January 18th, 2004, 04:02 AM
Hijack This and Spybot Search and destroy are two programs that no Windows user should do without. I use them both, along with WinTasks 4 and Ad-Aware.
January 18th, 2004, 05:06 AM
Yea I tried the Spybot S&D. And for some reason I still have it. Its weird can anyone tell me if there is someway that I ca manually remove it?
January 18th, 2004, 06:33 AM
I don't know about manually removing it, but ad-aware will remove it, and ad-aware has an uninstall that actually works!
January 18th, 2004, 07:39 AM
Is ad-aware and S&D both updated?
Yea I tried the Spybot S&D. And for some reason I still have it.
January 18th, 2004, 10:01 AM
Both progs have an update function, I know with Spybot s&d it check for updates for the definitions as well as the core prog.. current version is 1.2..
BTW.. havent had problems uninstalling spybot.. some of my customers get a bit funny if you leave any "Unusual" Progs behind.. so I use it and remove it.. delete it's prog Files folder job 99.9% done.. . extra time goes on their bill.. to bad too sad.. the good customer read the instructions and I only visit once in a while to have a Beer..
"Consumer technology now exceeds the average persons ability to comprehend how to use it..give up hope of them being able to understand how it works." - Me http://www.cybercrypt.co.nr
January 18th, 2004, 01:27 PM
You have good advice so far, so please use it.
1. Update AdAware and Spybot S&D and your AV.
2. Reboot into safe mode and run them all again.
3. Get WinPatrol from http://www.winpatrol.com install it and check "Startup Programs" and "IE Helpers" (BHOs) look for items that refer to the malware you describe. I would kill all the BHOs you will be prompted to re-install as and when you need them RUN IN SAFE MODE
4. Go to http://www.merijn.org/downloads.html and get "CWShredder" and "Startuplist"... run them both and look for anything related to your malware in "Startuplist" You must not have any browser windows open. RUN IN SAFE MODE
5. Go to http://www.webattack.com/get/hostadmin.html and clear anything suspicious in the Windows Hosts folder.
7.Run HijackThis again and post the log file here and I will look at it for you.