Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

How to remove lingering remnants of 'Troj/Rustok-N'

9 views
Skip to first unread message

Exyen

unread,
Jul 14, 2009, 2:54:24 PM7/14/09
to

So I downloaded Spydoctor and I believe I removed 'Troj/Rustok-N' after
getting infected by it, but there seems to me that there are still some
things that are odd going in my computer

1) Whenever I boot up I run Registry Mechanic and it always "fixes" 3-5
registries everytime I boot up. Also while I am running my cpu, if I run
registry mechanic again it will always randomly pick up 2 or 3 errors. I
don't really know if I am just being paranoid or not.

2) Whenever I search on google, and click a link from it, it leads me
somewhere else first (other search sites, http://smartbizsearch.com/),
and then if I reload the search it takes me to the right place.

3) Today my ISP cut the internet connection saying I was infected by a
Bot Virus (Botnet drone or something similar), but he reconfigured it
after I said I had run anti-viruses.

After running Avira, Spyware Doctor, and Ad-Aware, nothing comes up, so
I am a bit at a loss on what to do at this very moment. Help would be
highly appreciated.


--
Exyen
------------------------------------------------------------------------
Exyen's Profile: http://forums.techarena.in/members/114724.htm
View this thread: http://forums.techarena.in/security-home-users/1214114.htm

http://forums.techarena.in

MowGreen

unread,
Jul 14, 2009, 6:04:47 PM7/14/09
to
Do you have the CD/DVD of the Operating System that is installed ?
Good.

Back up the date that you want to preserve and format the HardDrive.

The system has been *** severely compromised and can NOT be Trusted ***

The only method that will allow you to surf safely again on this system
is to format and reinstall. Period.


MowGreen
===============
*-343-* FDNY
Never Forgotten
===============

~BD~

unread,
Jul 15, 2009, 3:17:16 PM7/15/09
to
Just *how* did you come to this conclusion, Mow Green?

You friend Mr Bill Castner at www.aumha.net could provide a 'fix' in no
time at all ............ couldn't he?

Why have you not recommended running a HJT and posting on Aumha?

Just wondering.

--
Dave


"MowGreen" <mowg...@nowandzen.com> wrote in message
news:ug4TY8M...@TK2MSFTNGP02.phx.gbl...

~BD~

unread,
Jul 16, 2009, 3:30:40 AM7/16/09
to

"Peter Foldes" <ok...@hotmail.com> wrote in message
news:uYbY9hYB...@TK2MSFTNGP03.phx.gbl...
> You are a friggin idiot. ROFLMAO
>
>

Can anyone tell me what Mr Foldes finds funny here?

--
Dave


Peter Foldes

unread,
Jul 16, 2009, 7:54:50 AM7/16/09
to
Comprehension is not your forte David. You really will have to work on it if you
want to keep up with the
Jones's. :-)

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"~BD~" <Boate...@hotmail.co.uk> wrote in message
news:OegHRdeB...@TK2MSFTNGP03.phx.gbl...

Tom Willett

unread,
Jul 16, 2009, 8:57:42 AM7/16/09
to
You, of course.

"~BD~" <Boate...@hotmail.co.uk> wrote in message
news:OegHRdeB...@TK2MSFTNGP03.phx.gbl...

:
: "Peter Foldes" <ok...@hotmail.com> wrote in message

:
:


~BD~

unread,
Jul 16, 2009, 4:39:04 PM7/16/09
to
I meant someone of note, Tom (Pepper) Willet - not you!

--
Dave

"Tom Willett" <t...@youreadaisyifyoudo.com> wrote in message
news:uLNTKUhB...@TK2MSFTNGP04.phx.gbl...

Tom Willett

unread,
Jul 16, 2009, 5:00:38 PM7/16/09
to
I've got more note than you'd ever think of having, you hooplehead.

"~BD~" <Boate...@hotmail.co.uk> wrote in message

news:O5yTTWlB...@TK2MSFTNGP05.phx.gbl...
:I meant someone of note, Tom (Pepper) Willet - not you!

: > :
: >
: >
:
:


~BD~

unread,
Jul 16, 2009, 5:18:44 PM7/16/09
to

"Tom Willett" <t...@youreadaisyifyoudo.com> wrote in message
news:efwEBilB...@TK2MSFTNGP02.phx.gbl...

> I've got more note than you'd ever think of having, you hooplehead.


That's good to know, Tom!

What do you consider your number one achievement during your short
lifetime?

--
Dave


~BD~

unread,
Jul 17, 2009, 3:54:04 AM7/17/09
to

A certain amount of 'impostering' going on today!

"Tom Willett" <t...@youreadaisyifyoudo.com> wrote in message

news:efwEBilB...@TK2MSFTNGP02.phx.gbl...
> I've got more note than you'd ever think of having, you hooplehead.

"Jack Strapp" <t...@youreadaisyifyoudo.com> wrote in message
>> news:uLNTKUhB...@TK2MFTNGP04.phx.gbl...
>>> You, of course.

History under!

--
Dave


"JackStrap" <no...@therfore.cp> wrote in message
news:O4crDPpB...@TK2MSFTNGP02.phx.gbl...
> BD or whoever you are
>
> Stop posting here. We do not need your abnormality here. You are a
> messed up individual BD whoever the heck you are


>
>
> "~BD~" <Boate...@hotmail.co.uk> wrote in message

> news:O5yTTWlB...@T2MSFTNGP05.phx.gbl...
>>I meant someone that is a Troll, Jack Strap and not you!
>>
>> --
>> Dave
>>
>> "Jack Strapp" <t...@youreadaisyifyoudo.com> wrote in message
>> news:uLNTKUhB...@TK2MFTNGP04.phx.gbl...


>>> You, of course.
>>>
>>> "~BD~" <Boate...@hotmail.co.uk> wrote in message

>>> news:OegHRde...@T2MSTNGP03.phx.gbl...
>>>
>>> :Jack Strap is childish and has no xxxxxxxx
>>> :: --
>>> :Dave
>>> :
>>>
>>>
>>
>>
>


~BD~

unread,
Jul 17, 2009, 4:42:28 AM7/17/09
to

"JackStrap" <no...@therfore.cp> wrote in message
news:O4crDPpB...@TK2MSFTNGP02.phx.gbl...
> BD or whoever you are
>
> Stop posting here.

Imposter posts.

Are you in charge here Mr Strap?

I note that your contact address has changed, btw. Bit of a slip, I
guess!

I am, and have always been, BoaterDave! :)

--
Dave


~BD~

unread,
Jul 17, 2009, 6:56:50 AM7/17/09
to
I've told you before, Peter - the correct English is "... her Majesty's
Service".

We will be mooring outside Windsor Castle in a day or two - just in case
anyone reading here is vaguely interested. :)

--
Dave


"Peter Foldes" <ok...@hotmail.com> wrote in message

news:uL90jVnB...@TK2MSFTNGP05.phx.gbl...
>
That is the story going around in her Majesties Service. >


Milo

unread,
Jul 17, 2009, 2:05:30 PM7/17/09
to
Guys can we go back to the concern.... rather chat else where with your
disputes.

Exyen, can you download hijackthis and run a scan with it get the hijackthis
log / and get as well the startuplist log
ps. email me the logs for analysis since hijackthis isn't allowed to be
posted here.

jfcoel@(hotmail.com)

Many Thanks,

"Exyen" <Exyen....@DoNotSpam.com> wrote in message
news:Exyen....@DoNotSpam.com...

PA Bear [MS MVP]

unread,
Jul 17, 2009, 2:39:46 PM7/17/09
to
[OP's not been seen since he first posted (via techarena.in) on 14 July]

~BD~

unread,
Jul 17, 2009, 3:00:36 PM7/17/09
to

"Milo" <jfc...@hotmail.com> wrote in message
news:17E48A99-D73B-4CC7...@microsoft.com...

> since hijackthis isn't allowed to be posted here.
>
> jfcoel@(hotmail.com)
>
> Many Thanks,

Milo - I appreciate your comments and have no quarrel with you.

Tell me - *why* are HJT logs not allowed to be posted here?

Who is in charge? Who stipulates this rule?

Must we all do as directed by PABear? If so, why? I don't trust him - he
tells lies. I know that - he knows that. Others must be confused!

-- Dave


Milo

unread,
Jul 17, 2009, 4:35:35 PM7/17/09
to
Well one thing just kinda lighten down on those argument ^_^ BD honestly I
don't know who has claim to the NG - is it MS or the people / just to avoid
those long threads am doing my own reading since I have some good ties with
company who owns it ^_^..

"~BD~" <Boate...@hotmail.co.uk> wrote in message

news:eEpzjDxB...@TK2MSFTNGP05.phx.gbl...

Milo

unread,
Jul 17, 2009, 4:43:36 PM7/17/09
to
Just to elaborate ( company who owns it hijackthis )

"Milo" <jfc...@hotmail.com> wrote in message

news:04AE65BC-2EBC-4033...@microsoft.com...

PA Bear [MS MVP]

unread,
Jul 17, 2009, 4:49:38 PM7/17/09
to

[What are you smoking, Milo?]

Milo

unread,
Jul 17, 2009, 4:57:59 PM7/17/09
to
Hmmm Marlboro red/medium maybe I just got too much sun today ^_^


"PA Bear [MS MVP]" <PABe...@gmail.com> wrote in message
news:u3pZuByB...@TK2MSFTNGP03.phx.gbl...

~BD~

unread,
Jul 18, 2009, 2:30:25 AM7/18/09
to
Hello Exyen

See the post today entitled Re: Can The Real Truth MVP help with this
query?

Let folk here know how you get on!

--
Dave


"Exyen" <Exyen....@DoNotSpam.com> wrote in message
news:Exyen....@DoNotSpam.com...
>

Milo

unread,
Jul 18, 2009, 4:38:07 AM7/18/09
to

Hey BD,,, another thing - just convey to those guys arguing all the time
bring it to the criminal court - use the cyberlaw which apply to
slander/libel/stalking/spoofing etc etc.....


"~BD~" <Boate...@hotmail.co.uk> wrote in message
news:eEpzjDxB...@TK2MSFTNGP05.phx.gbl...
>

The Real Truth MVP

unread,
Jul 18, 2009, 11:03:32 AM7/18/09
to
Use my Remove-it software, it will remove that malware from your system.
Choose yes for all options when prompted. Download it here
http://www.ms-mvp.org/

--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.


"Exyen" <Exyen....@DoNotSpam.com> wrote in message
news:Exyen....@DoNotSpam.com...
>

PA Bear [MS MVP]

unread,
Jul 18, 2009, 12:50:05 PM7/18/09
to
<pft> What's the "real truth" about pcbutts1 (AKA The Real Truth MVP)? Read
on...

. Is he an MS MVP? No!
cf. http://mvp.support.microsoft.com/communities/mvp.aspx

. If xxx.ms-mvp.org redirects to xxx.pcbutts1.com, why didn't he post that
link to begin with?

. Is he a proven thief? Yes!
cf.
http://msmvps.com/blogs/hostsnews/archive/2006/11/10/pcbutts1-_2E00__2E00_.-the-saga-continues-_2E00__2E00__2E00_.aspx
cf.
http://groups.google.com/group/microsoft.public.security.homeusers/msg/213247814fb4d61e
cf.
http://groups.google.com/group/microsoft.public.security.homeusers/msg/e19fce884897662f

. What do real experts have to say about him? It ain't pretty.
cf. http://www.siteadvisor.com/sites/pcbutts1.com (Reviews)

. Does he have all his marbles?
cf. http://en.wikinews.org/wiki/NASA_van_rolls_off_California_mountain

Ignore this MVP imposter!
--
~Robear Dyer
MS MVP-IE, Mail, Security, Windows Client
https://mvp.support.microsoft.com/default.aspx/profile/robear.dyer


The Real Truth MVP wrote:
> Use my Remove-it software, it will remove that malware from your system.
> Choose yes for all options when prompted. Download it here

> xxx.ms-mvp.org/

David H. Lipman

unread,
Jul 18, 2009, 1:09:02 PM7/18/09
to
From: "~BD~" <Boate...@hotmail.co.uk>

| I meant someone of note, Tom (Pepper) Willet - not you!

Then I'll answer "You of course".

You are F'n trolling and bringing a lowlife scumbag thief such as Chris Butts (aka;
PCBUTTS1) does NOT help you or the cause you injected your BS into.

Mow Green knows perfectly well what a nasty RootKit the Rustock is.

/* S T A Y O U T O F I T ! */

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Larry Thomas

unread,
Jul 18, 2009, 2:01:53 PM7/18/09
to
A big fat lie!

"~BD~" <Boate...@hotmail.co.uk> wrote in message

news:%23yoNCqr...@TK2MSFTNGP04.phx.gbl...

~BD~

unread,
Jul 18, 2009, 2:53:36 PM7/18/09
to

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%23Bbv0p8...@TK2MSFTNGP02.phx.gbl...
> From: "~BD~" <Boate...@hotmail.co.uk>

You give orders without authority, David H Lipman.

You have in no way shown that you are deserving of my trust or confirmed
your role in 'real life'. Until you do so (email is acceptable) then do
*not* demand or expect me to unquestioningly do as you wish.

PA Bear has lied about me - he is not to be trusted. I know that and
*he* knows that. Mow Green will not correspond with me. As he is from
the same camp as PABear at www.aumha.net then, in my book, he's in the
same category.
--
Dave (the boater!)


David H. Lipman

unread,
Jul 18, 2009, 3:19:43 PM7/18/09
to
From: "~BD~" <Boate...@hotmail.co.uk>

| You give orders without authority, David H Lipman.

| You have in no way shown that you are deserving of my trust or confirmed
| your role in 'real life'. Until you do so (email is acceptable) then do
| *not* demand or expect me to unquestioningly do as you wish.

| PA Bear has lied about me - he is not to be trusted. I know that and
| *he* knows that. Mow Green will not correspond with me. As he is from
| the same camp as PABear at www.aumha.net then, in my book, he's in the
| same category.
| --
| Dave (the boater!)


You have NO IDEA who the "good guys" are.
You are truly one big jerk off.

~BD~

unread,
Jul 18, 2009, 3:28:47 PM7/18/09
to

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:uymH2y9B...@TK2MSFTNGP05.phx.gbl...

It is answers like yours, and this one, which really need to be
explored!

"Peter Foldes" <ok...@hotmail.com> wrote in message

news:emZcXu9B...@TK2MSFTNGP03.phx.gbl...
> You just nailed your coffin shut permanently with that answer. Lonely
> to be alone
> David as you will find out shortly but surely.

--
Dave

~BD~

unread,
Jul 18, 2009, 5:41:49 PM7/18/09
to
This one too!

"Peter Foldes" <ok...@hotmail.com> wrote in message

news:%23TnB7F%23BKH...@TK2MSFTNGP05.phx.gbl...
> You just put another nail in your coffin you fibbing Troll. Cannot
> help yourself from fibbing can you. Go get help since help is needed
> for you

--
Dave


~BD~

unread,
Jul 18, 2009, 5:51:17 PM7/18/09
to

"Milo" <jfc...@hotmail.com> wrote in message
news:0B4D7F2E-2AC5-4273...@microsoft.com...

> Hey BD,,, another thing - just convey to those guys arguing all the
> time bring it to the criminal court - use the cyberlaw which apply to
> slander/libel/stalking/spoofing etc etc.....

I try - but they don't listen!

You seem to want to help folk, Milo

......... and I have no doubt you are genuine!

I'm not at all sure about some of the others posting here though!

--
Dave


David B.

unread,
Jan 31, 2017, 3:35:44 AM1/31/17
to
A voice of authority on this matter!

--
"Do something wonderful, people may imitate it." (Albert Schweitzer)

Diesel

unread,
Jan 31, 2017, 7:26:40 AM1/31/17
to
"David B." <Dav...@nomail.afraid.invalid>
news:z%XjA.213212$AN5....@fx22.fr7 Tue, 31 Jan 2017 08:35:43 GMT
So the reason you initially supported him and invited others to read
his 'blog' (which was censored last time I checked, btw. You can't
leave real comments, he never approves them. ROFL. Not if their
honest and/or question him) was?

MID: <AAXjA.213211$AN5.1...@fx22.fr7>


You're a scumbag piece of shit, David. No doubt about it.



--
Sarcasm, because beating the living shit out of deserving people is
illegal.
0 new messages