Home > Cannot Remove > Cannot Remove The New Aol Virus? Bestfriends.scr

Cannot Remove The New Aol Virus? Bestfriends.scr

THAT IS THE LINK I CLICKED... and the link. Proffitt Forum moderator / December 30, 2004 7:37 AM PST In reply to: Ha 1. You can always delete it later when you find out if you actually need it or not. http://linux4newbie.com/cannot-remove/cannot-remove-klex-h-virus-unsure-if-i-even-have-it.html

Companion BHO = C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dllHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2} SpywareGuardDLBLOCK.CBrowserHelper = C:\Program Files\SpywareGuard\dlprotect.dllHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F} = C:\PROGRA~1\SPYBOT~1\SDHelper.dllHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58- Feb. 15, 2005 Previous issue | Next In this This demonstration will provide an overview of proper scanning techniques, resolution options, and how to optimize file size. I also cannot run 'msconfig' to start my computer in safe mode. DO NOT CLICK ON THIS LINK,THIS IS HOW I BELIEVE MY PROBLEMS BEGAN.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /hO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Web watch Adware/spyware resource page published Feb. 15, 2005 EDUCAUSE has created an Adware/Spyware resource page that includes links to resources at other universities and colleges. is spelled InstEnt with an E...

Problems are still persisting. Powered by vBulletin Version 4.2.0 Copyright © 2017 vBulletin Solutions, Inc. Let's try this scanner and see what it shows.Download WinPFind.zip and unzip the contents to the C:\ folder.Start in Safe Mode Using the F8 method:Restart the computer.As soon as the BIOS Here is my log please help!!!!

Yes, my password is: Forgot your password? Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder. can't figure out what's causing it though.... Justin Jeffries, Jul 19, 2004 #1 Advertisements Guest Guest Please see the following instructions.

I attached a paint file of the screen shot >>>> so you can see what is starting. You'll be able to ask any tech support questions, or chat with the community and help others. Here it is. I will try what you have suggested.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /hO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Click on the View tab and make sure that "Show hidden files and folders" is checked. Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

Spyware/Virus Removal: http://www.fixyourwindows.com/windowsxpsolutions.htm Startup and Temporary Files Cleanup: http://www.fixyourwindows.com/optimizewindows.htm "Justin Jeffries" wrote: > I was able to hit CTRL+Print Screen... http://linux4newbie.com/cannot-remove/cannot-remove-cryptor-virus-and-or-trojan-tdss-help-please.html Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Forums Recent Posts Members Members Quick Links extension. Be patient.

If you're having a computer problem, ask on our forum for advice. Thank you so much for your help! Is it JUST AIM that you are having problems with or are you also having task manager problems? useful reference Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.iwioqzywrftpy.net/piylJC/zOXn0u...GUN8uTCOA/.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blankF2 - REG:system.ini:

Jay Loden's site got rid of this problem but this morning I couldn't type anything in my IM window. I strongly suggest that you install an AV and firewall, See here for a few free ones. Anyway, this is the site: http://www.tech-recipes.com/instant_messaging_tips575.html.

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: &Yahoo!

The good news: Most infections can be easily prevented by following these instant-messaging rules: Don't click on web addresses received from friends through instant messaging. I cannot open task manager, and when i try to run msconfig, the window opens for a split second and then closes, just like the windows task manager does. Flag Permalink This was helpful (0) Collapse - Then what does show in... Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\newaim\aim.exeO9 - Extra button: Merriam-Webster - {BAC53F31-6090-11d5-8497-0048548030CA} - C:\WINDOWS\Downloaded Program Files\m-wtoolbar.dllO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

Wes In news:eEy$, Justin Jeffries <> hunted and pecked: > I was able to hit CTRL+Print Screen... Do not click it. This is being done for security reasons, since those older machines only run Symantec AntiVirus version 7.6. http://linux4newbie.com/cannot-remove/cannot-remove-this-virus-screen-shot.html If anything was found, right-click on the list and choose Select All and remove all it finds.OK.

I clicked that link on a buddy's away message (which was identical) and thats how this all started. Please use them so that others may benefit from your questions and the responses you receive.OldTimer Back to top #7 jhh3d jhh3d Topic Starter Members 39 posts OFFLINE Local time:06:50 Also in safe mode navigate to the C:\Windows\Temp folder. Logfile of HijackThis v1.97.7 Scan saved at 7:49:24 PM, on 6/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

The only thing was that the infected file on my > computer was not YAHOOMSG.EXE. Keep that tool that Bob got you because it takes up no room and you never know when you'll need it again. Web watch:Adware/spyware resource page Gem:Spanish Via Satellite instructor honored New viruses use instant messaging to entice users by J. Delete all infected files found:Housecall Online Scanner Panda Online ScannerAfter that, download, install, update, and run the free spyware removal tools in the links below:Ad-Aware Flag Permalink This was helpful (0)

That's what the forums are here for. Note the room change. Edit: Other files found which may be the cause of the problem (as taken from a HJT log): [AOL Messenger] HQSNPFLH.EXE [Microsoft Gina V Encryption] MSGINAV.EXE IF YOU HAVE OTHER SPYWARE I attached a paint > > file of the screen shot so you can see what is starting.

Dexter... 0 This discussion has been closed.