Antispyware hangs on scan

G

Guest

I have a winXP Pro PC with all current updates that is loaded with spyware.
I have attempted to run MS Antispyware scans dozens of times and never once
has the software successfully completed a scan.

Every instance the software has hung on:
scanning registry:
HKLM\software\microsoft\windows\currentversion\explorer\browser helpers

I have verified my HOSTS file is small (~1k), tried in safe mode and tried
all different combinations of scan options in the software. It always hangs
up at the same key in the registry.

One thing I noticed is that my page file usage grows from ~180mb to 977mb
within 5 seconds of hanging on this registry key. If I terminate the
GIANT####.exe process I can regain the use of my machine.

The frustrating part of this is that MS antispyware sees the garbage but it
waits until the scan is complete before it does anything to remove the crap.
I was hoping that I could stop the scan part way through and have the program
clean what it found but this doesnt work. I can count loads of little
spyware guys on this machine but I can't remove them.

Anyone who can lend some advice will be thanked. Anyone who comes to my
house and hauls the computer away with a promise to destroy it will receive a
free meal!
 
D

Dave M

D

Dave M

If desert is included, you might try taking a look in MSAS > Advanced Tools >
System Explorers > IE BHOs
for things you don't recognize or that are marked as potentially unwanted and
block/remove them before you rerun that scan
 
G

Guest

Thanks Dave,

Okay, I did download the crap cleaner you suggested. I ran it and cleaned
some of the junk using that tool. I tried running the Antispyware scan in
safe mode before and after the crap cleaner but the APP still hung when
scanning the browser helper part of the registry.

I uninstalled and reinstalled Antispyware and tried again. It hung up again
while in safe mode.

I tried to use Antispyware to remove some of the BHOs but it could not
remove them. Antispyware claimed that it removed them but they still showed
up in both Antispyware and inside IE options. Currently all of the suspect
ones are disabled using IE options.

At this point I have given up on my hope to restore the computer. It is
running better than before but the commie bastards are still in there;
they're just waiting until I return the computer to my friend and then they
will jump out and attack again. I hate them almost as much as I hate bad
drivers and stop lights.



Anyway, thanks for the suggestions. BTW, I said "meal" not 'dinner'. A
meal IS desert! Currently I'm all over little chocolate lava cakes with the
warm center served with real vanilla ice cream and real melted
chocolate...topped with sliced almonds. YUM!!! I'm going to celebrate my
failure alone. Sorry you are not invited. I'm 150lbs on my way to 300!!!
Yippie!!!
 
D

Dave M

Oh man, you have a bad one... Good to see you can maintain some level of humor
though it. I'm sorry it's being such a pain, but I really think what you need
to do at this point is get into a really aggressive mode with this junk. What
I've suggested in the past is this very analytical technique laid out at the
following site. Mind, we're not trying to blow you off, it's just that you
need to run some tools that would take too long to describe here and that we're
not equipped to support at this site including HijackThis.
Please go here and follow their instructions exactly, then come back and give us
your feedback. The good news is, you already have at least two of these tools
installed now (CCleaner&MSAS) :)

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
 
G

Guest

Hi,

Please ensure you are doing this under a Administrator accºunt.

Try

Ewido : Run in safe mode

http://www.ewido.net/en/

Install Ewido.
During the installation, under "Additional Options"
uncheck "Install background guard" and "Install scan via context menu".
Launch Ewido
On the left side of the main screen click update.
Click on Start and let it update.
Then Run a Complete System Scan

Panda
http://www.pandasoftware.com/activescan/
Choose to "Disinfect automatically," and follow the prompts. Delete any
viruses found, and restart your computer

I hope this post is helpful, let us know how it works ºut.

Good luck

Engel
 
G

Guest

Dave, Thanks for the help...

....here is the bottom line: I am through with this machine!

I invested many hours of my time in this darn computer and I could not solve
the problem completely. Although the computer boots now and runs without any
active spyware/virus processes there are still many, many bad guys aboard
that I couldn't remove.

After the spyware processes essentially rendered this computer useless last
Spring the owner replaced it and his new one runs very well. The computer
has been returned to the owner and it will sit in the garage as a spare.
Perhaps some new updates in the future might provide a quick and simple fix
for whatever is hanging it up now...

chalk up another mark for disposable computers! What has happened to the
computer industry/community? For the little guys we spend just as much time
maintaining and repairing computers as we save by using them. Its a draw.
We are stagnating rather than moving forward. Somebody stop the madness!

-now I have to go delete the 40 pieces of spam I received today. ;-)
-regards

PLEASE NOTE THAT I WILL NOT POST HERE ANYMORE. The hotmail account that I
had to create simply to post here will now go unused. So much waste.
Somebody stop the madness!
 
D

Dave M

You know sometimes it just makes more sense to start fresh with a disk format
and re-install, and a new e-mail account too.
Regular Backups including Disaster Recovery are a way of life I'm afraid, but
that way the pain level can be lowered. Sorry we didn't have more success this
time. Now if I could just get my new Backup program working...
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top