Re: HotBar issue

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/25/05


Date: Fri, 25 Feb 2005 07:20:38 -0500


"Belfastlad" <Belfastlad@discussions.microsoft.com> wrote in message
news:371780B4-E95D-4BB0-B38D-87ED5DA82A86@microsoft.com
| My Dad's PC uses Windows XP Home Edition. He recently switched his dial-up
| connection to cable connection. Shortly after doing so his internet access
| has become non-existant. Even when trying to log onto his homepage it can no
| longer find the server. Upon running a scan we found numerous infected files,
| most of which the anti-virus software eliminated. All except 2, which are
| HotBar applications that are listed as being in registry files. I cannot seem
| to eliminate these 2 items. Norton software will not recognize them in the
| scan and I can't get online to run the LiveUpdate option to update virus
| definitions. Any thoughts/ solutions would be greatly appreciated.

Dump the contents of the IE Temporary Internet Folder cache (TIF)

start --> settings --> control panel --> internet options --> delete files

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend signature files.
         http://www.trendmicro.com/download/pattern.asp

         Ad-aware SE (free personal version v1.05)
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt446.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) Update Ad-aware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible.
5) Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
        (a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
7) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
        System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point

* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html


Relevant Pages

  • Re: Virus/Worms
    ... Download the following two items... ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode ...
    (microsoft.public.windowsxp.security_admin)
  • Re: trusted web sites in ie6.0
    ... | are 3 'trusted site' entries left from the hijackThis scan that the ... Download SYSCLEAN.COM and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.security.virus)
  • Re: heretofind problem
    ... (e.g., "c:\New Folder") ... Download sysclean.com and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.scripting.virus.discussion)
  • Re: Need help IE uncrontrollable website access
    ... (e.g., "c:\New Folder") ... Download sysclean.com and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.security.virus)
  • Re: mcafee32.exe
    ... Dump the contents of the IE Temporary Internet Folder cache ... Download SYSCLEAN.COM and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.security.virus)