Archived from groups: microsoft.public.windowsxp.security_admin (
More info?)
Anytime !
--
Dave
"lozliz" <lozliz@discussions.microsoft.com> wrote in message
news
7FDBEC8-C95C-4E1E-967C-35C02DE5AF4A@microsoft.com...
| Dave,
|
| All clean for the time being! Thanks for all your help.
|
| Lozliz
|
| "David H. Lipman" wrote:
|
| > Bruce has provided pertinent information.
| > All I can say is "dump them all !"
| >
| > --
| > Dave
| >
| >
| >
| >
| > "lozliz" <lozliz@discussions.microsoft.com> wrote in message
| > news:0F3EEF81-7BA8-4B25-B65E-20B0F62F1E93@microsoft.com...
| > | Dave,
| > |
| > | I have completed 2 runs of trends sysclean, ad-ware & McAfee stinger twice
| > | in safe mode. I have then run all three once in normal mode.
| > | Ad Aware now runs without shutting down XP. It does identify about 200
| > | items, which fall into the following categories.
| > |
| > | Windupdates: 5 objects
| > |
| > | Bargin Buddy: 90 objects
| > |
| > | BlazeFind: 1 object
| > |
| > | SahAgent: 30 objects
| > |
| > | Search Relevancy: 13 objects
| > |
| > | 180 solutions: 45 objects
| > |
| > | Radsol.Quadrogram: 1 object
| > |
| > | Other: 7 objects
| > |
| > | Are they all safe to delete? Any help would be appreciated.
| > |
| > | Thanks
| > |
| > | Lozliz
| > |
| > |
| > | "David H. Lipman" wrote:
| > |
| > | > WinXP Boot into Safe Mode --
| > | >
| >
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx
| > | >
| > | > How to perform a Clean Boot of WinXP --
| > | >
http://support.microsoft.com/kb/310353
| > | >
| > | > Generic Trojan, Spyware removal information --
| > | >
http://www.claymania.com/removal-trojan-adware.html
| > | >
| > | > Trend will automatically deleted viruses, worms and/or Trojans. Adaware will
provide
| > you
| > | > what it finds. You will have to check the box of the items it finds for it to clean
| > those
| > | > items selected.
| > | > --
| > | > Dave
| > | >
| > | >
| > | >
| > | >
| > | > "lozliz" <lozliz@discussions.microsoft.com> wrote in message
| > | > news:02F34A78-5AA0-4B3A-B8DF-A4CD8F6A4A56@microsoft.com...
| > | > | David,
| > | > |
| > | > | i have follwed points 1-3 below; however have stumbled at point 4.
| > | > |
| > | > | How do you reboot the computer into safe mode.
| > | > |
| > | > | Also once i run the various programmes how do i know what to delete and what
| > | > | not to delete ?
| > | > |
| > | > | Any advice would be appreciated.
| > | > |
| > | > | thanks
| > | > |
| > | > | lozliz
| > | > |
| > | > | "David H. Lipman" wrote:
| > | > |
| > | > | > That means you are infected with non-viral malware. It is a self preservation
| > scheme
| > | > that
| > | > | > when you execute Adaware, the malware will shutdown the PC such that you don't
get a
| > | > chance
| > | > | > to remove it. I think that is pretty smart and I have run accross it a couple
of
| > times
| > | > it
| > | > | > is certainly PITA !
| > | > | >
| > | > | > However, you CAN overcome this self preservation attempt.
| > | > | >
| > | > | > When you execute Adaware and you get the shutdown message, go to..
| > | > | >
| > | > | > Start --> run
| > | > | > and type
| > | > | >
| > | > | > shutdown -a
| > | > | >
| > | > | > then hit the enter key. That should stop the shutdown sequence and allow you to
| > clean
| > | > the
| > | > | > system. The following is a set of instructions I suggest to help make that
cleaning
| > | > process
| > | > | > be effective as possible. Ignore the section about downloading Adaware unless
you
| > don't
| > | > | > have Adaware SE v1.05.
| > | > | >
| > | > | > 1) Download the following three items...
| > | > | >
| > | > | > Trend Sysclean Package
| > | > | >
http://www.trendmicro.com/download/dcs.asp
| > | > | >
| > | > | > Latest Trend Pattern File.
| > | > | >
http://www.trendmicro.com/download/pattern.asp
| > | > | >
| > | > | > Adaware SE (free personal version v1.05)
| > | > | > http://www.lavasoftusa.com/
| > | > | >
| > | > | > Create a directory.
| > | > | > On drive "C:\"
| > | > | > (e.g., "c:\New Folder")
| > | > | > or the desktop
| > | > | > (e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
| > | > | >
| > | > | > Download Sysclean.com and place it in that directory.
| > | > | > Download the Trend Pattern File by obtaining the ZIP file.
| > | > | > For example; lpt345.zip
| > | > | >
| > | > | > Extract the contents of the ZIP file and place the contents in the same
directory as
| > | > | > sysclean.com.
| > | > | >
| > | > | > 2) Update Adaware with the latest definitions.
| > | > | > 3) Disable System Restore
| > | > | >
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
| > | > | > 4) Reboot your PC into Safe Mode and shutdown as many applications as
possible
| > | > | > 5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of
| > your
| > | > | > platform and clean/delete any infectors/parasites found.
| > | > | > (a few cycles may be needed)
| > | > | > 6) Restart your PC and perform a "final" Full Scan of your platform using
both
| > the
| > | > | > Trend Sysclean utility and Adaware
| > | > | > 7) Re-enable System Restore and re-apply any System Restore preferences,
| > | > | > (e.g. HD space to use suggested 400 ~ 600MB),
| > | > | > 8) Reboot your PC.
| > | > | > 9) Create a new Restore point
| > | > | >
| > | > | >
| > | > | > * * * Please report your results ! * * *
| > | > | >
| > | > | >
| > | > | >
| > | > | > --
| > | > | > Dave
| > | > | >
http://www.claymania.com/removal-trojan-adware.html
| > | > | >
| > | > | >
| > | > | >
| > | > | >
| > | > | > "lozliz" <lozliz@discussions.microsoft.com> wrote in message
| > | > | > news:13E99000-CD2D-4619-8735-471A3CD41AFE@microsoft.com...
| > | > | > | I have installed lavasoft adware. Wwhen I run for the first time the
| > | > | > | computer then shuts down, which has been authorised by NT authority system.
| > | > | > | The actual error message is:
| > | > | > | WINDOWS MUST NOW RESTART BECAUSE THE DCOM SERVER PROCESS LAUNCHER SERVICE
| > | > | > | TERMINATED UNEXPECTEDLY.
| > | > | > |
| > | > | > | Everthing else appears to be okay.
| > | > | >
| > | > | >
| > | > | >
| > | >
| > | >
| > | >
| >
| >
| >