I think this is new

Discussion in 'Malware Help (A Specialist Will Reply)' started by hugenerd2004, Dec 12, 2005.

  1. hugenerd2004

    hugenerd2004 Private E-2

    I have a computer with a piece of spyware that I think may be new. I have run Spybot S&D, Microsoft Anti-spyware, Ad Aware and Hijack This. I can not remove this particular entry from the registry nor the file from the computer. The file is renamed every time I reboot the system, and the registry entry is changed also. I have tried to remove the file with Kill box to no avail. I am very experienced with spyware removal and virus removal, but I am stumped on this one. Any help would be appreciated. Oh I have tried scanning with McAfee, Norton, and AVG(none of these detect any viruses). None of the online virus scanners will complete. My Hijack This log is attached. The offender is an 020.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You have HijackThis installed incorrectly, install HijackThis to C:\HJT.

    Scan with HijackThis and Fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Running Spy Sweeper.

    Post the Spy Sweeper log and a fresh HijackThis log when finished with teh above.
     
  3. hugenerd2004

    hugenerd2004 Private E-2

    I think this may have done it. Here is the Hijack This log.
     

    Attached Files:

  4. hugenerd2004

    hugenerd2004 Private E-2

    Here is the SpwSweeper log.
     
  5. hugenerd2004

    hugenerd2004 Private E-2

    It won't let me upload my SS log for some reason.
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Make sure the extension is either txt or log. IF the log is more than 256Kb than zip the log and attach it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds