We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

pc help.....had spyware i think???

1246789

Comments

  • Donnie
    Donnie Posts: 9,862 Forumite
    crystal9 wrote: »
    ok will do and i will get rid of the norton anti virus i got with google pack

    Get rid of the GooglePack and it's add-ons. It's only more clutter.

    Run SmitfraudFix

    Suspicious entries: C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS Click Start > Run > and type in:

    services.msc

    Click OK.

    In the services window find PRISMXL.SYS
    Right click and choose "Properties". On the "General" tab under "Service
    Status" click the "Stop" button to stop the service. Beside "Startup Type"
    in the dropdown menu select "Disabled". Click Apply then OK. Exit the
    Services utility.


    Note: You may get an error here when trying to access the properties of the
    service. If you do get an error, just select the service and look there in
    the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.


    Fix:
    O4 - HKCU\..\Run: [PanelApp] C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    O4 - HKCU\..\Run: [loader.exe] C:\WINDOWS\system32\loader.exe
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    Donnie wrote: »
    Get rid of the GooglePack and it's add-ons. It's only more clutter.

    Run SmitfraudFix

    Suspicious entries: C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS Click Start > Run > and type in:

    services.msc

    Click OK.

    In the services window find PRISMXL.SYS
    Right click and choose "Properties". On the "General" tab under "Service
    Status" click the "Stop" button to stop the service. Beside "Startup Type"
    in the dropdown menu select "Disabled". Click Apply then OK. Exit the
    Services utility.


    Note: You may get an error here when trying to access the properties of the
    service. If you do get an error, just select the service and look there in
    the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.

    Fix:
    O4 - HKCU\..\Run: [PanelApp] C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    O4 - HKCU\..\Run: [loader.exe] C:\WINDOWS\system32\loader.exe

    thanks donnie i will try to do this and get rid of google pack shouldn't i keep the spydoctor tho as that did find a lot of spyware
    have now given up smoking since feb 13th 2014 loving the money I'm saving
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    Donnie wrote: »
    Get rid of the GooglePack and it's add-ons. It's only more clutter.

    Run SmitfraudFix

    Suspicious entries: C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS Click Start > Run > and type in:

    services.msc

    Click OK.

    In the services window find PRISMXL.SYS
    Right click and choose "Properties". On the "General" tab under "Service
    Status" click the "Stop" button to stop the service. Beside "Startup Type"
    in the dropdown menu select "Disabled". Click Apply then OK. Exit the
    Services utility.


    Note: You may get an error here when trying to access the properties of the
    service. If you do get an error, just select the service and look there in
    the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.

    Fix:
    O4 - HKCU\..\Run: [PanelApp] C:\Documents and Settings\tina deacon\Local Settings\Application Data\Valued Opinions\PanelApp\PanelApp.exe
    O4 - HKCU\..\Run: [loader.exe] C:\WINDOWS\system32\loader.exe

    couldnt run this as my mcafee blocked it didnt trust it at all
    have now given up smoking since feb 13th 2014 loving the money I'm saving
  • Donnie
    Donnie Posts: 9,862 Forumite
    Did you follow the other instructions?

    You may have to disable McAfee in order to be able to run SmitfraudFix. You can re-enable afterwards.

    Is PanelApp something you use?
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    Donnie wrote: »
    Did you follow the other instructions?

    You may have to disable McAfee in order to be able to run SmitfraudFix. You can re-enable afterwards.

    Is PanelApp something you use?
    think i might have diabled mcafee as i keep getting the yellow sign saying your pc isnt protected :confused:

    oh gawd im so useless with this stuff.

    value opinion is from a survey site and they told me months ago i have to leave it on
    have now given up smoking since feb 13th 2014 loving the money I'm saving
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    well done it not sure what it did tho, it asked me to delete register (i think) i said yes
    have now given up smoking since feb 13th 2014 loving the money I'm saving
  • kev1n3
    kev1n3 Posts: 567 Forumite
    If you ever think you may have any of the Vundo family of Trojans on your system download this great little tool. http://www.bleepingcomputer.com/malware-removal/remove-vundo-virtumonde its saved my bum a few times.
    Your tax bill is the penalty you pay for not helping the right candidates get into office.:D
  • Not sure where you are at presently - Value panel looks legit - if you want to remove it do.

    I am more concerned about loader.exe - this is a Zlob infection.

    Mcaffe will go nuts at this program but it is safe.

    Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

    Please download SDFix by AndyManchesta and save it to your desktop.
    When using this tool, you must use the Administrator's account or an account with "Administrative rights"
    • Double click SDFix.exe and it will extract the files to %systemdrive%
    • (this is the drive that contains the Windows Directory, typically C:\SDFix).
    • DO NOT use it just yet.
    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Open the SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Copy and paste the contents of the results file Report.txt in your next replyalong with a new HijackThis log.
    -- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
    Please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
    Press Ok and then run SDFix again.

    -- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\FixPath.exe /Q
    Reboot and then run SDFix again.

    -- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
    %SystemRoot%\system32\cmd.exe
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    kev1n3 wrote: »
    If you ever think you may have any of the Vundo family of Trojans on your system download this great little tool. http://www.bleepingcomputer.com/malware-removal/remove-vundo-virtumonde its saved my bum a few times.

    thank you, i never know what to use, ive never had any problems before just this once and still dont know how it got on pc im wondering if it was a site my son went onto who knows :confused:
    have now given up smoking since feb 13th 2014 loving the money I'm saving
  • crystal9
    crystal9 Posts: 3,813 Forumite
    Xmas Saver!
    Not sure where you are at presently - Value panel looks legit - if you want to remove it do.

    I am more concerned about loader.exe - this is a Zlob infection.

    Mcaffe will go nuts at this program but it is safe.

    Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

    Please download SDFix by AndyManchesta and save it to your desktop.
    When using this tool, you must use the Administrator's account or an account with "Administrative rights"
    • Double click SDFix.exe and it will extract the files to %systemdrive%
    • (this is the drive that contains the Windows Directory, typically C:\SDFix).
    • DO NOT use it just yet.
    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Open the SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Copy and paste the contents of the results file Report.txt in your next replyalong with a new HijackThis log.
    -- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
    Please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
    Press Ok and then run SDFix again.

    -- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
    %systemdrive%\SDFix\apps\FixPath.exe /Q
    Reboot and then run SDFix again.

    -- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
    %SystemRoot%\system32\cmd.exe

    wow this sounds scary for me to do not sure ill do it right ive got no printer at the mo as mine is broke .

    what i did earlier (what donnie said) would that of helped?
    have now given up smoking since feb 13th 2014 loving the money I'm saving
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.