Welcome, Guest

Go Back   TechieHQ - Computer Help Forum · » Operating System Support · System Infection Support
Reload this Page spyware ****!! Help please if you can...

spyware ****!! Help please if you can...

System Infection Support Support for virus, spy-ware, ad-ware, mal-ware and any other type of system infection.

Reply
 
Thread Tools Display Modes
  #1  
Old May 13th, 08, 1:01 AM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
spyware ****!! Help please if you can...

So I have a program called antispyspider that continuosly redirects my browser and has put up a new wall paper telling me I'm under attack and yadda yadda yadda. My task manager has been disabled and I can't seem to get rid of it. I've used Spybot, Adaware, SuperAntispyware and tried to use Smitfraudfix, but it will not let me delete registry values as it has taken over my task manager and admin settings. Any ideas? Startup takes about 10 minutes and everything is just screwy in general.



__________________
Signature placeholder
Reply With Quote
  #2  
Old May 13th, 08, 3:29 AM
spike228's Avatar
spike228
Nismo Tuned Mod
Posts: 2,179
Status: Offline
shield_mod.giftechie.gif
 
From: Honolulu, Hawaii
Joined: Jul 2004
Rep: spike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to behold
Try doing what you have already attempted in safe mode.


An antivirus scan might help too. Unfortunately, these type of things aren't always fully deleted when removed, so they may resurface at some random time. I suggest you back up everything thats important then reformat.



__________________
Spike
Reply With Quote
  #3  
Old May 14th, 08, 11:27 PM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
so i've repeatedly tried to get rid of the bad files with superantispyware and others but they just come on back. So now I'm think about reinstalling windows. Can I just reinstall windows on my "C" drive while leaving all the other virtual drives on the same hard drive alone? Would it be just easier to reformat and reinstall everything? Biggest pain is getting internet up and running with Time Warner Cable as this happened to me before. Also how do I find my password when I use outlook express to access my roadrunner email account? Any other tips for an easier install?



__________________
Signature placeholder
Reply With Quote
  #4  
Old May 15th, 08, 12:33 AM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,951
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
Have you tried using HijackThis and posting the log here? That might be a good first step.



Reply With Quote
  #5  
Old May 15th, 08, 11:30 PM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
Here is the logfile generated.
Don't know why I can't paste it in this page....
Attached Files
File Type: txt hijackthislogMay16th.txt (5.1 KB, 1 views)



__________________
Signature placeholder
Reply With Quote
  #6  
Old May 17th, 08, 12:58 AM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
any ideas anyone? I am thinking I I have made some kind of progress although my internet access is spotty. Popups and general slow system have made it hard. Also I can't access certain websites...they just don't load. This one does so I guess it is meant for me to get help here..



__________________
Signature placeholder
Reply With Quote
  #7  
Old May 17th, 08, 12:59 AM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
any ideas anyone? I am thinking I I have made some kind of progress although my internet access is spotty. Popups and general slow system have made it hard. Also I can't access certain websites...they just don't load. This one does so I guess it is meant for me to get help here..



__________________
Signature placeholder
Reply With Quote
  #8  
Old May 19th, 08, 2:03 AM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,951
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
This should all go:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
O4 - HKLM\..\Run: [BM0f95b787] Rundll32.exe "C:\WINDOWS\system32\soabvpok.dll",s

O4 - HKLM\..\Run: [0ca6841b] rundll32.exe "C:\WINDOWS\system32\cjxcgbbw.dll"
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://81.175.116.204/activex/AMC.cab

O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)



Reply With Quote
  #9  
Old May 19th, 08, 9:10 PM
ruslanb76's Avatar
ruslanb76
pivo prosim
Posts: 433
Status: Offline
techie.gif
 
From: usa
Joined: Jul 2004
Rep: ruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heartruslanb76 is a nerd at heart
Done as you suggested Fenis. I'm getting there but everything is still acting really slow and internet is real finicky about what it wants to open (sites) and how fast it wants to do them.



__________________
Signature placeholder
Reply With Quote
  #10  
Old May 20th, 08, 7:10 PM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,951
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
Once those entries are gone, boot into safe mode (F8 right after the BIOS screen) and run your antispyware/antivirus tools there. That should help a lot.



Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
spyware Supra Internet 3 Feb 13th, 05 8:59 AM
Help Me Please - Spyware javierito System Infection Support 4 Sep 16th, 04 3:59 AM
Help with spyware!!!!!!!! mike m System Infection Support 3 Jul 21st, 04 5:53 PM
Spyware Help karansaraf Software Support 7 Jul 13th, 04 11:05 PM
Spyware Help BobbyDigital Internet 9 Jul 1st, 04 8:37 PM


All times are GMT +1. The time now is 7:44 AM.