Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93125 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

I hope you can help


  • This topic is locked This topic is locked
183 replies to this topic

#61 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 05:42 PM

You need to decide which one you want to keep, Grisoft or Trend Micro. Use Add/Remove Programs and remove one of them.

I dont get any warning that the site is blocked, just poof im offline.

Do you have a cable modem and Router? If so, shutdown your PC, unplug the Power from both, if you have both, or if you only have a cable modem unplug the Power. Wait 5 mins. Plug the Power back in. Wait another 5 mins. and restart your PC.

Let me know if this helps.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

    Advertisements

Register to Remove


#62 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 06:12 PM

I have a cable modem but dont know what a router is so I guess i dont have one. According to trend micro there software is compatible with avg. I dont know, if you want me to uninstall one I will. I have just done a trend micro scan using the msconfig to boot into safe mode. Here is what I get. ( I unplug my cable and turn off my modem several times a day since this problem and I leave it off at night) I dont know if it means anything but ccleaner removed windows/system32/msxm/3a.dll hklm/software/microsoft current version/shared dlls after the scan when I ran to check for issues --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 16:33:54 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Started Scanning Programs in Memory Finished Scanning --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 18:04:13 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Started Scanning Programs in Memory Finished Scanning --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 18:06:51 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Started Scanning Programs in Memory Finished Scanning --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 19:41:38 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Started Scanning Internet Cookies CoolWebSearch Variants (CWShredder) Programs in Memory Windows Registry Internet URL Shortcuts Files and Directories Finished Scanning Started Cleaning Internet Explorer/MSN/AOL Cache Delete History Items on Startup: Cleaned 'Internet Explorer/MSN/AOL Cache' in '' Windows Temp Files Delete History Items on Startup: Cleaned 'Windows Temp Files' in '' Cookies Delete History Items on Startup: Cleaned 'Cookies' in '' Finished Cleaning --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 19:50:16 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Started Scanning Programs in Memory Finished Scanning Started Scanning Internet Cookies CoolWebSearch Variants (CWShredder) CoolWebSearch Variants (CWShredder): Found 'CWS.MSConfig' in '' Programs in Memory Windows Registry Internet URL Shortcuts Files and Directories Finished Scanning Started Backup Finished Backup Started Cleaning CoolWebSearch Variants (CWShredder): Cleaned 'CWS.MSConfig' in '' Finished Cleaning Started Cleaning Internet Explorer/MSN/AOL Cache Delete History Items on Startup: Cleaned 'Internet Explorer/MSN/AOL Cache' in '' Windows Temp Files Delete History Items on Startup: Cleaned 'Windows Temp Files' in '' Cookies Delete History Items on Startup: Cleaned 'Cookies' in '' Finished Cleaning --------------------------------- Anti-Spyware session started --------------------------------- Machine=DHWSSV31 Time=Tue Oct 04 20:02:40 2005 Product Version=3, 0, 1, 23 OS Version=Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

Edited by kaminikij, 04 October 2005 - 06:19 PM.


#63 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 06:36 PM

I disabled the venus fly trap in the trend micro. That monitors the system.

#64 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 06:37 PM

Go to the link below and download to your Desktop msconfig for Windows XP SP1
http://www.richardth...lionhearted.com

You need to search for the location of the msconfig.exe you have now.
Mine is located in C:\Windows\servicepackfiles\i386

Rename the msconfig.exe to msconfig.old.

Now copy the one you just downloaded to the directory where your msconfig is. Double click it and unzip it to this directory.

Reboot and make sure msconfig works. If all is OK, delete the msconfig.old file.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#65 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 07:02 PM

Ok I will try. I hope I know what im doing. Before I start this i am alittle confused. When I go into system 1386 i find the file msconfig. Click on properties it says unknown. I would guess this is the culprit. Now when I type msconfig.exe into the search box it finds 2 more files. One in windows/service pack files/1386 and one in pc health which is the msconfig utility.the service packfiles/1386 properties are from microsoft. So I leave them alone? The next question is where do I find the msconfig file to unzip the new file in? Sorry for me being so lame. I dont want to do the wrong thing and make it worse.

Edited by kaminikij, 04 October 2005 - 07:29 PM.


#66 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 07:47 PM

I cant find this download from the link you gave me? I am also having trouble moving around the site. I tried to get the download from going to cool wesearch chroncles and searching for cws.msconfig. There is a link there to download msconfig. But When I tried to open it I recieved page can not be displayed. Tried using Ie and got knocked offline.

#67 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 07:51 PM

Lets see if I can add the msconfig.zip as a attachment.

Attached Files


The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#68 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 08:25 PM

I deleted again the prefetch files and then was able to move around the site. I found the file to download and was able to do so but when I tried to unzip it, it said there were no files to unzip. I will try the attachment Ok I got and copied it to service pack. God I hope thats right. But do I have the right language? It says Hulpprogramma voor systeem config?

#69 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 08:26 PM

Did you unzip it?

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#70 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 08:38 PM

I unzipped it and then copied to my service pack files. Now when i search for msconfig.exe I find 3 cofiguration utilities and one is in German. I hpoe you dont mind if I call it a night and resume tommorow. Im really beat and using this computer is the equal of pushing a lawn mower Is that OK?

Edited by kaminikij, 04 October 2005 - 08:45 PM.

    Advertisements

Register to Remove


#71 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 08:44 PM

what happens when you do: Start>Run type in Msconfig tap enter key.
Does msconfig work?


Download this file from the link to your desktop.
http://www.mvps.org/.../DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'


Now run CWShredder, SpyBot and Ad-Aware.

reboot and see if you can find
CWS.MSConfig,

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#72 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 08:56 PM

I just rebooted . Its worse than ever. I Typed ms config into run but didnt open it. It looks to be in english. I do this download now and run the spyware.

all Im getting here is text?
; DelDomains.inf
; Created by: Mike Burgess Microsoft MVP
; http://mvps.org/winhelp2002/
;
; Warning: Deletes all entries in the Restricted & Trusted Zone list
;
; To execute this file: in Explorer - right-click (this file)
; Select Install from the Menu.

[version]
signature="$CHICAGO$"

[DefaultInstall]
DelReg=DelTemps
AddReg=AddTemps

[DelTemps]
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"

; Recreate the keys to avoid a restart

[AddTemps]
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"

#73 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 04 October 2005 - 08:59 PM

That's what that program is suppose to do.

Did you run those programs? SpyBot, etc.?

Its worse than ever

Can you explain that please?

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#74 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 04 October 2005 - 09:42 PM

Ok here is what I did. I used the msconfig and booted in safe mode. Cw shredder again removed ms config. ran adaware and spybot. Nothing cc cleaner deleted some files when I ran the issues. The computer feels better after running cw shredder. I also deleted ms config from the prefetch files. I dont know if im supposed to do that but I feel like I havent got anything to loose. My settings look to be the same as they were in the restriced zone and in the trusted zone if thats what the download was supposed to change. I will run everything again when I turn my computer on in the morning and see what happens. Thanks for being here for me. I will let you know the rest in the morning You must be tired of me !

Edited by kaminikij, 04 October 2005 - 09:49 PM.


#75 kaminikij

kaminikij

    Authentic Member

  • Authentic Member
  • PipPip
  • 111 posts

Posted 05 October 2005 - 07:02 AM

Good morning. Here is what I did this morning: When I type in msconfig in the run I think I still get the old version. I typed msconfig in the search box and chose the msconfig I downloaded last night ( and it is in another language) I ran trend micro and it found again and removed cws.msconfig. I searched for some of the files they say it could be running as and found nothing so I opened regedit. I removed madopew.dll, MFC Application, Ne5, Cws, and CoolWebSearch.info. I was afraid to go further in the registry without you. What I found in there also was winlink and IExplore. I was afraid to delete them. I rebooted and then turned the computer of & unplugged the cable for about 10 minutes. When I restarted It again it stated up like when it was new. 1 2 3. It feels better but I havent done anything online yet other than coming here. Im going to surf around for a little bit and see if it works any better. I am still using the mozilla browser and dont know if I should run IE. I will wait to here from you before I do anything else.

Edited by kaminikij, 05 October 2005 - 07:04 AM.

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users