Computer Troubleshooters - Oakleigh

      Computer Troubleshooters - Oakleigh assumes no liability for or consequences from unlicenced software,
      problems caused by software or user or data loss on any media through the use of information on this blog.

Archive for the ‘Spyware’ Category

Windows System Suite Spyware

Monday, August 10th, 2009

This a particularly nasty spyware. Firstly run MalwareBytes or Spybot to remove most of it. then you have to manually remove some files.

This link has instructions. http://www.bleepingcomputer.com/virus-removal/remove-windows-system-suite

After this, Windows may still report that an Antivirus program is currently installed, reporting it as Windows System Suite.

Do the following:

In Control Panel click on Administrative Tools, then Services, from the list of services find Windows Management Instrumentation right click mouse and from dropdown list stop the service.

Find folder C:\windows\system32\wbem, inside this folder identify the repository folder and delete only this folder (the repository folder) from your computer.

In Administrative Tools find Windows Management Instrumentation service again, and re-start the service by right clicking mouse and pressing start from dropdown list. Restarting this service re-builds the repository folder database on your computer, which should now only contain information about your currently installed antivirus & firewall programs.

To reset the Windows Security Centre you must re-boot your computer.

You should then be able to reinstall you AV program.

However, I was still having trouble installing AVG, it kept failing to start the AVG Service at the end of the install.

Following the mentioned thread and the directions for windows registry corruption:

“Please open Windows Registry Editor
- open menu Start -> Run -> enter “regedit” and cofirm OK
In opened Registry Editor find this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
Check that none of sub-keys have name like AVG processes (all AVG processes):
avgam.exe
avgcfgex.exe
avgcmgr.exe
avgcsrva.exe
avgcsrvx.exe
avgdiag.exe
avgdiagex.exe
avgdumpa.exe
avgdumpx.exe
avgemc.exe
avgfrw.exe
avgfws8.exe
avgfwwiz.exe
avgiproxy.exe
avgnsa.exe
avgrsa.exe
avgscana.exe
avgscanx.exe
avgsrmaa.exe
avgsrmax.exe
avgstrma.exe
avgstrmx.exe
avgsysta.exe
avgsystx.exe
AVGToolbarInstall.exe
avgtray.exe
avgui.exe
avgupd.exe
avgwdsvc.exe
fixcfg.exe
And remove them from registry. ”

I deleted those entries in the registry and, finally I was able to install successfuly the AVG 8.5.

Windows gets IP address and can browse LAN but not Internet

Friday, November 7th, 2008

This is becoming more and more common. Your PC gets IP address settings OK, can browse the LAN but cannot access the Internet. Spyware cleaners cannot update because they use the same setting as IE. Hijack This shows the list of items loading at startup. Look for a registry entry for Internet Explorer for the ‘proxy override’ or ‘proxy server’, usually it is set to 127.0.0.1 (localhost) or .local which causes IE to look at the local computer (itself) for internet access.

Remove these entries and reboot will normally get the browsing and online updates happening again, and still do a scan for spyware using Spybot and Malware Bytes.

userinit.exe failed to initialize and desktop without icons

Tuesday, August 26th, 2008

This is due to Malware/Spyware. To get things going again go into Task Manager, CTRL+ALT+DEL and then File, New Task and enter explorer. This may get your desktop up and running to do other things. If not, then go back to Task Manager and run ‘msconfig.exe’ and turn off all services and startup items and reboot. The idea is to first get CCleaner installed to remove rogue items from startup and then install/update/run Spybot and Malwarebytes. A couple of runs of these should clear most things.

WinXP Antivirus 2008 & WinXP Antifraud 2008

Sunday, August 24th, 2008

This is spyware which is usually transmitted via a hoax email regarding an undeliverable package with an attachment saying it is from UPS or Fedex. The attachment has a filename.exe (executable file) within a .zip file. If the .exe file is run then registry settings are created/changed disabling your Display Settings, Task Manager and removing your System Restore Points. It also install the BSOD(Blue Screen of Death) ScreenSaver which makes you think your PC has crashed when in fact it is OK. It is very sneaky in that it shows you a Windows XP Splashscreen as if it is booting up and then a BSOD. Just hit spacebar and your desktop will reappear. Installation/Update/Run the following programs, SpyBot and MalwareBytes will get rid of most of it, but not all of it. Some registry settings may have to be manually removed. Use CCleaner to edit the startup items in the registry. You may see an entry for something like hpchj0d43 as an example. Delete it.