adware/spyware removal

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

For the past little while now I have been trying to reove 3 spywares and they
keep coming back I cannot stop it from comming back. I have tried looking it
up and using the removal steps and even going into the registryto try and
find it but I can't. Here are the three I am getting on my xp home edition,
W32.sinnakaA@mm, clearsearch, and exploit toolbarpartner.com
 
From: "stacey" <[email protected]>

| For the past little while now I have been trying to reove 3 spywares and they
| keep coming back I cannot stop it from comming back. I have tried looking it
| up and using the removal steps and even going into the registryto try and
| find it but I can't. Here are the three I am getting on my xp home edition,
| W32.sinnakaA@mm, clearsearch, and exploit toolbarpartner.com



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate utility.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud, SpyAxe, SpyFalcon, et. al., removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in your bowser
but your PC will automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.


ALTERNATE:

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.


Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.



* * * Please report back your results * * *
 
I went through the steps like was ask of me and in the first one I could not
find any of the files to delete not even SpyFalcon and I tried several times
both in normal and safe mode. The second and third steps it kept comming up
saying they could not find cetain files I even tried it with firewall off. I
also tried them several times. I then went into my Spyware killer to see if
those 3 spyware were still there and to my surprise it found 89 new spyware
in the registry. I thank you for the post but can you please tell me What Is
Going On?
 
stacey said:
I went through the steps like was ask of me and in the first one I
could not find any of the files to delete not even SpyFalcon and I
tried several times both in normal and safe mode. The second and third
steps it kept comming up saying they could not find cetain files I
even tried it with firewall off. I also tried them several times. I
then went into my Spyware killer to see if those 3 spyware were still
there and to my surprise it found 89 new spyware in the registry. I
thank you for the post but can you please tell me What Is Going On?

You didn't tell us the exact name of your "Spyware killer" but there are
several variations of that name on the rogue anti-spyware list here at
MVP Eric Howes' website:
http://www.spywarewarrior.com/rogue_anti-spyware.htm#products

Check and see if your "Spyware killer" is on the list. If it is, that
would explain why you may be getting false positives. Uninstall any
rogue programs and scan with accepted antimalware programs like
Ad-aware, Spybot Search & Destroy, etc.

If you do not have a rogue anti-spyware program (and I really think you
do), you can run a HijackThis log and post it to one of the specialty
forums listed below (not here, please):

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net/viewforum.php?f=30
http://castlecops.com/forum67.html
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

Malke
 
The spyware killer I use is Cosmi and it was not on the list and I also use
Ad-ware and spybot. I do use Bazooka which is on that list of rogue spyware
killers so I will delete it. How do I run a Hijackthis log?
 
stacey said:
The spyware killer I use is Cosmi and it was not on the list and I
also use Ad-ware and spybot. I do use Bazooka which is on that list of
rogue spyware killers so I will delete it. How do I run a Hijackthis
log?

Refer to the links I already gave you. Here they are again:

As I said before, do not post your log here; register and post at one of
the forums listed above.

Malke
 
Back
Top