Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 How to remove " I HATE MODZILLA " spyware?

views
     
TSvladimir
post Oct 4 2007, 10:27 AM, updated 19y ago

MYHYPERSTORE ONLINE TRADER
****
Senior Member
639 posts

Joined: Oct 2004
From: NEW GENERATION ONLINE STORE



I dont know whether is Virus or Malware or spyware...but i need u guys help... my whole office got this problem prompt out ..



Attached Image


pls help thx!!!


edan1979
post Oct 4 2007, 10:37 AM

*GruMpy_MoDe*
*******
Senior Member
5,511 posts

Joined: Jun 2006
From: On Earth.



aha... meet this thing recently and this is what i do...

1. Press CTRL+ALT+DEL and go to the processes tab
2. Look for svchost.exe under the image name. There will be many but look for the ones which have your username under the username
3. Press DEL to kill these files. It will give you a warning, Press Yes
4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
5. Now open My Computer
6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
7. Delete all the files here
8. Now go to Start --> Run and type Regedit
9. Go to the menu Edit --> Find
10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
11. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
12. Now close the registry editor.
lamely_named
post Oct 4 2007, 10:45 AM

I got younger. ROLLZ.
******
Senior Member
1,931 posts

Joined: Jan 2003
From: Human Mixbreeding Farm
QUOTE(edan1979 @ Oct 4 2007, 10:37 AM)
aha... meet this thing recently and this is what i do...

  1. Press CTRL+ALT+DEL and go to the processes tab
  2. Look for svchost.exe under the image name. There will be many but look for the ones which have your username under the username
  3. Press DEL to kill these files. It will give you a warning, Press Yes
  4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
  5. Now open My Computer
  6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
  7. Delete all the files here
  8. Now go to Start --> Run and type Regedit
  9. Go to the menu Edit --> Find
  10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
  11. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
  12. Now close the registry editor.
*
nothing like good old instruction from former victims.

works better than most help.

smile.gif
TSvladimir
post Oct 4 2007, 11:30 AM

MYHYPERSTORE ONLINE TRADER
****
Senior Member
639 posts

Joined: Oct 2004
From: NEW GENERATION ONLINE STORE



after deleted the hidden files ..

when search the regedit .. it seems doesnt have this : "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"

but we have the normal C:\heap41a
lamely_named
post Oct 4 2007, 11:35 AM

I got younger. ROLLZ.
******
Senior Member
1,931 posts

Joined: Jan 2003
From: Human Mixbreeding Farm
QUOTE(vladimir @ Oct 4 2007, 11:30 AM)
after deleted the hidden files ..

when search the regedit .. it seems doesnt have this : "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"

but we have the normal C:\heap41a
*
that's ok, sometimes the virus will not drop certain file that it's suppose to drop, no idea why. Lauzy coding perhaps.


TSvladimir
post Oct 4 2007, 11:52 AM

MYHYPERSTORE ONLINE TRADER
****
Senior Member
639 posts

Joined: Oct 2004
From: NEW GENERATION ONLINE STORE



QUOTE(lamely_named @ Oct 4 2007, 10:35 AM)
that's ok, sometimes the virus will not drop certain file that it's suppose to drop, no idea why. Lauzy coding perhaps.
*
okok tenkiu big bro~! all bros helped me owe u a teh tarik!

 

Change to:
| Lo-Fi Version
0.0168sec    0.21    6 queries    GZIP Disabled
Time is now: 6th December 2025 - 07:22 AM