Windows XP Community - XPHeads



Spyware advise

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 03-29-2008, 01:04 AM
John
 
Posts: n/a
Spyware advise
Hi

I have run the following;

ComboFix
SpyBot
SDFix
SmitfraudFix
smitRem

But the spy ware keep coming back. What else can I run?

Thanks

Regards


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 03-29-2008, 01:15 AM
Shenan Stanley
 
Posts: n/a
Re: Spyware advise
John wrote:
> I have run the following;
>
> ComboFix
> SpyBot
> SDFix
> SmitfraudFix
> smitRem
>
> But the spy ware keep coming back. What else can I run?


"the spy ware" eh?

LavaSoft Ad-Aware
Spybot Search and Destroy
SuperAntiSpyware
HijackThis!

Sometimes you need to do them in safe mode.

Follow that up with Computing Common Sense to keep from being re-infested.

Also - when asking for help please give as much information as possible.

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-29-2008, 01:28 AM
David H. Lipman
 
Posts: n/a
Re: Spyware advise
From: "John" <info@nospam.infovis.co.uk>

| Hi
|
| I have run the following;
|
| ComboFix
| SpyBot
| SDFix
| SmitfraudFix
| smitRem
|
| But the spy ware keep coming back. What else can I run?
|
| Thanks
|
| Regards
|

Time to get expert advise!



1. Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en...HJTInstall.exe

2. Disable Notepad's word wrap:
In Notepad.exe; Format --> uncheck; "Word wrap"

3. Download/run Deckard's System Scanner:
http://www.techsupportforum.com/sect...eckard/dss.exe

4. Save the scan results (Main.txt and Extra.txt)

5. And then post the contents of Main.txt and Extra.txt in your post in one of the below
expert forums...


{ Please - Do NOT post the HJT and Deckard's System Scanner Logs here ! }

Forums where you can get expert advice for HiJack This! (HJT) and Deckard's System Scanner
Logs.

NOTE: Registration is REQUIRED in any of the below before posting a log

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html

Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/...splay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malwa..._Here-f37.html
http://gladiator-antivirus.com/forum...?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/...p?showforum=18
http://www.malwarebytes.org/forums/i...hp?showforum=7
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 03-29-2008, 01:44 AM
PA Bear [MS MVP]
 
Posts: n/a
Re: Spyware advise
What "spy ware"?

What anti-virus application or security suite is installed? What
anti-spyware applications (other than Defender)? What third-party firewall
(if any)?

Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_R...:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/...moving_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/


John wrote:
> Hi
>
> I have run the following;
>
> ComboFix
> SpyBot
> SDFix
> SmitfraudFix
> smitRem
>
> But the spy ware keep coming back. What else can I run?
>
> Thanks
>
> Regards


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 03-29-2008, 01:46 AM
PA Bear [MS MVP]
 
Posts: n/a
Re: Spyware advise
David H. Lipman wrote:
<snip>
> Forums where you can get expert advice for HiJack This! (HJT) and
> Deckard's
> System Scanner Logs...


And http://aumha.net
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 03-29-2008, 01:52 AM
John
 
Posts: n/a
Re: Spyware advise
Here is one (attached).

Firewall: ISA server 2006 as it is connecte dto win 2003 sbs server.
Antivirus: trend Micro CSMS

"PA Bear [MS MVP]" <PABearMVP@gmail.com> wrote in message
news:uT8cs6TkIHA.484@TK2MSFTNGP06.phx.gbl...
> What "spy ware"?
>
> What anti-virus application or security suite is installed? What
> anti-spyware applications (other than Defender)? What third-party
> firewall
> (if any)?
>
> Unexplained computer behavior may be caused by deceptive software
> http://support.microsoft.com/kb/827315
>
> Run a /thorough/ check for hijackware, including posting your hijackthis
> log
> to an appropriate forum.
>
> Checking for/Help with Hijackware
> http://aumha.org/a/parasite.htm
> http://aumha.org/a/quickfix.htm
> http://aumha.net/viewtopic.php?t=5878
> http://wiki.castlecops.com/Malware_R...:_Introduction
> http://mvps.org/winhelp2002/unwanted.htm
> http://inetexplorer.mvps.org/data/prevention.htm
> http://inetexplorer.mvps.org/tshoot.html
> http://www.mvps.org/sramesh2k/Malware_Defence.htm
> http://defendingyourmachine2.blogspot.com/
> http://www.elephantboycomputers.com/...moving_Malware
>
> When all else fails, HijackThis v2.0.2
> (http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
> It will help you to both identify and remove any hijackware/spyware with
> assistance from an expert. **Post your log to
> http://forums.spybot.info/forumdisplay.php?f=22,
> http://castlecops.com/forum67.html,
> http://forums.subratam.org/index.php?showforum=7,
> http://aumha.net/viewforum.php?f=30, or other appropriate forums for
> review
> by an expert in such matters, not here.**
>
> If the procedures look too complex - and there is no shame in admitting
> this
> isn't your cup of tea - take the machine to a local, reputable and
> independent (i.e., not BigBoxStoreUSA) computer repair shop.
> --
> ~Robear Dyer (PA Bear)
> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
> AumHa VSOP & Admin http://aumha.net
> DTS-L http://dts-l.net/
>
>
> John wrote:
>> Hi
>>
>> I have run the following;
>>
>> ComboFix
>> SpyBot
>> SDFix
>> SmitfraudFix
>> smitRem
>>
>> But the spy ware keep coming back. What else can I run?
>>
>> Thanks
>>
>> Regards

>





Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 03-29-2008, 01:53 AM
John
 
Posts: n/a
Re: Spyware advise
Here is another (attached).

Thanks

Regards

"PA Bear [MS MVP]" <PABearMVP@gmail.com> wrote in message
news:uT8cs6TkIHA.484@TK2MSFTNGP06.phx.gbl...
> What "spy ware"?
>
> What anti-virus application or security suite is installed? What
> anti-spyware applications (other than Defender)? What third-party
> firewall
> (if any)?
>
> Unexplained computer behavior may be caused by deceptive software
> http://support.microsoft.com/kb/827315
>
> Run a /thorough/ check for hijackware, including posting your hijackthis
> log
> to an appropriate forum.
>
> Checking for/Help with Hijackware
> http://aumha.org/a/parasite.htm
> http://aumha.org/a/quickfix.htm
> http://aumha.net/viewtopic.php?t=5878
> http://wiki.castlecops.com/Malware_R...:_Introduction
> http://mvps.org/winhelp2002/unwanted.htm
> http://inetexplorer.mvps.org/data/prevention.htm
> http://inetexplorer.mvps.org/tshoot.html
> http://www.mvps.org/sramesh2k/Malware_Defence.htm
> http://defendingyourmachine2.blogspot.com/
> http://www.elephantboycomputers.com/...moving_Malware
>
> When all else fails, HijackThis v2.0.2
> (http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
> It will help you to both identify and remove any hijackware/spyware with
> assistance from an expert. **Post your log to
> http://forums.spybot.info/forumdisplay.php?f=22,
> http://castlecops.com/forum67.html,
> http://forums.subratam.org/index.php?showforum=7,
> http://aumha.net/viewforum.php?f=30, or other appropriate forums for
> review
> by an expert in such matters, not here.**
>
> If the procedures look too complex - and there is no shame in admitting
> this
> isn't your cup of tea - take the machine to a local, reputable and
> independent (i.e., not BigBoxStoreUSA) computer repair shop.
> --
> ~Robear Dyer (PA Bear)
> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
> AumHa VSOP & Admin http://aumha.net
> DTS-L http://dts-l.net/
>
>
> John wrote:
>> Hi
>>
>> I have run the following;
>>
>> ComboFix
>> SpyBot
>> SDFix
>> SmitfraudFix
>> smitRem
>>
>> But the spy ware keep coming back. What else can I run?
>>
>> Thanks
>>
>> Regards

>





Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 03-29-2008, 01:59 AM
John
 
Posts: n/a
Re: Spyware advise
Both the above attached screens appear from time to time.

Thanks

Regards

"PA Bear [MS MVP]" <PABearMVP@gmail.com> wrote in message
news:uT8cs6TkIHA.484@TK2MSFTNGP06.phx.gbl...
> What "spy ware"?
>
> What anti-virus application or security suite is installed? What
> anti-spyware applications (other than Defender)? What third-party
> firewall (if any)?
>
> Unexplained computer behavior may be caused by deceptive software
> http://support.microsoft.com/kb/827315
>
> Run a /thorough/ check for hijackware, including posting your hijackthis
> log to an appropriate forum.
>
> Checking for/Help with Hijackware
> http://aumha.org/a/parasite.htm
> http://aumha.org/a/quickfix.htm
> http://aumha.net/viewtopic.php?t=5878
> http://wiki.castlecops.com/Malware_R...:_Introduction
> http://mvps.org/winhelp2002/unwanted.htm
> http://inetexplorer.mvps.org/data/prevention.htm
> http://inetexplorer.mvps.org/tshoot.html
> http://www.mvps.org/sramesh2k/Malware_Defence.htm
> http://defendingyourmachine2.blogspot.com/
> http://www.elephantboycomputers.com/...moving_Malware
>
> When all else fails, HijackThis v2.0.2
> (http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
> It will help you to both identify and remove any hijackware/spyware with
> assistance from an expert. **Post your log to
> http://forums.spybot.info/forumdisplay.php?f=22,
> http://castlecops.com/forum67.html,
> http://forums.subratam.org/index.php?showforum=7,
> http://aumha.net/viewforum.php?f=30, or other appropriate forums for
> review by an expert in such matters, not here.**
>
> If the procedures look too complex - and there is no shame in admitting
> this isn't your cup of tea - take the machine to a local, reputable and
> independent (i.e., not BigBoxStoreUSA) computer repair shop.
> --
> ~Robear Dyer (PA Bear)
> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
> AumHa VSOP & Admin http://aumha.net
> DTS-L http://dts-l.net/
>
>
> John wrote:
>> Hi
>>
>> I have run the following;
>>
>> ComboFix
>> SpyBot
>> SDFix
>> SmitfraudFix
>> smitRem
>>
>> But the spy ware keep coming back. What else can I run?
>>
>> Thanks
>>
>> Regards

>



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 03-29-2008, 02:16 AM
David H. Lipman
 
Posts: n/a
Re: Spyware advise
From: "PA Bear [MS MVP]" <PABearMVP@gmail.com>

| David H. Lipman wrote:
| <snip>
>> Forums where you can get expert advice for HiJack This! (HJT) and
>> Deckard's
>> System Scanner Logs...

|
| And http://aumha.net

That would throw Boater Dave for a loop :-)

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 03-29-2008, 02:21 AM
David H. Lipman
 
Posts: n/a
Re: Spyware advise
From: "John" <info@nospam.infovis.co.uk>

| Here is one (attached).
|
| Firewall: ISA server 2006 as it is connecte dto win 2003 sbs server.
| Antivirus: trend Micro CSMS
|

PC-Antisyware is a rogue application!

As I stated before... go to an expert forum.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:19 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74