Geordie Boyo 24 Posted January 2, 2006 Share Posted January 2, 2006 I've got a major problem and I need....well you know...! After a search for new downloads I came across something that has enabled this to happen and its driving me crazy...! No matter how many times I try and change the Address in Internet properties it wont work! This is my current home page...! c:\secure32.html Detected SPYware! System error #384 __________________________________________________________________________ Your IP address is.......Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited. __________________________________________________________________________ Your computer is full of evidences! ISP of transmission: CO Your IP address: They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Supplied by blueyonder) Your computer is: Windows XP Risk status for further investigation: VERY HIGH RISK My drive recently knacked up. I had some bloke come out to take it away to fix it. He installed new software, avest etc. Is there some way I can sort my home page out and get everything back to normal? Link to comment Share on other sites More sharing options...
peasepud 59 Posted January 2, 2006 Share Posted January 2, 2006 This is a twat of a Spyware this one so could require more than just the following: First go into Add/Remove Programs and look for NewDotNet and remove it. Then reboot, after that you'll need to download the following: http://www.winsockfix.nl/winsockxpfix.exe Link to comment Share on other sites More sharing options...
Geordie Boyo 24 Posted January 2, 2006 Author Share Posted January 2, 2006 Mate, I don't have NewDotNet in the list of the Add & Removie programs Should I just click on the link and follow the procedures? Link to comment Share on other sites More sharing options...
Geordie Boyo 24 Posted January 2, 2006 Author Share Posted January 2, 2006 Andy, I did what you said. Spybot couldn't find anything, so I downloaded hijackthis. I used it, clicked on all the boxes that appeared and clicked on fix problems. Should I have done that Link to comment Share on other sites More sharing options...
Geordie Boyo 24 Posted January 2, 2006 Author Share Posted January 2, 2006 Pud, I used that download, rebooted my system and it worked! Your my hero! Thank you very, matey. Link to comment Share on other sites More sharing options...
peasepud 59 Posted January 2, 2006 Share Posted January 2, 2006 All in a days work mate Link to comment Share on other sites More sharing options...
Craig 6700 Posted January 2, 2006 Share Posted January 2, 2006 All in a days work mate 73062[/snapback] Shame you can't say that at HMRC though, eh? Link to comment Share on other sites More sharing options...
Geordie Boyo 24 Posted January 2, 2006 Author Share Posted January 2, 2006 Andy I can't log into Newcastle GREAT! Online...! But here's the log file agian. ogfile of HijackThis v1.99.1 Scan saved at 23:02:21, on 02/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\DOCUME~1\nil\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ O2 - BHO: GB2 Class - {0A3101FB-06E3-4C67-BB16-A3CB19B2781D} - C:\WINDOWS\system32\gb2.dll O3 - Toolbar: GB2 Class - {0A3101FB-06E3-4C67-BB16-A3CB19B2781D} - C:\WINDOWS\system32\gb2.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe Link to comment Share on other sites More sharing options...
Andy 0 Posted January 2, 2006 Share Posted January 2, 2006 (edited) Ok, it's now clean. (And worryingly empty ) Edited January 2, 2006 by Andy Link to comment Share on other sites More sharing options...
Geordie Boyo 24 Posted January 2, 2006 Author Share Posted January 2, 2006 Ok, it's now clean. (And worryingly empty ) 73072[/snapback] Nice one, cheers Now, is there anyway I can get that avast anti virus icon back in the right-hand corner again? I'm just not sure its operating again because of it.... Link to comment Share on other sites More sharing options...
peasepud 59 Posted January 2, 2006 Share Posted January 2, 2006 Andy I can't log into Newcastle GREAT! Online...! 73067[/snapback] Can I have that virus please? <---- oh god that'll start another war Link to comment Share on other sites More sharing options...
Andy 0 Posted January 2, 2006 Share Posted January 2, 2006 (edited) If you run the program and look in the options, there should be some kind of "run on startup" button kicking around somewhere. Re-tick that. Personally though, I would uninstall Avast and just download AVG free edition instead. Edited January 2, 2006 by Andy Link to comment Share on other sites More sharing options...
Andy 0 Posted January 2, 2006 Share Posted January 2, 2006 Andy I can't log into Newcastle GREAT! Online...! 73067[/snapback] Can I have that virus please? <---- oh god that'll start another war 73077[/snapback] *raises alarm* Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now