Spyware Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Snake Eyes77, Oct 27, 2005.

  1. Snake Eyes77

    Snake Eyes77 Private E-2

    I believe my computer has been infected with Spyware and Viruses. I ran Microsoft Anti-Spyware and AVG Anti-Virus. AVG found the w?nspool.exe but said there was an error and it could not be activativated. I did a search online (which took me to this site :) http://forum.majorgeeks.com/showthread.php?t=48064) and followed the instructions already posted in that thread, yet when I ran HJS, I didn't really find all the files that were listed. I followed the rest of the instructions including using Safe Mode, yet still could not find any of the files really needed. I deleted all the files in the Temp drive and Temporary Internet files and when I run MS Anit Spyware it doesn't find the w?nspoll.exe file but I am still getting pop ups of dl anti spyware software and such and its kinda a pain :D. Anywho is there anyone who can help me please? Any help would be greatly appreciated.

    Also in case it helps, I have also run Ad Aware and Spybot Search and Destroy which has found a few files and deleted them.
     
  2. Snake Eyes77

    Snake Eyes77 Private E-2

    Anyone have any ideas? I could really use the help.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  4. Snake Eyes77

    Snake Eyes77 Private E-2

    Well the problems still seem to be here (and seem to have gotten more annoying) and I think whatever is on here is now forcing my computer to occasionally get the blue screen o'death and reboot. Here is the results from everything before running Hijack This, the log for it is attached to this post. Hope someone can help.

    Spybot S&D: Unable to download Detection Rules for October 28 and English Help for TeaTimer on July 25. Info says bad checksum. Ran the updater again and was able to at least get the TeaTimer Help.

    Bitdefender: Was running it when I recieved a blue screen of death and computer rebooted. When it finished rebooting, no problems. 2nd time through, no problems found.

    Trend Micro: found nothing

    Trojan Scanner: C:\Program Files\DivX\DivX Pro Codec\Gain_Trickler.exe, C:\Program Files\mIRC\mirc.exe, and
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll found.

    Pandascan: see file attached.

    Spybot, Adaware, and Microsoft Antispyware: Didn’t find anything.

    CWShredder: found CWS.Qttasks.exe and removed it.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just change to one of the other Download sites (just to the Right of the Search for updates area). This will solve the checksum problem.

    You did not follow the directions for installing and running HJT. See the below lines:
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Documents and Settings\Joseph\Desktop\Unused Desktop Shortcuts\Hijack This Folder\HijackThis.exe

    Spybot should not be running at this time and HJT is not installed in a proper folder as requesed.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After correctly installing HJT, continue with the below.


    Note: Ares contains malware unless you use the lite version. Consider not using this.
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    It is not normal for Windows Media Player to load at startup and the below line with the [infamous.exe] in it makes it seem even more like malware. Unless you know that this is something special you installed. I would fix the O4 line with infamous.exe in the below procedure.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {4EDB1450-E063-2F90-8601-605508F27816} - C:\WINDOWS\System32\zlfpy.dll (file missing)
    O2 - BHO: (no name) - {7630AB6D-5BE6-C0AF-EE74-55DA8F18C91C} - C:\WINDOWS\system32\ntak32.dll (file missing)

    Fix the next line if you do not know what it is:
    O4 - HKLM\..\Run: [infamous.exe] C:\Program Files\Windows Media Player\wmplayer.exe

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/apop/default/popcaploader_v6.cab

    After clicking Fix, exit HJT.
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    I will not be around until about 11/15/05 but one of our other capable Malware Fighters can continue to help you if still necessary.
     
  7. Snake Eyes77

    Snake Eyes77 Private E-2

    I've made the changes you commented on and hope that that'll fix it. The Windows Media Player/infamous.exe is something that has been on my laptop since I got it. What it does is it loads Win Media Player whenever I start up the computer. It is somewhat annoying but if I make the changes there will it affect Media Player later on? I have also moved the HJT into a new folder (in the Program Files) and have no idea how u saw that Spybot was running. I exited out of it before I ran HJT and the only reason it might have been running is because the tutorial said to run it. I am gonna post the new log and will let ya know if any other problems arise. Thank you MGs for all the help :)
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    chaslang is on vaction. Your log looks clean. How is your computer running.
     
  9. Snake Eyes77

    Snake Eyes77 Private E-2

    Evening Shadow :) well thus far I have only had one search pop-up appear on my screen. Other then that everything seems to be running okay. Will keep ya informed (but will try not to be annoying).
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Not all pop-ups are bad. SOme are actual ads, to generate revenue, by some of the sites you visit.

    Did you happen to notice what was in the title bar of teh pop-up?
     
  11. Snake Eyes77

    Snake Eyes77 Private E-2

    No title bar, it was just like I had gone to google or some search page (which I hadn't) and gave me some results for the TF web page I was on (though their TF were electrical :D ).

    Also just by going to this site, a search page for Spybot came up.
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments
     
  13. Snake Eyes77

    Snake Eyes77 Private E-2

    Here are the logs u requested. Just wondering, my computer has been doing reboots occasionally on its own. Most of the time it's when I close my notebook and later when I raise the top back up and it comes out of Standby mode occasionally it will give me a small blue screen of death (the size of my window when I boot into Safe Mode) and then just restarts. Like I said though, this doesn't happen all the time but it does happen a little bit. Thanks again for your help Shadow :)
     

    Attached Files:

  14. Snake Eyes77

    Snake Eyes77 Private E-2

    Here's the last one. Sorry bout that :D
     

    Attached Files:

  15. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Boot to safe mode, open Windows Explorer navigate to a delete the following:
    Empty the MS AntiSpyware Quarantine.

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a Fresh HijackThis log as an attachment.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds