spyware problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Taylor93, Jan 21, 2006.

  1. Taylor93

    Taylor93 Private E-2

    I have a IBM thinkpad t42 and im having problems with spyware. I have a trojan some where on my computer launching internet explorer and its constantly creating popups. pop up blocker isnt doing anyhting and neither norton antivirus adaware se, spybot, or any of these programs can find the trojan and delete it. ive tried evrything my system restore isnt working and theres no way to restore my machine. I was wondering if anyone could help me out?
     
  2. AbbySue

    AbbySue MajorGeeks Administrator

    Welcome to Majorgeeks!:)

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. You also should be telling us what problems you are having but I can see a whole bunch of them (multiple trojans, Look2Me infection, bad service, home page hijack).

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis
     
  3. Taylor93

    Taylor93 Private E-2

    I followed all the steps in the proscess as told to....but unfortunatley im still having pop ups and they wont go away.
     

    Attached Files:

  4. Taylor93

    Taylor93 Private E-2

    i posted the bitdefender scan..i tried the panda scan but it woulnt load and i wasnt able to use it
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post your HijackThis log
     
  6. Taylor93

    Taylor93 Private E-2

    done
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You are running an anti-spyware program which is not trusted or recognised to be safe, this link provides some details: - http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Therefore it is recommended that you remove it using the Add/Remove option on your computer:

    Start-Control Panel-Add/Remove

    Look for the following program and remove it:

    SpySpotter

    Uninstall Ares.

    Empty Your Internet Explorer Cache.

    Empty the Java Cache.

    Empty the Norton Quarantine Folder.

    Empty the Norton Protected Recycle Bin.

    Scan with HijackThis and fix the following:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Follow the directions for Running Ewido Security Suite.

    Post the Ewido log and a fresh HijackThis log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds