Off Topic Cafe If it doesn't belong in any of the other forums. Post all Off Topic stuff here.

Spyware/adware Remover?!? Help!

Thread Tools
 
Old 10-19-2005, 10:17 PM
  #21  
Senior Member
Thread Starter
 
NightShark's Avatar
 
Join Date: Feb 2003
Posts: 945
Likes: 0
Received 0 Likes on 0 Posts
Default

thanks.. i'll try these... if you don't see me back on in a while you'll know how it turned out.. lol
Old 10-20-2005, 03:43 AM
  #22  
Senior Member
 
OzFxCoupe's Avatar
 
Join Date: Sep 2006
Posts: 2,357
Likes: 0
Received 0 Likes on 0 Posts
Vehicle: 1997 Hyundai Fx Coupe
Default

C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\Ati2evxx.exe (shows up twice for some reason)
C:\WINNT\AGRSMMSG.exe
O2 - BHO: MSEvents Object - {8DBF02DA-4360-4A7E-BEA1-347B87816327} - C:\WINNT\system32\qomnm.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeh
O20 - AppInit_DLLs: katrack.dll MsgPlusLoader.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: QConGina - C:\WINNT\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: qomnm - C:\WINNT\system32\qomnm.dll
O20 - Winlogon Notify: tphotkey - C:\WINNT\SYSTEM32\tphklock.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe


They're all the ones that I'd bin (unless you know what the ATI Technologies Inc. stuff is). If any of them are needed, you'll soon find out wink1.gif

I'd also go into the registry & at least perform a search for "winfixer" & delete any entries that are found.
Old 10-20-2005, 04:46 AM
  #23  
Senior Member
 
00tibby's Avatar
 
Join Date: Aug 2006
Posts: 1,276
Likes: 0
Received 0 Likes on 0 Posts
Vehicle: 2000 Hyundai Tiburon
Default

alright well i work all day removing spyware and viruses. heres how we do it.

first disconnect from the internet(just to be sure nothing is going to come back)
1) run something that will clean out all users temp files/cookies/temp internet files/recycle bin/etc. I believe its called C Cleanup (pm me with your email and ill send you a copy)
2) run Adaware (make sure you get the VX2 addon, once again i can email that)
3) run Spybot
4) run Microsoft AntiSpyware
5) run CWShredder
6) run HiJackThis (but be careful you can really f*** things up with this program)
7) run Norton Antivirus

all of the above are free except norton. most universities will give you a copy of Symantec Antivirus Corporate if you work for them or are a student. (symantec makes norton products)

alright. now uve done that in normal mode. reboot and push f8 to get a boot screen option.... you then want to go to safe mode and run the same scans. repeat until completely clean.

hopes this helps guys. not saying this the "best" way, but this is the meathod we use all day to remove spyware and is very effective.
Old 10-20-2005, 06:17 AM
  #24  
Senior Member
 
ammoman's Avatar
 
Join Date: May 2001
Posts: 132
Likes: 0
Received 0 Likes on 0 Posts
Default

PestPatrol...it even picked up some adware on my machine from iolo and MS anti-spyware...the Army types should already know about this one, since the fully licensed version is free on AKO...
Old 10-20-2005, 06:42 AM
  #25  
Senior Member
 
Loyen's Avatar
 
Join Date: Jul 2005
Posts: 701
Likes: 0
Received 0 Likes on 0 Posts
Default

ATI stuff is the video card support.

and it shows up 3 times - it is fine.
Old 10-20-2005, 07:18 AM
  #26  
Moderator
 
JonGTR's Avatar
 
Join Date: May 2001
Location: San Antonio, TEXAS!!!
Posts: 7,164
Received 6 Likes on 5 Posts
Vehicle: 01 Tiburon Turbo, 99 Tiburon F2E, 2013 Avalon XLE Touring
Default

QUOTE (NightShark @ Oct 19 2005, 09:47 PM)
haha.. who can live without porn

this is the website that keeps popping up
http://www.winfixer.com/pages/scanner/inde...id=RON&p=3&ax=0

That is the same damn popup I'm getting on my GF's laptop. I've run several different programs and her computer is just fuxored. It's a slow POS now because of it.
Old 10-20-2005, 07:51 AM
  #27  
Senior Member
 
supercow's Avatar
 
Join Date: Mar 2006
Location: Ashland, KY
Posts: 4,244
Likes: 0
Received 0 Likes on 0 Posts
Vehicle: 2001/Hyundai/Tiburon
Default

google for winfixer there are lots of good sites with how-to's to remove it.

here's the best way to remove spyware - reinstall xp

here's the second best way:

1. do your scans - adaware, spybot, install and update spywareblaster

2. run hijackthis and found any bad stuff then google for it. 90% of the time simply removing it with hijack this isn't going to cut it. thats the reason adaware and the rest couldn't remove it.

3. quit installing spyware, never install software that has spyware integrated, when installing software to make sure google for "the software name" spyware and i'm sure you'll find plently of people complaining about it if spyware is in it.

edit: here's a site where someone is having the same issue

http://www.bullguard.com/forum/8/Winfixer-...help_18685.html

l2mfix is how i've removed winfixer in the past - it's a pain in the butt, but be glad you didn't install the porn dialer.....
Old 10-21-2005, 10:56 AM
  #28  
Senior Member
 
00tibby's Avatar
 
Join Date: Aug 2006
Posts: 1,276
Likes: 0
Received 0 Likes on 0 Posts
Vehicle: 2000 Hyundai Tiburon
Default

just to double check. i recommend the system i posted as we clean like 600 computers a month. but make SURE your doing the scans BOTH in normal mode and SAFE mode. if that does not work. you may have to try looking into knoppx or something that is NOT windows runs from cd+ram and can read windows files and scan with an antivirus and other tools. there are some NASTY stuff where doing it in BART PE or Knoppix is the only way to fix it do to it always running in windows and auto recreating itself (even in safemode 02.gif )

also, disable system restore while running the scan... right click my computer --> properties --> system restore tab --> uncheck

when you remove it reenable it.

also watch out for random "spyware removers" ive seen them actually be viruses themselves 02.gif . if you KNOW its winfixer do a google search and look for the symantec site url. they should i have individual remover for it.
Old 10-26-2005, 10:14 AM
  #29  
Senior Member
Thread Starter
 
NightShark's Avatar
 
Join Date: Feb 2003
Posts: 945
Likes: 0
Received 0 Likes on 0 Posts
Default

ok.. so far so good. i think its gone. i havent seen the pop up come in a few days or anything weird like that.. and now my computer can actually Suspend. before it wouldnt let me it kept waking up.
Old 10-26-2005, 10:37 AM
  #30  
Senior Member
 
KayJai's Avatar
 
Join Date: Jul 2001
Location: Winnipeg
Posts: 4,828
Likes: 0
Received 0 Likes on 0 Posts
Default

What did you end up doing?



All times are GMT -6. The time now is 12:15 AM.