[quote name=\'guestolo\' date=\'May 17 2005, 09:46 PM\']==Download RKFiles.zip from the link
http://skads.org/special/rkfiles.zip (http://\"http://skads.org/special/rkfiles.zip\")
UNZIP the contents to it's own folder
Could you post the log produced by Rkfiles.bat[/quote]C:\rkfiles
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\system32\Dwapilib.tlb: dwProvSpec2
Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
C:\WINDOWS\gr.exe: UPX!
Finished
bye
Also
Could you download and UNZIP to a folder Hijackthis 1.98.2 (http://\"http://www.merijn.org/files/hijackthis1982.zip\")
Do a scan with this version of Hijackthis and save the log
Post it back here
I'll look at it first thing when I get off work tomorrow
[post=\"41645\"]<{POST_SNAPBACK}>[/post]
I wasn't able to run this version of hijack this either. Same results as before, it ran for a second, then shut down.
In the mean time, MS anitspyware has run automatically and found more spyware, big surprise! A new one that has popped up recently that I didn't have before is PeopleOnPage. Also it found AproposMedia and IST.IST bar. the usual suspects there.
I'm going to allow MS to try and clean the system. I know if I run SPYBOT and AdAware, it will find more and different ones.
Do you want me to clean my system today, the same way I do every darn day?
Any ideas abotu running a succesful hijack this?
[quote name=\'guestolo\' date=\'Jun 7 2005, 09:24 PM\']How is everything?
Not that I want you to run Nortons firewall and XP's at the same time
But can you let me know if you can enable XP's Firewall please
[post=\"44375\"]<{POST_SNAPBACK}>[/post]
[/quote]
As far as I can tell, everything seems to be working correctly. I do not have Norton's firewall installed, nor do I own the program.
I did enable the windows xp firewall, the "internet connection firewall" is the one I enable, I am assuming that is the correct one?
Previously I was unable to share my internet connection, which I could share before all the spyware, and now that sharing has been restored.
I guess everything is working good, but I have doubts about my ability to keep it all from coming back.
I saw a news special a few nights ago where they ran Ad Aware and it found no spyware. Then they visitied a half dozen kid's sites, not sure which ones, and after, Ad Aware found a whole bunch of spyware. Of course the companies denied having anything to do with it.
But that news story bothers me.
Will the internect connection firewall protect my computer?
Also, I have two other computers on my network. A win98se machine and another XP Home SP1 machine. The other XP machine is the kids computer and I know it is majorly infected.
Will that computer somehow infect my computer that is now apparently clean?
I'm going to start a new thread with a hijack this from my kid's computer so we can start cleaning it.
Thanks again for all your help, it is amazing to me that you do this for free! I would like to help pay for some of the needs that arise from running a site like this, what are the methods that I can do this?