Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security Cleanup » HJT LOG - PC sends out massive random emails, locks up!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Always get redirected after clicking link in google »
« [Trojan] Help me...I think I killed Tina's laptop :(  
AuthorAll Replies


bcastner
Premium,MVM
join:2002-09-25
Chevy Chase, MD
clubs:
·Verizon Online DSL

reply to fjr1966
Re: HJT LOG - PC sends out massive random emails, locks up!

DISABLE Spyware Doctor --
It is a good program, but ... it may hinder the removal of some malware entries. You can re-enable it after you're clean.
From within Spyware Doctor, click the "OnGuard" button on the left side.
Uncheck "Activate OnGuard".

1. Using your mouse, left click once where it says: Copy to clipboard to capture the entire contents of the Code box below, including blank lines:

Open a new Notepad document. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Right-click | Paste the Code box contents from above into Notepad. Click File, Save as..., and enter (including quotation marks) as the filename: "RegFix.REG". Exit Notepad.

Double click your new file and agree to the registry merge when asked. You can then delete this new file.

2. Using your mouse, Highlight and then Right-click | Copy the entire contents of the Quote box below, including blank lines:
quote:
@echo off
cd %~dp0

REM :!: malware removal script only for this user
REM :!: Please do not use.
REM :!: Unintended consequences are likely if you are not this user.
REM :!: Authored by Bill Castner, BroadBandReports Forum

@echo off
cd %~dp0

del /a /f /q C:\Program Files\Messenger\kygeta.html
del /a /f /q C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe
del /a /f /q D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe
del /a /f /q G:\SYSTEM TOOLS\keyfinder.exe

del %0
exit


Open a new Notepad document. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Right-click | Paste the Quote box contents from above into Notepad. Click File, Save as..., and enter (including quotation marks) as the filename: "Cleanit.cmd". Exit Notepad.

Double click your new file to run the script. It will briefly open a black box and then exit..

3. Please download AproposFix from here:
Save it to your desktop but do not run it yet.
Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop.
Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.
When the tool is finished, please post the entire contents of the log.txt file in the aproposfix folder.

--
============
MS-MVP 2004 - -2008, ASAP Member
Users Helping Users


fjr1966

join:2008-04-24
Dublin, OH

Spyware Doctor has been disabled whenever I am executing the instructions you have been providing me to this point. Items 1, 2 & 3 have been completed. Log from aproposfix.exe provided below. Thank you.

************************

Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\FRANK\Desktop\aproposfix

************

Registry entries found:

************

No service found!

Removing hidden folder:
No folder found!

Deleting files:

Backing up files:
Done!

Removing registry entries:

REGEDIT4

Done!

Finished!
-
Forums » Up and Running » Security » Security CleanupAlways get redirected after clicking link in google »
« [Trojan] Help me...I think I killed Tina's laptop :(  


Wednesday, 20-Aug 18:49:54 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [93] Was FiOS a Good Idea?
· [77] Landscaping, Courtesy of AT&T?
· [68] ISPs Whine About Network Neutrality 'Paranoia'
· [60] FCC Finally Issues Comcast Throttling Order
· [55] Google Launches White Space Broadband Website
· [53] Craig Moffett: Network Upgrades Are For Ninnies
· [52] Qwest, Unions Strike Deal
· [49] Olympics Didn't Cause The Exaflood
· [49] AT&T Cooking Up New VoIP Product
· [44] First Android Phone Gets FCC Approval
Most people now reading
· How I Stole Someone's Identity [Security]
· Unsupported Computer Configuration [AT&T Southeast]
· How do you file things on your computer? [General Questions]
· [iPhone] 2.0.2 firmware is out, Please post outcome [All things Macintosh]
· [Connectivity] Sandvine kills more than just P2P [Comcast HSI]
· Fios Pro and Cons [Verizon FIOS TV]
· [XP Pro] Changing the start button behavior [Microsoft help]
· Anyone know how to capture NBCOlympics.com video streams [General Questions]
· Just recently switched to Teksavvy... very slow! [TekSavvy]