Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security Cleanup » HJT LOG - PC sends out massive random emails, locks up!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Always get redirected after clicking link in google »
« [Trojan] Help me...I think I killed Tina's laptop :(  
AuthorAll Replies


bcastner
Premium,MVM
join:2002-09-25
Chevy Chase, MD
clubs:
·Verizon Online DSL

reply to fjr1966
Re: HJT LOG - PC sends out massive random emails, locks up!

DISABLE Spyware Doctor --
It is a good program, but ... it may hinder the removal of some malware entries. You can re-enable it after you're clean.
From within Spyware Doctor, click the "OnGuard" button on the left side.
Uncheck "Activate OnGuard".

1. Using your mouse, left click once where it says: Copy to clipboard to capture the entire contents of the Code box below, including blank lines:

Open a new Notepad document. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Right-click | Paste the Code box contents from above into Notepad. Click File, Save as..., and enter (including quotation marks) as the filename: "RegFix.REG". Exit Notepad.

Double click your new file and agree to the registry merge when asked. You can then delete this new file.

2. Using your mouse, Highlight and then Right-click | Copy the entire contents of the Quote box below, including blank lines:
quote:
@echo off
cd %~dp0

REM :!: malware removal script only for this user
REM :!: Please do not use.
REM :!: Unintended consequences are likely if you are not this user.
REM :!: Authored by Bill Castner, BroadBandReports Forum

@echo off
cd %~dp0

del /a /f /q C:\Program Files\Messenger\kygeta.html
del /a /f /q C:\Documents and Settings\FRANK\My Documents\Computer Tools\SYSTEM TOOLS\keyfinder.exe
del /a /f /q D:\Computer Tools\SYSTEM TOOLS\keyfinder.exe
del /a /f /q G:\SYSTEM TOOLS\keyfinder.exe

del %0
exit


Open a new Notepad document. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
Right-click | Paste the Quote box contents from above into Notepad. Click File, Save as..., and enter (including quotation marks) as the filename: "Cleanit.cmd". Exit Notepad.

Double click your new file to run the script. It will briefly open a black box and then exit..

3. Please download AproposFix from here:
Save it to your desktop but do not run it yet.
Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop.
Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.
When the tool is finished, please post the entire contents of the log.txt file in the aproposfix folder.

--
============
MS-MVP 2004 - -2008, ASAP Member
Users Helping Users


fjr1966

join:2008-04-24
Dublin, OH

Spyware Doctor has been disabled whenever I am executing the instructions you have been providing me to this point. Items 1, 2 & 3 have been completed. Log from aproposfix.exe provided below. Thank you.

************************

Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\FRANK\Desktop\aproposfix

************

Registry entries found:

************

No service found!

Removing hidden folder:
No folder found!

Deleting files:

Backing up files:
Done!

Removing registry entries:

REGEDIT4

Done!

Finished!
Forums » Up and Running » Security » Security CleanupAlways get redirected after clicking link in google »
« [Trojan] Help me...I think I killed Tina's laptop :(  


Tuesday, 07-Oct 16:43:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [113] It's Cable TV Rate Hike Season
· [69] Half Of New iPhone Owners Came From Verizon
· [62] Supreme Court TiVo/Echostar Ruling
· [58] XOHM Online In Additional Launch Markets
· [54] AT&T Kills Off $20 Unlimited Pre-Paid Data
· [46] Wholesale Bandwidth Prices Still Dropping
· [32] Customers Still Annoyed By FiOS Billing
· [23] Verizon Says Alltel Deal On Schedule
· [22] Verizon Pushes Toward a 100Gbps Core
· [22] Portland Lets Wi-Fi Network Rust
Most people now reading
· Valvoline put 5w20 in my camry! [Automotive]
· KFC 10.00 challenge [General Questions]
· new speeds? [Comcast HSI]
· Texas Realignment Thread - 10/6 [Verizon FIOS TV]
· Testify [General Questions]
· [XP Home] I can't get past blue screen [Microsoft help]
· To teksavvy and their new call back polocy & Shame on Bell [TekSavvy]
· [TWC] TWC SoCal, former Adelphia territory Slowness [Road Runner]
· [WotLK] 5Kg / week? [World of Warcraft]
· sockstress [Security]