Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Closed Thread
 
Thread Tools Display Modes
  #21  
Old 07-20-2005, 09:14 AM
PaulB1955's Avatar
PaulB1955 PaulB1955 is offline
Member
 
Join Date: May 2005
Posts: 41
OK Mobo, There is only one problem, about every 2 minutes I get a pop up from Trend Micro PC-cillin Internet Security Notification saying: Real-time Scan
Trend Micro PC-cillin Internet Security has detected a virus, spyware application, or other Internet threat, and performed the action specified.

Infected file: C:\WINDOWS\SYSTEM32\WININET.DLL
Virus name: TSPY_ALEMOD.A
User name: Brian
Scan action result: The Quarantine action was unsuccessful. Manually delete the file if you are sure that it is not needed.
Note: If Search for and clean Trojans is enabled and is executed after scanning, you can click Next to view final scan result information. How do I get this :censored: to go AWAY!!! Thanks, Paul
  #22  
Old 07-20-2005, 01:59 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Thats simple enough ot rid:
Download this please - http://www.downloads.subratam.org/KillBox.zip

Unzip to your desktop then doble click on killbox.exe. Then in the space provided paste this: C:\WINDOWS\SYSTEM32\WININET.DLL

Then tick the "delete on reboot" option and then click the red x to set it to reboot.
  #23  
Old 08-06-2005, 05:54 PM
PaulB1955's Avatar
PaulB1955 PaulB1955 is offline
Member
 
Join Date: May 2005
Posts: 41
Hi Mobo, Just got back from vacation and I am STILL getting this anoying pop-up from Trend Micro saying: Trend Micro PC-cillin Internet Security has detected a virus, spyware application, or other Internet threat, and performed the action specified.

Infected file: C:\WINDOWS\SYSTEM32\WININET.DLL
Virus name: TSPY_ALEMOD.A
User name: Brian
Scan action result: The Quarantine action was unsuccessful. Manually delete the file if you are sure that it is not needed.
Note: If Search for and clean Trojans is enabled and is executed after scanning, you can click Next to view final scan result information. I went to their web page and did EVERYTHING that they said, I also downloaded Killbox and did EVERYTHING that you said. My computer seems to be working OK, except for this :censored: pop-up that keeps showing up every couple minutes! Is there ANYTHING that I can do to get rid of it???? Thanks again, Paul
  #24  
Old 08-06-2005, 06:46 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Ok paul. This is tried tested and true..


Go to start
run
cmd

Type this exactly as shown----> cd\windows\system32

Then type exacxtly as shown here-->del wininet.dll

Then download the attached file unzip and put that wininet.dll in the system32 folder.
  #25  
Old 08-07-2005, 02:22 PM
PaulB1955's Avatar
PaulB1955 PaulB1955 is offline
Member
 
Join Date: May 2005
Posts: 41
OK Mobo, When I typed del wininet.dll and hit rerturn it comes up with: ACCESS IS DENIED! Now WHAT??? Paul
  #26  
Old 08-07-2005, 05:19 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Are you logged in as administrator ? If not then log into an admin account.Then right click on the wininet.dll file in the system 32 folder. Select properties and uncheck any of the two boxes if they are checked and apply.
  #27  
Old 08-07-2005, 07:47 PM
PaulB1955's Avatar
PaulB1955 PaulB1955 is offline
Member
 
Join Date: May 2005
Posts: 41
Mobo, Yes...I am logged in as Administrator. Everytime I try to delete wininet.dll it says Access is Denied. Paul
  #28  
Old 08-07-2005, 08:08 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Download smitRem.zip and save the file to your desktop.
Right click on the file and extract it to it's own folder on the desktop.
http://noahdfear.geekstogo.com/click%20cou.../click.php?id=1



Next, please reboot your computer in SafeMode by doing the following:[list=1][*]Restart your computer[*]After hearing your computer beep once during startup, but before the Windows icon appears, press F8.[*]Instead of Windows loading as normal, a menu should appear[*]Select the first option, to run Windows in Safe Mode.


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply
  #29  
Old 08-07-2005, 08:20 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Better still Bill.

Disable system restore http://www.cyberanswers.org/forum/index.ph...e&pg=sysrestore


Download the attached file, unzip and double click on the fix.reg file.


Then reboot, rescan with trend micro.
  #30  
Old 08-12-2005, 06:04 PM
PaulB1955's Avatar
PaulB1955 PaulB1955 is offline
Member
 
Join Date: May 2005
Posts: 41
Mobo, Well I did as you suggested and disabled system restore, downloaded the fix.reg file, rebooted and rescanned with trend Micro. After the scan it comes up with one virus C:\WINDOWS\SYSTEM32\WININET.DLL However, I am unable to get rid of it :censored: Do you have ANY other ideas?? Paul
Closed Thread

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    eliteuvf32.exe?? AdWare? Alex Spyware / Virus Removal 31 05-17-2005 09:50 PM
    Problems here... sula Spyware / Virus Removal 16 04-16-2005 12:16 AM
    Popups have seized my computer skinsfan87 Spyware / Virus Removal 234 04-11-2005 02:18 PM
    got some virus problems scott86 Spyware / Virus Removal 3 04-05-2005 02:20 PM
    Pop-up crazy MOJET Spyware / Virus Removal 11 03-30-2005 09:22 PM



    All times are GMT -5. The time now is 06:24 PM.


    Firefox 2