having trouble removing some spyware

View previous topic View next topic Go down

having trouble removing some spyware

Post by reyz324 on Sat Mar 28, 2009 6:37 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:44 AM, on 3/28/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\PROGRAM FILES\A-SQUARED FREE\A2FREE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\System32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AppRanger IE Sandbox - {1ec7abb1-e555-404b-901c-6d24af4ce44d} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SWTray] C:\Program Files\AppRanger\SWTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\scieplugin.dll
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\DEFEND~1\DEFEND~1.0\adialhk.dll,C:\PROGRA~1\DEFEND~1\DEFEND~1.0\r3hook.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Defender Pro Internet Security (AVP) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 3999 bytes

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sat Mar 28, 2009 6:42 pm

Lets run a general scan.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sat Mar 28, 2009 7:19 pm

it didnt find anything
Malwarebytes' Anti-Malware 1.35
Database version: 1911
Windows 6.0.6000

3/28/2009 12:18:15 PM
mbam-log-2009-03-28 (12-18-15).txt

Scan type: Quick Scan
Objects scanned: 53118
Time elapsed: 2 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sat Mar 28, 2009 7:20 pm

Yep. What problems still remain?

We can go deeper if your still having problems?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sun Mar 29, 2009 3:52 am

well i have to run my pc in safe mode because if i run it normal as soon as it loads it freezes

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sun Mar 29, 2009 1:53 pm

Then it's probably not malware related.
I see this is Vista, can you hardware handle Vista? (RAM, processor, etc)


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sun Mar 29, 2009 6:43 pm

yea it was running just fine until i got malware i did a full scan instead of a quick scan and it found 1 malware and i had it removed but its still acting up

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sun Mar 29, 2009 6:45 pm

What program detected it? and what was it that it detected? did it say where?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sun Mar 29, 2009 7:19 pm

Malwarebytes' Anti-Malware 1.35
Database version: 1911
Windows 6.0.6000

3/28/2009 10:50:53 PM
mbam-log-2009-03-28 (22-50-53).txt

Scan type: Full Scan (C:\|)
Objects scanned: 156780
Time elapsed: 1 hour(s), 37 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\DefenderPro\Updates\ASUpd.exe (Rogue.MalwareSweeper) -> Quarantined and deleted successfully.

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sun Mar 29, 2009 7:23 pm

Hello.
Do you use DefenderPro?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sun Mar 29, 2009 7:26 pm

yea but ever since my computer started acting up defender pro doesnt work no more and i cant uninstall it because i cant start my pc iwth out using safemode and it wont uninstall in safemode

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sun Mar 29, 2009 7:30 pm

Okay, open up MBAM again.
Go into the Quarantine tab.

Highlight the line of Defender Pro, and press Restore.
See if you can uninstall it now.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Sun Mar 29, 2009 7:35 pm

no it says i cant uninstall because windows installer service is not accessible in safe mode

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by Belahzur on Sun Mar 29, 2009 7:47 pm

Lets kill some startup items first of all.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: AppRanger IE Sandbox - {1ec7abb1-e555-404b-901c-6d24af4ce44d} - (no file)
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SWTray] C:\Program Files\AppRanger\SWTray.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


  • Press "Fix Checked"
  • Close Hijack This.

Reboot normally, see if you can get to normal mode.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Re: having trouble removing some spyware

Post by reyz324 on Mon Mar 30, 2009 12:24 am

alright

reyz324
Novice
Novice

Status :
Online
Offline

Posts : 8
Joined : 2009-03-28
OS : vista

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum