Just can't get rid of spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by lotus1, Sep 21, 2006.

  1. lotus1

    lotus1 Private E-2

    Hope someone can please help me with this as it's driving me mad!

    I've never really had a major problem with spyware before, as I've scanned about once a week with ad-aware and spybot and kept avast up to date.

    However the last few days, I've had warnings from Windows that my computer is infected with spyware. Everytime i removed it with ad-aware or spybot it just kept coming back! Zonealarm kept flagging up an .exe that wished to connect to the net but i think that's now been removed.

    After running through the steps on the READ & RUN ME thread, i still can't get rid of it.

    I'm currently running:
    Ad-aware
    Spybot
    A-squared (free version)
    Ewido (free version)

    The hijackthis log i've attached is from the newest scan I've performed.

    Please help :(
     

    Attached Files:

  2. lotus1

    lotus1 Private E-2

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2

    Now PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    After doing the above and attach the new rapport.txt log, also attach the below new logs:
    - HJT
    - ShowNew
    - GetRunKey
     
  4. lotus1

    lotus1 Private E-2

    Thanks for the quick and useful reply chaslang.

    Just one thing before i start the process, i couldn't find a file named smitfraudfix.cmd in my SmitfraudFix Folder on my Desktop?

    I've attached a printscreen showing the files in the folder in case i've missed something.

    Thanks again
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I forgot to have you download the tool. This is not the same as SmitRem.

    Download SmitfraudFix (by S!Ri) to your Desktop. Then continue with my other directions.
     
  6. lotus1

    lotus1 Private E-2

    D'oh I didn't even think that it could be another program :)

    Please find the attached files you asked for.
     

    Attached Files:

  7. lotus1

    lotus1 Private E-2

    And the final file....
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now make sure you are in normal boot mode and that you also have not disable any startups via MSconfig and then attach new logs from HJT and GetRunKey.

    How is everything running right now?
     
  9. lotus1

    lotus1 Private E-2

    Attached are the new logs.

    I'm no longer getting warnings from Windows about a spyware infection but I am still getting a lot more tracking cookies show up in Ad-aware than usual.

    Not sure if this is a symptom of the earlier problem?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything!

    Cookies are not problems and you will get them anytime you surf. Read step 11 of the below:

    How to Protect yourself from malware!
     
  11. lotus1

    lotus1 Private E-2

    Oops, sorry - they are attached this time :)

    Good point about the cookies, I guess I'm just being paranoid thinking that there are more showing up than before.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can use HijackThis to fix the below line (unless you configured it that way for some reason)?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;127.0.0.;;<local>

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should now work thru all steps in the below (you already know step 11 now ;) ):

    How to Protect yourself from malware!
     
  13. lotus1

    lotus1 Private E-2

    No I didn't configure it like that but HijackThis sorted it out.

    Many thanks for all your help chaslang, couldn't have done it without you :D
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds