MALWARE ALERT HELP! spywarequake

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by einstein007, Jun 5, 2006.

  1. einstein007

    einstein007 Private E-2

    I am suffering under this virus, and as a Windows Tech I am suprised at how resilant this thing is, and how pervasive it it. I used Hijack this, rid myself of all questionable items... so I felt good there, went to my registry, found an entry, killed it.. went to MSconfig, searched it all, found some in the services I questioned, killed them... found these (just below) in System32, and deleted them successfully in safe mode... however IT LIVES STILL!


    C:\Documents and Settings\All Users\Desktop\Online Security Guide.url
    C:\Documents and Settings\All Users\Desktop\Antivirus Test Online.url
    C:\Documents and Settings\doug\Favorites\Antivirus Test Online.url
    C:\Documents and Settings\doug\Favorites\Online Security Guide.url
    C:\WINDOWS\system32\dcomcfg.exe
    C:\WINDOWS\system32\hp100.tmp
    C:\WINDOWS\system32\simpole.tlb


    Symptoms and signs of it still around:
    pop ups saying I am slowing down, and to dl this and that adware/spyware remover
    popups for antivurus
    Severe slow downs periodically
    All internet pages close periodically
    Internet crashes 5-8 times an hour (this is frustrating my attempts to DL, on dialup, a antivirus proggy)
    Periodical popups of the main subscreen indiciating I have viruses and to goto thier website for the solution
    A permament icon in the task bar area next to my clock, interchanging so as to prevent it from being hidden by Windows.
    Permament fixed homepage to their site
    I also think it is trying to quietly dial on my dialup when it crashes my internet
    Refresh does NOT work, instead redirected to a new page, where upon the malware says it blocked it due to innapropriate content.
    Caches pages for real, so as to make appear that I am having faster connections to pages such as google (Loads when I am offline, rofl!)
    All passwords have been deleted, lol... I think it is probably copying my newly typed ones :(

    I am up against the ropes here, and no known solution to this issue. I give myself to the true pros and hope for an answer.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    First run this procedure and attach the requested log: SpywareQuake & SpyFalcon Removal Procedure

    If you still have problems after running the above, please continue to the below.


    You sound cluey on what your doing so I dont want this to sound patronising but please run the guide I'm posting below as it has steps and apps to run in a specific order as to maximise removal of malware,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    Then one of our resident experts in malware removal will get to it as soon as they possibly can, both are very busy at present so please bare with us.
     
    Last edited by a moderator: Jun 5, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds