Any help?
| Any help?
1. Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
2. Disable Notepad's word wrap:
In Notepad.exe; Format --> uncheck; "Word wrap"
3. Download/run Deckard's System Scanner:
http://www.techsupportforum.com/sectools/Deckard/dss.exe
4. Save the scan results (Main.txt and Extra.txt)
5. And then post the contents of Main.txt and Extra.txt in your post in one of the below
expert forums...
{ Please - Do NOT post the HJT and Deckard's System Scanner Logs here ! }
Forums where you can get expert advice for HiJack This! (HJT) and Deckard's System Scanner
Logs.
NOTE: Registration is REQUIRED in any of the below before posting a log
Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0
Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.malwarebytes.org/forums/index.php?showforum=7
Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://aumha.net/viewforum.php?f=30
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
this makes no sense. why would posting a scan results on a forum
remove malware from my systems HD and registry? It seems kinda bogus
to me.
Than Google and educate yourself.
> why would posting a scan results on a forum remove malware
> from my systems HD and registry?
The friendly and knowledgable person(s) of the fora will after, careful
examination of the scan result, advice an appropriate course of action.
> It seems kinda bogus to me.
Google is your friend.
< snip >
| this makes no sense. why would posting a scan results on a forum
| remove malware from my systems HD and registry? It seems kinda bogus
| to me.
HJT and Deckard's utility create log files of startup loactions where malware use to load
themselves.
The forums I posted have personnel who are trained at a malware university of sorts. They
are trained on how to interpret the logs and how suggest a set of tools that can be used
by the infected poster where the tools can remove the malware.
Additionally, they may have the infected user post the malware files to the forums where
the forum administrator(s) can then provide the malware files to the various anti malware
companies such that they can be identified and the files can then be used to generate anti
amlware signatures.
This system is far from bogus and all the expert forums I suggested are trusted and
vetted.
delete these files
C:\Documents and Settings\Pune.Admin\Application
Data\Sun\Java\Deployment\cache\javapi\*.*
C:\WINDOWS\system32\intefltr.dll
C:\WINDOWS\system32\systems.txt
& remove these entries
HKEY_CURRENT_USER\SOFTWARE\Microsoft\bind "comment"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.Bho
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BhoNew.Bho.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4937D5D1-2039-409A-BD83-FEC9B39B2356}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CAF9D798-C659-4B9B-8E19-EE27C3D04EE7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{15C7D7AD-A87A-4C0D-9D8B-637FCD3488EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AD3A71E-8ED4-40F5-9A81-69245BDCBB75}
This worked for me after trying almost every free antispyware tool.
Thanks, Wooter!
Martin.