Author Topic: Question for Questolo  (Read 381 times)

Offline amazon84

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
Question for Questolo
« on: May 22, 2008, 12:22:33 AM »
Hi, I'm sorry to bother you. I have a question. My cousin's computer has some really nasty spyware on his computer. I've been over to his home these past 3 days trying to get rid of the damn thing. Here are some of the things that the spyware does:

1. Disabled the task manager (tried 3 different ways to enable the task manager to no avail)
2. "Anti-Spyware" Popups
3. Blocks access to real anti-spyware websites or blocks internet access altogether


Here are some of the things I've tried:
1. Restoring System (The virus/or spyware was gone http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/laugh.gif\' class=\'bbc_emoticon\' alt=\':lol:\' /> BUT the internet (shortcut, connection, everything) was gone http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> . They have ATT&Yahoo, would it be possible to restore the system and create a new network connection and just do it like that before the virus can sneak back in?
2. Downloading and installing Norton Antivirus. (Their computer needs Windows XP Service Pack 2 or above first though). So I'm working on getting the XP service pack on it.
3. Downloading CA Security Suite on my own personal computer, attaching and sending it to my own email, and accessing my email with the CA Security Suite in it on his computer since the spyware wont let me access the CA website

Any suggestions ?

Offline greazee

  • Hero Member
  • *****
  • Posts: 3229
  • Karma: +0/-0
    • View Profile
    • http://
Question for Questolo
« Reply #1 on: May 22, 2008, 12:42:00 AM »
It is a G not a Q!

People get that messed up a lot http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/tongue.gif\' class=\'bbc_emoticon\' alt=\':P\' />
Elite Anti-Scammer

Free MMing

IM: [email protected]


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Question for Questolo
« Reply #2 on: May 22, 2008, 04:55:14 AM »
Try not to install Service pack 2 yet, it may go bad with infections on the computer

Do the following for me first if you can
You will have to transfer this from your computer to the other
You may want to use CDRW, etc...
I know you may have a flash drive, but with the rise of flash drive infections, it may not be the best choice

Also suggest that you don't run these tools from the CD or similiar, but actually copy>paste them to the infected computers desktop

Use the following link
http://www.thetechguide.com/forum/index.php?showtopic=22942

On guidelines on how to download Hijackthis 2.0.2
Of course you will download it to your computer
Install on the other
Well your at it however
Instead of posting me the HIjackthis log
After you install Hijackthis, just close it

Well your transferring Hijackthis, you could also transfer
 [color=\"#008000\"]Deckard's System Scanner (dss.exe)[/color] to the infected computers desktop. Tr
Close all applications and windows.
Double-click on dss.exe to run it and follow the prompts.
When the scan is complete, two text files will open; main.txt, which will be maximized and extra.txt, which will be minimized.

Post back just the Whole contents of Main.txt and Extra.txt

dss.exe will also run a hijackthis scan, that's why I would like to see it's logs

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Question for Questolo
« Reply #3 on: July 06, 2008, 08:05:33 PM »
Since the original poster has not returned, I'll lock this topic

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here