Need help ensuring Spyware is gone.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bijan, Mar 18, 2005.

  1. Bijan

    Bijan Private E-2

    I had some malware on my computer about a week ago and I went through the processes listed on your READ FIRST post and other posts and thought I had deleted the problem. Then yesterday the file came back as a different name Volumecontrol.exe. I ran all the spyware scanners and virus scanners but came up with nothing. I then went through all the process and deleted the file but it evolved one more time and came back as MSPN32.exe. I deleted this file but then it started running on my computer w/o any existence of it showing on the harddrive even though I had show hidden and system files on. I downloaded zonealarm and it said this file is attempting to access internet so i blocked it. It then said Userinit.exe is trying to get MSPN32.exe to access internet so I blocked that. At this point I ran Hijack this (which I originally had to rename to "this thing.exe" because the first spyware kept shutting it down) and deleted all references of Mspn32.exe. I opened msconfig and made sure it wasn't loading on startup. I also checked regedit and it seemed to be clear of any reference to MSPN32.exe. At this point I want to know if I am safe from being hacked. Zonealarm shows that SVCHOST.exe is trying to listen from certain I.P addresses but is being blocked. It also came up with a warning that an address was trying to access your computer. All virus and spyware scanners are coming up clean at this point. Thank you for you time sorry for the length
     
  2. TheOldThug

    TheOldThug First Sergeant

    Welcome :eek:

    I know on my computer that file accesses the internet also and in fact I must let it to be able to connect to the internet.

    If you still have a problem after doing all of the READ ME then do the following: Please try to turn OFF any applications that are not needed It makes it much easier to look at the HJT log.
    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    Good Luck :)
     
  3. Bijan

    Bijan Private E-2

    Sorry for the delayed response. Ya I would guess that SVChost.exe isn't always a hacker but I just seems weird that it is coming from different addresses and ports. Could it be because I connect to the internet through my apartments network? The one which zone alarm considers high rated were occuring every 20 to 30 mins. Here is my Hijack log. Thank you for your time.
     

    Attached Files:

  4. TheOldThug

    TheOldThug First Sergeant


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds