There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
access audio avg avg 8 bios blue screen boot browser bsod computer crash css dell desktop driver drivers dvd email error excel explorer firefox firefox 3 freeze gimp graphics hard drive hardware help please hijackthis hjt install internet internet explorer itunes javascript keyboard laptop log malware monitor network networking openoffice outlook outlook 2003 outlook express password php popups problem router seo slow sound sp3 spyware startup trojan usb video virtumonde virus vista vundo windows windows xp winxp wireless youtube
Malware Removal & HijackThis Logs
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
delete help with winpcdoctor


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
06-Apr-2008, 02:16 PM #46
Thank you Cookiegal-- I expected you to take the weekend off. You must really love helpint folks like us. It is appreciated!
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
06-Apr-2008, 03:00 PM #47
smitfraudFix report
SmitFraudFix v2.309

Scan done at 11:55:22.14, Sun 04/06/2008
Run from C:\Documents and Settings\Ben Gilmore\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\PROGRA~1\COMMON~1\INTERN~1\giw.exe
C:\Program Files\USS\USS.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Express ClickYes\ClickYes.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\USS\{D1957FF4-EA22-4b4a-81A1-C62068479DED}\wasffNT.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ben Gilmore


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ben Gilmore\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BENGIL~1\FAVORI~1

C:\DOCUME~1\BENGIL~1\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{C14FE8EC-0A4B-454C-8108-C949F9DD1E46}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{C14FE8EC-0A4B-454C-8108-C949F9DD1E46}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{C14FE8EC-0A4B-454C-8108-C949F9DD1E46}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Cookiegal's Avatar
Administrator with 51,851 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
06-Apr-2008, 04:55 PM #48
You should print out these instructions or copy them to a Notepad file for reading while in Safe Mode because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear
  • Select the first option, to run Windows in Safe Mode then press "Enter"
  • Choose your usual account
Once in Safe Mode, double-click smitfraudfix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process. If it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process. Please copy/paste the content of that report into your next reply along with a new HijackThis log. The report can also be found at the root of the system drive, usually at C:\rapport.txt
__________________
Microsoft MVP - Consumer Security

Alliance of Security Analysis Professionals
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
06-Apr-2008, 10:18 PM #49
Nothing seems to come easily!
Cookiegal--

When I click the smitfraudfix icon on my desktop in normal mode, I get the list of options
"1,3,4..."

When I click on that icon in safe mode I get a different window without any numbered options? See attached screenshot.
Cookiegal's Avatar
Administrator with 51,851 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
07-Apr-2008, 02:27 PM #50
Please attach the screen shot.
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
07-Apr-2008, 05:02 PM #51
screen shot
I scroll(ed) down below this to manage attachments and browsed for the bmp file I saved from mspaint screenshot. clicked it and clicked upload. When the progress field indicated complete, I scrolled to the bottom and closed the page. Now I'll submit this reply. Hope you get it.
Cookiegal's Avatar
Administrator with 51,851 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
07-Apr-2008, 06:57 PM #52
It's not there. After you've browsed to the file on your computer, you have to click on "Open" in that window first and then click on "upload".
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
07-Apr-2008, 08:56 PM #53
screenshot
Did it come through? Is there a place on this site that indicates an attachment is fixed?
Cookiegal's Avatar
Administrator with 51,851 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
07-Apr-2008, 09:49 PM #54
You would see it at the bottom of the post.
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
08-Apr-2008, 03:28 AM #55
Screenshot 3rd Try!
I scroll down to "manage attachments and click
Then browse to the file containing the screenshot.
(note-- before trying this, I went to MSpaint and opened the file to make sure the shot was there. It was)
I hilighted the file and clicked open.
(note- I saw no change anywhere)
Then I clicked "upload"
(The progress field indicated upload)
Then I scrolled down to "close this window" and clicked
(Still no indications anywhere)
Cookiegal I'm at a loss.
Cookiegal's Avatar
Administrator with 51,851 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
08-Apr-2008, 10:43 AM #56
Let's leave it for now and do this please:

Please download Malwarebytes Anti-Malware form Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply along with a new HijackThis log please.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
__________________
Microsoft MVP - Consumer Security

Alliance of Security Analysis Professionals
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
08-Apr-2008, 01:09 PM #57
MBAM Report
Malwarebytes' Anti-Malware 1.11
Database version: 600

Scan type: Quick Scan
Objects scanned: 34084
Time elapsed: 11 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 43
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 16

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{50ccd00a-66b6-4d95-aaef-8ee959498f92} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e94eb13e-d78f-0857-7734-5e67a49ffff1} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d70e9b0f-aabc-4066-8176-c6de84d92fa1} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4567ab12-a884-4ca6-b739-cedb12fef096} (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{4567ab12-ae24-4fd6-b479-e2b464f32da6} (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{_clsid_washellexecutecheck} (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d761645b-6b20-4698-aee8-729981152a82} (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sbiebho.iefw (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\sbiebho.iefw.2 (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{14e6d991-db22-4661-981d-20c168d6847b} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2242513c-f5e9-41b3-bc89-4d9daf487450} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3b489b37-fc1b-45c8-b1ce-78d9aef5b336} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3d6a6e24-fdff-418e-a93d-9fbdcba377af} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e318e44-0c35-4292-af91-18dd17795636} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{495349a3-3a35-465f-88df-6ccfc1348246} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{575e8879-d6cf-4992-a7fe-651da9277bcb} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{76a15001-ff88-47ee-9e34-9f68e34246af} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{819a1c55-735f-4696-8727-3772ec87ad26} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8dc7e656-ffbc-4ba2-af81-1c6c4fe04407} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a86bed71-2b56-4778-9c48-829a3d01c687} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ae119e11-cf86-43cb-91aa-1acf2bbf9ec6} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b5a1ce7f-011d-4475-98db-076aaf3b1d18} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b667f141-171c-4ac6-bd2b-8e0c646fb920} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{da4f8351-05ef-4956-b9ab-1093b732436f} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e1e4e46d-53b8-45dc-abf0-3e7adef79012} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{83b0cadc-ea64-4ac6-822a-3ece95f44da6} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Purchased Products (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WinPCDoctor (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\WinPCDoctor (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\WinAnonymous (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WinAnonymous (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\NetProject (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inte rnet Service (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Secu re Browsing (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\stfngdvw.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WinSpyControl (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\WinSpyControl (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoPl.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weat her Services (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Start Menu\Programs\WinSpyControl (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAnonymous (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinPCDoctor (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\SYSTEM32\sqlite3.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSpyControl\Contact Customer Support.lnk (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSpyControl\Uninstall WinSpyControl.lnk (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinSpyControl\WinSpyControl.lnk (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAnonymous\Contact Customer Service.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAnonymous\Uninstall WinAnonymous.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAnonymous\WinAnonymous unregistered.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAnonymous\WinAnonymous web page.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinPCDoctor\Contact Customer Service.lnk (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinPCDoctor\Uninstall WinPCDoctor.lnk (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinPCDoctor\WinPCDoctor.lnk (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ben Gilmore\Desktop\WinPCDoctor.lnk (Rogue.WinPCDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ben Gilmore\Desktop\WinAnonymous unregistered.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ben Gilmore\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAnonymous unregistered.lnk (Rogue.WinAnonymous) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\WinSpyControl.lnk (Rogue.WinSpyControl) -> Quarantined and deleted successfully.
C:\Documents and Settings\Ben Gilmore\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
08-Apr-2008, 01:22 PM #58
MSN Toolbar
Cookiegal-

Don't know if this is a factor or not--

On my tool tray appears a note about trouble with the MSN Toolbar. When I click it I get a dialog box that I put on a screenshot. I'll try to attach it here.

Sigh Nothing appears at the foot of this note. I gues it is the same problem with screenshots.
Attached Thumbnails
delete-help-winpcdoctor-msn-toolbar-dialog-box.jpg  
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
08-Apr-2008, 02:59 PM #59
ignire this message please
beenthere7659's Avatar
Computer Specs
Senior Member with 128 posts.
 
Join Date: Mar 2008
Location: near Sacramento, California
Experience: Intermediate
08-Apr-2008, 03:46 PM #60
Spyware popup
Perhaps the problem was .bmp rather than .jpg

At any rate, here is a screenshot of the pesky popup that blocks the lower right screen. The only way I have found to get rid of it is to click block attack which opens the web and I click the red X in the upper right before it does anything. What follows is a dialog box that informs me I have to close all tabs and I get kicked off the net.

Last edited by Cookiegal : 08-Apr-2008 05:09 PM.
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:48 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.