Re: Same Malware shows up in Ad-Aware results after each restart

From: FISH (no_at_spam.com)
Date: 04/30/04


Date: Thu, 29 Apr 2004 22:28:43 GMT

Thank you for the link, but I ran into a few problems trying to follow the
instructions:

1.) I couldn't find one of the three files in my registry I needed to delete
(the HKEY_CLASSES_ROOT:CLSID... file couldn't be found)

2.) I deleted the other two files and then after restarting my system went
into Windows Explorer to delete the file "Jeired" as instructed by the
instructions from the link, but that file couldn't be found either.

After doing the steps I was able to complete (deleting 2 of the 3 files from
my registry) and restarting my system once again, I did another search using
Ad-Aware and sure enough...the malware files showed up again.

Any other advice on how I can permanently get rid of these files?

Thanks again...

<null@zilch.com> wrote in message
news:fqn290p8hgsi98btba81hq09qutjg434ip@4ax.com...
> On Thu, 29 Apr 2004 17:17:38 GMT, "FISH" <no@spam.com> wrote:
>
> >Hello all,
> >
> >I recently installed Ad-Aware 6.0 on my computer (using SpyBot SD prior
to
> >installing Ad-Aware). I did a search and Ad-Aware came up with some
tracking
> >files/malware that SpyBot kept missing. I deleted them via Ad-Aware and
> >restarted my computer after things were "clean" again. Three Malware
files
> >showed up again right after doing another scan at startup. I deleted them
> >again and did another search...my computer was clean again. I restarted
my
> >system once again and did another search. As I'm sure you could
guess....the
> >same three Malware files were back again.
> >
> >Here is what Ad-Aware lists them as:
> >
> >Vendor Type Category Object
> >__________________________________
> >Jeired RegKey Malware
> >HKEY_LOCALMACHINE:SOFTWARE\Microsoft\Windows\Current
> >Version\Explorer\Browser Helper Objects\{707e6776-9ffb-4920.......and so
> >on.....
> >
> >
> >Vendor Type Category Object
> >__________________________________
> >Jeired RegValue Malware
> >HKEY_CURRENT_USER:Software\Microsoft\Internet Explorer\URLSearchHooks\
> >
> >
> >Vendor Type Category Object
> >__________________________________
> >Jeired RegKey Malware
> >HKEY_CLASSES_ROOT:CLSID\{707e6f76-9ffb-4920....and so on...
> >
> >
> >How can I permanently get rid of these???
> >
> >(I'm running XP Home)
>
> Googling up manual/auto removal instructions for Jeired:
>
> http://www.kephyr.com/spywarescanner/library/jeired/index.phtml
>
>
> Art
> http://www.epix.net/~artnpeg



Relevant Pages

  • Re: FW:A Letter To The FLEX-ES Community
    ... rid of the developers of software products for your system. ... get rid of all of the really small companies off the mainframe that will never now grow into large customers. ... The last we discussed it on IBM-Main, if I remember correctly, you couldn't run 64 bit addressing mode, meaning z/OS 1.6 and above wouldn't run on it. ... For IBM-MAIN subscribe / signoff / archive access instructions, ...
    (bit.listserv.ibm-main)
  • Re: Desk top Wallpaper frozen
    ... Leythos the stalker http://www.leythosthestalker.com, David ... H. Lipman, Max M Wachtell III aka What's in a Name?, Fitz, Beauregard T. ... instructions to rid myself of it using the Smitfraudfix and it worked well ...
    (microsoft.public.windowsxp.general)
  • Re: security message
    ... Your Anti Virus will not get rid of the Smitfraud trojan. ... It also has instructions for David Lipmans Multi AV. ... downoad spyware remover.I'm believing now that this is the spyware because I ... download system doctor.I keep clicking no but every 15 minutes it still come ...
    (microsoft.public.windowsupdate)
  • Re: Trojan Virus
    ... >quarentine it. ... I also ran the stinger from McAfee but the ... How can I get rid of it? ... Read it all through and follow all instructions that apply. ...
    (microsoft.public.security.virus)
  • Re: Downloads and Spyware
    ... differ from the Outlook Express instructions and the Outlook Express ... This one is someone with wtools problems: ... > want to make sure I am not getting rid of something I ... will completely rid you of all the spyware - but it looks like it should be ...
    (microsoft.public.windowsxp.basics)