Visit the Ironworks Gaming Website Email the Webmaster Graphics Library Rules and Regulations Help Support Ironworks Forum with a Donation to Keep us Online - We rely totally on Donations from members Donation goal Meter

Ironworks Gaming Radio

Ironworks Gaming Forum

Go Back   Ironworks Gaming Forum > Ironworks Gaming Forums > General Discussion > General Conversation Archives (11/2000 - 01/2005)
FAQ Calendar Arcade Today's Posts Search

 
 
Thread Tools Search this Thread
Old 10-29-2003, 11:59 AM   #1
Larry_OHF
Ironworks Moderator
 

Join Date: March 1, 2001
Location: Midlands, South Carolina
Age: 48
Posts: 14,759
Note: My final post lists the first step to take in cleaning this hijacker from your system. Also, go to the symantec link I provided here to get the needed information on how to wipe out the dirty files from the registry. PM me if you would like assistance with this.


I have a persistant Browser Hijacker that will not go away, even after I follow the instructions from Symantec and another website, as well as my own methods. Can anyone tell me how to clean this out?

This is what I have: http://securityresponse.symantec.com...e.winshow.html

and that link explains what to delete to clean you of this rat.

Here is another website that takes a different approach:
http://www.spywareguide.com/product_show.php?id=609

I have followed these instructions as well as used spybot, adaware and all that, but when I reboot, the items come back! What can I do now?


[ 10-29-2003, 04:01 PM: Message edited by: Larry_OHF ]
__________________
Larry_OHF is offline  
Old 10-29-2003, 12:02 PM   #2
harleyquinn
Symbol of Cyric
 

Join Date: November 25, 2002
Location: NY
Age: 48
Posts: 1,190
Have you tried some type of registry cleaner?
__________________
[img]\"http://www.bethspage.us/sig.jpg\" alt=\" - \" />
harleyquinn is offline  
Old 10-29-2003, 12:07 PM   #3
WillowIX
Apophis
 

Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
Quote:
Originally posted by harleyquinn:
Have you tried some type of registry cleaner?
Shouldn't make a difference since he has unregistered all components. You did remove the files right Larry? If you did it almost sounds like the thing keeps installing when you reboot. Try cleaning out your temporary files and your temporary internet files. Perhaps the little installer is hiding there.

Edit: Did you remember to remove the trojan as well?

[ 10-29-2003, 12:09 PM: Message edited by: WillowIX ]
__________________
Confuzzled by nature.
WillowIX is offline  
Old 10-29-2003, 12:10 PM   #4
philip
Galvatron
 

Join Date: June 24, 2002
Location: aa
Posts: 2,101
i don't know if this has anything to do with it but it helped me to delete some files that got back everytime i rebooted.

disable system restore in your configuration.

edit: i think you need to put restore of to delete the trojan WillowIX mentioned

[ 10-29-2003, 12:13 PM: Message edited by: philip ]
philip is offline  
Old 10-29-2003, 12:20 PM   #5
Larry_OHF
Ironworks Moderator
 

Join Date: March 1, 2001
Location: Midlands, South Carolina
Age: 48
Posts: 14,759
I will try what you have suggested now and return and report.
Larry_OHF is offline  
Old 10-29-2003, 12:58 PM   #6
Yorick
Very Mad Bird
 

Join Date: January 7, 2001
Location: Breukelen (over the river from New Amsterdam)
Age: 52
Posts: 9,246
That's bloody frightening Larry! Heck!
__________________

http://www.hughwilson.com
Yorick is offline  
Old 10-29-2003, 01:01 PM   #7
Larry_OHF
Ironworks Moderator
 

Join Date: March 1, 2001
Location: Midlands, South Carolina
Age: 48
Posts: 14,759
I disabled the restore option, I deleted all .tmp files, cookies, and all that, ran through the registry to delete all files that were either named winshow or started with 6cc1c918 as the tage name, ran searches on all this stuff, then went over to my wife's login and did the same. Upone rebooting I find that all the deleted files are back in place as though I did nothing.

I have not found the trojan then, and it must be named something other than all the names I have searched for. Any ideas? I cannot believe Symantec's walk-through did not help.
__________________
Larry_OHF is offline  
Old 10-29-2003, 01:04 PM   #8
Larry_OHF
Ironworks Moderator
 

Join Date: March 1, 2001
Location: Midlands, South Carolina
Age: 48
Posts: 14,759
By the way, the crap seems to be a part of startup, because when I first boot up, my PC's protection program tells me that 6CC1C918...is trying to take over the browser. This happens at each startup.
__________________
Larry_OHF is offline  
Old 10-29-2003, 01:22 PM   #9
WillowIX
Apophis
 

Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
Quote:
Originally posted by Larry_OHF:
By the way, the crap seems to be a part of startup, because when I first boot up, my PC's protection program tells me that 6CC1C918...is trying to take over the browser. This happens at each startup.
Have you got cable Larry? If so try disconnecting your computer before rebooting. The trojan will connect to the net immediately. F-secure lists it as Ouch.A. Apparently it uses a vulnerabillity in Microsoft VM, there's a patch here. That should close up the hole the trojan is using. So when cleaning it out and rebooting it can't access the net. [img]smile.gif[/img]

[ 10-29-2003, 01:23 PM: Message edited by: WillowIX ]
__________________
Confuzzled by nature.
WillowIX is offline  
Old 10-29-2003, 01:59 PM   #10
philip
Galvatron
 

Join Date: June 24, 2002
Location: aa
Posts: 2,101
also you can find a lot of trojans with a normal virus scanner, they're not necesarrily in the temp folder or in the cookies
philip is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
"Clean" NRL Leslie Baldurs Gate II: Shadows of Amn & Throne of Bhaal 40 01-07-2005 12:25 PM
Searching for "Star Blazers" aka "Uchuu Senchen Yamato," or "Space Battleship Yamato" Skydracgrrl Entertainment (Movies, TV Shows and Books/Comics) 3 12-17-2004 01:38 PM
Searching for "Star Blazers" aka "Uchuu Senchen Yamato," or "Space Battleship Yamato" Skydracgrrl General Conversation Archives (11/2000 - 01/2005) 0 12-02-2004 09:27 PM
Do you have "computer clean up" day? Xen General Discussion 13 10-30-2004 10:19 AM
status on "pool of twilight" & "EOB4, xanathar's revenge"? manikus Dungeon Craft - RPG Game Maker 0 05-03-2003 07:28 PM


All times are GMT -4. The time now is 06:13 PM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
©2024 Ironworks Gaming & ©2024 The Great Escape Studios TM - All Rights Reserved