problems with spyware stormer

Discussion in 'Malware Help (A Specialist Will Reply)' started by lulubell3, Jul 24, 2006.

  1. lulubell3

    lulubell3 Private E-2

    I have
    spyware blaster
    avg free
    ad aware
    peer guardian
    spybot sd

    recently i have been finding spyware stormer with spybot
    after fixing it with spybot less than 3 hours later it will find it again
    i don't know where it's coming from or why my programs aren't blocking it
    but web browsing gets more and more difficult to where i have to system restore and start all over again

    the files i find are called
    InetCtls.1net.1
    InetCtls.1net
    clsid|48259293-9880-11cf-9754-ooaaoocoo908

    does anyone know what i should do?
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Welcome to MajorGeeks.com, please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (
    these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. lulubell3

    lulubell3 Private E-2

    Okay I did everything I was supposed to do before I asked
    nothing was found on ANY program in safe mode and i cleaned everything with ccleaner
    but it's still happening and bitdefender found lots

    here are the results of panda bit and hijack
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>


    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  5. lulubell3

    lulubell3 Private E-2

    before you posted i nailed the adware with killbox and simply deleted the whole folder of blaze media because the uninstaller wasn't working
    i hope I didn't leave anything behing because i did it wrong.
    anyway...looks like my computer is pretty clean now...
    EXCEPT for that darn spyware stormer...pops up every 4-5 hours on spybot scans... could it be coming from a website?
    i have peerguardian and spyware blaster running constantly.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    CTRL+ALT+DEL
    click the "Processes" tab
    click on "SpywareStormer.Exe"
    Click on "End Task" button
    close taskmanager

    Uninstall SpywareStomer, using Add or Remove Programs in the Control Panel.

    Boot the Safe Mode and delete C:\Program Files\
    Security iGuard.

    Reboot.

    Post a fresh HijackThis log.
     
  7. lulubell3

    lulubell3 Private E-2

    i don't have and never have had spyware stormer installed on my computer
    it is not running like a program it is embedded in the registry-which i cannot figure what program will find and clean it
    these are the results i get from spybot every 3-4 hours after "fixing it" with spybot

    SpywareStormer: Root class
    HKEY_LOCAL_MACHINE\Software\Classes\InetCtls.Inet

    SpywareStormer: Root class
    HKEY_LOCAL_MACHINE\Software\Classes\InetCtls.Inet.1

    SpywareStormer: Class ID
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, post a complete Spybot Scan Report.
     
  9. lulubell3

    lulubell3 Private E-2

    here's the same results i get all the time
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Reboot to Safe Mode.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Reboot to Normal Mode.

    Spybot still find those registry keys?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds