New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 22)
· Marcia's (CO8)
· Bill G's (CO10)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 857
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Help! I have a virus that I can\'t get rid of!

 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My!
View previous topic :: View next topic  
Author Message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Thu Jun 03, 2004 9:45 pm    Post subject: Help! I have a virus that I can\'t get rid of!
Reply with quote

I found this wonderful site and I\'ve been reading all the great help that people have given. I was hoping that someone could help me with this. I\'ve had over 30 viruses since clicking a link a couple of days ago and one I just can\'t get rid of! Can someone help me pretty please???

Logfile of HijackThis v1.97.7
Scan saved at 9:39:31 PM, on 6/3/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\\WINNT\\System32\\smss.exe
C:\\WINNT\\system32\\winlogon.exe
C:\\WINNT\\system32\\services.exe
C:\\WINNT\\system32\\lsass.exe
C:\\WINNT\\system32\\svchost.exe
C:\\WINNT\\system32\\LEXBCES.EXE
C:\\WINNT\\system32\\spoolsv.exe
C:\\WINNT\\system32\\LEXPPS.EXE
C:\\PROGRA~1\\Grisoft\\AVG6\\avgserv.exe
C:\\WINNT\\System32\\drivers\\CDAC11BA.EXE
C:\\Program Files\\Executive Software\\DiskeeperLite\\DKService.exe
C:\\WINNT\\System32\\svchost.exe
C:\\WINNT\\System32\\pctspk.exe
C:\\WINNT\\system32\\regsvc.exe
C:\\WINNT\\system32\\MSTask.exe
C:\\WINNT\\system32\\tlntsvr.exe
C:\\WINNT\\wanmpsvc.exe
C:\\WINNT\\System32\\WBEM\\WinMgmt.exe
C:\\WINNT\\System32\\mspmspsv.exe
C:\\WINNT\\Explorer.EXE
C:\\Program Files\\Browser Mouse\\Browser Mouse\\1.0\\lwbwheel.exe
C:\\WINNT\\TPPALDR.EXE
C:\\Program Files\\Grisoft\\AVG6\\avgcc32.exe
C:\\PROGRA~1\\BILLPS~1\\WINPAT~1\\WinPatrol.exe
C:\\Program Files\\Yahoo!\\Messenger\\ymsgr_tray.exe
C:\\Program Files\\Internet Explorer\\iexplore.exe
C:\\Program Files\\Internet Explorer\\iexplore.exe
C:\\Documents and Settings\\Dorrie Burke\\Desktop\\HijackThis.exe

O4 - HKLM\\..\\Run: [TPP Auto Loader] C:\\WINNT\\TPPALDR.EXE
O4 - HKLM\\..\\Run: [NeroCheck] C:\\WINNT\\system32\\NeroCheck.exe
O4 - HKLM\\..\\Run: [GLSetIT32] c:\\winnt\\system32\\cmereg
O4 - HKLM\\..\\Run: [WinPatrol] C:\\PROGRA~1\\BILLPS~1\\WINPAT~1\\WinPatrol.exe
O4 - HKLM\\..\\Run: [CountrySelection] pctptt.exe
O4 - HKLM\\..\\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\\..\\Run: [TClockEx] C:\\Program Files\\TClockEx\\TCLOCKEX.EXE
O4 - HKCU\\..\\Run: [Yahoo! Pager] C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://12.47.101.191/central/02030105/c...ontent.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://C:\\moo.mht!http://www.rarsoft.co.uk//M.CHM::/ISASS.EXE
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://activex.microsoft.com/activex/co.../Swdir.cab
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/3110/...rix6ie.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {4A752EEF-26FA-4E8F-8FF0-4EB40FE1D33B} (ACNPlayer2 Class) - http://204.118.132.145/Harris/eplayer.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/...brkpie.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...6918865741
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - http://activex.microsoft.com/activex/co...ontrol.cab
O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4003/...brxpie.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/sho...wflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.c..._0_2_1.cab
Back to top
View users profile Send private message
mrrockford

AVPE Host
wackyidea guy


Joined: Apr 24, 2004
Posts: 235
Location: Germany/USA

PostPosted: Fri Jun 04, 2004 1:27 am    Post subject:
Reply with quote

Howdy,

Where are the viruses located (complete path)?
Back to top
View users profile Send private message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Fri Jun 04, 2004 6:05 am    Post subject:
Reply with quote

Hi, the virus is a trojan horse downloader and its located at:

c:\winnt\system32\fmsujq.exe

I have used several different virus programs to try and get rid of it and I haven't found one yet that will.

Any suggestions and/or help is greatly appreciated! I figure this is how I ended up with around 30 trojans on my computer!
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 921
Location: Canada

PostPosted: Mon Jun 07, 2004 12:52 am    Post subject:
Reply with quote

Hi OhEvilOne!

I am analysing your log. Could you please move your HijackThis to a regular folder such as C:\Program Files\HijackThis ? It cannot save proper backups in a desktop and not in a Temp folder. Thanks.


Best regards and welcome to Computer Cops!
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 921
Location: Canada

PostPosted: Mon Jun 07, 2004 4:19 pm    Post subject:
Reply with quote

Hi OhEvilOne!

You have more than one trojan there. Wink

Please download an evaluation version of Trojan Hunter from www.misec.net. install it, update using directions here http://www.misec.net/support/trojanhunter/updating/

Then reboot and do a full system scan. Post back any results, and/or if you need any help using Trojan Hunter.

You also have the Sasser Worm. Please go to Microsoft: http://www.microsoft.com/security/incid...t2000.mspx
The download for the patch is near the bottom of the page.

After completing these steps run and post a fresh HijackThis Log.

_________________
ASAP - Expert
Help those who help! Please donate to Computer Cops
Back to top
View users profile Send private message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Mon Jun 07, 2004 7:54 pm    Post subject:
Reply with quote

Prince, first off - a BIG THANK YOU TO YOU!!!

I am currently doing a scan using Trojan Hunter and will download the MS patch after it is done and run another Hijack This log.

I have also moved HiJack This into its own file.

Thank you for your help so far!

I think I am in love!

OEO
Back to top
View users profile Send private message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Mon Jun 07, 2004 9:12 pm    Post subject:
Reply with quote

I can't thank you enough.

I have completed the above steps and here is the new hijack this log:

Logfile of HijackThis v1.97.7
Scan saved at 9:10:33 PM, on 6/7/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\pctspk.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\tlntsvr.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\mspmspsv.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINNT\TPPALDR.EXE
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\HiJackThis\HijackThis.exe

O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\TPPALDR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://12.47.101.191/central/02030105/c...ontent.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://C:\moo.mht!http://www.rarsoft.co.uk//M.CHM::/ISASS.EXE
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://activex.microsoft.com/activex/co.../Swdir.cab
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/3110/...rix6ie.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {4A752EEF-26FA-4E8F-8FF0-4EB40FE1D33B} (ACNPlayer2 Class) - http://204.118.132.145/Harris/eplayer.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/...brkpie.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...6918865741
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - http://activex.microsoft.com/activex/co...ontrol.cab
O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4003/...brxpie.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/sho...wflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.c..._0_2_1.cab
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 921
Location: Canada

PostPosted: Tue Jun 08, 2004 12:59 pm    Post subject:
Reply with quote

Hi OhEvilOne!

Copy and paste these instructions into Notepad for easy reference.

Run HijackThis, put a check beside each of the following entries, be sure all windows and browsers are closed (except HijackThis), then click "fix checked."

O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://12.47.101.191/central/02030105/c...ontent.cab

O16 - DPF: {11111111-1111-1111-1111-111111111123} - ms-its:mhtml:file://C:\moo.mht!http://www.rarsoft.co.uk//M.CHM::/ISASS.EXE

O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/3110/...rix6ie.cab

O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} -

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4018/...brkpie.cab

O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4003/...brxpie.cab

Next, boot into safemode. Safemode Instructions for all platforms.

Show Hidden Files and Folders on Windows 2000

Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

With Windows Explorer find and delete the following file in bold.

C:\WINNT\system32\tlntsvr.exe

REBOOT

Then run HijackThis again, scan and post a fresh log here.
Back to top
View users profile Send private message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Tue Jun 08, 2004 8:05 pm    Post subject:
Reply with quote

Prince, you are AWESOME! I don't know how to thank you for all of your help! Since I've followed the steps above it is like my computer is on steroids again. Smile

I also deleted the following file from the c:\winnt\system32 file: tlntsvrp.dll and I noticed these programs in there:

tlntadmn.exe and tlntsess.exe

Should I get rid of those also?

Here is my latest Hijack this log:

Logfile of HijackThis v1.97.7
Scan saved at 8:02:19 PM, on 6/8/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\pctspk.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINNT\TPPALDR.EXE
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\HiJackThis\HijackThis.exe

O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\TPPALDR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://activex.microsoft.com/activex/co.../Swdir.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {4A752EEF-26FA-4E8F-8FF0-4EB40FE1D33B} (ACNPlayer2 Class) - http://204.118.132.145/Harris/eplayer.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...6918865741
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - http://activex.microsoft.com/activex/co...ontrol.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc...wflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.c..._0_2_1.cab

Thank you again! Your a doll!
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 921
Location: Canada

PostPosted: Wed Jun 09, 2004 10:45 am    Post subject:
Reply with quote

Hi OhEvilOne!

Really glad to see everything is working okay again! Thumbs Up

Quote:
tlntadmn.exe and tlntsess.exe

Should I get rid of those also?


Definitely NOT. Those are good Telnet Server programs. The one you removed is a virus/trojan.

Your log is clean now. To keep it clean I would suggest you keep your OS patched, your AV updated daily (run full scans at least weekly), get yourself a firewall, and here is a list of antispyware and anti-adware applications that we all use here (all are freewares):

SpywareBlaster and SpywareGuard http://www.javacoolsoftware.com/spywareblaster.html

These one's come with instructions too! Wink

ADAWARE - Removes spywares and adwares from your computer

1. Download and install Adaware (free edition). (Click on "Adaware" in the left-hand column near the top at their website to download the free edition.)

2. After installing go to Start > Programs > Lavasoft and click on AdAware 6 to open the program

3. Look at the icons on the top right of the page and click on the ‘world’ and let AdAware update the spyware reference list (Note: Always update Adaware before you scan.)

4. Once the update is finished click on the ‘Gear’ icon (second from the left) to access the preferences/settings window

1. In the ‘General’ window make sure the following are selected:
· Automatically save log-file
· Automatically quarantine objects prior to removal
· Safe Mode (always request confirmation)

2. Click on the ‘Scanning’ button on the left and select :
· Scan Within Archives
· Scan Active Processes
· Scan Registry
· Deep Scan Registry
· Scan my IE favorites for banned URL’s
· Scan my Hosts file
· Under ‘Click here to select drives + folders’, choose:
· All of your hard drives

3. Click on the ‘Advanced’ button on the left and select:
· Include additional process information
· Include additional file information
· Include environment information
· Include additional object details

4. Click the ‘Tweak’ button and select:
· Under the ‘Scanning Engine’:
· Unload recognized processes during scanning
· Include basic Ad-aware settings in logfile
· Include additional Ad-aware settings in logfile
· Under the ‘Cleaning Engine’:
· Let Windows remove files in use at next reboot

5. Click on ‘Proceed’ to save the settings.

6. Click ‘Start’ and on the next screen choose ‘Activate in-depth Scan’ at the bottom of the page and then choose:
· Use Custom Scanning Options

7. Click ‘Next’ and AdAware will scan your hard drive(s) with the options you have selected.

8. Save the log file when it asks and then click ‘finish’

9. REBOOT
----------------------------------------------------------
SPYBOT SEARCH & DESTROY - Removes spywares, spybots, and adwares

1. Next, download and install Spybot Search and Destroy.

2. Go to Start > Programs >Spybot - Search & Destroy and choose ‘Spybot S&D - easy mode’

3. Close ALL windows except Spybot S&D

4. Click the button to ‘Search for Updates’ and download and install the Updates.

5. Next click the button ‘Check for Problems’

6. When Spybot is complete, it will be showing ‘RED’ entries ‘BLACK’ entries and ‘GREEN’ entries in the window

7. Put a check mark beside the RED entries ONLY.

8. Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.

9. REBOOT

Take good care now. Very Happy

_________________
ASAP - Expert
Help those who help! Please donate to Computer Cops
Back to top
View users profile Send private message
OhEvilOne

Cadet
Cadet



Joined: Jun 02, 2004
Posts: 8
Location: USA

PostPosted: Wed Jun 09, 2004 7:54 pm    Post subject:
Reply with quote

Prince,

THANK YOU AGAIN FOR ALL OF YOUR HELP! You really are a Prince! I would not be disease free and cruising the superinformation highway with this speed if it weren't for you and your great help and simple steps! Wink

I should mention that I run AVG and Housecall on a daily basis, as well as Adaware and SpyBot. I also update them each time I use them. The only thing I don't have that I know of is a firewall and after this mess, I will be getting one! Cool

Thank you again! I think I will go figure out how to make a donation!

OEO
Back to top
View users profile Send private message
Prince_Serendip

AVPE Host
Premium Member
Premium Member


Joined: Sep 07, 2002
Posts: 921
Location: Canada

PostPosted: Sun Jun 13, 2004 11:27 am    Post subject:
Reply with quote

Hi OhEvilOne!

Glad to help. If you make a donation, you will get to become a Premium Member. It means extra perks.
If you don't want to use PayPal, there's a hard address that can take snail mail. You can send a money order that way. Wink

Here's the link to our Firewalls Downloads Pages:
http://www.computercops.biz/downloads-cat-5.html


All the best! Very Happy

_________________
ASAP - Expert
Help those who help! Please donate to Computer Cops
Back to top
View users profile Send private message
lilliebet65

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Dec 03, 2003
Posts: 2036
Location: UK

PostPosted: Sun Jun 13, 2004 11:30 am    Post subject:
Reply with quote

Glad we were able to help. Smile

NOTE: This thread is now closed. Should you need it reopened, please PM a mod.
Everyone else having a similar issue, please launch a new topic for yourselves.

To reduce the chances of future Spyware/Hijacking problems, please follow the suggestions here: http://www.computercops.biz/postt7736.html

_________________
I'm Spartacus!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops