Re: Browser takeover

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 11/29/04


Date: Sun, 28 Nov 2004 20:03:07 -0500

I look forward to your results Tom.

Dave

"Tom B." <TomB@discussions.microsoft.com> wrote in message
news:346E9048-CE74-4CD7-9D79-C4C0DA63C74A@microsoft.com...
| David,
| Thanks. I'll try that. I'm not sure how comfortable I am in Safe Mode, but
| there's someone who I can call to help. I'll let you know. Tom
|
| "David H. Lipman" wrote:
|
| > That's your problem.
| > Adaware 6 has been discontinued, it won't get new updates and is no longer supported by
| > Lavasoft.
| >
| > Please perform the following set of instructions...
| >
| > 1) Download the following three items...
| >
| > Trend Sysclean Package
| > http://www.trendmicro.com/download/dcs.asp
| >
| > Latest Trend signature files.
| > http://www.trendmicro.com/download/pattern.asp
| >
| > Adaware SE (free personal version v1.05)
| > http://www.lavasoftusa.com/
| >
| > Create a directory.
| > On drive "C:\"
| > (e.g., "c:\New Folder")
| > or the desktop
| > (e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
| >
| > Download SYSCLEAN.COM and place it in that directory.
| > Download the Trend Pattern File by obtaining the ZIP file.
| > For example; lpt265.zip
| >
| > Extract the contents of the ZIP file and place the contents in the same directory as
| > SYSCLEAN.COM.
| >
| > 2) Remove Adaware6
| > 3) Install Adaware SE
| > 4) Update Adaware SE with the latest definitions.
| > 5) If you are using WinME or WinXP, disable System Restore
| > http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
| > 6) Reboot your PC into Safe Mode
| > 7) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
| > platform and clean/delete any infectors/parasites found.
| > (a few cycles may be needed)
| > 8) Restart your PC and perform a "final" Full Scan of your platform using both the
| > Trend Sysclean utility and Adaware
| > 9) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
| > System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
| > 10) Reboot your PC.
| > 11) If you are using WinME or WinXP, create a new Restore point
| >
| > * * * Please report back your results * * *
| >
| > Dave
| >
| >
| >
| >
| > "Tom B." <TomB@discussions.microsoft.com> wrote in message
| > news:8B7F7113-F52A-44EC-8E11-F85DC78E8B83@microsoft.com...
| > | I run AdAware 6.0.
| > |
| > | "David H. Lipman" wrote:
| > |
| > | > What version of Adaware ?
| > | >
| > | > Dave
| > | >
| > | >
| > | >
| > | > "Hypnotised" <Hypnotised@discussions.microsoft.com> wrote in message
| > | > news:5BFCCEE1-1280-4C12-BBFC-710E48169059@microsoft.com...
| > | > | I pride myself on keeping abreast of all spyware and viruses. I run Panda
| > | > | virus scan, AdAware, Spybot and HijackThis once a week and never have any
| > | > | problems, UNTIL A WEEK AGO! I have this nasty spyware that takes over my
| > | > | browser. I have to run Hijackthis 3 or 4 times a day to remove this spyware
| > | > | called HotWebSearch.com and there are always the same 6 entries every time.
| > | > | It either opens a new browser windwow in FRONT of my msn homepage which i
| > | > | quickly delete, or it then hijacks the homepage. This occurs numerous times
| > | > | all day! How do I get rid of this nasty new spyware. I've run everything, and
| > | > | it won't go away. Thanks.
| > | >
| > | >
| > | >
| >
| >
| >



Relevant Pages

  • Re: TGCMD.EXE
    ... > I ran the utilities as instructed by you and Adaware found and quarantined ... > safe mode and normal mode but still get the tgcmd.exe error at startup. ... >>| Thanks Dave, ... Otherwise I'll just use modem to download updates for the ...
    (microsoft.public.win2000.general)
  • Re: Your password will expire in __ days Do you want to change it now?
    ... It would not hurt to run a pass in Safe Mode if there is a stealth infector. ... Dave ... | I downloaded Adaware. ... |> Download sysclean.com and place it in that directory. ...
    (microsoft.public.security.virus)
  • Re: what is the skq.exe process Virus? Hacker??
    ... Dave does it matter what sequence that you run these different programs ... reneable all of these before running these deep scans in safe mode or will ... > executed Adaware and it turned out to be Adaware 6.. ... > the case but make sure Adaware SE is updated, and a full and complete deep scan is performed ...
    (microsoft.public.security.virus)
  • Re: Corrupted URLs
    ... Adaware6 was superceded by Adaware SE and Adaware6 is no longer supported. ... Dave ... The Sysclean took ... | Thanks for the try both David and Bill. ...
    (microsoft.public.win2000.general)
  • Re: XP Computer disappears from network
    ... Dave ... | Thanks, David. ... I have already used the Adaware SE. ... But will try the Trend ...
    (microsoft.public.windowsxp.general)