View Single Post
Old 08-16-2005, 03:19 AM   #2 (permalink)
POADB
Moderator, Microsoft Support
 
POADB's Avatar
 
Join Date: Jul 2004
Location: United Kingdom
Posts: 6,481
OS: XP SP2


Please download CleanUp! (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Do not run it yet!

Download, install, update, configure and run a scan with Ad-aware SE v1.06:
  1. Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  2. Close ALL windows except Ad-Aware SE.
  3. Click on the ‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
    1. In the ‘General’ window make sure the following are selected in green:
      1. Under [Safety]:
        • Automatically save log-file
      2. Automatically quarantine objects prior to removal
      3. Safe Mode (always request confirmation)
    2. Under [Definitions]:
      • Prompt to update outdated definitions - set the [number of days]
  5. Click on the ‘Scanning’ button on the left and select in green:
    1. Under [Driver, Folders & Files]:
      • Scan Within Archives
    2. Under Select drives & folders to scan:
      • choose all hard drives
    3. Under [Memory & Registry]: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
  6. Click on the [‘Advanced’] button on the left and select in green:
    1. Under [Shell Integration]:
      • Move deleted files to recycle bin
    2. Under [Logfile Detail Level]: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    3. Under [Alternate Data Streams]:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: [CA_INOCULATEIT]
  7. Click the ‘Tweak’ button and select in green:
    1. Under [Scanning Engine]:
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    2. Under [Cleaning Engine]:
      • Let Windows remove files in use at next reboot
    3. Under [Log Files]:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not Select: Include Module list in logfile
  8. Click on ‘Proceed’ to save the settings.
  9. Click ‘Start’
  10. Choose 'Perform Full System Scan'
  11. DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  12. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  13. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  14. Right-click on the list and choose [Select All]
  15. Click the [Next] button to finish removing the items that were found
  16. When finished, REBOOT to complete the removal of what Ad-Aware SE found

~~~~~~~~~~~~~~~

Download Spybot S&D.
  1. After you have installed it, Click on the Search for Updates button. Install any updates that are available.
  2. Go to the Mode menu and choose Advanced Mode.
  3. Next click on Immunize to your left.
  4. In the ensuing window, Click the Immunize button (green cross) on top to Immunize your computer - you should do this each time there is an update.
  5. Click on the 'Spybot-S&D' option on the top left to go back to the main screen.
  6. Click on the Check for Problems button. Let it run the scan.
  7. If it finds something, Select all those in RED and hit the Fix Selected Problems button.
  8. Exit Spybot.
If you keep getting the DSO Exploit entries, even after you updated Windows and fixed them, then download the Spybot DSO Exploit Fix and install it over the current Spybot installation.


~~~~~~~~~~~~~~~

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
    [X]Scan local drives for temporary files (Please uncheck this option)
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.

WARNING - CleanUp! will delete all files and folders contained within Temporary Directories. If you knowingly have items you would like to keep stored in these locations, Move them now!!!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them in your next post.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Perform an online scan in Internet Explorer with Panda ActiveScan
  1. Click on the Scan your PC button & a 'pop up' window shall appear. * ensure that your pop up blocker doesn't block it
  2. Click On 'Scan Now'
  3. Enter your e-mail address & click 'Scan Now' ...begins downloading Panda's ActiveX controls.- 8MB
  4. Begin the scan by selecting My Computer
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
  5. If it finds any malware, it will offer you a report. Click on see report
  6. Then click Save report
  7. Post the contents of the report in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
__________________


POADB is offline