Lowyat.NET Forums

Welcome Guest ( Log In | Register )

 
RSS feedBump TopicReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> How to remove " I HATE MODZILLA " spyware?

vladimir
post Oct 4 2007, 10:27 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #1


:: ONLINE TRADER ::
****

Group: Senior Member
Posts: 614
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Oct 2004
From: ONLINE STORE






I dont know whether is Virus or Malware or spyware...but i need u guys help... my whole office got this problem prompt out ..



Attached Image


pls help thx!!!

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
edan1979
post Oct 4 2007, 10:37 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #2


n00b you are
*****

Group: Senior Member
Posts: 906
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jun 2006
From: Somewhere Over The Rainbow






aha... meet this thing recently and this is what i do...

1. Press CTRL+ALT+DEL and go to the processes tab
2. Look for svchost.exe under the image name. There will be many but look for the ones which have your username under the username
3. Press DEL to kill these files. It will give you a warning, Press Yes
4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
5. Now open My Computer
6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
7. Delete all the files here
8. Now go to Start --> Run and type Regedit
9. Go to the menu Edit --> Find
10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
11. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
12. Now close the registry editor.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lamely_named
post Oct 4 2007, 10:45 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #3


I got younger. ROLLZ.
******

Group: Senior Member
Posts: 1,931
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: Human Mixbreeding Farm




QUOTE(edan1979 @ Oct 4 2007, 10:37 AM)
aha... meet this thing recently and this is what i do...

  1. Press CTRL+ALT+DEL and go to the processes tab
  2. Look for svchost.exe under the image name. There will be many but look for the ones which have your username under the username
  3. Press DEL to kill these files. It will give you a warning, Press Yes
  4. Repeat for more svchost.exe files with your username and repeat. Do not kill svchost.exe with system, local service or network service!
  5. Now open My Computer
  6. In the address bar, type C:\heap41a and press enter. It is a hidden folder, and is not visible by default.
  7. Delete all the files here
  8. Now go to Start --> Run and type Regedit
  9. Go to the menu Edit --> Find
  10. Type "heap41a" here and press enter. You will get something like this "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"
  11. Select that and Press DEL. It will ask "Are you sure you wanna delete this value", click Yes
  12. Now close the registry editor.
*



nothing like good old instruction from former victims.

works better than most help.

smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
vladimir
post Oct 4 2007, 11:30 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #4


:: ONLINE TRADER ::
****

Group: Senior Member
Posts: 614
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Oct 2004
From: ONLINE STORE






after deleted the hidden files ..

when search the regedit .. it seems doesnt have this : "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"

but we have the normal C:\heap41a
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lamely_named
post Oct 4 2007, 11:35 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #5


I got younger. ROLLZ.
******

Group: Senior Member
Posts: 1,931
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: Human Mixbreeding Farm




QUOTE(vladimir @ Oct 4 2007, 11:30 AM)
after deleted the hidden files ..

when search the regedit .. it seems doesnt have this : "[winlogon] C:\heap41a\svchost.exe C:\heap(some number)\std.txt"

but we have the normal C:\heap41a
*



that's ok, sometimes the virus will not drop certain file that it's suppose to drop, no idea why. Lauzy coding perhaps.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
vladimir
post Oct 4 2007, 11:52 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #6


:: ONLINE TRADER ::
****

Group: Senior Member
Posts: 614
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Oct 2004
From: ONLINE STORE






QUOTE(lamely_named @ Oct 4 2007, 10:35 AM)
that's ok, sometimes the virus will not drop certain file that it's suppose to drop, no idea why. Lauzy coding perhaps.
*



okok tenkiu big bro~! all bros helped me owe u a teh tarik!
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Bump TopicReply to this topicTopic OptionsStart new topic
 

Lo-Fi Version Time is now: 10th February 2010 - 02:25 AM
All Rights Reserved 2003-2009 Vijandren Ramadass (~living on a prayer~)