Home > My Computer > My Computer Seems To Be Riddled With Spyware! Please Help!

My Computer Seems To Be Riddled With Spyware! Please Help!

Uninstall it. Uncheck the following ...Sections IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. You can also mount the registry hive of another windows system to edit startup entries manually (great time to do a virus check from a windows system, and a defrag) or If this is the case you may have to perform multiple actions simultaneously, and the only reliable way to do this is to use a batch script.

Don't bother quaranteening things - just go right ahead and delete them. Using a linux live CD/USB also allows you to copy whatever data that can be saved (photos, music, etc) into an external drive first before reinstalling. –Mart Nov 27 '12 at self protection module/ALWIL Software) ZwOpenProcess [0xEFCEFFEC]SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! First try to clean the system with the free tools described above.

Join By signing up, to you agree to our Terms of Use and our Talk Guidelines. Back to top BC AdBot (Login to Remove) Register to remove ads #2 PropagandaPanda PropagandaPanda Malware Response Team 10,433 posts OFFLINE Gender:Male Local time:11:20 PM Posted 21 November Show Ignored Content As Seen On Welcome to Tech Support Guy!

I'd also suggest doing file level recovery at this point. Windows won't boot to safe mode it stumbles at \WINDOWS\System32\Drivers\Mup.sys if I try a normal boot now it throws up the error; Issas.exe - System error and says password return is Its quite straightforward. Please help me figure out what is going on!HiJackThis LogLogfile of Trend Micro HijackThis v2.0.2Scan saved at 1:35:34 PM, on 11/14/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16735)Boot mode:

Back to top #8 PropagandaPanda PropagandaPanda Malware Response Team 10,433 posts OFFLINE Gender:Male Local time:11:20 PM Posted 25 November 2008 - 04:36 PM Hello. share|improve this answer answered Nov 29 '12 at 14:17 community wiki g19fanatic add a comment| protected by Daniel Beck♦ Nov 27 '12 at 7:14 Thank you for your interest in this From the command prompt launch procexp and autoruns via the renamed executables. If your mind is set with staying in Windows, here are your steps: Locate a system restore disc or a legitimate version of the operating system that you wish to install.

starlover-im tempted to just unplug it and bin it!!!!!!!!!! Also, during a pre-boot scan with Avast, many viruses detected come up as "file not found" or "not accessible." I've been trying to download SP3 for a week now, and the It is OFFLINE, boot a CD or USB drive with the it installed to scan the not running system for malware (it's detailed on the link i posted) –deveneyi Nov 27 AVG No! –pratnala Nov 27 '12 at 10:00 2 When I tried in a similar situation, AVG said the system is clean.

This will rule out most problems with memory and hard drive issues. To do so, from the Start menu choose "Run," and type msconfig. Gringo __________________ 03-23-2010, 01:56 PM #4 redwill Registered Member Join Date: Mar 2010 Posts: 2 OS: Windows XP Professional Hi there, thank you for the response. Once a machine is infected this badly it's likely loaded with all kinds of bad stuff.

So... check over here share|improve this answer edited Nov 30 '12 at 12:43 community wiki 3 revs, 2 users 87%HairOfTheDog 60 While I normally discourage short answers with lack of detail, these four words It has 3-4 different software solutions that will go out to the net and fetch its latest definitions before it starts its scanning/cleaning process. It does not remove any malware it finds.Please also include a fresh HijackThis log.With Regards,The Panda If I have been helping you (including trainees) and do not reply within 48 hours,

Log in with Mumsnet Sign in with Facebook Sign in with Google Active| I'm on| I'm watching| I started| Last 15 minutes| Last hour| Last Day Please login first. On the rare occasion I run Windows - it's MSE for me. –nerdwaller Nov 28 '12 at 5:58 | show 1 more comment up vote 8 down vote At the end Share your story - chance to win vouchers + nappies! share|improve this answer answered Nov 29 '12 at 13:10 community wiki Alex Forbes add a comment| up vote 0 down vote You could have a look at Windows Defender Offline, it

You may want to remove it from the computer and install it in another (or in an external enclosure), but that is far from the same thing. –Michael Kjörling Nov 27 But Kaspersky caught the culprit. If you're prevented from running the command prompt, a renamed copy from another PC can be effective (sometimes you can get away with simply making a copy on the same machine).

Make sure it is set to Instant Notification, then click Subscribe.

Ante-natal clubs Chat Conception Parenting Relationships Site stuff Style and beauty Full Talk topics list Popular Pages Active Conversations Baby name finder Child development calendar Due date calculator Mumsnet weekly deals iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Curse yourself for not having a more recent backup or implementing a system image backup routine. Given that this one clearly has root access you're going to be hunting for it in system directories, but there could be a watcher in there and usually the infection originates

self protection module/ALWIL Software) ZwOpenKey [0xEFCF05AE]SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! Do not start a new topic. You shouldn't need to enter anything manually (although I know in spyware the right mouse click / select all scum / remove all process isn't quite as intuitive as it should weblink If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

If you want to spend your time using your computer rather than fixing it, you may want to consider an Apple. If this doesn't help, then re-installing the Windows system might be the only choice left.