TechSpot

Windows Vista infected with Spy.Win32@mx

By collins5
Oct 23, 2007
  1. Please Help!! I am running Windows Vista and I keep getting a pop-up window about a security warning. I downloaded the VirusHeal software it referred me to, but deleted it after I realized there was a charge for it. I thought why should I pay for this when Windows should be offering something for free? Besides that, I've already paid to have TrendMicro and Webroot Spysweeper installed. After running Spysweeper, I keep getting this security warning screen each time I log onto the internet. Please help!!
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

    If after reading the above, you wish to clean your system, do the following.

    Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT, AVG Antispyware and Combofix logs as Attachments into this thread, only after doing the above.

    Also, let me know the results of the AVG Antirootkit scan.

    Regards Howard :wave: :wave:

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. collins5

    collins5 TS Rookie Topic Starter

    Having trouble running HJT scan. My computer tells me it is already running. Also, since running Combofix, the time on my computer is showing up as military time. How do I fix this?
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Open your task manager and click on the processes tab. End process for Crusty.exe if there. Then, try running a HJT scan again.

    As for your clock problem, once we`ve got rid of any malware, we should be able to fix that without too many problems. there`s no point in doing it now, as you may need to run further Combofix scans.

    Regards Howard :)

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. collins5

    collins5 TS Rookie Topic Starter

    Ok, here are my log files for HJT and AVG Anti-Spyware. I'm not sure if my Combofix scan was successful because I received an Error msg: "Freeware implementation of REG.EXE has stopped working". But then later received a message saying "Stage 1 Completed" and typed "1" and "Enter" per your instructions. I don't know if it gave me a report or if so, I'm not sure where I saved it.
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    No problems there.

    Combofix saves it`s log file in C:\combofix.txt. Have a look in that location and attach the Combofix log if there.

    Regards Howard :)

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  7. collins5

    collins5 TS Rookie Topic Starter

    I re-ran Combofix and am attaching the report below. I know now that my first attempt at running the program was not successful. Each time, I received a pop-up window with this message: "Spybot Search & Destroy has detected an important registry entry. Allow or Deny?" This time I did not select either, and Combofix was able to keep running successfully. It appears to have deleted 2 files from Windows System 32.
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Can`t see anything nasty there.

    Delete the C:\Qoobox folder.

    Are you still having problems?

    Regards Howard :)

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  9. collins5

    collins5 TS Rookie Topic Starter

    It appears that I am problem-free at this point. Thank you sooooooooo much!! 1) I deleted the Qoobox folder as you said. 2) Since running the Combofix program successfully earlier today, my clock now shows the correct time. Yea! 3) When going thru the 15 steps I tried to download Panda Antiroot Kit before I realized it wasn't compatible with Vista, so I now have a folder called "Pavark" in C. It's empty, so is it okay to delete it? 4) Also tried to download Comodo firewall, which is not compatible yet, and am currently using Windows Defender as a firewall. Is this okay? 5) One last thing, AVG Anti-Spyware shows as inactive in my tray. Should I activate it and leave it on, or only activate it when I want to run a spy check?
     
  10. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    yes, you can get rid of the Panda Antirootkit file. It`s the AVG Antirootkit that`s compatible with vista. ;)

    I suggest you uninstall AVG Antispyware.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  11. samjohnson

    samjohnson TS Maniac Posts: 238

    Ok I don't know how good windows defender is as a firewall since I have never used it. But if you are looking for a different one that is compatible with vista try the PC tools firewall plus. I downloaded that one for my sisters laptop that is running vista so I know it works with vista.
     
  12. collins5

    collins5 TS Rookie Topic Starter

    Wrong Date

    Since going through the 15 steps to clear up a virus, my computer system has the wrong date. The time is correct, but the date is listed as one day later than it should be. For instance, today is Thursday, November 1st. My computer shows today being Friday, November 2nd. How can I fix this?
     
  13. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Double click the clock in your system tray.

    Under the date and Time tab, click the correct day in the calendar and click apply/ok.

    Regards Howard :)

    This thread is for the use of collins5 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  14. collins5

    collins5 TS Rookie Topic Starter

    Thank You!!

    Thanks Howard! It worked!

    This thread is now closed: If you need this thread unlocking, please pm a moderator with a link to the thread.

    Only the original thread starter can do this. Anyone else, will be ignored.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...