Spyware/malware.. maybe more problems

By gnrtool82
Nov 6, 2007
Topic Status:
Not open for further replies.
  1. I believe I have serious problems with my computer. My background changed randomly to red text with a black background telling me that my computer has been infected via my IP address and unautorized access was gained by another computer. IE windows constantly open trying to sell me anti spyware programs.

    The panda anti-root scan did not find anything after the scan.

    Here are the three logs requested. Let me know if you need anymore information, thanks in advance.
  2. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Delete all files in AVG Antispyware quarantine.

    Download and run this Symantec/Norton removal tool.

    Go to add remove programmes in your control panel and uninstall anything to do with(if there).

    p2pnetworks
    e-zshopper
    acespy

    Close control panel.


    Open notepad and copy/paste the text in the code box below into it:
    NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
    Also ..

    Pay particular attention to this :-

    Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
    Code:


    Save this as CFScript.txt

    Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

    [​IMG]

    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.

    Regards Howard :)

    This thread is for the use of gnrtool82 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. gnrtool82

    gnrtool82 Newcomer, in training Topic Starter Posts: 27

    A problem has arisen after using the Norton Removal Tool. I cannot log into my username on windows. It's there, but when I click on it, it goes to a black screen saying "domain name not available." then returns me to the Windows login in which I cannot do anything.
  4. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Boot into safe mode and try a system restore. See is that helps.

    If it does, follow the instructions in my post above, without removing Norton.

    Regards Howard :)
  5. gnrtool82

    gnrtool82 Newcomer, in training Topic Starter Posts: 27

    After a couple restarts it was able to login into windows, but after a couple seconds windows explorer encountered a problem and had to be shut down withdr watson postmortem debugger message coming up. So, after going into safe mode then restoring I was able to do the rest, of course, Norton is still there.

    hjt and combofix included
  6. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    The reason I wanted you to uninstall Norton, is because you`re currently running AVG and Nortons, both at the same time. In addition to that, you`re also running Norton`s firewall as well as the Kerio firewall. This state of afairs is definitely not good and can cause serious conflicts. You should only have one AV and one Firewall running.

    Try uninstalling Norton from add remove programmes.


    Go to add remove programmes in your control panel and uninstall anything to do with(if there).

    viewpoint
    viewpoint manager
    viewpoint toolbar

    Close control panel.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Viewpoint Manager Service

    Close the services window.


    Run this Combofix script as before.


    Post fresh HJT and Combofix logs.

    Regards Howard :)

    This thread is for the use of gnrtool82 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  7. gnrtool82

    gnrtool82 Newcomer, in training Topic Starter Posts: 27

    I think things might be going in the right direction.
  8. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    All clean.

    Delete the following folder.

    C:\qoobox

    Turn off system restore.(XP/ME only) See how HERE.

    Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.

    Go HERE, download and install the latest version of Java.

    Once it`s installed, go to add remove programmes in your control panel and uninstall all previous versions of Java, except version 6 update 3. Close Control panel.

    The only thing you have left to solve, is the fact you`re running 2 AV and 2 firewalls.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of gnrtool82 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.