SpyBlocs

Discussion in 'Malware Help (A Specialist Will Reply)' started by BrankoZ, May 25, 2007.

  1. BrankoZ

    BrankoZ Private E-2

    During a routine scan, SpyBot found some type of spyware called SpyBlocs. It had an "ssstbar" which I believe was an exe and some other stuff. I'd been using a free antispyware program called CyberDefender, which I found out is made by the same company that makes SpyBlocs, but CyberDefender has been found to be legitimate. Nevertheless, SpyBot also flagged CyberDefender as spyware, so I let SpyBot remove it. Only other items any of my 4 anti-spyware utilities found were tracking cookies, but I'd like to make sure this SpyBlocs is cleaned, and if you can tell me what type of spyware it is, that would be great.

    I did read through the Malware Removal thread; I've used it once before. Here are HJT, AVG anti-spyware (already used up CounterSpy), and BitDefender logs. Other three to follow
     

    Attached Files:

    Last edited: May 25, 2007
  2. BrankoZ

    BrankoZ Private E-2

    Here are Panda, GetRunKey, and ShowNew files. Thanks in advance.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have not come across a reference for SpyBloc. You do have a few items to fix, but I am not seeing indications of malware.

    Please use windows explorer to find and delete:
    C:\Documents and Settings\brian\Desktop\Early Detection Center.lnk
    C:\Documents and Settings\brian\Local Settings\Application Data\CyberDefender
    C:\Documents and Settings\brian\Local Settings\Application Data\sssTbarcfg.ini
    C:\Documents and Settings\brian\Local Settings\Application Data\sssTbarSettings.ini
    C:\WINDOWS\system32\ssldivx.dll

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  4. BrankoZ

    BrankoZ Private E-2

    You guys are awesome. Thanks so much for the quick response. Here are the new files. Assuming everything's fixed, can I start using msconfig again? All that stuff in the tray makes me edgy...
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    To clean out your system please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Your logs look clean. You may uninstall any programs we had you download (including CouterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds