trojan [CLOSED]
Started by
destro1972
, Jun 21 2005 11:35 AM
#1
Posted 21 June 2005 - 11:35 AM
#2
Posted 21 June 2005 - 12:18 PM
Download Hijack This and save it a new folder - C:\HJT.
Run HJT and click on scan. Post the log here in your next reply
Run HJT and click on scan. Post the log here in your next reply
#3
Posted 21 June 2005 - 12:46 PM
i cant run hijackthis as i cant access anything on the computer, the only way i can use the desktop items or start menu options is through safe mode. i am using a friends computer at the moment to write this. it wont let me access my floppy so i cant even run a copy of hijack this that way or dsi clean. the whole system just freezes up in normal mode. i have adaware on my desktop but cant use it
anything else i can try ?
anything else i can try ?
#4
Posted 21 June 2005 - 02:32 PM
Please read these instructions carefully and print them out! Be sure to follow ALL instructions!
During the fix, u will be asked to fix some entries, delete some files or uninstall sosme programs. If in case, you do not see those entries / files / programs, please make a note of it. Continue with the fix and in your next post please inform me of all deviations from the fix prescribed.
1. Download Programs
Please download these programs and save them in a new folder on your desktop -
CleanUp
The Hoster
Unzip Hoster and save it in the same folder.
DelDomain.inf
Ewido Security Suite
Smitfraud.reg and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.
Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.
Install Ewido, and update the definitions to the newest files. Do NOT run a scan yet.
2. Remove Infections
Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.
Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:
Security IGuard
Virtual Maid
Search Maid
PSGuard
Exit Add/Remove Programs.
Run Ewido full scan. Let it fix any items it finds.
3. Delete Rogue files
Using Windows Explorer, delete the following, if found,
FOLDERS to delete (in bold) if found:
C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\LogFiles
C:\Program Files\Security IGuard
C:\Program Files\PSGuard
Reboot the PC in Normal Mode
Run this online virus scan: ActiveScan - Save the results from the scan!
Post a new HiJackThis log along with the results from ActiveScan and Ewido.
During the fix, u will be asked to fix some entries, delete some files or uninstall sosme programs. If in case, you do not see those entries / files / programs, please make a note of it. Continue with the fix and in your next post please inform me of all deviations from the fix prescribed.
1. Download Programs
Please download these programs and save them in a new folder on your desktop -
CleanUp
The Hoster
Unzip Hoster and save it in the same folder.
DelDomain.inf
Ewido Security Suite
Smitfraud.reg and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.
Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.
Install Ewido, and update the definitions to the newest files. Do NOT run a scan yet.
2. Remove Infections
Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.
Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:
Security IGuard
Virtual Maid
Search Maid
PSGuard
Exit Add/Remove Programs.
Run Ewido full scan. Let it fix any items it finds.
3. Delete Rogue files
Using Windows Explorer, delete the following, if found,
FOLDERS to delete (in bold) if found:
C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\LogFiles
C:\Program Files\Security IGuard
C:\Program Files\PSGuard
Reboot the PC in Normal Mode
Run this online virus scan: ActiveScan - Save the results from the scan!
Post a new HiJackThis log along with the results from ActiveScan and Ewido.
#5
Posted 03 July 2005 - 08:20 AM
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users