Reply
Visitor
bestofmillions
Posts: 6
Registered: ‎07-29-2009
Accepted Solution

Antispyware Soft

This program keeps popping up saying im infected and i need to run a scan and i cant open anything that will help me shut down the pop ups. example Task manger that doctor spyware thing a anything that might harm it. i cant use internet explorer but it keeps pulling it up going to spam sights, so im using firefox which is working fine. it just popped up out of no where my coomputer went to sleep i woke it up and it just started flipping out. i need help because this is really annoying.

 

Waiting for Quads

 

 

Bot Obliterator
Quads
Posts: 13,247
Registered: ‎07-21-2008

Re: Antispyware Soft

Antispyware Soft is the same rogue family as "Antivirus Soft" and "Antivirus Suite"

 

Download "Hijackthis.com" from http://homepages.slingshot.co.nz/~crutches/Loggers/

 

Run it creating a log, and post the log as an attachment back here.

 

Quads

Visitor
bestofmillions
Posts: 6
Registered: ‎07-29-2009

Re: Antispyware Soft

It wont let me save it to notepad i had to change the name just to open the program.

Bot Obliterator
Quads
Posts: 13,247
Registered: ‎07-21-2008

Re: Antispyware Soft

As long as Hijackthis saves the file, either a .log or .txt file you can  upload and attach it to a post

 

Quads

Visitor
bestofmillions
Posts: 6
Registered: ‎07-29-2009

Re: Antispyware Soft

ok heres the results

Bot Obliterator
Quads
Posts: 13,247
Registered: ‎07-21-2008

Re: Antispyware Soft

Ok 

 

Now start Hijackthis and you will see beside each entry a little box that you can tick the entries you want.

 

With Hijackthis tick / check these entries below

 

 


 

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe

O4 - HKCU\..\Run: [luuqyncj] C:\Users\Lelia\AppData\Local\yusxwxusn\cdcwotqtssd.exe

 

O17 - HKLM\System\CCS\Services\Tcpip\..\{16102FF1-45AE-474D-A3AA-E526074B71D1}: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B441F19-9542-4E88-AF93-7A6E9EC180AC}: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\..\{16102FF1-45AE-474D-A3AA-E526074B71D1}: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\..\{16102FF1-45AE-474D-A3AA-E526074B71D1}: NameServer = 85.255.112.234,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.234,85.255.112.185

 

 

Now Click the "Fix Checked" button.  That should remove those entries.

 

Now restart the PC, the rogue should not start up on the restart.

 

Quads

 

Bot Obliterator
Quads
Posts: 13,247
Registered: ‎07-21-2008

Re: Antispyware Soft

Hang On, I've been way for awhile,

 

All I have done is disabled the Malware (rogue included) so that the Files don't run on the restart.

 

Next, check the Internet Connections so that the Proxy is NOT selected, see the link below

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/Firefox-and-Netscape-browsers-work-bu...

 

Quads

 

 

shannons
Posts: 10,668
Topics: 44
Kudos: 104
Solutions: 7
Registered: ‎01-07-2009

Re: Antispyware Soft

shannons
Posts: 10,668
Topics: 44
Kudos: 104
Solutions: 7
Registered: ‎01-07-2009

Re: Antispyware Soft

Symantec Employee
JerryM
Posts: 1,515
Registered: ‎08-10-2009

Re: Antispyware Soft