![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 23,927
OS: WinXP and Vista
|
NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help
Welcome to Tech Support Forum Virus/Trojan/Spyware Removal Help (formerly Hijackthis Log Help) * DO NOT FIX ANY ENTRIES OR DELETE ANY FILES YOURSELF. Do not run any specialized tools that you see being used in other threads without direct supervision from one of our trained analysts. Be advised that running any specialized tools not listed in this topic, on your own, is done solely at your own risk * It is also this forum's policy that we only address users with a legal copy of Windows. If during the course of a fix it is determined that the copy is not legal, we must stop the cleansing process. ============================= How Soon Can I Expect Help? ============================= Please be considerate of the fact that the people helping you are all volunteers, and in many cases usually have a job, and a limited amount of time to help, and therefore can only do so much. Also please note that there are many more people in need of assistance than there are trained staff members who may assist. Patience for this free assistance is required. If there is an immediate need, please take the machine to a local technician. If no one has replied to your thread within 72hrs after you posted, please reply in your thread with the words "BUMP, please" to move it forward. Do NOT bump the thread unless 72 hours has passed. We try to work from oldest to newest posts so your wait will be longer if you bump it forward before the 72 hours is up. When looking threads to respond to, we look for thread with 0 reply, or 1 reply. So, do not bump more than once. If you do, it may appear as though the thread is being handled, and it may be overlooked. Early bump posts will be deleted. NOTE: We are aware that users sometimes seek help from several Forums at the same time. Unfortunately, this can cause confusion and actually wastes time and resources - yours, ours and other Volunteers across the community. If you have already posted at another Forum, please advise us, or them, and choose just one. Also be advised: It is not our intent to repeatedly remove malware from the same member's machines. The intent of this free service performed by volunteers is to help remove malware from your machine, educate you on how it may have happened, and how to prevent that from happening again. To this end, we provide links to articles and tools which should make your visit to the Virus/Trojan/Spyware Help section of TSF a one time event. Please do enjoy the rest of Tech Support Forum as many times as you like! =========================================== Preparing for the Malware Removal Process =========================================== While we try our hardest to avoid them, accidents do happen. With today's malware being as it is, neither Tech Support Forum nor the Analyst providing the advice may be held responsible for any loss of your data. You're following the instructions given at your own risk. We recommend that you back up any data that’s important to you beforehand, just in case the worst happens. 1. As a general rule, to offset any unexpected mishaps, your personal data should be backed up regularly. If you do not already have a process in place that backs up your data, it is highly recommended you do this now. Click here for guidelines on what to back up and how to do it. 2. If you suspect the machine to have cracked (illegal) software installed, click here. 3. Uninstall the following via Add or Remove Programs in Control Panel:
================================= Downloads and Reports Required: ================================= Before scanning, make sure all other running programs are closed There shouldn't be any scheduled antivirus scans running while the scan is being performed. Do not use your computer for anything else during the scan. ==== DDS: ==== ![]() Download DDS and save it to your desktop from here or here. Disable any script blocker, and then double click dds.scr to run the tool.
===== GMER: ===== ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries =========================== How the logs should be furnished: =========================== Copy/Paste the contents of 'DDS.txt' to be posted as text to your post The other two logs ... * attach.txt * ark.txt ... should be zipped/archived before attaching to the post ![]() When posting your reply, the zipped file may be attached by clicking the [Manage Attachments] button. It's located under [Additonal Options] on the composition page. Browse to where you saved the file, and click Upload. ![]() ================================= When posting the logs please observe the following =================================
Click here to post the following logs in the Virus/Trojan/Spyware Help Forum Checklist
Once you have posted, subcribe to your thread by going to Thread Tools located at the top of the thread. Select Subscribe. Make sure it is set to Instant Notification. This concludes the basic steps required before posting your logs. Thank you for taking the time to read this. Last edited by Ried; 05-13-2009 at 10:32 PM. |
|
|
| Sponsored Links |
|
|
#2 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 23,927
OS: WinXP and Vista
|
Re: NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help
Why we don't ask you to run ComboFix from the onset
As stated by the author of ComboFix: ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop. We first need to verify if there's any rootkits present and how they could affect our tools. DDS & GMER are preliminary scans. We use their logs to map our strategy for attack. With these logs we can determine the infections present & decide whether to deploy ComboFix. Last edited by Ried; 11-30-2008 at 12:20 PM. |
|
|
![]() |
| Thread Tools | |
|
|