SpyBot 1.3 (Recovery Question)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JoeN, Jun 1, 2004.

  1. JoeN

    JoeN Corporal

    Just installed SpyBot 1.3, uninstalled old ver. 1st, did a full install, and unchecked everything on the install page with Tea Timer on it, want to run in manual mode only, ran SpyBot, it found 5 items, clicked "fix selected items" and everything seem to go fine untill I checked "Recovery" and found nothing there, old ver. put everything in there for 30 days or until you purged it - have I missed something ???????? not liking this at all !!!
     
  2. JoeN

    JoeN Corporal

    Thank you - I'll try what you suggest
     
  3. JoeN

    JoeN Corporal

    Tried what you suggested xflat, didn't help, been over all items and think I have things set up same as with previous version - I have tried reinstalling 3 times - same thing - any other suggestions,
     
  4. JoeN

    JoeN Corporal

    Running ver. 1.3 downloaded from MG - have installed 3 times and throughly cleaned up before each install - tried running SpyBot in the "default" mode - same thing happens - finds problems, says it will remove them, and does remove them, just not backing up into "recovery" - I think next option is to uninstall again and remove copy of SpyBot - clean up Reg. , files and folders and go out and get a fresh copy of SpyBot and try again
     
  5. JoeN

    JoeN Corporal

    Yes I put it into " C:/Program Files/SpyBot", - and this sure is strange - never had any trouble with ver. 1.2
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just wondering...could there be a spyware/trojan program running that is causing issues with SpyBot.

    Xflat, do you think getting a HiJaak This log at this point could be useful.
     
  7. JoeN

    JoeN Corporal

    Also have AdAware installed, updated and have run it - not showing any problems
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. JoeN

    JoeN Corporal

    OK, here is the Log from HiJack This - 1st an update on what I've done, I have REMOVED ALL traces of SpyBot from computer and downloaded another copy from Download.com - went to install and got a "corrupt set-up file" error - deleted copy from Download .com and did as you asked - I am not fimiliar at all with this program - hope it helps you - appericate all of every bodies time and effort

    Logfile of HijackThis v1.97.7
    Scan saved at 11:06:34 AM, on 6/2/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\DOWNLOAD\SYSTEM\EM_EXEC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\UNZIPPED\HIJACKTHIS.EXE
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.syracuse.com/
    F1 - win.ini: run=hpfsched
    O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEINT.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar2.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar2.dll
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EM_EXEC] C:\DOWNLOAD\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O8 - Extra context menu item: Download with Star Downloader - C:\PROGRAM FILES\STAR DOWNLOADER\sdie.htm
    O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: AIM (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw14fd.law14.hotmail.msn.com/activex/HMAtchmt.ocx
    O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) - http://activex.microsoft.com/activex/controls/iptdweb/ikcntrls.cab
    O16 - DPF: {E2CF5C45-7CCC-11D4-9BD1-0080C6F60B6A} (CouponsComBrxpdf2 Control) - http://ftp.coupons.com/brxpdf2.cab
    O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/ProductUpdates/content/opuc.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37866.7097685185
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Joe,

    Your log is pretty clean other than:

    F1 - win.ini: run=hpfsched
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)


    HPFSCHED is a small TSR that will remind you to clean the cartridges in your DeskJet from time to time in order to keep print quality high. It can be removed from the run line in win.ini if you do not want that feature.

    So have HiJaak This fix the O3 line. The hpfsched line is up to you.

    Also, listen to what Xflat said. Delete the SpyBot versions you downloaded elsewhere and download from here as he said much earlier: http://majorgeeks.com/download2471.html
     
  11. JoeN

    JoeN Corporal

    I have already deleted the copy from Download.com and downloaded a copy of SpyBot ver 1.3 again from MG - I will take care of the Norton item that HiJack This found - and one more thing - when you guys run SpyBot and the scan finds items either bots or usage tracks - and you choose to "fix selected items", do they show up in your "Recovery" ?????
     
  12. JoeN

    JoeN Corporal

    Yes, I went there 1st and made sure all those were checked - haven't reinstalled ver. 1.3 yet, did remove the Norton item with HiJack This, will update this post as soon as I install SpyBot again and run scan
     
  13. JoeN

    JoeN Corporal

    Well guys here is the bad news - reinstalled SpyBot from MG download, did "custom install", unchecked desk top icon, tea timer and IE helper, checked "advanced mode", under "settings" everything appears to be checked, by default, correctly, ran scan for "bots" only, 5 were found, selected "fix all problems", was asked if I wanted to remove these problems, clicked "yes", problems were removed BUT not "backed-up" in "Recovery" - I'm totally stumped here !!!!
     
  14. JoeN

    JoeN Corporal

    This is getting stranger by the day - ran SpyBot first thing today and same items appear as they did yesterday - appearently the program is NOT removing these items after a scan therefore there is nothing to place in "Recovery" - in the ver. 1.2, when "fix selected problems" was checked and confirmed, the items would be "grayed out" along with a check mark, I get the check mark but the items are not "grayed out" - I guess the whole program is just not working for me -
     
  15. JoeN

    JoeN Corporal

    Finally figured this thing out - apperantly ver. 1.3 does NOT save "cookies" to "Recovery " , got this info from SpyBot forums, also after downloading AGAIN this time from "Tucows" the program DID put all "Usage tracks" in to "Recovery" - so everything is working OK - THANKS AGAIN to all who offered help - this is the BEST forum I found
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds