Spyware on computer and cant get it off, PLEASE HELP

Spyware on computer and cant get it off, PLEASE HELP

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Spyware on computer and cant get it off, PLEASE HELP Clemmis99 04-07-2006
Posted by =?Utf-8?B?Q2xlbW1pczk5?= on April 7, 2006, 5:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello all,

I just purchased and new computer and I have a 160 gig hard drive. I looked
a couple days ago at my space and it says I only have 40 gigs of free space
left. I was dumbfounded with that cuz I have nothing at all on my computer.

I contacted Dell and they had me start my computer in safe mode. In there it
showed the correct free space of 139 gigs. Did a spyware scan and it came up
with 3 high level threats. iSearch.DesktopSearch, Coolsavings Coupon Manger,
and My Way Speedbar.

The promblem I am having is, I can not delete them in safe mode with Norton.
They do not show up at all when I scan with it, and I used the Beta and it
only found 1 registry key infected. How do i get this off, and get my
computer back to having 139 gigs free?

Posted by David H. Lipman on April 7, 2006, 5:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hello all,
|
| I just purchased and new computer and I have a 160 gig hard drive. I looked
| a couple days ago at my space and it says I only have 40 gigs of free space
| left. I was dumbfounded with that cuz I have nothing at all on my computer.
|
| I contacted Dell and they had me start my computer in safe mode. In there it
| showed the correct free space of 139 gigs. Did a spyware scan and it came up
| with 3 high level threats. iSearch.DesktopSearch, Coolsavings Coupon Manger,
| and My Way Speedbar.
|
| The promblem I am having is, I can not delete them in safe mode with Norton.
| They do not show up at all when I scan with it, and I used the Beta and it
| only found 1 registry key infected. How do i get this off, and get my
| computer back to having 139 gigs free?

Dell ships their computers with a vulnerable version of Sun Java so the below is
*very*
pertinent.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp


For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser
Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?Q2xlbW1pczk5?= on April 7, 2006, 6:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

Thank you so much for your reply and help. I am in the process of trying to
uninstall or delete the registry keys by the Norton self help guide. Should I
wait untill I do the options you mentioned or am i ok? Shouldn't Norton have
caught this? That is what I purchased it for. Again, thanks for your help. I
will wait for your reply B4 i procedd.

"David H. Lipman" wrote:

>
> | Hello all,
> |
> | I just purchased and new computer and I have a 160 gig hard drive. I looked
> | a couple days ago at my space and it says I only have 40 gigs of free space
> | left. I was dumbfounded with that cuz I have nothing at all on my computer.
> |
> | I contacted Dell and they had me start my computer in safe mode. In there it
> | showed the correct free space of 139 gigs. Did a spyware scan and it came up
> | with 3 high level threats. iSearch.DesktopSearch, Coolsavings Coupon Manger,
> | and My Way Speedbar.
> |
> | The promblem I am having is, I can not delete them in safe mode with Norton.
> | They do not show up at all when I scan with it, and I used the Beta and it
> | only found 1 registry key infected. How do i get this off, and get my
> | computer back to having 139 gigs free?
>
> Dell ships their computers with a vulnerable version of Sun Java so the below
is *very*
> pertinent.
>
> If you are using any version of Sun Java that is prior to JRE Version 5.0,
> then you are strongly urged to remove any/all versions that are prior to JRE
> Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
> It is possible that is how you got infected with malware.
>
> Therefore, it is highly suggested that if there are any prior versions of Sun
Java
> to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0
Update 6
> be installed ASAP.
>
> http://www.java.com/en/download/manual.jsp
>
>
> For non-viral malware...
>
> Please download, install and update the following software...
>
> * Ad-aware SE v1.06
> http://www.lavasoft.de/
> http://www.lavasoftusa.com/
> http://www.lavasoft.de/ms/index.htm
>
> * SpyBot Search and Destroy v1.4
> http://security.kolla.de/
> http://www.safer-networking.org/microsoft.en.html
>
> * SuperAntiSpyware
> http://www.superantispyware.com/superantispywarefreevspro.html
>
> After the software is updated, I suggest scanning the system in Safe Mode.
>
> I also suggest downloading, installing and updating BHODemon for any Browser
Helper Objects
> that may be on the PC.
>
> * BHODemon
>
>
http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d
>
> For viral malware...
>
> * Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file. http://www.ik-cs.com/multi-av.htm
>
> Additional Instructions:
>
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on April 7, 2006, 7:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hello,
|
| Thank you so much for your reply and help. I am in the process of trying to
| uninstall or delete the registry keys by the Norton self help guide. Should I
| wait untill I do the options you mentioned or am i ok? Shouldn't Norton have
| caught this? That is what I purchased it for. Again, thanks for your help. I
| will wait for your reply B4 i procedd.
|


Norton is anti virus not anti adware/spyware. Therefore it is not going to do
well.

The Ad-aware SE, SpyBot S&D and SuperAntiSpyware are anti adware/spyware.

The Multi AV Scanning Tool will use signature and heuristic based scanning to
catch what NAV
missed.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?Q2xlbW1pczk5?= on April 7, 2006, 7:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello there again,

Thanks for the reply. I have Norton Internet Security AntiSpyware Edition.
So that should have caught that correct?


"David H. Lipman" wrote:

>
> | Hello,
> |
> | Thank you so much for your reply and help. I am in the process of trying to
> | uninstall or delete the registry keys by the Norton self help guide. Should I
> | wait untill I do the options you mentioned or am i ok? Shouldn't Norton have
> | caught this? That is what I purchased it for. Again, thanks for your help. I
> | will wait for your reply B4 i procedd.
> |
>
>
> Norton is anti virus not anti adware/spyware. Therefore it is not going to do
well.
>
> The Ad-aware SE, SpyBot S&D and SuperAntiSpyware are anti adware/spyware.
>
> The Multi AV Scanning Tool will use signature and heuristic based scanning to
catch what NAV
> missed.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Similar ThreadsPosted
Can Updates be transfered from computer to computer. June 14, 2007, 5:43 am
The Difference Between Adware, Spyware and Anti-virus.(spyware blockers) April 4, 2008, 5:53 am
http://www.spyware-solutions.info a website about spyware solutions November 11, 2006, 8:07 pm
Help!! My computer is possessed! July 18, 2005, 11:35 am
NEW COMPUTER-Microsoft December 27, 2005, 3:49 pm
"Your computer is infected" July 1, 2006, 10:59 am
computer question August 5, 2006, 4:14 pm
Don't think your computer has errors January 12, 2007, 7:42 am
Secure "Lab" Computer January 27, 2007, 8:17 pm
virus on my computer February 15, 2007, 11:12 pm

The site map in XML format XML site map

Contact Us | Privacy Policy