|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread |
Rating:
|
Display Modes |
|
|
#31 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
Schools
Hello everyone
I asked to put this up and got the go ahead. If anyone is interested in becoming a malware ( Spyware, Adware, dialers, Trojans, Viruses, and Browser Hijackers.) fighter There are a few schools out there that can teach you how to read Hijack this Logs, as well as some of the other fancy tools we use to combat malware. Tech Support Forums < Im a mod of the academy here but they are all good schools. SpywareInfo Tom Coyote I strongly suggest you learn how to read Hijack this logs before giving advice on what to remove, and how to remove. There are certain infections that can break your Internet connections (NEW.NET being one of them) or even stop your conmputer from running if not removed properly (BubE infection). These things we will teach you. Now i sound like an ad lol. sorry don't mean to. Hope to see some of you there. Jose aka Lobos |
|
|
|
|
|
#32 | |
|
Moderator
Staff
Premium Member
|
Quote:
__________________
Computer: Intel Core i5-750 2.66 GHz quad-core processor @ 3.71 GHz | Asus P7P55D-E motherboard | Crucial 4 GB DDR3-1333 RAM | nVidia GeForce 8600GT | 2x WD Caviar Black WD1501FASS 1.5TB hard drives in RAID 1 | Antec Sonata III case with Antec EarthWatts 500-watt PSU | Dual Dell UltraSharp 2408WFP 24" widescreens | Windows 7 Ultimate 64-bit Other: 2005 Subaru Legacy 2.5GT sedan 5MT | Samsung Epic 4G Smartphone | Mamiya M645 1000S medium-format SLR with 55mm f/2.8, 70mm f/2.8, 210mm f/4, teleconverter, 120 and 220 film backs | Olympus E-PL1 Micro-4/3s DSLR with 14-42mm and 40-150mm lenses |
|
|
|
|
|
|
#33 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
|
I suggested he post it right here, this is the sticky thread talking about HJT log procedures.
- Moderator - |
|
|
|
|
|
#34 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
|
Need to add something - you may have to run your tools in safe mode with system restore disabled. It's getting rough out there. As always, please make sure you have the latest versions of the tools with the latest signature updates. You must be prepared to give up and reformat, so if you have a way to back up your important files, do so before starting a cleanup.
|
|
|
|
|
|
#35 | |
|
Member (8 bit)
Join Date: Feb 2005
Location: Oakland, CA
Posts: 199
|
ahaaaaaaaaaaa!
Quote:
Yes, thank you all! I will also be bookmarking many things from this thread as well! Lobos- Do these schools you mention charge? glc- How would I go about disabling system restore, and cutting down on the number of programs running in the background so as to make it easier as you mentioned in one of the above posts? Last edited by EDB; 05-22-2005 at 02:12 AM. |
|
|
|
|
|
|
#36 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
|
XP: http://service1.symantec.com/SUPPORT...rc=sec_doc_nam
ME: http://service1.symantec.com/SUPPORT...rc=sec_doc_nam 9x and 2K don't have system restore. 98/ME/XP has msconfig, use that to cut down your startups. With 95 and 2K you have to manually edit the registry but msconfig.exe from an XP box will work in 2k, just drop it in c:\winnt. We are not asking you to cut down on the startups, we are asking you to run HJT immediately after a restart before you MANUALLY open any programs. We need to see what's in your startup because that's a major clue to what infections you have. You cannot delete a post, you can only edit it for 12 hours. |
|
|
|
|
|
#37 |
|
Member (10 bit)
Join Date: Mar 2004
Location: California
Posts: 936
|
LIst to help you keep your computer clean
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
|
|
|
|
|
|
#38 |
|
Member (4 bit)
Join Date: Oct 2005
Posts: 9
|
Thanks everybody,
I'll try everything here and see whatt happens |
|
|
|
|
|
#39 |
|
Member (10 bit)
Join Date: Nov 2003
Location: NJ
Posts: 855
|
Here is my contribution.
Some things I found yesterday, that are great! http://www.help2go.com/detective.html http://www.help2go.com/article153.html And some general security info: http://www.help2go.com/article217.html |
|
|
|
|
|
#40 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
|
I've become very impressed by Ewido antimalware - it's a EXCELLENT scanner and cleaner. They are now offering an online scan. I'd ask everyone to run it before posting a HJT log.
http://www.ewido.net/en/onlinescan/ |
|
|
|
|
|
#41 | |
|
~ Ryan ~
|
Quote:
__________________
RiotCats.com, an internet domain specifically fabricated and visually erected for the appreciation of the feline kingdom! |
|
|
|
|
|
|
#42 |
|
Member (6 bit)
Join Date: Jan 2007
Location: PA
Posts: 57
|
This is Ewido 4.0 renamed
Download and install AVG Anti-Spyware 7.5
(This is Ewido 4.0 renamed. If you already have Ewido installed, please update to AVG Anti-Spyware which has a special "clean driver" for removing persistent malware) 1. After download, double click on the file to launch the install process. 2. Choose a language, click "OK" and then click "Next". 3. Read the "License Agreement" and click "I Agree". 4. Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install". 5. After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray. 6. The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. 7. Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows". 8. Go to Start > Run and type: services.msc
Exit AVG Anti-Spyware when done - DO NOT perform a scan yet. Reboot your computer in "SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Scan with AVG Anti-Spyware as follows: 1. Launch AVG Anti-Spyware, click on the "Scanner" button and choose the "Settings" tab.
3. Click "Complete System Scan" to start. 4. When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine. IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button? 5. Click on "Save Report" to view all completed scans. Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\ 6. You will need the report if you are active in a HJT log and are instructed to post the report, otherwise you will not need to post anything. Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. Doing so may hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection. AVG Anti-Spyware is free for 30 days and all the extensions of the full version will be activated. After the 30 day trial, active protection extensions will be deactivated and the program will turn into a feature-limited freeware version that you can can continue to use as an on-demand scanner or you may purchase a license to use the full version.
__________________
ALWAYS BACK UP YOUR REGISTRY BEFORE EDITING I don't accept emails .........please keep all questions within the forum. Visiting Assistant Manager ASAP Certified |
|
|
|
|
|
#43 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
|
It appears that Trend Micro has bought HijackThis.
http://www.trendsecure.com/portal/en...hijackthis.php It's still free and they have added quite a bit of documentation. Use it and look over their documentation before posting your logs. |
|
|
|
|
|
#44 |
|
Member (2 bit)
Join Date: Jun 2007
Posts: 3
|
HI members..
I am new here to his forum and friend recommended me this site. Great Site link and information. I came dome here to figure out some of the problem that my computer has been having for long time.. John Smith |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|