![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#21 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 17
OS: xp
|
Re: Pop ups and slow computer
I just wanted to say thank you very much for your time. It is invaluable!
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#22 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,208
OS: 2000 Pro; XP Pro; XP Home
|
Re: Pop ups and slow computer
Looking much better.
Of the items found by Kaspersky, many are in System Resore points, which we'll address later. A couple are in Windows One Care Quarantine. Since I've never used it, I can't advise on how exactly to finally remove the items from quarantine, but there should be a way to access that feature from within the application. Something like: Click Change OneCare Settings in the Main OneCare user interface Click on the Viruses & Spyware Tab And then click on the Quarantine button There should be some sort of option to finally remove items from quarantine. If you can't find it, don't worry, as items in quarantine have been rendered harmless, I'm just being tidy. Other items are in Spybot's quarantine: When files found by other scanners are in the Recovery directory inside the Spybot-S&D directory, it is only a backup. It is no longer of any harm there, as the file won't be loaded from there. But once you are sure you don't need the backup, go to the Recovery section inside Spybot-S&D and purge the files. 1. Open Spybot. If you have a shortcut on your desktop, double click it. or Click Start, then All Programs, then Spybot - Search & Destroy and then Spybot - Search & Destroy. 2. On the left side, click "Recovery". 3. Select (place a check) beside ALL the backup files that contain quarantined items. 4. Click on the Purge Selected Items button. 5. A dialog will appear, stating that the backup will be removed. Click Yes. 6. When the Recovery window is empty, Exit Spybot. Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist: My Way Search Assistant See here: http://www.bleepingcomputer.com/unin...Assistant.html --------------------------------------------------------------------------------------------- Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll Close HijackThis now. --------------------------------------------------------------------------------------------- Delete this folder if it exists: C:\Program Files\MyWaySA Let me know how the machine is behaving, and if you had any troubles with the last steps.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#23 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 17
OS: xp
|
Re: Pop ups and slow computer
before you started dialog with me, I had uninstalled spybot...please let me know if I have now caused drama.
in running hijackthis to fix the selected, the only ones I could find were the 2nd and 3rd items on your list. also, there was no mywaysa in the program files on the C drive. I was also able to remove the quarantine items from microsoft onelive. please let me know what free antivirus/spyware software you recommend. I will let you know how the computer runs in a sec |
|
|
|
|
#24 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,208
OS: 2000 Pro; XP Pro; XP Home
|
Re: Pop ups and slow computer
I see now that Spybot is not installed. No, no drama, since it's uninstalled, you can delete this entire folder where the quarantined items are held:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy As far as free AntiVirus and AntiSpyware applications, you can click the link in my signature, "PC Safety and Security--What Do I Need?" I also give final protection instructions when we're done. You have Windows Live OneCare, which is supposed to be all that. If you intend on using a different AntiVirus application, be sure to uninstall OneCare. Having more than one AV can be detrimental to the system performance and security.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#25 (permalink) |
|
Registered User
Join Date: Jan 2008
Posts: 17
OS: xp
|
Re: Pop ups and slow computer
Thank you so much for all your help. I removed the spybot directory and I will address a different AV program when live one care expires.
If you don't mind answering another question, how do you feel about accepting updates or upgrades for things like dell support and IE, etc? |
|
|
|
|
#26 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,208
OS: 2000 Pro; XP Pro; XP Home
|
Re: Pop ups and slow computer
IE should get updated as often as they come out. Dell, well, that's up to you. I don't have a Dell, and I'm not sure what their support does for you. If it's related to keeping your system secure, it should probably be fine to accept.
Your logs appear clean.You should be good to go. We still have a few items to address. Go to -> Run -> copy/paste in the following single line command & click OKcombofix /u This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points. Now that your system is clean, to help protect your computer in the future I recommend that you follow these steps and use the following free programs:
Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer Here are some additional utilities that will further enhance your safety.
In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
| Thread Tools | |
|
|