We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Manual Removal

Appologies for starting a new thread so soon after my last issue!

While looking for info on my infections I ended up on the wiki virus site, it advised me to download Spyhunter 3 for free.

I did and it found loads of infections that all the rest missed (MBAM, SBS&D, SASP, AA -hope you understand the shortened versions of their names!)

Of course, to remove these items I need to pay, which I'm not going to do.

It does tell me where they are located to, is it as simple as using reg edit and removing said infected files?

See my earlier issues and Hijackthis logs here: http://forums.moneysavingexpert.com/showthread.html?t=1762027
Saving and spending in equal measure
«1

Comments

  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    Oh and to be clearer on where the infections are located, they are all in one place:

    HKLM\SOFTWARE\Microsoft Windows\Current Version\Internet Settings\ ZoneMap\ EscDomains\ xxxxx.com

    With the xxxxx.com being loads of different "adult" sites

    Result of a Zlob Trojan apparently
    Saving and spending in equal measure
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    While having an adventure into the ESCdomains section in regedit, I've noticed that it is filled, and I mean filled, with loads of nasty looking websites.

    I just want to delete the whole Ecdomains section now!

    Need advice on if that is a stupid thing to do.

    I'm on Vista 32 bit.
    Saving and spending in equal measure
  • -TangleFoot-
    -TangleFoot- Posts: 4,673 Forumite
    Part of the Furniture Combo Breaker
    This may shed some light on the matter.
  • when running anti virus and spyware removal software it's always best to do so from Safe Mode

    getting rid of Zlob & Smitfraud - Vista ONLY
    grab this http://www.malwarebytes.org/rogueremover.php save this to desktop rr-free-setup.exe update immediately, and scan, just follow instructions

    run hijackthis again and post log.
  • -TangleFoot-
    -TangleFoot- Posts: 4,673 Forumite
    Part of the Furniture Combo Breaker
    getting rid of Zlob & Smitfraud - Vista ONLY
    What makes you think they're responsible? This stuff could have been put there by SpyBot for all we know!
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    This may shed some light on the matter.


    It shed so much light I couldn't even understand it!

    I did think that the Spyhunter app may have just put stuff there.

    Do you think its safe to delete all the junk in Escdomains?
    Saving and spending in equal measure
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    when running anti virus and spyware removal software it's always best to do so from Safe Mode

    getting rid of Zlob & Smitfraud - Vista ONLY
    grab this http://www.malwarebytes.org/rogueremover.php save this to desktop rr-free-setup.exe update immediately, and scan, just follow instructions

    run hijackthis again and post log.

    They no longer run it seperate, it just advises to use Mal Bytes.

    I'll try run Mal Bytes in safe mode and see what it finds.

    Did you see some iffy stuff in my last Hijackthis log?
    Saving and spending in equal measure
  • -TangleFoot-
    -TangleFoot- Posts: 4,673 Forumite
    Part of the Furniture Combo Breaker
    0james0 wrote: »
    I did think that the Spyhunter app may have just put stuff there.
    Possible, but unlikely. I suspect they're all false positives. Y'see, the likes of Spybot and SpywareBlaster incorporate a sort of vaccination capability: they add a long list of nasty web addresses to Internet Explorer's Restricted Sites list, so that should you accidentally visit one you'll be moderately well protected from any gremlins that reside there. Some anti-malware applications notice these blacklisted addresses and assume that their presence is a Bad Thing. Frankly, I think you'd be better off removing SpyHunter instead. It has a rather unsavoury reputation.

    If you want to remove them regardless, you should be able to do so from within Internet Explorer.
  • What makes you think they're responsible?
    #I took his words literally "Result of a Zlob Trojan apparently "

    it's why I asked for a fresh log to be posted, no point in reading a log that has already been worked on. haven;t seen zlob on a pc for over a year.
  • forget Spy Hunter, it's shareware at best

    try either of these, use free versions only
    http://download.cnet.com/Advanced-SystemCare-Free/3000-2086_4-10407614.html

    http://download.cnet.com/SuperAntiSpyware-Free-Edition/3000-8022_4-10523889.html

    and try Firefox with the addons Noscript and ADBlock Plus instead of IE.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.