Author Topic: Infected by a Spyware Help Please  (Read 3176 times)

0 Members and 1 Guest are viewing this topic.

AJones

  • Guest
Infected by a Spyware Help Please
« on: February 01, 2006, 02:53:13 PM »
Hi: I was unlucky enough to double click a file called crack.exe on a CD, Now my WinXP is infected, I get this icon in the Icon bar mentioning WinXP is infected with Spyware, press click to download spyware removers (but does nothing beyond this message). I cannot get Opera to load any page, or any other browser for that matter. I constantly get a beeping sound, CPU is over 95%. Spybot S&D claims to have removed, DOS Exploits, WWW-Cache Trojans and some other WWW Trojans. AVAST on boot up scan removed a Trojan in System Volume Information. Thats it. I still get this Win XP ixon saying my System is infected and I still cannot get Opera or any other browser to load webpages Any leads as to how I remove this Virus the file I double clicked was crack.exe.

I removed several other spyware manually paytime.exe, & C:/Winstall.exe. I have smss.exe under it winlogon.exe consuming a lot of cpu ie 13 threads. I find on Google that smss.exe and winlogon.exe can be trojans disguised as WIndows files. both smss.exe and winlogon.exe are in C:/WINDOWS/System32 dir. Will it harm my computer. The message that stated you have been infected is removed sinc remove of paytime.exe, I still have this beeping noise and Opera wont work, Skype wont work they just crash

Thanks Much, AJ

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Infected by a Spyware Help Please
« Reply #1 on: February 01, 2006, 03:09:42 PM »
Hi AJones,

Please download SmitRem.exe from here:

http://noahdfear.geekstogo.com/

Download, install and update Ewido anti-malware program:

http://www.ewido.net/en/

(If you can't download it on your computer, you'll have to do it on another and save it onto disk. Also download the signature database here:

http://www.ewido.net/en/download/)

Download, install and update Ad-Aware, again on another computer if you have to, also downloading the definitions.

http://www.lavasoft.com/

(Go to download page.)

Reboot into safe mode (tap F8 while rebooting) and scan with SmitRem, Ewido, Spybot and Ad-Aware.)

Good luck!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

AJones

  • Guest
Re: Infected by a Spyware Help Please
« Reply #2 on: February 01, 2006, 06:18:39 PM »
Thanks Much: I downloaded SmitRem and Ewido and did as told.

Ewido seems to have removed 8 spyware, the rest Ad-Aware, SpyBot & SmitRem did not find anything. I am including the Ewido report. I continue to get teh same problem, My CPU is 95%, winlogon.exe whoes parent process is smss.exe is screwing it up. I have frequent beeping sound, Opera & Skype crash.

Any Help greatfully appricieated.

Thanks,
AJ

---------------------------------------------------------
 ewido anti-malware - Scan report
---------------------------------------------------------

 + Created on:         11:47:26 AM, 2/1/2006
 + Report-Checksum:      2B56CF41

 + Scan result:

   HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
   C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
   :mozilla.6:C:\RECYCLER\NPROTECT\00579191.MOZ -> Spyware.Cookie.Fuck-access : Cleaned with backup
   C:\System Volume Information\_restore{31882CA9-A57D-4B69-88CE-5DD3BBFE2D94}\RP9\A0013764.exe -> Hijacker.StartPage.adi : Cleaned with backup
   C:\System Volume Information\_restore{31882CA9-A57D-4B69-88CE-5DD3BBFE2D94}\RP9\A0013790.exe -> Not-A-Virus.Hoax.Win32.Renos.az : Cleaned with backup
   C:\WINDOWS\country.exe -> Trojan.Small : Cleaned with backup
   C:\WINDOWS\kl1.exe -> Logger.Small.eu : Cleaned with backup
   C:\WINDOWS\tool2.exe -> Not-A-Virus.Hoax.Win32.Renos.az : Cleaned with backup


::Report End

CharleyO

  • Guest
Re: Infected by a Spyware Help Please
« Reply #3 on: February 02, 2006, 04:17:25 AM »
***

Since you did not tell where the winlogin.exe is located, please read these first 2 links and decide if it is good or bad. The good one should be in
c:\windows\System32 and no where else.

http://process.networktechs.com/Winlogon.exe.php

http://www.pcreview.co.uk/startup/winlogon.exe.php

And basically, the same is true for smss.exe as it depends on where it is located as to whether it is good or bad. The good one should be in
c:\windows\System32 and no where else. Read the link below.

http://process.networktechs.com/Smss.exe.php

I hope this helps you.    :)


***

Spiritsongs

  • Guest
Re: Infected by a Spyware Help Please
« Reply #4 on: February 02, 2006, 08:07:34 PM »
 :)  Hi AJones :

     I believe I saw you post a similar request on the
     Annoyances.org site !? For SPYWARE problems, you
     should be asking for help on an antiSPYWARE forum,
     not an antiVIRUS forum; have you gone to :
     http://forums.spybot.info  as I suggested on Annoyances ?