Help! I cannot remove spyware

T

twitchin

I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing certain
spyware. Namely Topmoxie , WinAD, 180 Solutions and Blazefind. Ad-Aware
finds and removes them, but as soon as I do so, Ad-Aware Watch pops up and
tells me a Registry Modification has been detected and Topmoxie re-appears.
The others return randomly within minutes. I've tried other spyware
detectors such as Spybot, BPS, and XoftSpy with the same results.

How can I erase these for good? TIA.
 
M

Malke

twitchin said:
I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing
certain spyware. Namely Topmoxie , WinAD, 180 Solutions and Blazefind.
Ad-Aware finds and removes them, but as soon as I do so, Ad-Aware
Watch pops up and tells me a Registry Modification has been detected
and Topmoxie re-appears. The others return randomly within minutes.
I've tried other spyware detectors such as Spybot, BPS, and XoftSpy
with the same results.

How can I erase these for good? TIA.

Here are the normal spyware removal steps. My understanding about
XoftSpy is that it adds more spyware to your system, but don't quote me
on that. To make sure it is a good program, you can check out these
links:

http://www.netrn.net/spywareblog/
http://www.spywareguide.com/index.php
http://scumware.com/
and the forums on AumHA are always excellent:
http://forum.aumha.org/ - look under "Security" for various forums

You will note that my removal instructions call for doing the scans in
Safe Mode. This is key. Also, it is a good idea to always first look in
Add/Remove Programs. WinAD will have a removal program there. The
uninstaller probably won't get rid of everything (scumware lies), but
start there first.

With the BlazeFind trojan, after you remove it and before you shut down,
check and make sure the following registry key is correct:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Userinit string value should be:

C:\WINDOWS\system32\userinit.exe,

On the damaged installations it's one of these:

C:\WINDOWS\system32\wsaupdater.exe,
C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsaupdater.exe,

Note the trailing comma, which should be there.

1) Scan in Safe Mode with current version (not earlier than 2003)
antivirus using updated definitions;
2) remove spyware with Spybot Search & Destroy
(www.safer-networking.org) and Ad-aware (www.lavasoftusa.com). These
programs are free, so use them both since they complement each other.
You may also want to run CWShredder and HijackThis from
http://aumha.org/freeware.htm. Although CWShredder is no longer being
updated, it will still clean older variants of the CoolWebSearch
malware. If you do not have success with this, there are new removal
steps at http://www.silentrunners.org/sr_cwsremoval.html. A combination
of HijackThis and About:Buster (http://www.majorgeeks.com) works well
in removing homepage hijackers. Always read the instructions before
running a spyware removal tool. Be sure to update these programs before
running, and it is a good idea to do virus/spyware scans in Safe Mode.
Make sure you are able to see all hidden files and extensions (View tab
in Folder Options);
3) If you are running Windows ME or XP, you should disable/enable System
Restore because malware will be in the Restore Points. With ME, you
must disable System Restore completely. With XP, you can delete all but
the most recent (presumably clean) System Restore point from the More
Options section of Disk Cleanup (Run>cleanmgr).
4) make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update;
5) run a firewall.

Malke
 
T

TDP

twitchin said:
I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing certain
spyware. Namely Topmoxie , WinAD, 180 Solutions and Blazefind. Ad-Aware
finds and removes them, but as soon as I do so, Ad-Aware Watch pops up and
tells me a Registry Modification has been detected and Topmoxie re-appears.
The others return randomly within minutes. I've tried other spyware
detectors such as Spybot, BPS, and XoftSpy with the same results.

How can I erase these for good? TIA.
Disable "System restore" then run your Adaware then enable "system restore"
(nasties can be hiding in restore points).TDP.
 
T

twitchin

TDP said:
Disable "System restore" then run your Adaware then enable "system restore"
(nasties can be hiding in restore points).TDP.

Thanks for a good suggestion but it never worked.
 
A

Al Smith

Disable "System restore" then run your Adaware then enable "system
restore"



Thanks for a good suggestion but it never worked.

If I were you, I'd disconnect the computer from the Internet by
unplugging the data cable (if you are on a highspeed connection).

Then I'd disable System Restore and everything else I could
disable. By that, I mean I would go through Windows XP, especially
Internet Explorer, and systematically turn off everything that was
set to run automatically, or was not explicitly required for
Windows to run.

Then I'd boot into Safe Mode, and run my antivirus software (which
should be current in its virus definitions), and my AdAware and
SpyBot Search and Destroy -- taking note of any malware any of
these programs might happen across, particularly registry entries.
Check the logs.

I'd manually go through my file system and manually delete
anything that looked hinky to me -- or anything specifically
mentioned by the antivirus or spyware removers that they hadn't
already removed.

Then I'd reboot and see what the situation might be, before
reconnecting to the Internet.
 
G

Guest

twitchin said:
I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing certain
spyware. Namely Topmoxie , WinAD, 180 Solutions and Blazefind. Ad-Aware
finds and removes them, but as soon as I do so, Ad-Aware Watch pops up and
tells me a Registry Modification has been detected and Topmoxie re-appears.
The others return randomly within minutes. I've tried other spyware
detectors such as Spybot, BPS, and XoftSpy with the same results.

How can I erase these for good? TIA.

If your using Ad-Aware 6 build 181 read this"very important" in reguards to
Blazefind!
http://www.lavasofthelp.com/articles/v6/04/06/0901.html
 
C

CWatters

twitchin said:
I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing certain
spyware.

I had a similar problem. The bloody stuff repairs itself...

The solution I found was to...

1) Run Ad-aware, pest patrol etc

2) use the task manager to kill any processes that were suspect - look them
up on the web using google or here...
http://www.sysinfo.org/startuplist.php

3) Then remove any similar entries from the statrtup (run msconfig)

4) Then run Ad-aware, pest patrol etc again.
 
R

Rock

twitchin said:
I'm running windows xp (sp1 with all security updates) with the latest
Mcaffee Virus-scanner and firewall, and having trouble removing certain
spyware. Namely Topmoxie , WinAD, 180 Solutions and Blazefind. Ad-Aware
finds and removes them, but as soon as I do so, Ad-Aware Watch pops up and
tells me a Registry Modification has been detected and Topmoxie re-appears.
The others return randomly within minutes. I've tried other spyware
detectors such as Spybot, BPS, and XoftSpy with the same results.

How can I erase these for good? TIA.

Make sure you are doing the cleaning in safe mode. If all else fails
run HijackThis and post the log to one of the specialty forums, _NOT_
this one:

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top