Spyware / Virus Problem? Help Please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by XboxLivePerson, Nov 11, 2005.

  1. XboxLivePerson

    XboxLivePerson Private E-2

    Hello, My computer has been running very slow lately. I have been getting several pop ups (Casinos, What Im searching for in Firefox, Ads, ect). Also, sometimes Firefox or IE will not open. In addition, Task manager some times does not open either. Furthermore, When Firefox is opened, it takes a long period of time (5 minutes). In addition, when the computer is starting up, on the desktop this error shows up. Invalid Backweb application id "47822". Finally, when shutting down, two files fail to close ( .exe - dll). I tried the instrutions in the Sticky with the 4 programs. Ad-ware found no files, Spy bot found some spyware and removed them, and Microsoft found a few files and they were all removed. If anyone has any idea how to fix my computer, they are welcomed. Thanks.
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  3. XboxLivePerson

    XboxLivePerson Private E-2

    I'll Post a HJT log in a minute or two, but I forgot to add that when I connect a USB device and randomly, Windows crashes and I get a Blue Screen with "IRQL_NOT_LESS_OR_EQUAL" error. Finally, I also ran BitDeffender 8 and A squared with no results being found.
     
  4. XboxLivePerson

    XboxLivePerson Private E-2

    HJT log
     

    Attached Files:

  5. XboxLivePerson

    XboxLivePerson Private E-2

    Hi again, I changed my firewall and antivirus programs to those suggested by the other sticky and updates my HJT log, hes a newer one.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Uninstall BitDefender and F-Secure Antivirus, Completely having more than 1 AV program will interfer with each other. I see no firewall running according to your HijackThis log.

    Please do the following:
    Running Ewido Security Suite


    Run CCleaner before doing the below.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.

    Post the Ewido, WPFind logs and a fresh HijackThis log when completed with the above.
     
  7. XboxLivePerson

    XboxLivePerson Private E-2

    Thanks for the help, put I've had Ewido on my computer before and the Trail Expired. When I try to reinstall it and open it, it freezes up. I will try the other program though.
     
  8. XboxLivePerson

    XboxLivePerson Private E-2

    HJT and WPF logs. No Ewido because it freezes.
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Now scan and have HJT Fix the following:
    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds