Cannot delete spyware and it my damage my computer!

Therk

Senior member
Jul 15, 2005
261
0
0
Ok so it looks like I picked up some spyware from some site a couple of days ago. Now the mouse is normal then theres the little loading bar on the side every 3 sec or so. This does NOT stop and the CPU usage goes up and down like, 0%, then 50%, then 0% again, then 50%.

I've tried everything to remove it. Ad-aware, Spybot search and destroy, norton antivirus etc. They do remove it but the things just keeps on coming back after a restart and is pissing me off really bad.

Someone help me out here please!
 

Cdubneeddeal

Diamond Member
Oct 22, 2003
7,473
3
81
What about booting into safemode. But first, find out which programs are running that's spyware. Right them down, then go into safemode. Search for the files directly (Make sure to have hidden folders and files showing), then delete them. I think booting into safe mode won't load them into memory so you probably won't have a hard time deleting them.
 

Bozo Galora

Diamond Member
Oct 28, 1999
7,271
0
0
First of all this is not a GH question. Its O/S
Secondle, you could be talked thru this with use of things like HiJackThis and Ewido and Silent runners etc.
But these reappearing worms are just a pain, so I would reformat, it will take the same amount of time, and be a lot less aggravation.
Or you could go to the various virus forum sites like http://castlecops.com/
http://castlecops.com/forums.html and ask for help.

FWIW: At the very least, you must turn off the XP restore module and do all scanning in safe mode.
 

Bateluer

Lifer
Jun 23, 2001
27,730
8
0
Unplug it from the internet/network, reboot into safe mode, then try Spybot/AdAware. Reboot into normal windows and see if it comes back.

Reformating would probably be the safest bet though.
 

Nocturnal

Lifer
Jan 8, 2002
18,927
0
76
Your best bet is to visit www.geekstogo.com. Their forum is very imformative and there are many members there who volunteer their time helping people get rid of spyware infections without having to resort to formatting their computer.
 

w00t

Diamond Member
Nov 5, 2004
5,545
0
0
i would check out if there was any program in my add/remove programs list see if its in there than i would check regedit my run and than msconfig and than disable it from there.
 

DasFox

Diamond Member
Sep 4, 2003
4,668
46
91
No No No, NO NEED to reformat, at least not yet. This could be a trojan acting up on the system as well. Grab "The Cleaner"

http://www.moosoft.com/

I have used this program for around 7 years it's probably the best for trojans. Also you need more spyware programs, I am a PC tech I do this for a living cleaning peoples PCs out. You need like 4-5 spyware programs and then some, depending on how crazy things get out of hand.

Some of these apps are not freeware, BUT use them anyways they are good and either toss them out when done, or buy them, so grab these other programs to scan the system:

Spy Sweeper:
http://www.webroot.com/

Xcleaner_free:
http://www.xblock.com/download-freeware.php

Bazooka:
http://www.kephyr.com/spywarescanner/supportus.phtml

Then at this link are a HEAPS more spyware apps:
http://www.spychecker.com/software/antispy.html

But whatever you do and however many more you get run use Bazooka and run it "LAST", it's great little tool and anything left around it will pick up. BUT you have to remove the entries it finds by hand. SO then I recommend starting your scans over with some other spyware app until Bazooka doesn't say anything, OR you then click the name it shows in Bazooka and it will load the website online with information on how to deal with it.

Spyware = PATIENCE, I have spent many a hours ripping them out.

And when all the scanning is done and IF, I STRESS the word IF, you are fairly PC savvy, then grab JV 16 Power tools:

http://www.macecraft.com/downloads/

Grab ---> jv16 PowerTools 1.4

JV 16 Power Tools is to clean the registry of stray entries. A clean registry improves system performance, but make a mistake and you might not be running. But not to worry, with spyware this will be easy. Once the program is open you click, or put your mouse on the name "Registry tools" on the menu on the left, then 4 boxes appear on the right side, the 3rd one from the left, if you put the mouse over the boxes will give a description. The 3rd one is called the "Registry finder" CLICK that box and you will get a small white window, "Enter the search words" REMEMBER the names of the spyware and type them in this box. Then click "Continue" at the bottom when you have all the names you want, then in the next section at the top. "Select which root keys to scan" make sure they are ALL checked. Then under the "Search Options", I leave all the options as they are and also check, "Use as little processor power as possible" Then click START and when done you can remove anything you have found, BUT take your time and look through the results to see if you NOTICE these spyware names in there somewhere, try to becareful not to rip anything out, BUT to make sure you see then names in there.

When you are satisfied, you can then remove them, but if something ever goes wrong, then go to the Program Files directory and look for the jv16 PowerTools folder and inside you will see a "Backups" folder. From in there is the regedit files, you can just CLICK on them and they will put those entries back into the registry, in case you make any mistakes.

GL! :)
 

JEDIYoda

Lifer
Jul 13, 2005
33,986
3,321
126
Originally posted by: Therk
Ok so it looks like I picked up some spyware from some site a couple of days ago. Now the mouse is normal then theres the little loading bar on the side every 3 sec or so. This does NOT stop and the CPU usage goes up and down like, 0%, then 50%, then 0% again, then 50%.

I've tried everything to remove it. Ad-aware, Spybot search and destroy, norton antivirus etc. They do remove it but the things just keeps on coming back after a restart and is pissing me off really bad.

Someone help me out here please!

It keeps coming back becuase everytime you access the internet it replicates itself!
There are on eof 2 things you can do.....
Boot into safe mode and try that......but some computers still can access the ionternet in safe mode...or...

disconnect yourself from the internet by physically unplugging your computer and then stasrt your computer and run whatever it is that you have to get rid of the virus,

after you have don`t that reboot and then hook to the internet!

A reformatt is the last resort and should not be necessary.







 

Jiggz

Diamond Member
Mar 10, 2001
4,329
0
76
Originally posted by: sandorski
Spy Sweeper works very well, best anti-spy I ever used.



I'll second this one. I have both Spybot and Adaware but this one beats them all!
 

pontifex

Lifer
Dec 5, 2000
43,804
46
91
if your anti-spyware program is detecting them then boot into safe mode and run it. lots of spyware/adware use .dll files and you can't remove them unless they are not running. safe mode prevents them from running.
 

kitkat22

Golden Member
Feb 10, 2005
1,464
1,332
136
There are three things you absolutely need to do this. Spyware removers can't do it alone. I would grab these programs; Zonealarm, Avast!, Antispyware Beta 1, Search and Destroy, Adaware and Spywareblaster, install them all and update them, but don't run them. Restart your computer in safe-mode and run the programs. Delete all entries. Restart your computer and run Trendmicro's Housecall for viruses and spyware delete any leftover entries. Done.
 

kojak61

Senior member
Apr 16, 2001
253
0
0
Originally posted by: cscpianoman
There are three things you absolutely need to do this. Spyware removers can't do it alone. I would grab these programs; Zonealarm, Avast!, Antispyware Beta 1, Search and Destroy, Adaware and Spywareblaster, install them all and update them, but don't run them. Restart your computer in safe-mode and run the programs. Delete all entries. Restart your computer and run Trendmicro's Housecall for viruses and spyware delete any leftover entries. Done.

Also disable system restore, because the spyware maybe saved in one of its backups. Run scan after you disable system restore.
 

Fraggable

Platinum Member
Jul 20, 2005
2,799
0
0
Originally posted by: cscpianoman
There are three things you absolutely need to do this. Spyware removers can't do it alone. I would grab these programs; Zonealarm, Avast!, Antispyware Beta 1, Search and Destroy, Adaware and Spywareblaster, install them all and update them, but don't run them. Restart your computer in safe-mode and run the programs. Delete all entries. Restart your computer and run Trendmicro's Housecall for viruses and spyware delete any leftover entries. Done.

What I would have said. Be sure to get MS Antispyware - it works very well IMHO.