SAKY's AD/spy-ware problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Saky, Apr 1, 2005.

  1. Saky

    Saky Private E-2

    Hello, I am a A+ tech having problems removing spy/ad-ware from a client's machine. Any help would be appreciated. I am seeing a listing in add/remove programs called "Weboffer", I cannot remove this program and suspect it's malware. Everything else seems to be legit. I have taken the following steps to remove this (and other) malware from this machine.

    Ad-Aware Se: updated, ran a scan and attempted removal from safe mode

    Spybot S&D: updated, immunized, ran a scan from safe mode and at restart of XP (OS)

    Hijackthis!: scan run (now clueless for the most part, might need a trained eye for this)

    I am still getting popup ads on this machine. I have read that EULA software Co. makes this program but doesn't provide an uninstaller (bastards). I have read 10 sites or so with instructions on how to remove this pest manually but everything that is pointed out for removal (registry entries, file(s), processes) does not seem to be present on this machine.

    hijackthis! log is attached. Thank you.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:
    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.

    Second:
    Please close ALL browsers while running HJT.
    • C:\Program Files\Internet Explorer\iexplore.exe

    Third:

    For this entry you will need to run Spybot S&D , but before doing the scan go into Advanced Mode and uncheck ALL the ignored items. Then do a full scan!

    Fourth:
    Now, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal


    After doing ALL of the above, reboot and post a fresh HJT log.
     
  3. Saky

    Saky Private E-2

    ok, I'll get back ASAP, ty.
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good Luck!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds