We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
pc help.....had spyware i think???
Comments
-
For a first scan, yeah pretty normal. But they will be restricting your PCs performence and doing other, rather more concerning things.
Im not sure if its the same with spydoctor but threats or warnings are usually adware. More annoying than harmfull to begin with but if they build up then strange things start to happen.
After you get rid of those and scheduled a scan (chances are there is a little tutorial in the help menu or it is already setup) it should be kept to a minimum.0 -
-
paddytehpyro wrote: »For a first scan, yeah pretty normal. But they will be restricting your PCs performence and doing other, rather more concerning things.
Im not sure if its the same with spydoctor but threats or warnings are usually adware. More annoying than harmfull to begin with but if they build up then strange things start to happen.
After you get rid of those and scheduled a scan (chances are there is a little tutorial in the help menu or it is already setup) it should be kept to a minimum.
hi, ir wasnt the first scan ive been getting help here and have done quite a few scans to try get rid of some nasty stuff. thanks for advise
have now given up smoking since feb 13th 2014 loving the money I'm saving0 -
Reluctant_spender wrote: »Did Spydoctor produce a log, in which case posting it here will help.
sorry just looked and it logged that it had cleared 13 things but not what they were.
btw i tried opening up in safe mode again but that sdfix still wasnt on my desktophave now given up smoking since feb 13th 2014 loving the money I'm saving0 -
it's possible that something may have blocked the download and you have an empty shell on your desktop.
Try this programme - it is free and a standalone anti virus cleaner;
Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
Scan with Dr.Web CureIt as follows:- Double-click on launch.exe to start the program.
- Cancel any prompts to download the latest CureIt version and click Start.
- At the prompt to "Start scan now", click Ok. Allow the setup.exe/driver to load if asked by any of your security programs.
- The Express scan will automatically begin.
(This is a short scan of files currently running in memory, boot sectors, and targeted folders). - If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
- When complete, click Select All, then choose Cure > Move incurable.
(This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
- Now put a check next to Complete scan to scan all local disks and removable media.
- In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
- Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
- When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
- Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
- In the top menu, click file and choose save report list.
- Save the DrWeb.csv report to your desktop.
- Exit Dr.Web Cureit when done.
- Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
- After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
0 -
Reluctant_spender wrote: »it's possible that something may have blocked the download and you have an empty shell on your desktop.
Try this programme - it is free and a standalone anti virus cleaner;
Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
Scan with Dr.Web CureIt as follows:- Double-click on launch.exe to start the program.
- Cancel any prompts to download the latest CureIt version and click Start.
- At the prompt to "Start scan now", click Ok. Allow the setup.exe/driver to load if asked by any of your security programs.
- The Express scan will automatically begin.
(This is a short scan of files currently running in memory, boot sectors, and targeted folders). - If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
- When complete, click Select All, then choose Cure > Move incurable.
(This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
- Now put a check next to Complete scan to scan all local disks and removable media.
- In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
- Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
- When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
- Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
- In the top menu, click file and choose save report list.
- Save the DrWeb.csv report to your desktop.
- Exit Dr.Web Cureit when done.
- Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
- After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
ok will try this now, i have just done another scan and heres report
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/08/2008 at 10:00 AM
Application Version : 4.21.1004
Core Rules Database Version : 3625
Trace Rules Database Version: 1609
Scan type : Complete Scan
Total Scan Time : 00:47:23
Memory items scanned : 471
Memory threats detected : 0
Registry items scanned : 5045
Registry threats detected : 0
File items scanned : 78184
File threats detected : 21
Adware.Tracking Cookie
C:\Documents and Settings\tina \Cookies\tina_@bs.serving-sys[1].txt
C:\Documents and Settings\tina\Cookies\tina_@advertising[1].txt
C:\Documents and Settings\tina \Cookies\tina_@e-2dj6wmkiwkdjwgq.stats.esomniture[1].txt
C:\Documents and Settings\tina\Cookies\tina_@247realmedia[1].txt
C:\Documents and Settings\tina\Cookies\tina_@tracking.summitmedia.co[1].txt
C:\Documents and Settings\tina\Cookies\tina_@paypal.112.2o7[1].txt
C:\Documents and Settings\tina\Cookies\tina_@adviva[1].txt
C:\Documents and Settings\tina\Cookies\tina_@e-2dj6wcmiggd5ogp.stats.esomniture[1].txt
C:\Documents and Settings\tina \Cookies\tina_@apmebf[1].txt
C:\Documents and Settings\tina \Cookies\tina_@mediaplex[1].txt
C:\Documents and Settings\tina \Cookies\tina_@e-2dj6wdmyshdjmco.stats.esomniture[1].txt
C:\Documents and Settings\tina\Cookies\tina_@revsci[1].txt
C:\Documents and Settings\tina \Cookies\tina_@atdmt[2].txt
C:\Documents and Settings\tina \Cookies\tina_@adrevolver[2].txt
C:\Documents and Settings\tina \Cookies\tina_@stats.paypal[2].txt
C:\Documents and Settings\tina \Cookies\tina_@adtech[1].txt
C:\Documents and Settings\tina \Cookies\tina_@serving-sys[2].txt
C:\Documents and Settings\tina \Cookies\tina_@specificclick[2].txt
C:\Documents and Settings\tina \Cookies\tina_@media.adrevolver[1].txt
C:\Documents and Settings\tina \Cookies\tina_@e-2dj6wglyahczalo.stats.esomniture[1].txt
C:\Documents and Settings\tina \Cookies\tina_@doubleclick[1].txthave now given up smoking since feb 13th 2014 loving the money I'm saving0 -
Reluctant_spender wrote: »it's possible that something may have blocked the download and you have an empty shell on your desktop.
Try this programme - it is free and a standalone anti virus cleaner;
Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
Scan with Dr.Web CureIt as follows:- Double-click on launch.exe to start the program.
- Cancel any prompts to download the latest CureIt version and click Start.
- At the prompt to "Start scan now", click Ok. Allow the setup.exe/driver to load if asked by any of your security programs.
- The Express scan will automatically begin.
(This is a short scan of files currently running in memory, boot sectors, and targeted folders). - If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
- When complete, click Select All, then choose Cure > Move incurable.
(This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
- Now put a check next to Complete scan to scan all local disks and removable media.
- In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
- Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
- When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
- Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
- In the top menu, click file and choose save report list.
- Save the DrWeb.csv report to your desktop.
- Exit Dr.Web Cureit when done.
- Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
- After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
well i downloaded this but had no option to save to desktop and cant find it? when i clicked your link it just asked me if i wanted to run it
oops think i done it nowhave now given up smoking since feb 13th 2014 loving the money I'm saving0 -
ok - what operating system are you using - Xp or Vista
Superantispyware only found cookies so that's ok at the moment0 -
Reluctant_spender wrote: »ok - what operating system are you using - Xp or Vista
Superantispyware only found cookies so that's ok at the moment
all done and i think its deleted that loaded exe here goes
loader.exe;c:\windows\system32;Trojan.Fakealert.2085;Deleted.;
SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\tina deacon\Desktop\SDFix.exe;Tool.Prockill;;
SDFix.exe;C:\Documents and Settings\tina deacon\Desktop;Archive contains infected objects;Moved.;
Process.exe;C:\Documents and Settings\tina deacon\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\tina deacon\Desktop\SmitfraudFix;Tool.ShutDown.11;;
SDFix[1].exe\SDFix\apps\Process.exe;C:\Documents and Settings\tina deacon\Local Settings\Temporary Internet Files\Content.IE5\FB29XWCW\SDFix[1].exe;Tool.Prockill;;
SDFix[1].exe;C:\Documents and Settings\tina deacon\Local Settings\Temporary Internet Files\Content.IE5\FB29XWCW;Archive contains infected objects;Moved.;
restart.exe;C:\RECYCLER\S-1-5-21-2622397936-3775474779-1101431435-1007\Dc1;Tool.ShutDown.11;;
Process.exe;C:\RECYCLER\S-1-5-21-2622397936-3775474779-1101431435-1007\Dc11\apps;Tool.Prockill;;
A0032371.rbf;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485;Probably DLOADER.Trojan;;
A0032375.rbf;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485;Probably DLOADER.Trojan;;
stream000\sprtsync.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485\A0032404.MSI\stream000;Probably DLOADER.Trojan;;
stream000\modem_common.js;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485\A0032404.MSI\stream000;Probably SCRIPT.Virus;;
stream000\sma_common.js;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485\A0032404.MSI\stream000;Probably SCRIPT.Virus;;
stream000\sprtupdate.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485\A0032404.MSI\stream000;Probably DLOADER.Trojan;;
stream000;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485\A0032404.MSI;Archive contains infected objects;;
A0032404.MSI;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP485;Archive contains infected objects;Moved.;
A0034896.scr;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.7;;
A0034905.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.3;;
A0034906.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.4;;
A0034907.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MWS.78;;
A0034910.SCR;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.7;;
A0034913.EXE;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.9;;
A0034915.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.Msearch;;
A0034918.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.11;;
A0034922.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.12;;
A0034924.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MWS.76;;
A0034925.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.13;;
A0034926.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.14;;
A0034928.EXE;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.15;;
A0034929.EXE;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.Websearch.6;;
A0034931.EXE;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.Websearch.8;;
A0034936.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.Websearch.13;;
A0034937.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MyWebSearch.5;;
A0034938.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MWS.72;;
A0034939.EXE;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.Websearch.7;;
A0034940.DLL;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP499;Adware.MWS.74;;
A0035479.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP501;Adware.MWS.72;;
A0061955.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP563;Trojan.Fakealert.2085;Deleted.;
A0061956.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP563;Trojan.Fakealert.2085;Deleted.;
A0062126.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP564;Trojan.Fakealert.2085;Deleted.;
A0062127.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP564;Trojan.Fakealert.2085;Deleted.;
A0062152.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP566;Trojan.Fakealert.2085;Deleted.;
A0062153.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP566;Trojan.Fakealert.2085;Deleted.;
A0062233.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP566;Trojan.Fakealert.2085;Deleted.;
A0062234.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP566;Trojan.Fakealert.2085;Deleted.;
A0062260.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP568;Trojan.Fakealert.2085;Deleted.;
A0062261.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP568;Trojan.Fakealert.2085;Deleted.;
A0062337.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP569;Trojan.Fakealert.2085;Deleted.;
A0062338.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP569;Trojan.Fakealert.2085;Deleted.;
A0062348.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP570;Trojan.Fakealert.2085;Deleted.;
A0062349.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP570;Trojan.Fakealert.2085;Deleted.;
A0062355.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP570;Trojan.Fakealert.2085;Deleted.;
A0062356.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP570;Trojan.Fakealert.2085;Deleted.;
A0062429.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP571;Trojan.Fakealert.2085;Deleted.;
A0062430.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP571;Trojan.Fakealert.2085;Deleted.;
A0062441.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP572;Trojan.Fakealert.2085;Deleted.;
A0062442.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP572;Trojan.Fakealert.2085;Deleted.;
A0062448.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP572;Trojan.Fakealert.2085;Deleted.;
A0062449.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP572;Trojan.Fakealert.2085;Deleted.;
A0062481.exe;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Tool.Prockill;;
A0062548.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Trojan.Fakealert.2085;Deleted.;
A0062549.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Trojan.Fakealert.2085;Deleted.;
A0062557.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Trojan.Fakealert.2085;Deleted.;
A0062558.dll;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Trojan.Fakealert.2085;Deleted.;
A0062568.exe;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Trojan.Fakealert.2085;Deleted.;
A0062569.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573\A0062569.exe;Tool.Prockill;;
A0062569.exe;C:\System Volume Information\_restore{EBE7F5B4-9626-4FB0-8C04-62912E099CB4}\RP573;Archive contains infected objects;Moved.;
dbldrv.dll;C:\WINDOWS\system32;Trojan.Fakealert.2085;Deleted.;
dbxdrv.dll;C:\WINDOWS\system32;Trojan.Fakealert.2085;Deleted.;
Process.exe;C:\WINDOWS\system32;Tool.Prockill;;
please tell me its all ok was worried as i think i did something wrong i didnt uncheck heuristic thing as i didnt see ithave now given up smoking since feb 13th 2014 loving the money I'm saving0 -
Now that cleared out some serious crap, including the loader.exe
The vast majority of the above is from system restore.
I think you are clean now.- Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.
Go to Start > Programs > Accessories > System Tools and click "System Restore"
Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
Then go to Start > Run and type: Cleanmgr
Click "OK".
Click the "More Options" Tab.
Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
[*]Make sure you install all the security updates for Windows, Internet explorer & Microsoft Office
Whenever a security problem in its software is found, Microsoft will usually create a patch for it to that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
Go here to check for & install updates to Microsoft applications
Note: The update process uses activex, so you will need to use internet explorer for it, and allow the activex control that it wants to install0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 352.1K Banking & Borrowing
- 253.6K Reduce Debt & Boost Income
- 454.2K Spending & Discounts
- 245.1K Work, Benefits & Business
- 600.8K Mortgages, Homes & Bills
- 177.5K Life & Family
- 258.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards