PDA

View Full Version : Spyware Problem


afireinside4848
03-28-2006, 08:06 PM
ive got the spyware quake adware shit on my comp and i need to get it off,i had a spyware strike problem b4 and used smitrem.exe to get rid of it,and this is a variant but it wunt go away even with that and my spyware doctor freezes up when i go to delete it(anyone know why?theres a lot of files that the adware are in ,like 1000's) anyone know how to get rid of it?its not in programs files or anything either as spyware quake or anything....



http://i6.photobucket.com/albums/y249/afireinside4848/Image7.jpg

heres what it looks like

Kommercial
03-28-2006, 08:12 PM
You should do a search and use Spybot and Ad-aware, and that should get rid of it for you.

TheGrimKreeper
03-28-2006, 08:20 PM
Try Microsoft AntiSpyware. I had a big spyware problem a while back, and Microsoft AntiSpyware fixed my system back to better than before, and I haven't had any problems since. It's the best AntiSpyware program I know of, and it's free.

I think they've changed its name recently, but here's the link:

http://www.microsoft.com/athome/security/spyware/software/default.mspx

afireinside4848
03-28-2006, 08:38 PM
i fixed it with spyware doctor but it came back out of nowhere

Hey Now!
03-28-2006, 09:09 PM
It looks more like a virus. Try using a good anti-virus program.

You most likly have a file that triggers the virus/spyware.

afireinside4848
03-29-2006, 03:41 PM
i have panda antivirus and it didnt get it,it got all the other viruses and always does when i go onto mscracks.com cause they try to send u bad stuff but it always catches it right away..i had regisrty mechanic,thats the only new program ive used,i uninstalled it but the popups still there

Quiet_Riot
03-29-2006, 03:51 PM
Download both SpyBot search and destroy, and AdAware, and scan with them both in safe mode (hold f8 at statrup).

a_brainless_guy
03-29-2006, 04:15 PM
^^ what he said.

a/k
03-30-2006, 09:25 AM
* Click here (http://noahdfear.geekstogo.com/click%20counter/click.php?id=1) to download smitRem.exe. Save the file to your desktop.
It is a self extracting file.
Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.
If the link to SmitRem above is not working try this one. (http://downloads.subratam.org/smitRem.exe)


*Please download Ewido Security Suite (http://www.ewido.net/en/download/) trial version.
Install Ewido security suite
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
Launch Ewido, there should be an icon on your desktop double-click it.
The program will now go to the main screen
You will need to update Ewido to the latest definition files.
On the left hand side of the main screen click update
Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates (http://www.ewido.net/en/download/updates/). Do NOT run a scan yet.

* Click Here (http://www.downloads.subratam.org/KillBox.exe) and download Killbox and save it to your desktop.


* Click here (http://castlecops.com/zx/flrman1/FixSQ.zip) to download FixSQ.zip and save it to your desktop.
Unzip it to extract the FixSF.reg file it contains.


* Click here (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406) for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Go to Add/Remove programs and uninstall SpywareQuake if it is there. Do not restart your computer if it asks you to do so.


* Doublclick on the FixSQ.reg file to add it to the registry.
Answer yes to confirm the merge.


* Double-click on Killbox.exe to run it.
Put a tick by Standard File Kill.
In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

C:\WINDOWS\system32\stickrep.dll

C:\Program Files\SpywareQuake


Click on the button that has the red circle with the X in the middle after you enter each file.
It will ask for confimation to delete the file.
Click Yes.
Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.
Killbox may tell you that one or more files do not exist.
If that happens, just continue on with all the files. Be sure you don't miss any.
Exit the Killbox.


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Run Ewido:
Click on scanner
Click Complete System Scan and the scan will begin.
During the scan it will prompt you to clean files, click OK
When the scan is finished, look at the bottom of the screen and click the Save report button.
Save the report to your desktop



* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.

* Restart back into Windows normally now.


* Run ActiveScan online virus scan here (http://www.pandasoftware.com/products/activescan.htm)

When the scan is finished, save the results from the scan!

SmitRem creates a log file with the results of it's fix in C:\smitfiles.txt. Go to your C drive and locate the smitfiles.txt file. Copy and paste the contents of the smitfiles.txt file in your next reply here along with a new HiJackThis log and the results from ActiveScan.

Also your friend needs to save HJT to a permanent folder.
Click here (http://www.thespykiller.co.uk/files/HJTsetup.exe) to download HJTsetup.exe
Save HJTsetup.exe to your desktop.

Double click on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
Put a check by Create a desktop icon then click Next again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click Finish and it will launch Hijack This.
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.

Post it in the computer thread next time... :)

afireinside4848
03-31-2006, 08:33 PM
thanks it worked