Windows XP IE8 SVC pack 3
How to get rid of please. I have tried Hijackthis,combofix, disinfectant etc, etc but I still have it.
Perhaps it needs to be removed manually???
RonB
Ron..
Did you scan with Malwarebytes' Anti-Malware? If you're having a problem with Trojan.DNSChanger, it should help. Try scanning with it, and do the same with SUPERAntiSpyware FREE Editon in safe mode. They are both free. If neither help, in lieu of trying to delete it manually, I would suggest posting your logs at one of the forums which analyze them. Here's a couple:
http://www.malwarebytes.org/forums/index.php?showforum=7
http://www.bleepingcomputer.com/forums/forum55.html
Best of luck..
Carol
Thanks Carol, I have posted my request on the Malwarebytes forum you suggested. if I get any solution I will pass it on in case you have the same problem later on.
Cheers for now,
RonB
..a link to someone else that received assistance in removing the same problem.. Did you try the steps in that thread? Here it is again:
http://forums.techguy.org/malware-removal-hijackthis-logs/823827-cannot-remove-gxvxccounter-browser-hijacked.html
Hope this helps.
Grif
Grif,
I tried to download combofix to my desk top a little screen opened and told me I could not rename combo fix and to use another name using only alph characters. There wasn't any further activity from the programme so I got stuck. I tried to download again but no go. I had turned off my AVG and was raring to go!
Damned nuisance. Abny ideas pleasse?
RonB
cos here you have 2 anti-rootkit applications, desgined for the soul purpose or weeding out rootkits. yeh well alpha characters are a-z in case you didnt realise. good luck with your "spyware" problem anyhow.
Since yours is infected, use a separate, clean computer to download the file.. Once it's on the desktop of the clean computer, rename it to something like gogetum.com, then copy it to a CD or flash drive and transfer it to the infected computer.
Hope this helps.
Grif
Thanks Grif for that. Unfortunately I don't have another computer so that won't work. I have been in touch with a computer guru who is coming round on Friday to try and remove the trojan and if that fails he will reformat my HD and I will do a reinstall of of my programmes. If that is the case, at least I will be rid of it permanently and I will have a clean HD.
I would like to get my hands on the clown who designed this trojan and sent it to me in the first place, it's caused nothing but hassle and problems.
Thanks for all your help and advice, I do appreciate it.
Best wishes,
RonB
I'm surprised no one else thought of this, but I downloaded combofix.exe and renamed it to Griff's suggestion of "GoGetUm.exe". I uploaded it to box.net, a free file sharing service. You have to trust me, of course, so that's up to you. But if you check my history, I think I deserve it.
So, if interested in the renamed combofix.exe, get it here:
http://www.box.net/shared/pmkmupqy95
You'll see that it is renamed to "GoGetUm.exe", and it's the latest version of Combofix (as of June 3 2009) directly from BleepingComputer.com.
Good luck.
Hi,
Thanks a million, if you were close by, I would buy you a large whisky, it worked and the Trojan has gone. Combofix found two drivers and two .dll files all starting with gxvxc which it deleted. I now have my computer back thanks to you.
Glad to help, but also run Malwarebytes again just to be sure. And as usually the case, these help sessions are the result of group efforts. It was Griff's suggestion that led me to uploading the renamed file. I actually like having it handy, now, in case I ever need it! Box.net is good that way.
Good luck!
Be sure to toggle OFF your System Restore and then toggle it back ON. Why? Because it will dump all the old restore points, which still contain references to the trojan. And then it will create a new restore point for your freshly cleaned system.
Steps: http://support.microsoft.com/kb/310405
It's OK, I have just turned it off and back on again using the M'soft Guided Instructions.
Oh dear!, I forgot to toggle off my Restore Point! I assume that if I make a new one on the 4th that will be alright? I certainly wouldn't want to restore back before the 3rd!
| Forum legend: | |
| Locked thread | |
| Moderator | |
![]() |
CNET staff |
![]() |
Samsung staff |
| Norton Authorized Support team | |
| AVG staff | |
| Windows Outreach team | |
![]() |
Dell staff |
| Intel staff | |