Cyberanswers is now on youtube

Register a free account
ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Spyware / Virus Removal
The Software Store

Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #1  
Old 02-15-2005, 07:14 PM
susanwilborn susanwilborn is offline
Junior Member
 
Join Date: Feb 2005
Posts: 1
I know there are several things on my computer that are't suppose to be there. I had major crashing issues this wekend. I was finally able to boot in safe mode and run virus and spy doctor. But nothing much showed and the files keep coming back.

Any ideas ?

Thanks.[attachmentid=25]
Reply With Quote
Sponsored Links

  #2  
Old 02-15-2005, 07:17 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Hi and welcome aboard susan. There are some things that need to be removed so just sit back and hold a minute while I prepare a response.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #3  
Old 02-15-2005, 07:25 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Now rescan once again with hijack, insert a check next to each of the following, then close all other open browser windows and click "fix checked"
<span style="color:#FF0000">Step 1</span>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [Only Registered and Activated Users Can See Links. Click Here To Register...]

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm


R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)


O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\WINDOWS\ZServ.dll


O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)


O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - C:\WINDOWS\System32\shdocvw.dll (HKCU)

O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - [Only Registered and Activated Users Can See Links. Click Here To Register...]

O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - [Only Registered and Activated Users Can See Links. Click Here To Register...]



<span style="color:#FF0000">Step 2</span>
Then set the system to show hidden files and folders as per:
[Only Registered and Activated Users Can See Links. Click Here To Register...]

<span style="color:#FF0000">Step 3</span>
Reboot back into safe mode again

<span style="color:#FF0000">Step 4</span>
Then open windows explorer, find then delete:
C:\WINDOWS\farmmext.exe

<span style="color:#FF0000">Step 5</span>
Then Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


<span style="color:#FF0000">Step 6</span>
Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

<span style="color:#FF0000">Step 7</span>
Empty the Recycle Bin


<span style="color:#FF0000">Step 8</span>
If you have not run an Adaware scan then do this:
Get The latest version of Adaware
You can download the free version here:
[Only Registered and Activated Users Can See Links. Click Here To Register...]

or here (alternate download location)
[Only Registered and Activated Users Can See Links. Click Here To Register...]

You need to be logged on as Adminstrator through the installation.
For ease in installation and operation, view the tutorial here [Only Registered and Activated Users Can See Links. Click Here To Register...]

Just download it to your desktop and then to install click on the file you just downloaded (aawsepersonal.exe). You will be guided through the installation. It is recommended to use the default setting of "Protect anyone who uses this computer".

On the main screen of Adaware please look for the *check for updates now* link, just above the start button in the bottom right corner or you can click on the Webupdate button that looks like a globe icon at the top. Press * connect* to let it check for any recent updates. If any are found, please let it download and install them.

Now, configure your settings. Click the gear icon at the top. These are the recommended settings:

AAW SE settings

General Button
Safety:
Check (Green) all three.

Advanced Button
Logfile Detail Level:
All options under this should be checked (Green).

Tweak Button
Check (Green) the following:
Log Files
Include basic Ad-Aware settings in logfile:
Include additional Ad-Aware settings in logfile:
Please do not check (Green): Include Module list in logfile:

On your first scan, use the Full Scan (Perform full system scan) mode.

Let Adaware remove any *bad* objects found. Reboot your PC and scan again. Repeat this process until no more bad items are found. It may take several scans to clean everything, depending on the type of infections found.

<span style="color:#FF0000">Step 9</span>
Reboot, rescan with hijack and post a fresh log please.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't Run Any .exe Files c_hustler Windows 2000 | Windows xp | Vista 8 07-13-2005 12:08 PM
Can't get rid of this nasty bugger k4tj3 Spyware / Virus Removal 8 03-14-2005 04:19 PM
ISP cut us off and I can't find what's wrong :( stephthegeek Spyware / Virus Removal 6 02-19-2005 08:06 PM
ssl32dr.exe can't remove it :( robinsonpr Spyware / Virus Removal 2 02-18-2005 06:11 AM
can't delete an exe off my desktop dgapultos Spyware / Virus Removal 2 02-08-2005 12:38 PM


All times are GMT -5. The time now is 04:34 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved