Spy Bot Cant Remove This Spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mavshah, Dec 17, 2004.

  1. mavshah

    mavshah Private E-2

    spybot is not able to remove this spyware.. any idea what i should do..?
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ISEXEng

    also treid ad aware.. it doesnt even catch it..
     
  2. solaris89

    solaris89 First Sergeant

    This should help.
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Mavshah,

    Here is a link: http://www.wilderssecurity.com/showthread.php?p=323615#post323615

    If you'd rather have some assistance, send us a HijackThis Log. Be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been pretty busy with work lately, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  4. mavshah

    mavshah Private E-2

    I tried the link u provide and tried to use that method. Wont allow me to choose properties. says that registry has been removed.
    am going to try to get the log file to u.. so it works...
    appreacite the assistance
     
  5. mavshah

    mavshah Private E-2

    here is the hijack this txt file that i got. attaching it to this..its driving me nuts.. feels like i might have to reformat the whole freaking thing.
     
  6. mavshah

    mavshah Private E-2

    attaching the file m ight help
    here u go
     

    Attached Files:

  7. yukon98

    yukon98 Specialist

  8. PhilliePhan

    PhilliePhan Guest

    Hi Mavshah,

    I agree with Yukon98 that you should probably just delete it from the registry. There are no signs of the original infection in your HJT Log. Are you experiencing any symptoms, or is this just something that turns up after Spybot scans? All that is in your log are a few minor cleanup items:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} - http://arcade.icq.com/multiplayer/odyssey_web8.cab

    I recommend flushing WildTangent and the like as they only lead to similar headaches:
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab


    Take a look at Chaslang's suggestions for future protection: How to Protect yourself from malware!

    PP :)
     
  9. mavshah

    mavshah Private E-2

    THis is somethign that came up with the SPYBOT checker. Also my computer seem to have slowed down a bit.
    I am wondering if reformating the computer would help me clean up everything? restart from scratch with the factory installs. I know woudl be pain to get all the codecs and all other files that I had. Is there a way to back up all those stuff on a cd and so that I can get it all back straight away instead of going through the pain of finidng it.
    Or would you guys say its nothing major and just continue with this.
    Any suggestions?
     
  10. PhilliePhan

    PhilliePhan Guest

    Hi Mavshah,

    This is cretainly not an issue to reformat your machine over. I think the actaul Malware is long gone and all that is left to do is delete that registry key as Yukon98 suggested. You might also want to explore a registry cleaner as well. It could help performance - Just be sure to back up the registry beforehand!
    There are many other causes for slow performance - You may be well served to start a new topic in the Software Forum about how to address this,

    Should you go the reformat route, you have many options for backing up data you'd like to keep.

    http://majorgeeks.com/downloads3.html

    Backing Up Your Computer


    PP :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds