1
   

[OLD] Spyware, Browser Hijacks, Yuckware? Check here 1st

 
 
Reply Mon 22 Mar, 2004 05:54 pm
IMPORTANT: THIS TOPIC SHOULD BE CONSIDERED INFORMATION ONLY; CURRENT YUCKWARE REMOVAL TIPS MAY BE FOUND HERE



Update: See also THIS TOPIC and THIS TOPIC

Please start a new topic if you need further help. Don't post your help request to this thread, or to an existing help thread. There's no other way to keep things sorted out and provide for individual attention



Yuckware ... viruses, trojans, worms, browser hijackers, spyware, redialers, and the like ... has become one of the biggest problems on the internet. Removing it from your computer will be quite a bit more time consuming than putting it there was. We'll be glad to help, if you'll take the time and effort to go through all the following steps first. Please read, understand, and follow this list ... it is the starting point for yuckware removal, and in most cases will do the trick all by itself!!!

Do ALL of this, don't skip over anything. Every step is necessary, and the order in which they are performed is important to the success of the plan. This process will call for you to find and delete some things and to download and install a variety of updates and/or applications, in a particular order, and to execute certain of the applications in a particular order. If done as detailed, none of this will harm your system. If any step is skipped, or performed out of order, the desired fix likely will not be achieved. Please read, understand, and be prepared to exactly follow these instructions before beginning. If you have any questions, feel free to ask before taking any chances. Know what you're going to have to do before you start to do it. If you do have questions, it is best to open a new topic with your particular concern rather than asking on this thread - you're more likely to get attention that way.

Note: the bold, italicized, underlined blue items are links that will take you to the appropriate pages for necessary downloads and/or instructions. Just click on them to get to where you have to go. Save all downloads to separate, appropriately named folders on your desktop or to your root drive as directed. To create a folder on your dektop, just right-click on any area of the desktop not occupied by icons, select "New>Folder", then type a distinctive, decriptive name in the highlighted box beneath the icon for the folder that will appear as "New Folder"on your desktop. To create a folder on your root drive, open "My Computer", select your root dive - the drive on which Windows resides (usually "C:\") - go to the toolbar, select "Files", select "New", select "Folder", and name the folder accordingly.

First, if you are using WinME or XP, DISABLE SYSTEM RESTORE!
When ALL the following have been done, re-enable it by following the same instructions, and replacing the checkmark you removed. Doing any of the rest of this with Restore enabled likely will be useless. Note: You will lose your saved restore points when you do this.

Now, look for "TwainTech" , one of the most common hijackers, and if its on your system, get rid of it. Go to Start>SETTINGS>CONTROL PANEL>ADD/REMOVE PROGRAMS, and look for a program named "twain-tec", "TwainTech", or some close variant. If its there, click ADD/REMOVE and confirm you want to uninstall it.

If there is no entry entry in ADD/REMOVE PROGRAMS, it still may be there. Assume it is, and do the following:

For Win95, Win98 and WinXP users:

a) To permanently disable the software click "Start" and then "Run" and type the following command which unregisters the software:

regsvr32 c:\windows\twaintec.dll
(Note: Be sure to include the space between "regsvr32" and "c:\windows")

You then should see a confirmation the operation was successful, or a notification " ... The specified module could not be found". In either case, move on as appropriate.

b) To completely remove the software: reboot and then go to Sart>Run>Search>For Files and Folders, enter "xtarget.dll" (without the quotes), and click "Find (or Search) Now". It will take a while, but wait untill either it finds the file, or says "There are no files to display". If found, right-click on the file, then select-and-confirm delete. Find-and-delete any other files or folders with "twaintec" or "xtarget" in the name.
Don't delete "Twain" files or folders ... just "TwainTech", "twain-tec", or very similar variations. The "Twain" files and folders are needed by your camera or scanner.

For Win2K, WinME and WinNT users:

a) To permanently disable the software click "Start" and then "Run" and type the following command which unregisters the software:

regsvr32 c:\winnt\twaintec.dll
(Note: Be sure to include the space between "regsvr32" and "c:\winnt")

You then should see a confirmation the operation was successful, or a notification " ... The specified module could not be found". In either case, move on as appropriate.


b) To completely remove the software: reboot and then Find and Delete the file twaintec.dll, and find-and-delete any other file or folder with "twaintec*" (without the quotes, but include the *) in its name. Reboot.

Next, in your browser's toolbar, select Tools>Internet Options>Delete Files>Apply>OK. Then, empty your recycle bin. Next, go to Windows Update[/i] and fully update your Windows and your browser. If you primarily use a browser other than Internet Explorer, be sure it too is fully updated.

Then, download and run the latest version of Network Associate's free STINGER before doing anything else.

Next, update your own antivirus program to the latest files, and run a full system scan. If you don't have a currently subscribed antivirus, a few free ones are available, such as Trend Micro's HOUSECALL , Panda's Active Scan, Grisoft's AVG Free[/i][/u], or Symantec's Security Check Free Virus Scan, among others. Whatever you use, do a full system scan, and follow any repair or removal instructions to the letter.

When ALL those steps have been accomplished, download CoolWWWSearch.SmartKiller removal tool and
CWSHREDDER. Note: These files are perfectly safe, and will not harm your system. Save each to your desktop, into separate, dintinctively named folders you will be able to locate easily.

If you are running Win 95 or 98, you'll need a zip utility to extract the files. If you're running Win ME, 2K, or XP, a zip utility is unneeded. Install the apps and run them, CoolWWWSearch.SmartKiller removal tool FIRST, then CWSHREDDER, letting them fix whatever, if anything, they find.

Next, download and install both
Spybot S&D and AdAwareSE , but DO NOT RUN THEIR SEARCHES untill you have opened each one and updated it using its web update function, as explained in the help file for each.

When both products have been updated, disconnect from the internet and reboot your machine into safemode. If you are running Win95, Win98, or some versions of WinME, and customarily use a USB keyboard and/or mouse, you will need to substitute a standard PS2 Keyboard and/or mouse for the rest of this procedure, as the USB devices will not be recognized. If you are running any version of XP, thiat will not be a consideration. On most systems, you can enter safemode from a reboot by tapping F8 as soon as the machine begins to boot up, before any other screen appears. You may hear a beeping noise, and/or see a "Keyboard Error" message. Ignore them and keep tapping. You should soon be presented with a black-and-white boot choice screen. Select the #3 option, "Safe Mode", either by typing the numeral 3 or by using the up/down arrows of your keyboard, and hit enter. Your machine will boot up with only the barest necessities, and no background applications, running. Your display will probably look very different. Ignore that. If the F8 method does not work, another possibility is to tap, or sometimes to hold down, the "Esc" key as soon as the system begins to boot. If methods don't work for you, consult the User Support documentation that came with your machine or as available on the website of its manufacturer.

Once in Safemode, go to Start>Programs>LavaSoft AdawareSE>AdawareSE.exe . When it opens, select "start" from its splashpage and let it run to completion. It may take quite a while. When it has finished, let it "Fix" anything it has found.

Now, go to Start>Programs>Spybot Search and Destroy, and open it. Select "Immunize" , then click "Install". Then select "Permanently running bad download blocker for Internet Explorer", and click "Install". DO NOT place checks in any of the three "Recommended miscellaneous protections" panel at this time. Now, select "Search and Destroy", then select, down at the bottom of the page "Search for problems". Let it run to completion, which also may take quite a while, and let it "Fix" anything it finds. Run it one more time. It should find nothing.

Once again, empty your recycle bin, then, while still in safemode, defragment your drive. That too will likely take quite a while.

Now, open a browser (If necessary, choose "Work off line" and pay no attention to the "Cannot Display Page" message, and, from the browser's toolbar, select Tools>Internet options, and on the General, Security, and Privacy tabs, select the defaults and apply, then click "OK" and close the browser.

Finally, reboot normally. Before doing any other browsing, messaging, chat, email checking or downloading, run HijackThis with no other browsers open or apps running, and save the log.

Now go out on the web as you normally would, being careful what you click on. DO NOT reactivate System Restore unless and untill your machine is behaving properly.

If you insist on things like opening attachments from unknown senders, hooking yourself up with "Exciting Free Browser Add-Ons", "Incredible Search Enhancers", or any other "Amazing Helpers", P2P file sharing, Porn, and surfing without up-to-date security and privacy software, you're on your own. If not, and you're still having problems, start a new topic in The Computers Forum, detailing exactly what you did, what the results were, and paste your Hijack This log into your post.

Remember, do everything listed, in the order listed, and please start a new thread if you need further help. Don't post your help request to this thread, or to an existing help thread. There's no other way to keep things sorted out and provide for individual attention.

Edited occasionally to update links and/or info as needed
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 47,261 • Replies: 64
No top replies

 
pueo
 
  1  
Reply Mon 22 Mar, 2004 05:59 pm
hey there timber, bookmarking.
0 Replies
 
colorbook
 
  1  
Reply Mon 22 Mar, 2004 06:46 pm
I'm bookmarking too.
0 Replies
 
husker
 
  1  
Reply Mon 22 Mar, 2004 07:13 pm
holy icecube - how long does it take to do all that?
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 07:26 pm
Thanks Timber, I'm going to get right on it, I'll let you know husker.
0 Replies
 
timberlandko
 
  1  
Reply Mon 22 Mar, 2004 07:26 pm
husker wrote:
holy icecube - how long does it take to do all that?


Prolly oughtta set aside at least a whole day, or maybe a couple evenings ... a pretty stiff price to pay for a problem likely brought on by a single mouse-click and/or inattention to updates and security, but its what it takes. Consider it a learning experience.
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 08:16 pm
I have already reached an impass. Although I can see 'twain' folders in my program files the twaintec.dll is not pulling anthing up.
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 08:24 pm
If I delete the folders do I screw up the registry?
0 Replies
 
timberlandko
 
  1  
Reply Mon 22 Mar, 2004 08:44 pm
Don't delete "Twain" folders ... just "TwainTech", "twain-tec", or very similar variations. The "Twain" folders are needed by your camera or scanner ... and if you're uncertain, leave 'em. I guess I'd better make that clear in the above instructions. Glad you spotted it.
0 Replies
 
Monger
 
  1  
Reply Mon 22 Mar, 2004 08:53 pm
Also Ceili, entering... regsvr32 c:\windows\twaintec.dll ...in the Start->Run box isn't necessarily going to bring anything up that you can see, even if you've got the twain-tech stuff on your system, and if any of the files mentioned don't exist on your PC, don't sweat it. It just means you have one less thing to deal with.

Quote:
If I delete the folders do I screw up the registry?

Deleting folders mentioned above will not cause any registry problems.
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 10:50 pm
Thanks, one more question if I may...
I already have spybot and adaware on the computer. How does this change the procedure, or do I just get the update?
0 Replies
 
timberlandko
 
  1  
Reply Mon 22 Mar, 2004 10:53 pm
Just update 'em. That should work fine. How ya comin along' otherwise? Anything else not clear?
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 10:59 pm
I'm slogging through, I'll back to you. I'm kinda of computer dyslexic so this might take a while, thanks for standing by so far.
0 Replies
 
Ceili
 
  1  
Reply Mon 22 Mar, 2004 11:18 pm
I'm slogging through, I'll back to you. I'm kinda of computer dyslexic so this might take a while, thanks for standing by so far.
0 Replies
 
Tomkitten
 
  1  
Reply Tue 23 Mar, 2004 03:38 pm
Yuckware
OK, Timberlandko, I'm bookmarking too. Thanks!
0 Replies
 
freakymom
 
  1  
Reply Mon 5 Apr, 2004 08:14 pm
timberlandko great advice, but still need help
Hi timberlandko, thank you for the Yuckware, etc help. This is the first time I have ever posted to site and am challenged!! I want to post my final highjack this log to a new thread, but not knowing all the lingo, I am not sure if this means a "new post" or if I'm suppose to head somewhere else! Help! Defraging my computer helped with the speed, however, I'm still having a problem when I shut down. When shutting down, I get a window stating, "Program not responding" message even though I have nothing open (to my knowledge). And to make matters worse, it doesn't indicate what program. I select end "end not" and it hangs for quite awhile, then the window dissappears as does my desktop (with the exception of the clouds background) and hangs for several seconds, then shuts down.

Prior to you troubleshooting advice, I would get 2 or 3 of those messages before it would shut down.

So, how do I start a new thread to post my hijackthis log?

Thanks so much for your help.
0 Replies
 
timberlandko
 
  1  
Reply Mon 5 Apr, 2004 08:44 pm
freakymom wrote:
So, how do I start a new thread to post my hijackthis log?


Find and click the nearest http://www.able2know.com/forums/templates/Able2Know/images/lang_english/post.gif button (even this one ... it'll work), give your topic a distinctive title (something a little more descriptive than "Help", or "Highjack This Log" would be good) in the "Subject" box ... a few words will do, and besides, that's all that will fit there.
In the body of your message, describe the problem you're having, what, if any, steps you've taken to try to solve it, and what, if anything, those steps accomplished. Then paste in your log, click "Submit", and somebody will be along to look at it before too long. Be patient ... might take a few hours or even a day or so, but somebody will check it out and post a reply to your thread. Check back from time to time; even bookmark it or add it to your browser's "Favorites" to make it easy to find when you want it. You can also turn on email updates for a topic by clicking the "Turn on email updates" link down at the bottom right of each page in that topic's threads.

BTW ... I doubt shutdown problems are directly yuckware related, but we'll see what we can do about those, too. And welcome to A2K. Glad you found us; hope you like it enough here to stick around and chime in on the discussions that interest you once in a while.
0 Replies
 
K e v i n
 
  1  
Reply Mon 5 Apr, 2004 09:13 pm
thanks, I'm bookmarking
0 Replies
 
rappyjuno007
 
  1  
Reply Sun 11 Apr, 2004 09:19 pm
It doesn't work
Ok, I followed your steps for removing twaintec exactly, or so I think. I disabled system recovery, did the run prompt, searched for twaintec and tried to delete it. But I keep getting the error message:

Quote:
Cannot delete twaintec: Access is denied.

Make sure the disk is not full or write-protected and that the file is not currently in use.


What should I do? Thanks in advance!
0 Replies
 
timberlandko
 
  1  
Reply Sun 11 Apr, 2004 09:45 pm
Have you attempted to delete the file while in safemode? If not, give that a shot. Also, did you unregister the software with regservr?
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » [OLD] Spyware, Browser Hijacks, Yuckware? Check here 1st
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 04/19/2024 at 09:39:22