Can anybody tell me how to de-bug this thing and get me back up and running normal??
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.Windows Security Center Alerts...spyware?
#1
Posted 03 December 2007 - 09:37 AM
Can anybody tell me how to de-bug this thing and get me back up and running normal??
#2
Posted 03 December 2007 - 09:46 AM
Use Super Antispyware to identify and remove the malware.
Post back with what SAS found and for further instructions.
Install Super Antispyware free. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/
How to Start Windows in Safe Mode:
http://www.bleepingcomputer.com/tutorials/how-to-start-windows-in-safe-mode/
#3
Posted 03 December 2007 - 10:36 AM
Help??
#4
Posted 03 December 2007 - 11:10 AM
How to Use the "Run As" Command to Start a Program as an Administrator.

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
#5
Posted 03 December 2007 - 11:10 AM
#6
Posted 03 December 2007 - 01:20 PM
so...I ran it in Safe Mode....found a bunch of issues and deleted them.
Re-start computer and......same thing.... black screen.. with warning about Spyware.
Any suggestions?
#7
Posted 03 December 2007 - 01:32 PM
#8
Posted 03 December 2007 - 04:00 PM
Thank You!!
#9
Posted 03 December 2007 - 04:42 PM
http://www.bitdefender.com/scan8/ie.html
Post Bit Defender's log here.
#10
Posted 04 December 2007 - 02:27 PM
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 12/04/2007 at 12:56 PM
Application Version : 3.9.1008
Core Rules Database Version : 3354
Trace Rules Database Version: 1353
Scan type : Custom Scan
Total Scan Time : 01:14:35
Memory items scanned : 640
Memory threats detected : 1
Registry items scanned : 5448
Registry threats detected : 1
File items scanned : 49140
File threats detected : 15
Trojan.Unclassified/SLDR
C:\WINDOWS\SYSTEM32\LWINUPDATE.EXE
C:\WINDOWS\SYSTEM32\LWINUPDATE.EXE
Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.adbrite[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ads.pointroll[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@zedo[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@e-2dj6wjkocmcpego.stats.esomniture[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@adultadworld[1].txt
Trojan.Media-Codec/V4
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#E404Helper [ {6bd36adb-7281-4670-bff3-c029d9d8f2c3} ]
#11
Posted 04 December 2007 - 02:51 PM
Now go to Start > Run and type: regedit
Press "OK" and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
In the right pane you should see the default entry for Userinit and the "Value data" should read: C:\WINDOWS\system32\userinit.exe,
Let me know what it says but don't make any changes.

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
#12
Posted 04 December 2007 - 02:53 PM
#13
Posted 04 December 2007 - 03:24 PM
quietman7, on Dec 4 2007, 02:51 PM, said:
Now go to Start > Run and type: regedit
Press "OK" and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
In the right pane you should see the default entry for Userinit and the "Value data" should read: C:\WINDOWS\system32\userinit.exe,
Let me know what it says but don't make any changes.
quietman7....Here goes it.
C:WINDOWS\system32\winupdate.exe,c:WINDOWS\system32\userinit.exe
#14
Posted 04 December 2007 - 03:34 PM
buddy215, on Dec 4 2007, 02:53 PM, said:
Yup. My 'puter is much quicker now...probably the quickest it's ever been. The annoying Windows Security Center alerts have disappeared along with the alert bubbles that appeared in the lower right hand corner.
Home page is good now too. No more issues there too.
But the black screen w/warning is still over top of my desktop pic.
What I have noticed is that when I start my computer...after my log on screen...it used to put up my desktop pic and icons right away when loading.
Now (since I ph*cked up this thing),my desktop pic comes up a bit later and stays there while everything is loading. No icons yet though.
After a few minutes of loading...it flashes to the black screen w/warning and THEN my icons appear.
It stays like that as long as my 'puter is on.
#15
Posted 04 December 2007 - 03:36 PM
alternate download
When using this tool, you must use the Administrator's account or an account with "Administrative rights"
- Double click SDFix.exe and it will extract the files to %systemdrive%
- (this is the drive that contains the Windows Directory, typically C:\SDFix).
- DO NOT use it just yet.
Open the SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
- Copy and paste the contents of the results file Report.txt in your next reply.
Please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press Ok and then run SDFix again.
-- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\FixPath.exe /Q
Reboot and then run SDFix again.
-- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
%SystemRoot%\system32\cmd.exe

Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Help


Back to top









