Recommended Driver Scanner

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » Spyware won't go away!

Spyware / AdWare - Spyware won't go away! posted in the Security & Safety forums; A while ago, I was infected with something called UnSpyPC (A fake spyware program). I got most of it out with adaware, but something must still be here. When I ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
acontrasto - See this Members User comments on their Profile page
Default Spyware won't go away!

A while ago, I was infected with something called UnSpyPC (A fake spyware program). I got most of it out with adaware, but something must still be here. When I start my computer, I get an advertisement on the right side of my screen with links to different gambling, dating, XXX sites, and more. I found the actual picture files stored on my hard drive that are loaded into this ad in the system32 directory, and I delete them every time my computer starts, but they keep coming back. I noticed that, every time my system starts, norton AV is loaded, but the spyware must somehow stop the internet protection because it always seems to be able to download those files again. I came on here and saw someone with a similar problem, I followed the advice given to him but it didn't work for me.

Please help!
Andrew
Attached Files
File Type: log hijackthis.log (4.2 KB, 6 views)


  #2  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Acontrasto , welcome to PCHF.

Youre hjt log looks clean , nothing visible there.

But have a look if you have this file:

C:\ProgramFiles\UnSpyPC\uninstall.exe

And run it if you do and see if that helps.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
acontrasto - See this Members User comments on their Profile page
Default

Nope, there isn't even an UnSpyPC directory anymore. That was probably one of the first things I got rid of.


  #4  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Can you start hjt , select the "open the misctools section" and then "open uninstall manager" then press "save list" and post that list here?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
acontrasto - See this Members User comments on their Profile page
Default Uninstall List

Here's the uninstall list. I did a scan with bitdefender and found some new information that norton AV didn't find... I had a virus called Trojan.Downloader.FFZ. I chose to delete all files infected. IE is still sometimes being redirected when I do a google/yahoo/msn search though, so problem not solved yet.
Attached Files
File Type: txt uninstall_list.txt (2.1 KB, 4 views)


  #6  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

The only app im not sure about is SymNet , it brings up mixed results when looking it up. Do you know it/install it?


Also have look if one of these rootkit scanners finds something:

http://www.f-secure.com/exclude/blacklight/index.shtml

http://www.greatis.com/unhackme/download.htm

And report back if they find anyhing.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 12-20-2005
Bronze Member
 
Join Date: Dec 2005
Posts: 5
acontrasto - See this Members User comments on their Profile page
Default Found a few things...

I do not recognize symnet. As for the other two programs, blacklight found 6 hidden files, and the other found nothing. I renamed the files and rebooted. When my computer started up, there was still something stopping norton auto protect, but this time, no advertisement popped up on the right, and when I checked in the system32 directory, those files that I had previously deleted were still deleted, so that's a step in the right direction. I also found 5 of the 6 files that I renamed and moved them to the recycle bin. The files I found are called: cseiz.exe, sphlp32.exe, favset.exe, filesafer23.exe, and idemlog.exe. I also did another norton AV check, and I came up with an adware found. Filename: Dc77.ren, Threat Name: Adware.Livechat. I'm guessing that this file is the 6th renamed file since it ends with .ren. IE is still being redirected.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Webroot guesstimates inflate UK spyware problem. joe5 Security Watch 0 10-21-2005 07:04 PM
Spyware and Adware: A Warrior's Guide. joe5 Security Watch 0 10-10-2005 08:51 PM
New Sinister Spyware Out merlin Security Watch 0 08-31-2005 12:59 AM
Inside Spyware - 4 part article. joe5 Security Watch 0 08-15-2005 09:13 PM
[FIXED] bad spyware kennyblankenship [Fixed] Hijackthis! Logs 11 05-02-2005 09:31 PM

All times are GMT +1. The time now is 11:28 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top