Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works

Serious help need please

  • Please log in to reply




  • Member
  • PipPip
  • 25 posts

I recently agreed to install some active x controls because i wanted to watch some videos on a website. It was a big mistake as after that my web browser kept on opening new windows advertising many websites.

i am not a novice user, i have zonealarm pro and i installed spybot search and destroy 1.4 prior to this problem. I do not have an anti virus software, i decided to remove it after i had problems installing norton anti-virus 2005. i ran spybot s&d and it removed a number of spyware. I noticed that many programs were trying to communicate with other programs in the web as my firewall asked for permission. I prevented them from running. Back to the story of spybot s&d, i found one persistant problem that spybot detects but is unable to fix. I found out that my windows security centre has been disabled such that my anti-virus, windows firewall and update has been shut down. I get spybot to fix these problems and it shows that they have been fixed, yet when i run it again it shows that the problems still exist. My zonealarm pro has an anti-spyware feature but everytime i try and run it, it shuts down and has to restart.

I decied to call microsoft and they recommanded that i download these programs like avast anti-virus software, hijack this which records down a list of my comp's registry and e-mail it to a technican. I also installed ad-aware personal SE.

The technican e-mailed me back what i should do to change the registry by deleting a couple of lines shown on the hijack this program, i did it. Next i had avast do a full system scan before the comp started up and it del quite a number of files from my winsystem32 folder, dll files that had been infected. I tried running spybot s&d in safe mode and removed all spyware, but everytime i fix the security thing it still shows again when i scan the comp again. I ran ad-aware Se and managed to remove some adwares but it is unable to remove the file nuss.dll everytime i restart and rescan again.

Therefore prior to this msg here i have run spybot over 10 times in safe and normal modes have avast anti-virus software running, have zonealarm pro set to stealth mode, avast managed to remove a lot of virus from my registry, but still in the end when i check my netstat i have 100s of connections attempting to connect to almost all my ports, even with ZA on in stealth mode, my comp always connects to this ip here or dl.devilbase.org. Webpages still keep on loading with adverts and strange exe files keep on appearing in my c drive like command.exe or netmon, i have removed all of them but there still is 1 remaining called rundll32, not sure if this is a virus or not as i understand this is quite an important file. Sometimes these files like netmon will reinstall themselves after i have del them.

SO u can see i have quite a number of defences like spybot proetcting my comp, avast antivirus runing, zone alarm running and still the problems remain albet somewhat not that serious compared to the first time. ANyone care to take up the challange to see what's wrong?

Sorry for such a lengthy post but i felt that i had to tell all the steps that i had taken to fix these problems that still persist.

  • 0





  • Retired Staff
  • 11,413 posts
Please Click here!, and follow the recommendations in the guide.

If you're still having trouble, We'll need you to use a free diagnostic tool, Hijack This. Follow the instructions in step five of this guide, and post your log as a new topic in the Hijack This forum. It will get a better response there from the people most qualified to analyze logs.

Most of what Hijack This lists lists will be harmless or even essential, DO NOT delete or modify anything yet! Someone will be along to tell you what steps to take after you post the contents of the scan results.
  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP