Multiple spyware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by silverman, Dec 18, 2005.

  1. silverman

    silverman Private E-2

    Hello

    Having tried steps 1-6 on the sticky to little or no avail, I am left with no choice but to start this thread in an attempt to exorcise this spyware which annoying the hell outta me, making my PC sluggish, (and probably logging internet activity?)

    Well anyways heres low down

    When I start windows a box saying "runtime error 5 at 004046ED" appears, it may or maybe related to spyware? I don't know, but a vertical side bar with buttons and pictures saying "gambling, pharmacy, xxx, spyware, insurance" appears on the right of my screen also.
    Furthermore the desktop says "danger: spyware" and I cant right click on it, and it advertises raze spyware, all in a black box in the centre of the screen surrounded by a red background. I can't change this wallpaper due to the disabled right click.

    Well I think thats all of it, all is help appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    D3,

    If you were thinking the 020 line is related to a Look 2 Me VX2 infections and that is why you rean Spy Sweeper, it is not a Look 2 ME infection. The two items below:

    O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
    O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe

    are present because this is a pirated version of Windows XP.

    Also note that silverman has not run the steps in the READ & RUN ME. No online scanners were run and also MS Antispyware is not installed (possibly due to the illegal OS not allowing it).
     
  3. silverman

    silverman Private E-2

    S*** what do you mean is a pirated windows XP, we bought this PC from an official company, Barda I think it was, and a damn good deal too, we met the guys who sold to us at an official computer fair, and ordered it from there. There are regulations and identity checks etc to ensure all traders there are official and legal etc... I'm pretty sure you've got your wires mixed up dude, that reset 5 must be a piece of spyware of some sort, or maybe caused by malware to make life difficult for people. surely a pirated copy of windows should be exactly the same as a normal copy, just copied.

    anyway how do I get rid of it so I can make my copy of windows properly "official" as it were.

    And by the way I did run online scanners, panda and a few others, I just removed traces of them using a registry editor, it shows registry keys of programs not frequently used, and voila, I delete (its called "regcleaner"). I also removed plugins etc associated with them.

    Anyhow here is the spysweeper log and a new HJT log

    Thank you for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! It is definitely an illegal copy of the OS. This is common knowledge. You can look it up on any search engine too. Probably part of the reason you got a good deal. Try going to Windows Update and see how far you get. You will not be able to get your Windows XP version validated as genuine.

    And by the way I did run online scanners, panda and a few others, I just removed traces of them using a registry editor, it shows registry keys of programs not frequently used, and voila, I delete (its called "regcleaner"). I also removed plugins etc associated with them.
    [/quote]
    Why?? We did not ask you to do that. And besisdes if you just ran them, they were just used. Also where is MS Antispyware.
     
  5. silverman

    silverman Private E-2

    If you want me to go back and run those steps again, without deleting any signs on online scanners, I can, if you think it'll help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will help you fix your malware but if we fix the reset5, srvany, and resetservice files. Your system will always be asking you to validate your Windows license. You really need to buy a valid copy of WinXP. As it is now, you cannot get any Windows updates which means you also cannot upgrade to WinXP SP2.

    The below item needs to be fixed:
    O4 - HKCU\..\Run: [startman] media64.exe

    And then you should delete the file in safe mode. It is probably in the c:\windows\system32 folder
     
  8. silverman

    silverman Private E-2

    ok, ok, thanks for letting me know. so I can remove it using the procedure shown, I was conned is what your saying basically. what about the spyware though, is it because of reset 5 or something else?
     
  9. silverman

    silverman Private E-2

    so it will keep bugging me to validate it, ok. so what? I really don't want to have to shell out on a new copy, that isn't fair, is there no way around this?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! Unless you go back to where you bought it and make them give you a valid license (ain't gonna happen).
     
  11. silverman

    silverman Private E-2

    ok well, then, em, uh, your not gonna help me unless I get a legit copy of windows?

    I looked up the validation /activation thing, I'll have a month then I'm locked out. Thats a raw deal, may as well contact the guys who sold it, see what they say....
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already did help you:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I thought so! ;)
     
  14. silverman

    silverman Private E-2

    ok thankyou for all your help guys - appreciate it, especially about the pirated windows thing, you may as delete the thread now, unless there's something else.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing else! Also we do not delete threads!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds