![]() |
|
|||||||
| Adware & Spyware Think you may have an Adware or Spyware problem? Discuss it here. |
|
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Friendly Neighborhood
Super Moderator
Join Date: Apr 2002
Location: San Diego, Ca.
Posts: 3,882
|
apopos spyware keeps coming back after removal
hey guys got a strange one. my very good co-worker's
sister keeps getting this pop up from ms antispyware that it finds and deletes this. I've tried cwshredder, ms anti-spyware, spybot. finds it then deletes it. did it in safemode without LAN connection. but after awhile comes right back. I've did a search to del manually, but the services, dll, or files are not in the system or in the registry to del. anyone got a magic pill that will work on it. |
|
|
|
|
|
#2 |
|
Security Intelligence
TZ Veteran
Join Date: Jul 2002
Location: Software Paradise
Posts: 4,210
|
I can order the blue magic pills over the weekend Phish...
![]() This doesnt look good: "A secret or undocumented means of getting into a computer system, or software that uses such a means to penetrate a system." HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run autoupdater , delete it and reboot the machine immediately. If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run autoupdater "c:\program files\autoupdate\autoupdate.exe", delete it and reboot the machine immediately. If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\autoloaderaproposclient, delete it and reboot the machine immediately. If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\autoloadertw011aklknla, delete it and reboot the machine immediately. If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\autoupdater, delete it and reboot the machine immediately. If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\pm7r36p, delete it and reboot the machine immediately. unregister these dlls cxtpls.dll proxystub.dll dude, there are heaps more files and crap etc in c:\windwos and system etc etc.... Really looks like a format job... hey, at least you get more time at home
__________________
![]() --- 0wN3D by 3gG --- |
|
|
|
|
|
#3 |
|
Triple Platinum Member
Join Date: Nov 2004
Location: London
Posts: 907
|
http://esd.element5.com/publisher/50...r/FixAprop.exe
Removal tool from Symantec - may work. Otherwise post HijackThis log and we have the technology to help you.
__________________
I'm using Windows 7 - you got a problem with that? |
|
|
|
|
|
#4 |
|
Triple Platinum Member
Join Date: Nov 2004
Location: India
Posts: 888
|
Why not use System Restore?
__________________
del.icio.us |
|
|
|
|
|
#5 | ||
|
Titanium Member
Join Date: Jul 2002
Location: blk helo target, WA
Posts: 4,078
|
Reformat. Like everyone always tells me. Unless it's just a cookie - those always come back just by visiting this one message board I go to.
**edit - that's a browser helper object. Yeah, you can use Hijack this or maybe winpatrol will remove it and keep an eye on it. Winpatrol and other like (registry watchers) - won't allow a BHO unless I allow it. I'm not sure why I'm unable to get to this site but it shows how to: http://66.102.7.104/search?q=cache:M...&hl=en&start=7 Quote:
Quote:
Last edited by lynchknot; May 12th, 2005 at 18:13 PM. |
||
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|