spyware probs

Discussion in 'Malware Help (A Specialist Will Reply)' started by sam21, May 20, 2006.

  1. sam21

    sam21 Private E-2

    hi i was here a few months ago and you guys help me alot.ty

    i think i have done steps correctly the only problem i had was windefender
    couldnt load page so i continued.

    i bought this pc in 2003 from a little computer shop i didnt get a real copy of windows xp pro he gave me a burnt copy i didnt care untill now when i reformat and whammo infections right from a fresh install no inet connected either.So i install from the disk he gave me activate buy phone,install avg
    and it starts to find tons of trojans etc...... install zone alarm which i have both avg free and ZA on disk. now connect to inet and get updates for everything
    now problems are the pc wont let me install sound card it gives me a NTreadword......something and on the fresh install of win it said it couldn't find Driver.cab is that related???

    of topic why would a pc dealer do that to anybody....

    i am at the stage for system restore i guess because that is the only place that has infections I THINK i hope :rolleyes:

    for som reason it says the html file from bitdefender is wrong format?
    did i mess up again geez sry what dod i do now?????
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Follow the directions for Look2Me VX2 Removal.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to AolSoftware ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HijackThis, but instead of scanning, click on the 'None of the above, just start the program' button at the bottom of the choices. At the lower right, click on the 'Config' button, and then the 'Misc tools' button ... select 'Delete an NT Service' ... copy/paste the following into the box that opens, and press 'OK':

    AolSoftware

    In HJT Choose Open the Misc Tools Section choose Process Manager, Highlight:
    Choose Kill Process

    Now scan and have HJT Fix the following:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackTHis log.
     
  3. sam21

    sam21 Private E-2

    well i think thats it all though i noticed something on hjt
    the last entry i deleted it

    did both l2mefix and killbox
    safe mode found nothing desided to run a scan spybot
    just regular windows override stuff as i have yet to finish setting this pc up
    anyways heres HjT log
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    THat log is from Safe Mode. I need one fom Normal Mode. Don't fix things I didn't tell you to fix.
     
  5. sam21

    sam21 Private E-2

    ooops sry what i del is still there and sry its taking me along time to respond i am working at the moment.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    No it's gone. The file you see is in Sytem32 and that is the legit file. Your log is clean.

    Lets flush all your restore points and create a new clean one for your system.

    Disable And Enable System Restore
    How to Protect yourself from malware!

    Safe surfing.
     
  7. sam21

    sam21 Private E-2

    good news ty so much dude you rock
    and i am getting better habits lol

    ty again
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're Welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds