View Single Post
Old 07-14-2005, 03:21 PM   #8 (permalink)
MicroBell
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
Quote:
Delete Prefetch files box
Sorry my mistake. Windows 2000 doesn't have that folder.


Make sure the following files have been deleted.

C:\WINNT\system32\config\svchost.exe
C:\WINNT\Config\FireDaemon.exe
C:\WINNT\system32\spool\drivers\msgfix.exe

Empty your recycle bin!

Open add/remove programs. Check for a listing for either Lycos or Sidesearch. Remove either.

C:\Program Files\Lycos <--delete that folder.

C:\WINNT\system32\fiz1 <--if this isn't a folder...then it's a file. Delete it and any others that start with fiz.

Some examples you may find..

C:\WINNT\system32\fiz0
c:\WINNT\system32\fiz1
c:\WINNT\system32\fiz2
c:\WINNT\system32\fiz3
c:\WINNT\system32\fiz4
c:\WINNT\system32\fiz6
c:\WINNT\system32\fiz7
c:\WINNT\system32\fiz8
c:\WINNT\system32\fiz10
c:\WINNT\system32\fiz12
c:\WINNT\system32\fiz13
c:\WINNT\system32\fiz15
c:\WINNT\system32\fiz16
c:\WINNT\system32\fiz19



Once done post another Ewido scan and Panda log along with the log from this tool...

Download Silent runners.Vbs http://www.silentrunners.org/
1. Make sure you have any script blocking software disabled
2. Run the program. It will take a few minutes to complete.
3. Once complete it will produce a log named “StartupPrograms” with Your user and date in the filename. Open that txt file and posts it contents in your next post.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline