Jump to content
xisto Community
Sign in to follow this  
feipoh

Spyware- How Do I Remove These Spyware?

Recommended Posts

I scan my laptop and found these.. Can anyone tell me how to remove them manually, please? Thank you.



Registry keys recognized:
=========================

[eSpyNow]
HKEY_CLASSES_ROOT\xzipper30.xzipper

[GAIN]
HKEY_USERS\.default\software\microsoft\systemcertificates\trustedpublisher\ctls

[GAIN]
HKEY_USERS\.default\software\microsoft\systemcertificates\trustedpublisher\crls

[iETop100]
HKEY_CURRENT_USER\Software\NJStar\NJStar Asian Explorer\Settings

[iETop100]
HKEY_CURRENT_USER\Software\NJStar\NJStar Asian Explorer\IDNS

[iETop100]
HKEY_CURRENT_USER\Software\NJStar\NJStar Asian Explorer\_Toolbar-Summary

[iETop100]
HKEY_CURRENT_USER\Software\NJStar\NJStar Asian Explorer

[iETop100]
HKEY_CURRENT_USER\Software\NJStar

[Remote Password Stealer]
HKEY_CURRENT_USER\SOFTWARE\ESELLERATE

[Remote Password Stealer]
HKEY_CURRENT_USER\SOFTWARE\ESELLERATE\AFFILIATES

[Remote Password Stealer]
HKEY_LOCAL_MACHINE\SOFTWARE\ESELLERATE

[Remote Password Stealer]
HKEY_LOCAL_MACHINE\SOFTWARE\ESELLERATE\AFFILIATES

__________________________________________________


Notice from BuffaloHELP:
Use QUOTE bbcode for all copied material

Share this post


Link to post
Share on other sites

Top Manual Spyware Removal:*Windows XP users ONLY! I do not have access to a Windows ME or lower computer to test my methods for a guide
(This method does NOT remove ALL spyware. Just some. Use at your own risk)
1) Open My Computer (Pressing Window* + E also opens this)
*Window key is the little picture of a window on your keyboard
2) Click into your main drive (For this tutorial we are using Local Drive C:/)
3) Open Documents and Settings
4) Open your User Folder
4a. My computer consists of the following folders: Administrator, All Users, Default User, Family, LocalService, Matt, NetworkService, and The Kids.
4b. For my computer I would click on Matt
5) Once in the folder, open the folder called Cookies
6) Delete all the .txt files in the folder, which is all of them except index.dat
6a. This will cause auto-login's and other convenient web site features to disable the first time you go on a site. So make sure you know your password and username so you can come back on
7) Click the Back button to get back to your user folder.
8) Open the folder called Local Settings
8a. Some of you may not be able to see this folder. This is because it is hidden, follow the next steps to show it.
8b. Click Tools up at the top of the screen
8c. Click Folder Options
8d. Click the View tab
8e. Scroll down to Hidden Files and Folders and check the dot that says Show Hidden Files and Folders next to it
8f. Click Apply, then Ok and proceed to step 9.
9) Open the Temp folder
10) Delete all the files in the Temp folder. (Some may be in use, just delete the ones around them)
11) Click the Back button and get back to the Local Settings folder
12) Open the Temporary Internet Files folder
13) Delete all the files in the Temporary Internet Files
14) Repeat steps 4 through 13 for ALL user folders
15) Close out Explorer and you are done!


I got this from a very trusted site. I hope it helps!

Share this post


Link to post
Share on other sites

don't you have an anti-spyware that you have to remove it? i'm asuming thats how you scanned your computer. otherwise try googling it and see the proper ways to go around removing them. but wow thats a lot of spyware! do you update and scan with a anti-spyware agent regularly?

Share this post


Link to post
Share on other sites

Our Computer in my laboratorium is infected by DODOL.This virus is copied the infected folder and sometimes it make the computer restart automatically.Can anyone tell me how to remove them manually, please? Thank you................................. :):):rolleyes::rolleyes:

Share this post


Link to post
Share on other sites

Like randomdood asked, don't you have some type of spyware program to help your remove these?If you don't and want something free, Spybot Search and Destroy is always a good bet. Free download, pretty good program for removing spyware. I use Counterspy, it is a $19.99 program that you can download and then just activate. It does an amazing job scanning and finding all types of spyware. They claim they find up to 99.9% of all internet spyware. Typically there are daily updates that download automactically each time I turn on my computer that keeps me up to date. A very good option if you want something to make all your spyware worries go away.

Share this post


Link to post
Share on other sites

To remove manually, you would use REGEDIT command.

 

Run REGEDIT and search for those key values. As you can see, you can look for them according to a registry value. Just scroll down until you find the exact one.

 

But the problem may be even deeper. Although you can remove those registry values, if a spyware is still present in your system the next reboot can cause it to reappear again. This is a normal practice for majority of spyware--since it took a hard/easy try to get into your system, it will hide itself and multiply if one of its clones gets somehow deleted.

 

You can find out where the actual program could be located. When you find a registry value that you're looking for you can right click on the registry value and see its property. Sometimes you get lucky and see the full path where this registry value is calling an executable file. You should delete that file and then work on your registry.

 

CAUTION! Attempting to edit your registry file can cause your computer not to work properly. Always backup your registry before beginning anything and if you're not comfortable editing registry do not attempt it at all.

Share this post


Link to post
Share on other sites

To remove manually, you would use REGEDIT command.

 

Run REGEDIT and search for those key values. As you can see, you can look for them according to a registry value. Just scroll down until you find the exact one.

 

But the problem may be even deeper. Although you can remove those registry values, if a spyware is still present in your system the next reboot can cause it to reappear again. This is a normal practice for majority of spyware--since it took a hard/easy try to get into your system, it will hide itself and multiply if one of its clones gets somehow deleted.

 

You can find out where the actual program could be located. When you find a registry value that you're looking for you can right click on the registry value and see its property. Sometimes you get lucky and see the full path where this registry value is calling an executable file. You should delete that file and then work on your registry.

 

CAUTION! Attempting to edit your registry file can cause your computer not to work properly. Always backup your registry before beginning anything and if you're not comfortable editing registry do not attempt it at all.


Try Spybot search and destroy and Lavasoft Ad-aware. I this softwares to get rid of spywares and adwares...

 

By the way this softwares are free..

Share this post


Link to post
Share on other sites

Use webroot spysweeper or ad aware . Use need to use at least 2 or 3 anti spyware programs one by one for effective removal. If on windows xp u may download windows defender too. No one spyware program removesa ll spyware. But a combination is excellent.

Share this post


Link to post
Share on other sites

I use a combo of Adaware and AVG free 7.5 to get all viruses and spyware out of my pc. However, I haven't had many at all so I just use it in rare cases.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×
×
  • Create New...

Important Information

Terms of Use | Privacy Policy | Guidelines | We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.