Jump to content


Photo

Can't get rid of parasite


  • Please log in to reply
4 replies to this topic

#1 hammer2127

hammer2127

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 24 June 2004 - 06:53 PM

I have a spyware that cwshredder hasn't been able to remove. Please look at the following log from hijackthis and see if there is anything I can do. Thanks much!

Logfile of HijackThis v1.97.7
Scan saved at 6:57:03 PM, on 6/24/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\TBCTRAY.EXE
C:\WINDOWS\SYSTEM\IEBW32.EXE
C:\WINDOWS\JAVASN32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOWNLOAD FILES\CWSHREDDER\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jyenv.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://jyenv.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://jyenv.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jyenv.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://jyenv.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\jyenv.dll/sp.html#96676
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL (file missing)
O2 - BHO: (no name) - {EB604330-061B-8BFC-8801-1E88E0A67778} - C:\WINDOWS\SYSTEM\IPCV.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [IEBW32.EXE] C:\WINDOWS\SYSTEM\IEBW32.EXE
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM\TBCTRAY.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [JAVASN32.EXE] C:\WINDOWS\JAVASN32.EXE
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Encarta Encyclopedia (HKLM)
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Dell Home (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://business.dellnet.com/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com.../gigexagent.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://link.mindlead...abs/awswaxf.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.bright...bin/actxcab.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://cw.meriter.com/wficat.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38016.551099537
O16 - DPF: {80F1B906-D066-11D3-AD70-009027B8ADBC} (WebPlayer Class) - http://content.hiwir...5.30/Hiwire.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernet...urferplugin.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF} (eshare communications NetAgent Customer ActiveX Control version 2) - http://www.cabeagent...s/custappx2.CAB

#2 RubbeR DuckY

RubbeR DuckY

    Marcin

  • Developer
  • PipPipPipPipPip
  • 878 posts

Posted 24 June 2004 - 06:57 PM

Please download About:Buster by RubbeR DuckY ( thats me lol ) from

Here

Then Unzip it to your desktop. Do not run it yet. Print these directions or paste them into a text document as you will be running with your internet explorer closed. Restarting internet explorer may cause a reinfection.

Please start Hijack this and tick the boxes next to these items.


O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL (file missing)
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL (file missing)
O2 - BHO: (no name) - {EB604330-061B-8BFC-8801-1E88E0A67778} - C:\WINDOWS\SYSTEM\IPCV.DLL
O4 - HKLM\..\Run: [IEBW32.EXE] C:\WINDOWS\SYSTEM\IEBW32.EXE
O4 - HKLM\..\RunServices: [JAVASN32.EXE] C:\WINDOWS\JAVASN32.EXE


Then close all windows and hit fix checked. Now startup About:Buster. Hit ok on the first prompt and then hit start. Next hit ok. Wait till the scan completes and copy the report and save it somewhere. Rerun About:Buster to make sure everything was deleted. Then restart your computer.

It is now safe to reopen Internet explorer. Please post a new hijack this log along with a report.
Marcin Kleczynski
Chief Executive Officer
Malwarebytes Corporation

Follow me on Twitter or check out my Blog!

#3 hammer2127

hammer2127

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 25 June 2004 - 05:07 PM

Thanks for your help. I followed your instructions, but I figured they wouldn't work because since I posted this message, I have monkeyed around so much that the hijackthis log changed. So, please find the new hijackthis log and this time I won't play with anything or restart the computer until I hear back from you. I promise!

Logfile of HijackThis v1.97.7
Scan saved at 5:12:25 PM, on 6/25/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\APPJP32.EXE
C:\WINDOWS\SDKFM32.EXE
C:\WINDOWS\NTFD.EXE
C:\WINDOWS\NTIG.EXE
C:\WINDOWS\SYSTEM\SYSIV.EXE
C:\WINDOWS\SYSTEM\IEBW32.EXE
C:\WINDOWS\NTFD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SDKGE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\TBCTRAY.EXE
C:\WINDOWS\NTFD.EXE
C:\WINDOWS\IPDZ32.EXE
C:\MY DOWNLOAD FILES\CWSHREDDER\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\oplds.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://oplds.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://oplds.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\oplds.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://oplds.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\oplds.dll/sp.html#96676
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: (no name) - {F69A992B-1259-FA8F-7BB7-3DCC5E875A96} - C:\WINDOWS\WINIF32.DLL (file missing)
O2 - BHO: (no name) - {4A6990AE-EDB5-69DD-25C5-D906008ED823} - C:\WINDOWS\SYSTEM\ADDQC32.DLL (file missing)
O2 - BHO: (no name) - {57E092D9-D78D-97B1-8BE6-594F8C707DE0} - C:\WINDOWS\NETLG.DLL
O2 - BHO: (no name) - {6A8FA9C0-1C40-8A47-8010-34264B4D7631} - C:\WINDOWS\APIUY32.DLL (file missing)
O2 - BHO: (no name) - {78757ABE-9B3F-5C0D-83BD-10210B605EBD} - C:\WINDOWS\SYSTEM\ATLOV32.DLL (file missing)
O2 - BHO: (no name) - {E5E5B820-DA76-22FD-8822-57E0957A73BA} - C:\WINDOWS\SYSTEM\IPPC.DLL (file missing)
O2 - BHO: (no name) - {1B6C9632-0597-1169-E29C-35DC7064A9B8} - C:\WINDOWS\SYSTEM\NETYI.DLL (file missing)
O2 - BHO: (no name) - {94FA1857-F45F-A3BD-4797-991254ECF0FE} - C:\WINDOWS\SYSTEM\ADDBJ.DLL (file missing)
O2 - BHO: (no name) - {1C60B26C-69A0-A49D-97C3-BA933C381E9F} - C:\WINDOWS\IPSM.DLL (file missing)
O2 - BHO: (no name) - {49AC57E8-353B-7743-0031-4EF11F75AAF4} - C:\WINDOWS\SDKKH.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [IEBW32.EXE] C:\WINDOWS\SYSTEM\IEBW32.EXE
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM\TBCTRAY.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NTKT32.EXE] C:\WINDOWS\SYSTEM\NTKT32.EXE
O4 - HKLM\..\RunServices: [SYSGB.EXE] C:\WINDOWS\SYSTEM\SYSGB.EXE
O4 - HKLM\..\RunServices: [NTTX.EXE] C:\WINDOWS\SYSTEM\NTTX.EXE
O4 - HKLM\..\RunServices: [NTFD.EXE] C:\WINDOWS\NTFD.EXE
O4 - HKLM\..\RunServices: [NTIG.EXE] C:\WINDOWS\NTIG.EXE
O4 - HKLM\..\RunServices: [SYSIV.EXE] C:\WINDOWS\SYSTEM\SYSIV.EXE
O4 - HKLM\..\RunServices: [SDKFM32.EXE] C:\WINDOWS\SDKFM32.EXE
O4 - HKLM\..\RunServices: [APPJP32.EXE] C:\WINDOWS\SYSTEM\APPJP32.EXE
O4 - HKLM\..\RunServices: [SDKGE.EXE] C:\WINDOWS\SDKGE.EXE
O4 - HKLM\..\RunServices: [IPDZ32.EXE] C:\WINDOWS\IPDZ32.EXE
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Encarta Encyclopedia (HKLM)
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Dell Home (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://business.dellnet.com/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com.../gigexagent.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://link.mindlead...abs/awswaxf.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.bright...bin/actxcab.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://cw.meriter.com/wficat.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38016.551099537
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernet...urferplugin.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF} (eshare communications NetAgent Customer ActiveX Control version 2) - http://www.cabeagent...s/custappx2.CAB

#4 RubbeR DuckY

RubbeR DuckY

    Marcin

  • Developer
  • PipPipPipPipPip
  • 878 posts

Posted 25 June 2004 - 07:07 PM

Hello, The directions are the same except. Tick the boxes next to these items.


O2 - BHO: (no name) - {57E092D9-D78D-97B1-8BE6-594F8C707DE0} - C:\WINDOWS\NETLG.DLL
O4 - HKLM\..\Run: [IEBW32.EXE] C:\WINDOWS\SYSTEM\IEBW32.EXE
O4 - HKLM\..\RunServices: [NTKT32.EXE] C:\WINDOWS\SYSTEM\NTKT32.EXE
O4 - HKLM\..\RunServices: [SYSGB.EXE] C:\WINDOWS\SYSTEM\SYSGB.EXE
O4 - HKLM\..\RunServices: [NTTX.EXE] C:\WINDOWS\SYSTEM\NTTX.EXE
O4 - HKLM\..\RunServices: [NTFD.EXE] C:\WINDOWS\NTFD.EXE
O4 - HKLM\..\RunServices: [NTIG.EXE] C:\WINDOWS\NTIG.EXE
O4 - HKLM\..\RunServices: [SYSIV.EXE] C:\WINDOWS\SYSTEM\SYSIV.EXE
O4 - HKLM\..\RunServices: [SDKFM32.EXE] C:\WINDOWS\SDKFM32.EXE
O4 - HKLM\..\RunServices: [APPJP32.EXE] C:\WINDOWS\SYSTEM\APPJP32.EXE
O4 - HKLM\..\RunServices: [SDKGE.EXE] C:\WINDOWS\SDKGE.EXE
O4 - HKLM\..\RunServices: [IPDZ32.EXE] C:\WINDOWS\IPDZ32.EXE


And all items that have (file missing or no file) next to it.

If it still doesnt work. Reboot into safe mode by pressing f8 several times when the computer first boots.
Marcin Kleczynski
Chief Executive Officer
Malwarebytes Corporation

Follow me on Twitter or check out my Blog!

#5 hammer2127

hammer2127

    Member

  • Full Member
  • Pip
  • 5 posts

Posted 26 June 2004 - 03:14 PM

Thanks much! When following your instructions in safe mode, the problem, at least at this point, seems fixed. WHen I restarted in normal mode, the web address that the spyware put into IE was still there. I ran hijackthis and removed it. If you don't run AboutBuster in safe mode, key spyware components will not be removed. So, safe mode is the key. IN addition, even if you don't restart your computer, this brand of spyware keeps adding and changing files. So, I didn't follow your directions completely. I could tell there were corrupted files in hijackthis that you had not listed. I wonder if the programmer did this to thwart efforts of sites like this one. Anyway, I appreciate your efforts greatly.

One more question: What kind of computer skills do you need to be a helper here? I probably couldn't spend more than 15 min to 30 min a day helping, but this crap makes me so mad I wouldn't mind trying to fight it. I just wonder if I have the skill level to truly help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button