Run the online virus scan in my signature then follw this .And i only charge $25.00.lol
Download the latest version of Ad-Aware at http://download.com.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button
After installing AAW, and before running the program, you NEED to FIRST update the reference file following these instructions. http://www.lavahelp.com/howto/updref/index.html
Now do the follwing :
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."
Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:
Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"
Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.
Finally, close Ad-Aware, and reboot.
That ought to get rid of most of your spyware.
And after that, please do the following:
download and update
SPYBOT
how to setup SpyBot
reboot computer and post a new hijackthis log
caperjack
I hate 20 Questions
13,066 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
I am not sure if this is the right forum to post this but here goes:-
I had MS Blaster which was shutting down all my programs. Now I find I have WORM AGOBOT.UY which seems to prevent me from running any virus software. It is in C:\windows\system32\msnmsgr.exe and I tried the malaware fix but it never lists the program as running. I don't want to have to do a reformat.
This worm has various names. That's one of the problems with multiple anti-virus companies crawling over each other to "solve" your problems for competitive gain. Try this Symantec link, and enter the word Agobot in the search box. You can also try this Google search. I'm not sure which tool removes it.
TallCool1
Practically a Posting Shark
865 posts since May 2003
Reputation Points: 149
Solved Threads: 45
On boot up I also still getting a box that says "You (or a program) have requested information from storm.godofthe.net which connection do you wish to use?" The message also used to use the name "relay.kontiki.com" but Ad-Aware found the kontiki folder and removed same. Thanks all for your help this is driving me more insane that I already am.
O17 - HKLM\System\CCS\Services\Tcpip\..\{6179ED18-10E5-40A1-94DE-4AF6F58DEC60}: NameServer = 203.109.250.50 203.109.250.61
That last017 item is interesting. Are you in Australia, by chance? Is yout ISP iHug? If not, that may be your culprit, if "StormGod" is hosted by them.
Folks, when you sign up, at least tell us what country you are from. It is not at all unusual for that information to affect the answer. This is one of those cases.
You also seem to have a lot of references to the on-line virus scans that you did (nearly all the 016 items), but that probably has no effect on performance. They really should clean up after themselves better!
Other than that, I see nothing in the HijackThis log that seems amiss. There are a few things that I would remove because they are pigs, but that's just me. Have you cleared out your Internet Temporary Files folder lately?
TallCool1
Practically a Posting Shark
865 posts since May 2003
Reputation Points: 149
Solved Threads: 45