SpywareNo

Discussion in 'Malware Help (A Specialist Will Reply)' started by abcguy, Feb 10, 2006.

  1. abcguy

    abcguy Private E-2

    I recently scanned my PC with Ad-aware and the scan detected SpywareNo. I tried using Ad-aware to delete the threat but every time i reboot it comes back. I have already used spybot s&d and it comes out with no threats found and also hijackthis. I didn't found anything with hijackthis. I have also used the free trials of ewido and spysweeper, they were unable to detect any adware. I tired the instructions for removing SpywareNo on this forum aswell but to no avail.

    If anyone has information on getting rid of SpywareNO please tell me.

    Attached below are a few logs.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. abcguy

    abcguy Private E-2

    I have already done that. It switches my xp theme back to a classical theme and there ad-aware is able to delete the adware. However, when i reapply the xp theme, the adware comes back.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When did you do it? Just now when requested or before. And did you add in my registry patch or some other one.
     
  5. abcguy

    abcguy Private E-2

    i did it last night when i found out about the problem.

    "And did you add in my registry patch or some other one."

    I'm not sure what you mean by this.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do what it says in step 8 of SpySheriff (aka SpywareNo) Removal

    Does Ad-Aware give you a full log with better info? Something that properly shows the full registry key names. I wish the people selling these scanning programs would learn that full registry key path info is necessary ALWAYS.
     
    Last edited: Feb 10, 2006
  7. abcguy

    abcguy Private E-2

    Yes, i did exactly what it says in step 8.

    And here is a more indepth log.

    Edit: One more question, why can't i post in someone else's thread?
     

    Attached Files:

    • log.txt
      File size:
      28.4 KB
      Views:
      7
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Forum policies only allow certified Malware Fighters, Mods, and Admins to post replies in this forum. Users can only post replies in their own threads.

    Try the below registry patch. Make sure no browsers are open and shut down any protection programs (like MS Antispyware or similar) before running the patch.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
    Last edited: Feb 10, 2006
  9. abcguy

    abcguy Private E-2

    The patch didn't work.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure which aspect you mean did not work.

    Was it that it did not successfully add into the registry (it gave an an error message)?

    Or do you mean Ad-Aware is still detecting the problems? Are they still exactly the same? Some of those detection are wrong because they are normal registry entries. The below two are standard default values and are not SpywareNo:
    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\general]
    "WallpaperStyle"="2"
    [HKEY_CURRENT_USER\control panel\desktop]
    "WallpaperStyle"="2"
     
  11. abcguy

    abcguy Private E-2

    Sorry, I mean that ad-aware is still detecting the problems.

    I'll try to be clearer in future posts.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you disable ALL of SpySweeper's protections and were ALL browsers closed before trying the patch?

    Does Ad-Aware show exactly the same things?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download GetRunKey125b.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey125b.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment. Do this before continuing to the below.
     
  14. abcguy

    abcguy Private E-2

    I don't have spysweeper installed anymore and i am sure i don't have any other programs that protect registry changes. Also i am sure all broswers were closed. Ad-aware came up with the same thing.

    Attached is the runkeys.txt
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and install Registrar Lite

    Then run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_USERS\S-1-5-21-854245398-1960408961-839522115-1003\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}

    Then click the Security pull down menu and choose Take Ownership. Click OK in the next window to approve it. Now right click on the registry key and select Delete.

    Does this work?

    Attach your new Ad-Aware log.
     
  16. abcguy

    abcguy Private E-2

    I installed the program, but it says the Lite version does not let you take ownership.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! That's strange. Mine does! I wonder if the new version of Lite does not.

    What version do you have? Click Help, About.

    Mine is currently version 2.00, build 200.30803
     
  18. abcguy

    abcguy Private E-2

    Apparently, mine is version 4.03, build 403.30101 downloaded from the author's site.
     
  19. abcguy

    abcguy Private E-2

    Ok, i downloaded from one of the mirrors and got the same version that you have.

    I followed your instructions and took ownership of the registry key and then deleted it, but it came back after a restart. Also, i find that the key comes back every time i change wallpapers.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! At this point I'm pretty sure that you do not have a problem at all and the this is a False Positive from Ad-Aware. Part of the reason I say this is that several of the registry keys it is detecting are standard default keys with default values (I mentioned this earlier). You have a couple choices:

    1) Ignore Ad-Aware's report (I would not add them to the ignore list though).
    2) Disable Active Desktop and see if the problem goes away.

    Read the below on Active Destop


    1. Open the Control Panel.
    2. Open Display Properties.
    3. Click the Desktop tab.
    4. Click the Customize Desktop button.
    5. Click the Web tab in the Desktop Items window.
    If you wish to enable the Active Desktop, check "My Current Home Page". Add your current home page into your desktop or click New to add another web page and/or other Active Desktop features. To update the content, click the Synchronize button.

    If you wish to disable Active Desktop, make sure all checkboxes in this window are un-checked.

     
  21. abcguy

    abcguy Private E-2

    Diasbling active desktop doesn't help.

    I guess i'll have to wait until the next update of ad-aware and hope that it is a false positive.

    Thank you for all your help and I will post again if i still have the problem on the next release of updates.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    I'm convinced it is a false positive due to the view items that it detects that are valid registry keys.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds