kurenaiyue asked: I downloaded Spyware Doctor. I have the free version, which scans all your files and the difference is that you have to manually go into the registry or into folders to delete threats.
I have gotten rid of about 85% of all the things. I have rescanned several times…
These are what are giving me trouble (oh, by the way, I have everything set to “show hidden files/folders”)
Adware.TV_Media_Display (2 infections)
-Description: A potentially unwanted adware program that could be used to display various pop-up advertisements
-Threat level: Elevated (4/5)
—C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\ TEMPORARY INTERNET FILES\Tvm.log
—C:\DOCUMENTS AND SETTINGS\DAVID\LOCAL SETTINGS\ TEMPORARY INTERNET FILES\Tvm.log
—————-Problem: I cannot locate Tvm.log, even with “show hidden” selected
Adware.DelfinProject (1 infections)
-Description: A potentially unwanted adware program that could be used to display various pop-up advertisements
-Threat Level: High (5/5)
—C:\keys.ini
——————-Cannot locate
Rootkit.Agent (76 infections)
-Description: A threat that relies on rootkit-specific techniques in order to hide its presence in the system. In addition, the detected sample contains the following characteristics:
–a program that can be used to hijack certain aspects of users’ web browser functionality (such as homepage, search page, and security settings)
–a malicious trojan horse that may represent a security risk for the compromised system and/or its network environment
-Threat Level: High (5/5)
—–FILE:
—–C:\WINDOWS\SYSTEM32\drivers\core.sys
(It won’t delete. Says it is being used, and refuses to let me delete it)
—–STARTUP PROGRAM:
—–HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\core, ImagePath = system32\drivers\core.sys
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\core, ImagePath = system32\drivers\core.sys
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\core, ImagePath = system32\drivers\core.sys
—–REGISTRY KEY:
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\ENUM\ROOT\LEGACY_CORE
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\ENUM\ROOT\LEGACY_CORE
—–HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ENUM\ROOT\LEGACY_CORE
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\SERVICES\CORE
—–HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\SERVICES\CORE
—–HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\SERVICES\CORE
———–These will not allow me to delete them.
Trojan.Agent.AOY (10 infections)
-Description: A malicious program that may represent a security risk for your computer or network environment
-Threat Level: Medium (3/5)
—–REGISTRY KEY:
—–HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DOMAINSERVICE
————–It will not allow me to delete this or anything in it.
—–REGISTRY VALUE TO BE REPAIRED:
—–HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, SFCDisable
———I do not know what I am supposed to do with this since it says “to be repaired”
Adware.BHO.GEN (2 infections)
-Description: A malicious program that may represent a security risk for your computer or network environment.
-Threat level: Medium (3/5)
—–HKEY_CLASSES_ROOT\CLSID\e405.e405mgr
—————-I cannot find it in the registry.
Now, the items in the registry… I don’t know why they aren’t letting me delete them.
I have spent over 2 hours deleting threats from in the registry, so I know it’s not some sort of protection for the computer. It is apparently some way for this crap to keep itself from being deleted.
Any help you can provide will be appreciated.
I am looking to do this MANUALLY, not by purchasing the software or downloading anything else.
Is there anything I can do?
Caffeinated Content - Members-Only Content for WordPress