Need Urgent Help With Spyware Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ForevaYoung, Jun 6, 2006.

  1. ForevaYoung

    ForevaYoung Private E-2

    I HAVE READ "READ & RUN ME FIRST Before Asking for Support" AND DID MOST OF IT

    i need help from u guys, even after doing whatever it say on that thread, i still have
    -pop ups
    -home page is forever about:blank
    -bottom right hand coner of my screen has an icon telling me my com is infected
    -sudden closure of all my exploers
    -etc

    i will go through wadever i have done/missed and post all the logs/scans that i have done

    please i really need someone's help!!

    ok here i go, i will go through section by section ok?

    0: Preliminary House Cleaning

    i uninstalled the programme that i downloaded already
    i emptied all my quarantine folders of my spyware detectos
    but i can't find the place to empty my norton antivirus junk (srry)
    emptied recycle bin

    2: Enable viewing of hidden files, system files and file extensions

    yes i did that


    3: Do not use Multiple Antivirus Applications

    uninstalled everything, leaving my norton antivirus, zonealarm and my Ad-Aware SE

    4: Downloading Tools

    these are the programmes i downloaded and used
    - CCleaner
    - Ad-Aware SE
    - SpyBot - Search & Destroy
    - Microsoft Windows Malicious Software Removal Tool
    - CounterSpy

    5: Cleaning Malware

    i booted my com in safe mode (bloody big icons) and ran these programmes in order
    - CCleaner
    - Ad-Aware SE
    - SpyBot - Search & Destroy
    - Microsoft Windows Malicious Software Removal Tool
    - CounterSpy (i have a log of its scan)

    after scanning/cleaning i Disable System Restore temporarily and booted my computer into normal mode

    upon seeing that my com has not been totally cleaned i gave up, went surfing around (dunno if i got more spyware but i DID NOT download anymore stuff and continued step 6 the next day

    DAY 2 OF COMBANT

    6: Online Virus And Trojan Scanning

    ran that Bitdefender thingy got a report
    ran that Panda ActiveScan got a report too

    7: HijackThis log posting

    downloaded hijackthis and posting a log (don worry, it's pretty short)




    I think that's all i have to say, if you need more info im more than happy to give it to yaIF SOMEONE CAN PLEASE HELP ME CLEAN IT UP


    lastly i would like to thank u from the bottom of my heart for reading my post and helping me out
     

    Attached Files:

  2. ForevaYoung

    ForevaYoung Private E-2

    P.S. there's some prob with my counterspy...so srry, no log of it
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not empty your Norton Quarantine folder as requested in step 0 of the READ ME. Please empty it now.

    You also did not follow the directions in step 7 of the READ ME. You are running MSconfig.
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Please follow the directions in step 7 and select Normal Startup.

    You needed to click on the Special Removal Procedures link in the READ ME & then select the below and run it:

    SpywareQuake & SpyFalcon Removal Procedure

    After running the above procedure attach the requested smitfiles.txt log and then a new HJT log.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
    Are the below required Proxy settings that you setup?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*;<local>

    Please explain what the below are and why it is necessary to have them in the Trusted Zone. We always recommend removing items from the TZ unless they are absolutely necessary. And they almost never are:
    O15 - Trusted Zone: http://*.moreatonce.com
    O15 - Trusted Zone: http://schdnavdo.schooldna.com
    O15 - Trusted Zone: http://schdnaweb.schooldna.com
    O15 - Trusted Zone: http://schdnaweb1.schooldna.com
    O15 - Trusted Zone: http://schdnaweb2.schooldna.com
    O15 - Trusted Zone: http://www.schooldna.com
    O15 - Trusted Zone: http://*.schooldna.com
     
    Last edited: Jun 6, 2006
  4. ForevaYoung

    ForevaYoung Private E-2

    so i juz need to run SpywareQuake & SpyFalcon Removal Procedure, setup my HJT properly and then post a log then i shout be okay?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's only part of what I requested in my last message.

    You nee to empty your Quarantine folder.
    You must stop using MSconfig.
    You need to attach the smitfiles.txt log.
    Attach a new HJT log after installing correctly and disabling use of MSconfig.
    Attach the uninstall list from HJT.
    And you need to answer my questions.
     
  6. ForevaYoung

    ForevaYoung Private E-2

    Are the below required Proxy settings that you setup?
    no idea what's tt...

    Please explain what the below are and why it is necessary to have them in the Trusted Zone. We always recommend removing items from the TZ unless they are absolutely necessary. And they almost never are:
    i used to use them, but i have no need for them now

    and lastly...how do i get to the Norton Quarantine folder?

    tyvm
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is singnet.com related to your ISP.

    It should be an option with in the program when you run it. I don't use Norton so I cannot explain exactly how it is done from within the program. You may be able to either double click on a tray icon and see what menu options there are. Or maybe right click on the tray icon to get other options. Another way would be to just go to the folder and manually delete all the files after booting in safe mode. The folder was shown in your Bitdefender log:

    C:\Program Files\Norton AntiVirus\Quarantine

    You still need to complete the rest of what I listed in message # 5.
     
  8. ForevaYoung

    ForevaYoung Private E-2

    done

    haiz, srry im quite dumb with some computer terms...but i know is that im paying singnet for my internet connection

    aye, no prob
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'll be looking for the info.
     
  10. ForevaYoung

    ForevaYoung Private E-2

    done

    hopefully im not using tt, i click start>run>msconfig>normal boot

    done

    done

    okay...


    more info

    did the whole SpywareQuake & SpyFalcon Removal Procedure

    i could not find any of the programmes stated but i found some programmes with ALMOST the same names:

    %System32%\1025
    %System32%\appmgr.dll
    %System32%\autodisc.dll
    %System32%\dcomcnfg.exe
    %System32%\dfrgfat.exe
    %System32%\dfrgntfs.exe
    %System32%\dfrgres.dll
    %System32%\dfrgsnap.dll
    %System32%\dfrgui.dll
    %System32%\main.cpl
    %System32%\shdocvw.dll
    %System32%\stdole2.tlb
    %System32%\stdole32.tlb
    %System32%\users32.dll
    %System32%\users.exe


    either way, after running the whole SpywareQuake & SpyFalcon Removal Procedure, my computer is back to wat it used to be...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the names you listed are valid files for the OS. That is why the malware uses the names that it does use. It is trying to make them look like the good files so you don't notice them.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HijackThis fix the below lines and then your log is clean:

    O15 - Trusted Zone: http://*.moreatonce.com
    O15 - Trusted Zone: http://schdnavdo.schooldna.com
    O15 - Trusted Zone: http://schdnaweb.schooldna.com
    O15 - Trusted Zone: http://schdnaweb1.schooldna.com
    O15 - Trusted Zone: http://schdnaweb2.schooldna.com
    O15 - Trusted Zone: http://www.schooldna.com
    O15 - Trusted Zone: http://*.schooldna.com

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds