afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > spyfalcon and others!  
											
												
	
	
						 				 	
	
	
	
		
			
			
			
				
			
		 
	
												 
															
															
	
			
			
				
					spyfalcon and others!
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								HMT
							
							
								Newbie
								
									
								
							
							 
						7. March 2006 @ 08:23 Link to this message 
								  
								 
					
					
					
						
						
						
							
							pop-ups galore, re-direction on web pages, continuall "your computer is infected" ballons on the taskbar!
http://www.splfever.co.uk/ http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab http://acs.pandasoftware.com/activescan/as5free/asinst.cab http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab http://66.117.37.13/dba2339.exe  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							
						 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									1 product review 
								
							
							 
						7. March 2006 @ 18:03 Link to this message 
								  
								 
					
					
					
						
						
						
							
							im not the best at going through/reading log files but it sounds like a case of CWS (CoolWebSearch) one of the nastiest versions of spyware/browser hijacker/ etc. on the internet. luckily theres a tool owned by Trend Micro called CWShredder ( Cool Web Search Shredder) and it specializes in removing the CWS infection(s)!! its available for FREE download here   http://www.trendmicro.com/cwshredder/     good luck. 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						8. March 2006 @ 07:46 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Make a own folder to HijackThis , for example C:\Hjt and put it there.
Ewido 
http://www.ewido.net/en/download/  
Smitrem  
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1 FixSF  
http://www.bleepingcomputer.com/files/reg/FixSF.reg HijackThis , do a system scan only and check these: 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
  
Safe mode 
http://www.pchell.com/support/safemode.shtml  
delete  these files or folders if they exist: 
C :\Windows\System32\->dxmpp.dll
  
runthis.bat  
Ewido , let it clean everything that it finds and save report. 
 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									1 product review 
								
							
							 
						8. March 2006 @ 19:55 Link to this message 
								  
								 
					
					
					
						
						
						
							
							if this works congrats to jurpiss. 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									1 product review 
								
							
							 
						8. March 2006 @ 19:55 Link to this message 
								  
								 
					
					
					
						
						
						
							
							if this works congrats to jurpiss. 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									1 product review 
								
							
							 
						8. March 2006 @ 19:56 Link to this message 
								  
								 
					
					
					
						
						
						
							
							if this works congrats to jurpiss. 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								paco1taco
							
							
								Newbie
								
									
								
							
							 
						9. May 2006 @ 09:43 Link to this message 
								  
								 
					
					
					
						
						
						
							
							I have the same issue.  You can't delete winghy32.dll in safe mode.  I followed the steps exactly.  I tried trend micro, some other online virus scan, Ad-Aware , and spy-bot and nothing helped.
 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						9. May 2006 @ 10:02 Link to this message 
								  
								 
					
					
					
						
						
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								paco1taco
							
							
								Newbie
								
									
								
							
							 
						9. May 2006 @ 10:14 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Actually, after I found out I couldn't delete that file...I finished the rest of the steps and it looks like that E program got it.
 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						9. May 2006 @ 10:57 Link to this message 
								  
								 
					
					
					
						
						
						
							
							@paco1taco
 
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
							This message has been edited since posting. Last time this message was edited on 9. May 2006 @ 11:06 
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							  
					 
				
				
				
					
						
							
								paco1taco
							
							
								Newbie
								
									
								
							
							 
						9. May 2006 @ 19:05 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Nope, seems to be good now.  Maybe it'll come back when that trial is over :) 
							
						
						
						
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > spyfalcon and others!