search redirections
#16
Posted 18 March 2006 - 04:44 PM
Register to Remove
#17
Posted 18 March 2006 - 04:50 PM
Download, unzip and run 'RootkitRevealer' from Sysinternals:
http://www.sysintern...itRevealer.html
Once the program has started, press Scan and let it run.
When the scan is done, use 'File > Save' to place the logfile in a convenient location (such as the desktop). The default filename will be 'RootkitReveal.txt'.
Save your Log File
Copy/Paste the contecnts of that logfile into your next reply
NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !
That way you should have a much simpler and clearer log file in which to peruse and evaluate.
Also post another hijackthis log.
#18
Posted 18 March 2006 - 09:07 PM
#19
Posted 19 March 2006 - 07:29 AM
If not, remove Google and re-install but be sure to select disable advanced features when installing.
Edited by LDTate, 19 March 2006 - 07:29 AM.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#20
Posted 19 March 2006 - 07:40 AM
#21
Posted 19 March 2006 - 07:43 AM
Click the link below and get Google Toolbar.
Google toolbar has a very good built in popup blocker with a nice search bar. To provide privacy, select disable advanced features when installing.
http://toolbar.google.com/
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#22
Posted 19 March 2006 - 10:27 AM
#23
Posted 19 March 2006 - 10:33 AM
#24
Posted 19 March 2006 - 02:15 PM
Download Blacklight Beta from here:
http://www.f-secure....light/try.shtml
- Hit I accept. It will take you to download page.
- Download blbeta.exe and save it to the Desktop.
- Once saved... double click blbeta.exe to install the program.
- Click accept agreement and Click scan
This app too may fire off a warning from antivirus. Let the driver load.
Wait for it to finish. - If it displays any items...don't do anything with them yet. Just hit exit (close)
- It will drop a log on Desktop that starts with fsbl....big number
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#25
Posted 19 March 2006 - 04:43 PM
Register to Remove
#26
Posted 19 March 2006 - 04:51 PM
csiac.exe
dmvdi.exe
favset.exe
filesafer32.exe
howiper.exe
pppcgm.exe
sphlp32.exe
DO NOT rename: It's a windows file.
wbemtest.exe
Edited by LDTate, 19 March 2006 - 04:52 PM.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#27
Posted 19 March 2006 - 05:28 PM
#28
Posted 19 March 2006 - 05:45 PM
C:\WINDOWS\system32\
csiac.exe ren
dmvdi.exe ren
favset.exe ren
filesafer32.exe ren
howiper.exe ren
pppcgm.exe ren
sphlp32.exe ren
I beleive these were rootkits.
http://www.f-secure....t/rootkit.shtml
You can also do a Google search for rootkits and find lots of reading.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#29
Posted 23 March 2006 - 08:40 PM
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoy...showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users