Originally Posted by drkyello
i've tried to place (sorry don't know how to use the quote box on the forums)
C:\PROGRAM FILES\NOIAHOO! on killbox, but nothing happens when i press the red sign with the white x on it, does nothing at all.
Sometimes Killbox doesn't reboot automaticly , i don't know why really. But it probebly did its job anyway the first time you rebooted after that.
Originally Posted by drkyello
but i do get a startup file everytime i boot how do i remove it? not sure what it is or the name of the file is, so i cannot trace it. is there a way to check startup files and delete it?
I don't really understand what you mean here , does a program or a page start up or open?
Anyway check youre "startup" folder in youre start menu , or have a look at start/run/msconfig/startup tab and see if you can find it there.
Originally Posted by drkyello
is there some advice that might help me prevent this from happening
some program that i need to get rid of or help my computer run a little better?
You actually have youre computer pretty well protected it seems , looks like windows is up to date , and you have an AV and firewall.
Only what i mentioned before you have severall anti spyware apps running , that can cause performence and conflict problems wich can make them uselless. So i would recommend to choose just one.
Originally Posted by drkyello
i recently ran spyware doctor in safe mode and it seem to get rid of a lot and then i ran blacklight and it didn't find anything.
now im hoping that nothing happens from here on
As i mentioned , i think Killbox did its job anyway and looking at the blacklight log , almost all the "bad" files where in that folder. but not all..
So let's see if we can get them all.
Please download
CCleaner
Download
Ewido Security Suite- Install Ewido Security Suite.
- When installing, under Additional Options uncheck Install background guard and Install scan via context menu
- Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
- The program will prompt you to update click the "OK" button
- The program will now go to the main screen
- You will need to update Ewido to the latest definition files.
- On the left hand side of the main screen click update
- Click on Start
- The update will start and a progress bar will show the updates being installed.*
- After the updates are installed, exit ewido.
Don't run Ewido yet.
Boot youre pc in safemode again:
Start Killbox and place a tick next to [x] delete on reboot.
Copy this list to the windows clipboard:
C:\WINDOWS\SYSTEM32\COUS2_32.EXE
C:\PROGRAM FILES\NOIAHOO!
C:\WINDOWS\system32\drivers\nmnmusbd.sys
Back in Killbox go > file > paste from clipboard,
Click the
red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Then boot in safemode again and fix this line with
hjt:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
Then run Ccleaner , and ewido:
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
- Click on Scanner , Settings
- Under "How to scan" all boxes should be selected
- Under "Possibly unwanted software" all boxes should be selected
- Under "What to scan" select scan every file
- Click OK, Complete system scan
- Let the program scan the machine
- If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you
KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*
DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.
Once the scan has completed, there will be a button located on the bottom of the screen named
Save report.
Click Save report. Save the report to your desktop, exit ewido
Note:
If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.
Then please post a new
hjt log plus the Ewido log.