help w/spyware and other damage

Discussion in 'adware, spyware & hijack cleaning' started by themoot, Jul 5, 2004.

Thread Status:
Not open for further replies.
  1. themoot

    themoot Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    4
    I recently got hit by spyware.

    Here is what I've got: Win98, IE6.0, Norton AntiVirus (updated)

    I have the latest of: CWShredder, Spybot S&D, DSOStop2 and now HiJackThis. I have run them all.

    Issues Part I: I can remove .dll files w/CWShredder, but my IE browser defaults to an about:blank page each day (around 11:00AM). A daily run of CWShredder removes the DLL, but a pain. I ran Spybot and it found a couple file problems and removed them. Problem returned. I ran Spybot again, and it continued to find DSO issues. I downloaded and ran DSOStop2. After the first run, it seems to be OK. I have included a HiJackThis Log, as Log (see issues part II). One other note. If I try to upgrade CWShredder, the virus kicks it, a note appears stating a Trojan Virus has been found and it trys to bypass.... with no success.

    Issues Part II: I no longer have Notebook, so I cannot convert the HiJack this file to .txt. It seems to have dissapeared with the onslaught of this issue, along with .... FreeCell... damn. (any suggestions on how to bring those back?).

    Issues Part III: On reboot, I get a MAD - This program has performed an illegal operation warning, which I click and the startup continues.

    Thanks
     

    Attached Files:

  2. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    Hi,

    I'm very suspicious of wucrtupd.exe
    Can you send this file to submit@diamondcs.com.au please. It could possibly be legit and related to Windows Update notifications, but I dont think so. I'll let you know as soon as possible..

    Also send E:\Bin\html\files\MotivePreQual.cab if it exists..

    To restore system files on Windows 98a (original version) you need to either manually extract them from the CD, or you could reinstall Windows over itself - that is, reinstall Windows to the same Windows folder. This updates missing files and can often fix problems. You wont lose any programs either :)
     
  3. themoot

    themoot Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    4
    Gavin, thanks. exe file sent to the provided address. .cab file not found. Look forward to any thoughts or suggestions.
     
  4. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    Hi,

    I emailed you a fix for the sp.html junk
    Post a new log after you try it please !
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.