1. bamblack

    bamblack Private E-2

    I've followed all the steps on the Spyware Removal page. The only problem was I couldn't find the CounterSpy log. It said look
    "View -> Spyware Scan -> View Spyware Scan History" I couldn't find View to go into this. Other than that everything worked fine.

    Here are my logs
     

    Attached Files:

  2. bamblack

    bamblack Private E-2

    Here are the other logs including HiJack This
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKeys
    HJT
    Avenger
     
  4. bamblack

    bamblack Private E-2

    Hey thanks a bunch that got rid of those stupid pop-ups that always interrupted what I was doing

    Here are the new logs
     

    Attached Files:

  5. bamblack

    bamblack Private E-2

    And the HiJack This log
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Turn off all your active anti-spyware and anti-virus programs:

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Tell me if you have problems with these.

     
  7. bamblack

    bamblack Private E-2

    No problems at all, anything else I should do? If not, thanks a bunch for your help man. You guys rock!

    Keep it real,
    bamblack
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets be sure....attach both a new log for GetRunKeys and HJT.
     
  9. bamblack

    bamblack Private E-2

    Sure thing, here ya go
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is starting to tick me off ...let's try another way around it.

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt


    Now:
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach a new GetRunKey log and the log from Avenger.
     
  11. bamblack

    bamblack Private E-2

    I ran the Avenger and it gave me an error message after I rebooted.

    The title is

    Windows - No Disk
    Exception Processing message c0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is your system up and running?

    Can you get the logs?

    Can you also go to start / run / type "msconfig" without quotes and tell me what is in the start up tab.
     
  13. bamblack

    bamblack Private E-2

    Yeah it's running fine

    I can get the logs I'll attach them

    In the Start Up Tab under msconfig there is:
    ehtray
    readericon45g
    SOUNDMAN
    NvCpl
    nwiz
    NvMcTray
    Remind_XP
    RECGUARD
    mcmnhdlr
    oasdnt
    mcagent
    McUpdate
    MskAgent
    MSKDetct
    mcvsshld
    MpfTray
    wpctrl
    DTHtml
    qttask
    jusched
    dumprep 0 -k
    msmsgs
    ctfmon
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All of that is fine ...You may wish to use a Startup Manager

    Attach the logs when you are ready.
     
  15. bamblack

    bamblack Private E-2

    Oh forgot about that oops
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Something is blocking the registry fix......are you up to doing it manually?

    Go to start / run / type "regedit" without quotes.....now :
    expand [HKEY_LOCAL_MACHINE
    expand Software
    expand Microsoft
    expand Windows
    expand CurrentVersion
    expand Policies
    expand Explorer
    on the right you should see both:
    "some"
    "start"

    Right click each and delete.

    Tell me if that works.
     
  17. bamblack

    bamblack Private E-2

    Ok, I did that and I had no problem doing it
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  19. bamblack

    bamblack Private E-2

    Awesome thanks a bunch man, this place rocks!

    Keep it real
    bamblack
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds