Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Reply to this topicStart new topic
> How-To Remove RiyoCodec Hijacker (removal instructions), DO NOT install RiyoCodec
LDTate
post Sep 29 2007, 05:06 AM
Post #1


Forum God
Group Icon

Group: Root Admin
Posts: 41,944
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




QUOTE(Jacee @ Sep 27 2007, 02:08 PM) *
RiyoCodec's download link leads here:
hqcodec.net

This little goodie is installed:
hqcodec4279.exe

This group is known for malware:
Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website: hxxp://www.estdomains.com

Domain Name: HQCODEC.NET

RiyoCodec states that there is no spyware...they just don't mention the "hijack" that comes with the installation of the infested codec.



Hello and welcome to the WhatTheTech Forum's .

Use at your own risk: WhatTheTech forum's, does not take responsibility for any outcome of following these directions. Every computer is different, so we cannot guarante the outcome. If you are apprehensive, please post a log from HijackThis in the designated forum and let us take a look and guide you to a clean system.

This is a "self help" to remove the infections on Windows 2000 and all XP versions ONLY.If you don't have W2K or XP, please Register and post a HijackThis log for manual removal. Instructions are below.

Keep in mind this infection can be accompanied by other infections as well. We strongly suggest you Register after running this fix and posting a HijackThis log for one of the pro's to check over.


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download FixWareout from this site:
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.

Once the desktop loads a text that will open (report.txt) Please save this file, you'll need to post it with a new HijackThis log.


Next:

Now lets check some settings on your system.
Enter your Control Panel and double-click on Network Connections

Then right click on your Default Connection
Usually Local Area Connection for Cable and DSL
Left click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Select the radio dial that says Obtain DNS Servers Automatically
Press OK twice to get out of the properties screen and reboot if it asks

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two

you need to download HijackThis from here and post your HijackThis log here:

Please create a new Topic and post the requested items.
After reboot "copy/paste" the text file (report.txt) and a new Hijackthis log

Also please describe how your computer behaves at the moment.
Go to the top of the page
 
+Quote Post
LDTate
post Oct 7 2007, 08:24 AM
Post #2


Forum God
Group Icon

Group: Root Admin
Posts: 41,944
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




This infection can also include the Smitfraud infection.

Please follow ALL the instructions

QUOTE
Please create a new Topic and post the requested items.
After reboot "copy/paste" the text file (report.txt) and a new Hijackthis log
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No new  
22 TheRogueStar 648 Today, 02:58 AM
Last post by: ken545
No New Posts  
12 smithtr 263 Yesterday, 08:58 PM
Last post by: gringo_pr
No New Posts  
0 rumdup 13 26th August 2008 - 09:36 AM
Last post by: rumdup
No New Posts  
1 Bibbidybobbidyboo 41 25th August 2008 - 10:14 PM
Last post by: Bibbidybobbidyboo
No New Posts  
0 Alex Saucedo 21 25th August 2008 - 08:48 PM
Last post by: Alex Saucedo

RSS Time is now: 28th August 2008 - 07:24 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy