Infection possibly blocking spybot?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Moses, Jul 25, 2010.

  1. Moses

    Moses Private E-2

    Hello, cool people. My father's desktop was apparently infected with some spyware. I went through the posted cleaning procedures and fixed some stuff but am uncertain if everything's cleared up and wasn't sure if I should do the whole toggle-system-restore bit yet.

    Initial Symptoms:

    This part's tricky. This isn't my computer, so I don't know exactly when or how it was infected. Eight or so months ago my dad reported problems accessing his email through his MSN browser (which I'm trying to get him to stop using in favor of Firefox anyway). I didn't think it was a malware issue but he recently mentioned he was still having problems so I tried to check it out and discovered I couldn't open Spybot. The status bar that appears when Spybot's starting up would load fully but Spybot would never open up in either Normal or Safe Mode. So that's when I decided to come here.

    Problems during scanning:

    I found that I couldn't open RootRepeal in Normal Mode: the "Initializing" message comes up but then the computer would restart itself shortly thereafter. I found I could run it in Safe Mode though and in order to avoid having to restart between scans unnecessarily I ran RootRepeal first then rebooted into Normal to do everything else. Since I'm not sure if this is a malware interference issue or not I'm reluctant to try to open it again after having done all the other scans and fixes until I heard from you folks (since I haven't toggled system restore yet).

    Symptoms after scanning:

    The only thing I can tell is still wrong is that Spybot still won't open. However, I'm uncertain if this is a malware issue or if it's just because Spybot's really big resources-wise and this computer is operating with way less memory than it should (128 megs of RAM for Windows SP 2...).

    So please have a look at my logs if you can and let me know if there's anything wonky still happening. I plan to have a long talk with my dad about safe surfing after all this...
     

    Attached Files:

  2. Moses

    Moses Private E-2

    Last log. Remember when the maximum number of uploaded files was only 3 but the cleaning procedures asked for 4 logs? Can't catch a break, we can't.
     

    Attached Files:

    Last edited: Jul 25, 2010
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Moses

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Moses

    That is exactly the problem:
    Please update SpywareBlaster v3.5.1 to the current version SpywareBlaster 4.3

    *EDIT: SAS version is outdated!

    *You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Complete scan" of your system.

    Please attach the log if anything is found other than tracking cookies.

    -------------------------------------------------------
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
    Last edited: Jul 26, 2010
  5. Moses

    Moses Private E-2

    Hello, dr.,

    I did all you asked. Seems like I'm in the clear. I'll be heading out sometime this week to get my dad some more memory.

    Thanks very much!

    As always,

    you rock
     
    Last edited: Jul 26, 2010
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not positive what this PC can handle, but based on it being an old 900 Mhz PC, you may not be able to put in too much memory. If may have a 384 MB or 512 MB limit. If that is actually the case, don't waste your money on the memory because the PC is too old and too slow to have too much more life especially if you continue to update Windows XP and other applications like protection software.
     
  7. Moses

    Moses Private E-2

    Oh dear. I'll have to look into that. Thanks, chaslang.
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're very welcome, Moses.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds