Thread Solved

Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: ISPYNOW

 
0
  #11
Dec 1st, 2008
Sickofit,
==Download this file to your DESKTOP: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
.....or this file: http://subs.geekstogo.com/ComboFix.exe
-IMPORTANT! : disconnect from the web, turn off your Antivirus, Antispyware and Firewall for the duration of this scan. Don't forget to reset them before you go back on the web!
- to run it dclick the Combofix.exe icon and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
If by some chance Combofix will not run try renaming the combofix.exe to mycomfx.exe, and dclicking it.
Last edited by gerbil; Dec 1st, 2008 at 11:43 pm.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,011
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 758
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: ISPYNOW

 
0
  #12
Dec 1st, 2008
Try renaming MBAM and run it again.
Reply With Quote Quick reply to this message  
Join Date: Mar 2005
Posts: 25
Reputation: sickofit is an unknown quantity at this point 
Solved Threads: 0
sickofit sickofit is offline Offline
Light Poster

Re: ISPYNOW

 
0
  #13
Dec 1st, 2008
Gerbil

When I try to click on the link, my Internet Explorer will not let me get to the link. Says the page is unavailable. This is the problem I was telling you about, apparantely whatever this virus is, it has the ability to see if I am trying to access a page that has any type of spyware removal tools on it and it gives me the unavailable page.
Reply With Quote Quick reply to this message  
Join Date: Mar 2005
Posts: 25
Reputation: sickofit is an unknown quantity at this point 
Solved Threads: 0
sickofit sickofit is offline Offline
Light Poster

Re: ISPYNOW

 
0
  #14
Dec 2nd, 2008
Crunchie,

I've tried to rename it, with no luck. Seems to me that when I transferred the file from cd to the computer the virus locked it up. It will not let me run it and it will not let me remove it.

Ive tried renaming on the cd and moving it over again but that is not working either.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: ISPYNOW

 
0
  #15
Dec 2nd, 2008
Sickofit, can you try to access a Combofix dl site from Safe Mode with Networking? If successful, run Combofix from Safe mode.
You could try these scans, one should do, again from safe mode:
==Please use IE or Firefox to do an online scan at panda:- http://www.pandasecurity.com/activescan/index/
-First Register [otherwise there will be no disinfection, merely detection] with a valid email address for the free online virus scan and follow through.
Unlike Kaspersky this scan does not require Java. Panda will clean only virii, but it is superb at listing other malwares which can then be targeted.
Please ATTACH to your post the log it produces.
==Kaspersky Online Scan, from http://www.kaspersky.com/virusscanner -press the Kaspersky Online Scanner button, follow through....
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Mar 2005
Posts: 25
Reputation: sickofit is an unknown quantity at this point 
Solved Threads: 0
sickofit sickofit is offline Offline
Light Poster

Re: ISPYNOW

 
0
  #16
Dec 2nd, 2008
Ok, I can get to panda in safe mode. No luck on Kaspersky or on the Combo. Same problem.

I registered with panda, downloaded 2.0, enabled active x control, however, when it sets to update the active scan 2.0 I get an error and cant get any further.

sickofit
Last edited by sickofit; Dec 2nd, 2008 at 1:28 am.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,011
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 758
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: ISPYNOW

 
0
  #17
Dec 2nd, 2008
Do a system search for files named TDSSserv.*** and delete any that are found.
If you do find find and delete them, try running MBAM again and also Gerbil's advice.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: ISPYNOW

 
0
  #18
Dec 2nd, 2008
Ok. How annoying. You have a version of ISpyNow which is protected by a rootkit, it is very likely TDSS. So a few things we can try before you have to go walking with a flashdrive in your hot lil hand, to find a friendly type who will let you dl Combofix. We need it. Make sure to load the dl addy into the flashdrive... But first:
There is always another online scan: http://www.f-secure.com/security_center/
If it won't run, then:
==Download [currently it will not dl correctly with Opera; use IE] the latest standalone version of Blacklight from ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe - Start it, accept the agreement and Scan.

Else if we assume that it is TDSS, go into C:\WINDOWS\system32 and rename every file commencing with the letters TDSS to XXXTDSS. Here is a typical selection.. you may have some or none or similar others :

c:\windows\system32\TDSSblal.dat
c:\windows\system32\TDSScshc.dll
c:\windows\system32\TDSSdlpb.dll
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSojtp.dll
c:\windows\system32\TDSSqogd.log
c:\windows\system32\TDSSurev.dll
c:\windows\system32\TDSSwhke.log
c:\windows\system32\TDSSxnyq.dll
You may find some in c:\windows\system32\drivers\...
eg: c:\windows\system32\drivers\TDSSrfpc.sys

Try to run MBAM now [rename mbam.exe to mybm.exe first]. And then try to dl Combofix...
As crunchie said, you could delete any TDSS... files in system32 if you so wished. TDSS is a play on TSDDD, which is a valid displaydriver.
Last edited by gerbil; Dec 2nd, 2008 at 2:11 am.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,011
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 758
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: ISPYNOW

 
0
  #19
Dec 2nd, 2008
If you get to the stage where you can download combofix, rename it BEFORE you actually save it to your desktop.
Attached Thumbnails
CF_download_rename.gif  
Reply With Quote Quick reply to this message  
Join Date: Mar 2005
Posts: 25
Reputation: sickofit is an unknown quantity at this point 
Solved Threads: 0
sickofit sickofit is offline Offline
Light Poster

Re: ISPYNOW

 
0
  #20
Dec 2nd, 2008
Ok, cant get to either of the f-secure sites. Searched for the TDSSserv files and came up with 2 and deleted. Mbam still wont run. I am going to download some of these to disc from another computer and rename them. Hopefully "something" will work from there
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC