Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Virus, Spyware, and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

> 

When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.

> Spyware issues - cannot run cmd or regedt32, SD, MalwareBytes, Ad-Aware, Norton AV not helping
Jeff Melnik
post May 30 2009, 01:03 PM
Post #1


New Member
*

Group: Members
Posts: 14
Joined: 30-May 09
Member No.: 337,226



Recently cleaned off the fake spyware removal program SpyWare Protect 2009 with info found on this site - thanks!

However, still having the following symptoms of something still wrong on my computer:
- Norton AntiVirus has been detecting a Backdoor Trojan virus of some kind popping up - setup_u.exe. It does get quarantined - yet it seems to keep coming back.
- After running a Google search, when clicking on a link in the search results the browser (FireFox or IE) sometimes gets "hijacked" and brought to a separate site - usually some type of advertisement. Clicking the back button and re-clicking on the search result then gets me to the site I'm supposed to go to.
- Ad-Aware, Spybot SD, and Malwarebytes are all finding NOTHING.
- It would seem there is a registry entry I need to delete to clean this up, but I have found that I now can not run cmd.exe or regedt32.exe. MS Installer seems to be having issues as well, so I'm having trouble getting alternative scanning software to use to see what's going on. Was going to try re-installing the Installer based on Symantec recommendations, but when I try to move the old files by renaming them, the files keep coming back, almost as if I did a copy.

Per the prep guide, I downloaded DDS.scr and tried running it - but nothing happens (a command window opens for a fraction of a second, but it is blank, and then goes away before I can even blink), so unfortunately there is no output to attach here. So I guess the first thing would be if someone could tell me how to get DDS.scr to work, or has any idea what is going on based on what I am describing above.

Alternatively I could supply the TrendMicro HijackThis log, but I'll wait for some feedback first.

Thanks in advance for your assistance.
Go to the top of the page
 
+Quote Post

Posts in this topic
Jeff Melnik   Spyware issues - cannot run cmd or regedt32   May 30 2009, 01:03 PM
Budapest   Before we start fixing anything you should print o...   May 31 2009, 10:29 PM
Jeff Melnik   Thanks for the information. I finally had the tim...   Jun 4 2009, 05:16 AM
Budapest   Please print out and follow these instructions: ...   Jun 4 2009, 04:29 PM
Jeff Melnik   After multiple attempts, I can't get SDFix to ...   Jun 5 2009, 09:35 PM
garmanma   Topic reopened   Jun 7 2009, 04:26 PM
Budapest   Can you please update Malwarebytes, run a quick-sc...   Jun 7 2009, 11:32 PM
Jeff Melnik   OK, here's the latest quick scan log - "n...   Jun 8 2009, 05:53 AM
Budapest   What symptoms are you currently experiencing?   Jun 8 2009, 06:40 AM
Jeff Melnik   A file called "setup_u.exe" keeps poppin...   Jun 8 2009, 06:52 AM
Budapest   Please download ATF Cleaner by Atribune & save...   Jun 8 2009, 06:59 PM
Jeff Melnik   Sorry for the delayed response. I had an issue wi...   Jun 10 2009, 05:29 PM
Budapest   Yes, run SUPERAntiSpyware in Safe Mode.   Jun 10 2009, 05:33 PM
Jeff Melnik   OK, here is the log output. The last entry seemed...   Jun 11 2009, 04:17 AM
Budapest   Try the fix at Kelly's Korner. Lift Restricti...   Jun 11 2009, 04:04 PM
Jeff Melnik   OK, downloaded the script from Kelly's corner ...   Jun 12 2009, 06:41 AM
Jeff Melnik   One thing of note - after executing the last set o...   Jun 12 2009, 06:48 AM
Budapest   Try running SDFix again.   Jun 12 2009, 05:23 PM
Jeff Melnik   Still no luck, I'm afraid.   Jun 13 2009, 07:29 AM
Budapest   I think it's time to head on over to the Hijac...   Jun 13 2009, 05:25 PM
Jeff Melnik   Will look into that shortly, although I'm not ...   Jun 14 2009, 06:10 AM
Budapest   That's good news. You might want to run anothe...   Jun 14 2009, 06:01 PM


Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 24th November 2009 - 04:16 PM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides

© 2003-2009 All Rights Reserved Bleeping Computer LLC.