Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 34

Thread: Help with some spyware

  1. #21
    Join Date
    Apr 2007
    Posts
    27
    Okay here it is.
    Attached Files Attached Files

  2. #22
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, I see what it is...give me a bit and I will get back with you on this one.

  3. #23
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    The error is related to the removed Vundo infection. A start up registry entry remains but of course the infection is gone so the file is no longer on the computer but of course the computer doesn't know that and it keeps looking for it.
    Try this first;
    Download RegCleaner
    Run the program.
    When it opens go to the very top and choose Tools, Registry Cleanup, Do Them All.
    The program will then scan the registry for old entries, entries no longer needed, entries for removed programs, etc.
    This will just take a few minutes.
    Once complete it will show you a list of items found you no longer need.
    Then go up to Select. All.
    Checkmarks will be placed in items that will be deleted.
    Then click the Remove Selected Button.
    These items will be removed.
    Close out the program.
    This program DOES make a backup of all items removed so in the rare event something is removed that is incorrect you can put it back.
    Run the program, reboot and see if you still get the error.

  4. #24
    Join Date
    Apr 2007
    Posts
    27
    Ok I've done that, but I still get the error when my computer starts up.

  5. #25
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    I am as dumb as a box of rocks! I never had you run HJT again and do the fixes there
    Run HJT again and place checkmarks next to the following entries if they still exist;
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\fiobxsax.dll",setvm
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O15 - Trusted Zone: http://www.ti.com (Did you add this yourself? If NOT then place a checkmark next to this one too. If you DID add it then leave it.)
    O16 - DPF: {20050325-D35A-4233-926E-2E801AE25949} (NMJPStarter15 Class) - http://www.netmarble.jp/_common/cab/NMStarterJP5.cab

    Once you have placed the checkmarks then click the FIX button.
    Exit HJT.
    Reboot and run one more HJT scan.
    If you still get the error then you may have to go into the Registry manually and remove it.

  6. #26
    Join Date
    Apr 2007
    Posts
    27
    Okay that error is gone, thanks for the help. But I think I might have another problem.. there is a hidden folder in my C: drive called Uploads and its directly in it C:\Uploads. Inside of it are 15,000 zip folders all named after popular programs/games and other stuff..and they are all just 1 KB. Is this something to just delete or is there something else I need to do?

  7. #27
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, this appears to be a worm.
    WORM_VB.AQ
    This worm also drops the nonmalicious file BSZIP.DLL. It uses the said file to drop its compressed copy, A.ZIP, using ZIP compression.
    This worm creates UPLOADS folder in the root directory, which is usually C:/. It then drops several .ZIP copies of itself using file names of known applications in the created folder.
    Go here Trend Micro HouseCall

    Do their online scan and see if it will fix.

  8. #28
    Join Date
    Apr 2007
    Posts
    27
    Sorry for not posting a reply. I haven't been able to get to the computer at all this week. It seems my brother has downloaded some "game" or something... and unleashed a bunch more spyware on my computer. I tried using Trend Micro HouseCall but it froze during the cleaning process, and then caused internet explorer to crash. Should I try it again? And should I start the whole cleaning process over again now?

  9. #29
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    I would begin it all again using PP's link...sorry, but it wasn't clean to begin with and now you figure there is more. So let's start over with the steps in the link, post the requested logs and we will see where things stand.
    Judy

  10. #30
    Join Date
    Apr 2007
    Posts
    27
    Okay, I followed the sticky again. Windows Defender wasn't able to delete anything that it found, I let it run overnight trying to remove the things.. but it didn't make any progress. AVG did delete a few things. My newest log is attached.
    Attached Files Attached Files

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •