I beleive I've picked up some spyware. Every time I use google to search the links found are redirected to other sites. I've tried running Spybot and Adaware but they both crash before completeing the scan. Anyone else had similar experiences?
Try running spybot from Safe Mode. Also, you might try renaming the executable spybot.exe to dumdum.exe (or whatever). Sometimes spyware/viruses will try to prevent executables from running.
I also use Autoruns to ferret out what is running when Windows starts. If you take a look at what's starting (minus the Microsoft entries) you can uncheck things that appear suspicious, then reboot and try to run your scan.
The other thing you can do is create a BART PE boot CD and setup the spybot plugin (all free) to scan your system without having windows booted. That makes it easier to get the nasties out. I never leave home without it. You can also use a mcafee command line virus scanner from the same cd (free also).
to download HijackThis. Click scan and save a logfile, then post it here so
we can take a look at it for you. Don't click fix on anything in hijack this
as most of the files are legitimate.
Member of ASAP Alliance of Security Analysis Professionals
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:15 PM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
to your
desktop.
· Double-click VundoFix.exe to run it.
· Click the Scan for Vundo button.
· Once it's done scanning, click the Remove Vundo button.
· You will receive a prompt asking if you want to remove the files, click
YES
· Once you click yes, your desktop will go blank as it starts removing
Vundo.
· When completed, it will prompt that it will shutdown your computer, click
OK.
· Turn your computer back on.
Go here and downlaod the latest version of java, once
downloaded, go to add/remove and uninstall all previous versions of java
from add/remove and then instlall the latest version you just downloaded!
Please download SmitfraudFix
(by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.
You should print out these instructions, or copy them to a NotePad file for
reading while in Safe Mode, because you will not be able to connect to the
Internet to read from this site.
Next, please reboot your computer in Safe Mode by doing the following
:
Restart your computer
After hearing your computer beep once during startup, but before the
Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and
double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter"
to delete infected files.
You will be prompted: "Registry cleaning - Do you want to clean the
registry?"; answer "Yes" by typing Y and press "Enter" in order to
remove the Desktop background and clean registry keys associated with the
infection.
The tool will now check if wininet.dll is infected. You may be
prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process;
if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process;
please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt
Warning: running option #2 on a non infected computer
will remove your Desktop background.
NOTE: If you have downloaded ComboFix previously please delete that
version and download it again!
Restart your computer and begin tapping the F8 key on your keyboard just
before Windows starts to load. If done right a Windows Advanced Options menu
will appear. Select the Safe Mode option and press Enter.
Perform the following actions in Safe Mode.
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its
running. That may cause it to stall
post another hijack this log, the combo, the vundo and the smitfraud logs!
Member of ASAP Alliance of Security Analysis Professionals
You should run it from Internet Explorer as it didn't cooperate with Firefox when I tried it from my PC. You have to agree to run the ActiveX control for it to install/run.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.