• The Forums are now open to new registrations, adverts are also being de-tuned.

Spyware / Trojan / Warning

These are all the same infection. The program reporting the infection is the real culprit
 
Yes I thought so - I have run both the programmes you recommended -- and its still there........:mad:
 
This is where I get lost ..what is the hijack file?? How do I get it...?

Sorry for being thick...:o
 
Download a copy from here: http://www.masqueraid.eu/download/HT.zip
Unzip it onto your desktop, run it, and get it to produce a log file.
DON'T use it (yet) to alter anything on your machine. The log file can be saved in Notebook.

If you can get your computer to connect to www.hijackthis.de you can upload your log file to the site and it will give you a link (valid for about 3 days) that you can give to people so they can analyse it for you.

Some Smitfraud variants will block you trying to reach sites that can help remove them. If you can't connect to the site I'll PM you an email address as well.
 
did all that and it immediately analysed it for me..

two lines of data it didnt like

Managed to get rid of one but this one eludes me

C:\ProgramData\fwzgpgxw\fkvyzsxw.exe

if i go into startsearch and type it in i can find it but it wont let me delete it...

i think i'm on the right track....and learning masses..:D
 
OK another tool you might need for your new IT toolbox
http://ccollomb.free.fr/unlocker/

Download and install then right click on anything that won't delete.

However don't be suprised if there is another program hidden around that checks that C:\ProgramData\fwzgpgxw\fkvyzsxw.exe
is atill there and if not respawns it in another form.

EDIT - take care with HiJackThis - for such a tiny bit of software it is very powerful - it is easy to mess things up big time.
 
since i deleted the one line it seems to be ok....so I will now wait with baited breath..............again


Once again many thanks to all for help and support....much appreciated...:bannana:
 
Good stuff :D

Even though it appears fine though I'd recommend you run the two spycheckers again to clean up anythnig that might be left behind.


Might also be worth downloading and installing the latest version of Spybot S&D (download.com would be a safe site to get it from). Although it is falling behind in the antispyware league tables it does have a useful feature called "TeaTimer" which blocks known spyware sites from installing stuff on your PC + it notifies you if anything tries to change the settings in your registry and confirms with you that this is OK before allowing it.

+ Uninstall Unlocker if you don't need it - it just takes up space and if you ever need it again you can simply reinstall.
 
I had a super spy/ trojan remover once,,cant think what is is called

The nice feature was that you could open every file on the HD and by going into explore it would scan the program and let you know if there was was anything on it that should not be.. I found the hardest problem was knowing the coded numbers that mean nothing to me,, though cyou can check the dates when on the computer, some only give the modified date
 
I found the bug that Hijacked my browser, settled into my windows startup.
I tried just about every bit of software to scan for this file "dtjyo.exe" and not listed on the net which made me suspicious..
Hijack this was the ony one that listed it, and although i removed it from the registry, it still plagued my browser.

Other files even a general file seach did not find
C:\documents & settings\owner\local settings\application data\dtjyo.exe
C:\documents & settings\owner\local settings\application data\dtjyo.dat
C:\documents & settings\owner\local settings\application data\dtjyo_navps.dat
C:\documents & settings\owner\local settings\application data\dtjyo_nav.dat
C:\windows\prefech\dtjyo.exe-od9c7854.pf
 
Last edited:

Users who are viewing this thread

Back
Top Bottom