Alternative Nation
Go Back   Alternative Nation > Lounge > Computers & Technology > Tech Support

Notices

Tech Support Computer not working? Shiney new expensive electronic gadget not behaving? Asking here may very well be your best hope.

Reply
 
Thread Tools Rate Thread
Old 30th March 2008, 8:38pm   #1
Kurwa
 
ˇPunk!'s Avatar
 
Join Date: May 2001
Location: Merton Hotel
Posts: 21,586
Images: 233
ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’
Send a message via MSN to ˇPunk!
Hicham Needs You!!!

Quote:
Originally Posted by me and Stew on MSN earlier
I'm in Jersey says:
you busy?

Stu says:

Just cooking, what's up man?

I'm in Jersey says:

my flat mate has a trojan

dunno how to get rid of it

he's got a trial version of some software that's detected it but aint deleting/quarantining it

wont let him check his yahoo inbox

it says: "variant of the Trojan.win32.obfuscated.gx (porn adware)

w32/annew-fam read the link, allows remote access

spyware compnent related to downloadware and found in program filesKFH

I been trying to find it and delete it myself with no luch

only thing I can think of is to get him to download firefox and use that instead?

Stu says:

http://downloads.malwareteks.com/FixIEDef.exe if he downloads and runs this it will scan for the trojan and remove it

Then get him to download and run HiJackThis and post it up on AltNation for him/send me the text file it creates just incase it's spread anywhere else.

I'm in Jersey says:

he's french

ok

searched it

done the scan and nothing came up?

Stu says:

That's weird, HijackThis should pick it up then. http://download.hijackthis.eu/hijackthis_199.zip

It's not actually a virus, it's usually just a wee program that keeps making popups so that someone will buy the software it recommends.

I'm in Jersey says:

yeah

that's the one

i think he downloaded it as well

Stu says:

You could remove it manually if you want the instructions

I'm in Jersey says:

yeah batter on

Stu says:

Open up a command window (start -> run, type cmd and click open)

I'm in Jersey says:

i'm on vista

how do I run?

Stu says:

ah

hit the windows button and r

then type cmd and hit okay

I'm in Jersey says:

ok

got the command screen

Stu says:

then you want to type in “regsvr32 /u windivx.dll" and hit enter

I'm in Jersey says:

ok

Stu says:

and the same "regsvr32 /u ecxwp.dll", "regsvr32 /u stream32a.dlll", "regsvr32 /u vipextqtr.dll".

I'm in Jersey says:

"to register a module you must proivde a binary name"

Stu says:

the software must still be running that he downloaded.

to be entirely honest the easiest thing to do is probably to just roll back using system restore to a few days ago.

programs - accessories - system tools - system restore

I'm in Jersey says:

how the fuck do i get programs on vista?

Stu says:

oh yeah, vista sorry

in the start menu search box just type restore

or you can type rstrui into the search box and hit enter, up to yourself

I'm in Jersey says:

rstrui doesn't come up with anything

tried restore again and it says it's already running

cool

system restore is running now

Stu says:

excellent

does he know when it installed?

I'm in Jersey says:

so this will take his pc back to a couple of days ago and it'll be cool?

he says today

Stu says:

it'll roll back the drivers/things installed, but not damage any files he's made like a word document or anything.

I'm in Jersey says:

alright

so this will be back to a couple of days ago once he restarts?

Stu says:

Whatever date you pick, aye.

There's the recommended restore, or you can chose a different date.

I'm in Jersey says:

recommended was 28th

used that

Stu says:

Aye, that should be fine then.

I'm in Jersey says:

right cool

cheers

Stu says:
No problemo, I'm away for my steaks.
Well it never worked. He's still getting that damn pop up and shit.
Anyway I told him I'd try and sort it for him tomorrow. I'll run hi-jack this again but, beyond that, any ideas?
__________________
Quote:
Originally Posted by Ken Tynan
Don't you think there's a kind of super-vulgarity on the other side of vulgarity which is actually more sophisticated than sophistication?
ˇPunk! is offline   Reply With Quote
Old 30th March 2008, 10:55pm   #2
Registered User
 
jondejonjon's Avatar
 
Join Date: Mar 2008
Location: Glasgow
Posts: 206
jondejonjon posts = True Story
Send a message via MSN to jondejonjon
Re: Hicham Needs You!!!

He could try Search and Destroy - it gets rid of pretty much everything you could imagine. It's never met a trojan it didn't like.
jondejonjon is offline   Reply With Quote
Old 30th March 2008, 11:07pm   #3
Decaying
Moderator
 
karbon14's Avatar
 
Join Date: Mar 2005
Location: SPARTA!
Posts: 6,248
Images: 31
karbon14 is simply amazingkarbon14 is simply amazingkarbon14 is simply amazingkarbon14 is simply amazingkarbon14 is simply amazingkarbon14 is simply amazing
Send a message via MSN to karbon14
Re: Hicham Needs You!!!

go into system restore and turn it off, more harm than good.

install spybot, update it. install ad-aware, update it.

restart the computer in safe mode. (tap f8 while starting up)

scan with both of those and whatever antivirus you have (if you dont already go get AVG)

restart into windows, if it's still doing it run hijack this and post the log her.





then for the love of fucking god make a user account that isn't an admin so you need to put in the admin password when anything wants to installd and DONT JUST CLICK YES TO EVERYTHING.
karbon14 is offline   Reply With Quote
Old 30th March 2008, 11:11pm   #4
Registered User
 
crusher's Avatar
 
Join Date: Mar 2008
Posts: 203
crusher is on a distinguished road
Re: Hicham Needs You!!!

the best thing to use is smitfarudfix
which is actually designed to remove most if not all such software. there is a list at this site but I assure you it will fix more than is listed there
http://siri.geekstogo.com/SmitfraudFix.php
crusher is offline   Reply With Quote
Old 31st March 2008, 11:34am   #5
Kurwa
 
ˇPunk!'s Avatar
 
Join Date: May 2001
Location: Merton Hotel
Posts: 21,586
Images: 233
ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’ˇPunk! is too good at this 'forum game’
Send a message via MSN to ˇPunk!
Re: Hicham Needs You!!!

Quote:
Originally Posted by karbon14 View Post
then for the love of fucking god make a user account that isn't an admin so you need to put in the admin password when anything wants to installd and DONT JUST CLICK YES TO EVERYTHING.
I did say this to him as well.
__________________
Quote:
Originally Posted by Ken Tynan
Don't you think there's a kind of super-vulgarity on the other side of vulgarity which is actually more sophisticated than sophistication?
ˇPunk! is offline   Reply With Quote
Reply

Bookmarks
Digg del.icio.us StumbleUpon Google

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Sin 



 Classic Grand Advert





Powered by vBadvanced CMPS v3.0.0
Advertisement
   



All times are GMT +0. The time now is 9:11pm.

Forums Directory
Copyright 2000-2008, Alternative Nation

SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.
Page generated in 0.66818 seconds with 15 queries