you needed. I think MGtools ran in its entirety. I let it run for hours but never got confirmation saying it was finished. Please let me know if you need anything else.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Exactly what error are you getting......and do they apply to Running MGTools?

    Your logs are still not complete...are you getting the license agreement for HiJackThis?

    You need to tell me exactly what is happening.

    Let's try a reg. patch:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Did you run MAlwareBytes? Where is that log? (Run it again, please).
     
  6. enimrac1206

    enimrac1206 Private E-2

    I ran everything you wanted me too but MGtools. I tried running it but everytime I start running it I get "This application has failed to start b/c clb.dll was not found. Reinstalling the application may fix the problem" on a Regedit.exe error. I don't know if MGtools is running when this happens...is it? How long does it usually take to run MGtools? I deleted MGtools and reinstalled it. It gave me the option of running or saving and I saved it to my C drive. After that it asked me if I wanted to open it but I closed that box and went straight to the c drive and double clicked on the superman logo for MGtools.exe...it starts and then says something about file not being found and that when I start getting the regedit errors. I am attaching the logs that you asked for from malware bytes and avenger. The rest of the logs are attached to previous posts. Thanks for all of your help so far.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can download a fresh copy of clb.dll from here.

    Tell me if you have problems doing so....
     
  8. enimrac1206

    enimrac1206 Private E-2

    This may sound like a silly question but I have to ask where do I save it? I saved it in the windows file...is that where it's supposed to go? Thanks.
     
  9. enimrac1206

    enimrac1206 Private E-2

    The clb.dll file worked and I was able to run Mgtools. I am attaching the log. Thanks.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Much better......good job.

    Please use add/remove programs to uninstall:
    MarketResearch - if it is not there, look in CCLeaner.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now tell me how things are running.
     
  11. enimrac1206

    enimrac1206 Private E-2

    Everything seems to be running how it should. Thanks so much. What programs can we delete and what programs should we keep around just in case? Thanks again for your help. I have deleted all anti virus programs and would like to know which would be the best to have? Also, I have recommended using the Zone Alarm free firewall instead of AOL and Microsoft. Do you agree? I will password protect certain kinds of websites to ensure this doesn't happen again. I don't usually have a week to deal with cpu issues. Is there anything else you need?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would keep both Malwarebytes and SAS ....we will give some final cleanup on the next reply.....let me just see a new MGLogs.zip .....:)
     
  13. enimrac1206

    enimrac1206 Private E-2

    Alright, I have deleted everything I had installed exept what you told me to keep. I am attaching a new log for MGtools. Thanks again for all of your help. My aunt and uncle appreciate it.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds