View Single Post
Old 05-01-2007, 07:02 AM   #6 (permalink)
src2206
TSF Enthusiast
 
src2206's Avatar
 
Join Date: Apr 2006
Location: Kolkata, India
Posts: 2,068
OS: WinXP Pro SP3

My System

Send a message via Yahoo to src2206
Post Re: w32.spybot.worm- I can't get rid of it.

Hello Immune

Please follow the next set of instructions to continue the cleaning process.

Downloads

1. Please download CCleaner (freeware) from here:
http://www.ccleaner.com/download/
  • Run the CCleaner installer.
  • During installation process, please UNCHECK "Add CCleaner Yahoo! Toolbar".

2. 1.) Download and install SUPERAntiSpyware HERE. Save the installer on your desktop.

2.) During the installation process, the program will prompt you to download any updates, click Yes.

3.) After the update process has completed, a dialog box will state: Database definitions have been updated, click OK.

4.) At the SUPERAntiSpyware Main Menu, click the Preferences button.

5.) Click the General and Startup tab.
Under Start-Up Options, uncheck these boxes:
* Start SUPERAntiSpyware when Windows starts
* Show SUPERAntiSpyware icon in system tray

6.) Click the Scanning Control tab.
Under Scanner Options, place a check in these boxes:
* Ignore files larger than 4MB (recommended)
* Ignore non-executable files (recommended)
* Scan for tracking cookies
* Resolve Links/Shortcuts during scan (.lnk)
* Terminate memory threats before quarantining
* Scan Alternate Data Streams
* Use Kernel Direct File Access (recommended)
* Use Kernel Direct Registry Access (recommended)

Under Scanner Options, uncheck these boxes:
* Ignore System Restore/Volume Information on ME/XP
* Scan only known file types (.exe, .com, .dll, etc.)
* Close browsers before scanning

7.) Click the Hi-Jack Protection tab.
Under Home Page Protection, uncheck these boxes:
* Display notification when home page changed
* Protect home page from being changed. Changes can be made only here.

8.) Click Close at the bottom of the page.
Don't run SUPERAntiSpyware yet, we will use it later.

________________________________________________________________


Fix

Restart your computer and boot into Safe Mode by tapping the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

____________________________________________________________


CCleaner
  • Run CCleaner and click the Windows tab.
  • Select the following:
    • Check everything under the Internet Explorer section.
    • Check everything under the Windows Explorer section.
    • Check everything under the System section.
    • Check ONLY Old Prefetch data under the Advanced section.
  • Next, click the Options icon, then click the Advanced button:
    • UNCHECK : "Only delete files in Windows Temp folders older than 48 hours", click OK.
  • Next, click the Cleaner icon, then click the Run Cleaner button (bottom right), then Exit.

NOTE : Please do NOT use the Applications tab or the Issues icon. Keep to the Cleaner icon and the Windows tab.

----------------------------------------------------

SUPER Anti-Spyware

Open the SUPERAntiSpyware program.
1.) At the SUPERAntiSpyware Main Menu, under Scan for Harmful Software, click the Scan your Computer button, the SUPERAntiSpyware Scanner menu will appear.

2.) Make sure under Scan Location that your correct hard drive letter is checked.
(Example: C:\ - Fixed Drive (NTFS))
The correct hard drive letter should automatically be checked by default.

3.) Under Complete Scan, click Perform Complete Scan.

4.) At the bottom, click Next, to start the scan.
NOTE: This scan is very thorough, it will take a while to complete depending on the number of files and folders on the hard drive so please be patient. In future scans with SUPERAntiSpyware, selecting Perform Quick Scan should be sufficient.

5.) After the scan it will produce a report. Post back the content of the report here.

______________________________________________________________


Reboot your system in Normal Mode.

______________________________________________


With your next post please "Copy-Paste" the content of the SUPER AntiSpyware Scan report.
__________________
Registered Linux user #426065
src2206 is offline