Spybot won't run

Status
Not open for further replies.
Thanks again for everything. I'm 66 years old and a little slow sometimes.
I was born 4/19/1942 so now I don't know if I should call you sir or sonny? Only the Jax location in the profile information.

Let's move on, before we uninstall combofix there are files I was sure were bad that did not get removed by CFScript? At least it removed AWF and for that I am greatful.

The files are 15 that are marked as hidden files and they all look like this:
C:\WINDOWS\TEMP\Perflib_Perfdata_100.dat <<< this is just one, they are different numbers.
What I need to do is find out what they are, being Temp files, there should be no reason why we can not delete them.

Make sure you can view all files and folders here:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Now use one or more of these free online scanners to find out what they are:
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/

You do not need to scan them all, scan two or three at random, that will be enough so you will know if they are malware or not. Post that information for me to view. If the ones you scan are malware obviously, then delete them all. I can not tell when they were created, but you should be able to by right clicking and looking at properties. You may delete everything in that Temp folder. A few old files put there by Windows may not delete, but all recent files should, expecially anything put there by the malware.

uninstall list <<< I look for malware and security issues only, and I will not know them all.

Here is a small free tool that lets you know when something needs an update if you are interested:
https://psi.secunia.com/ While PSI runs in the System Tray for realtime notifications, I personally prefer to turn it off in MSConfig and run it from All Programs when I want to do a check.

Adobe Reader 7.0 <<< out of date and being exploited by hackers
http://www.filehippo.com/download_adobe_reader/

J2SE Runtime Environment 5.0 Update 2 <<< please see the information in this link:
Java(TM) 6 Update 2
http://forums.spybot.info/showpost.php?p=12880&postcount=2
(posted earlier in instructions)

SpywareBlaster v3.5.1 <<< a good program, but out of date. to update you must turn off the old program.
1) Open the interface and DISABLE ALL PROTECTION
2) Close the program and uninstall it in Add Remove Programs
3) Dolwnload v4.1 here: http://www.javacoolsoftware.com/spywareblaster.html
4) Make sure you update and then enable all protection

Merlin Snipe program <<< is that this:
http://www.pctechzone.com/merlin/ad/
Here is more information about AWF:
http://www.google.com/search?hl=en&q=trojan+AWF&btnG=Google+Search
This is a file infector trojan and if you look at the code box for CFScript you will see:
C:\Program Files\PC TechZone\AuctionMagic7\bak\Snipe.exe <<< the clue it was infected
That program was infected and replaced by the trojan. Though combofix does try to fix the problem, it may be you will have to install the program again.

When the hyper-links do not work, do you get any error message I can research?
Here is some generic informaton at Google:
http://www.google.com/search?hl=en&q=hyper-links+do+not+work&btnG=Search

Jim, let's see if we can get that far this time. I would not do a lot of online activites until we are sure you are clean and I have posted information to help you harden your defense.

Thanks

Phil from Clearwater
 
Phil, I'll have to start calling you Junior since my birthdate is 4/9/1942. 10 days is a lot of time :-)

There is only 1 file in c:\windows\temp and that is perflib_perfdata_588.dat but it won't let me delete it since it is in use.

I have opened up the viewfile settings.

The online scanners don't seem to work for me. When I select the file I want to scan it won't seem to upload. I tried it on all three sites.

I can't update anything such as J2SE or Adobe due to my missing admin privileges.

I re-installed Spyware Blaster and Snipe and they are both working fine now. It cleared up the problem I was having with Snipe.

Hyper-links are working everywhere except this forum. No error message. When I mousover the link, the full URL appears in the box on the lower left but clicking does nothing. I just right click on the link and choose copy shortcut and put it in the browser address box. Not really a problem.

In the meantime I have run Spybot and MBAM Spybot found "Right Media" which I think I get from the Drudge Report but MBAM ran clean.

Well Phil... whats next?

Thanks, Jim
 
Thanks for the feedback Old Timer. Let's see if we can clear up the last details.

There is only 1 file in c:\windows\temp and that is perflib_perfdata_588.dat but it won't let me delete it since it is in use.
Boot the computer into safe mode and delete that file there.
http://spyware-free.us/tutorials/safemode/
I can't update anything such as J2SE or Adobe due to my missing admin privileges.
Post for me exactly the message you get when you try to sign in as administrator so I can research the message.
Hyper-links are working everywhere except this forum.
did you look at the links in Google, perhaps you will recognize a similiar sy,ptom. I am hard pressed to know how to research this without more information.

http://www.lavasoftsupport.com/index.php?showtopic=19240

Watch for a private message so it does not go to the spambox.

Thanks Phil
 
Hi Phil, Thanks for the tip on going to safe mode for deleting those files. I have now deleted perflib_perfdata_588.dat and msziptools.dll.

Currently, aside from mopping up this malware mess, my biggest problem is that I don't have Windows Installer and I can't install it since Microsoft can't verify that I have a valid copy of XP. I can't use my installation disk because my CD drive is broken. I have one on order but it's not here yet. I have been to this point before and from what I remember, I will eventually get to a point where I get a message that says roughly "You cant install this because you are not an Administrator". I'm convinced that my admin privileges were taken away by malware over a year ago, but I didn't worry about it because my machine was doing all the things I needed. But now that I know the dangers of security risk, I want to get everything up to snuff.

I'm not worried about the hyperlink thing. I'm used to it since I can't use links from Email either.

Thanks for all your help and interest, and patience.

Regards, Jim
 
Thanks for providing that information, you did find the private message I sent you?

You will need to be able to get critical updates, so that issue must be cleared up. If you do not, you will continue to get infected.

Here are a few links that might help.

Microsoft Technical Support
http://support.microsoft.com/

Genuine Windows
http://www.microsoft.com/genuine/

Validate Windows XP
http://www.microsoft.com/windowsxp/using/setup/winxp/validate.mspx

Since you have issues I can not help with, let's do this:

Remove combofix from the computer like this:

Click START then RUN
Now type or copy Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.

CF_Cleanup.png


Clean infected System Restore files:
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

I suggest you update MBAM and run a scan to make sure it is scanning clean.

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

http://www.malwarecomplaints.info/

Thanks...Phil
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

http://users.telenet.be/bluepatchy/miekiemoes/Links.html
 
Status
Not open for further replies.
Back
Top