AlphaOmega 0 Posted May 15, 2006 Share Posted May 15, 2006 Ok, sorry about the repeat thread earlier in the day, basically I was hacked, lost money, yatta yatta yatta, and I lost my "coo," neglecting to use the search function in my delirium.So I've basically spent the whole day trying to quarantine and delete the spyware and stuff that is allowing someone to control my computer. I did a free scan from NoAdware.net, and they are finding something that is very similar to the malicious program that 2+2 was all over. It's different though, and I'm wondering if any experienced computer person can distinguish this program, and if it's useful to my system or what's causing this whole mess. The item description is entitled: "Severe," - allows hackers unauthorized access to your computer.Incidently, I was checking my firewall settings and my firewall was turned off (It's been on throughout the day, I've been checking). I know I didn't do it.The thing is called:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NPFNot exactly the same thing as what the 2+2 thread said to look for. I looked inside and I found something similar to what the thread said to look for, but not exactly the same:Name______________Type______________________Data ImagePath_________REG_EXPAND_SZ__________system32\drivers\npf.sysForgive me if this is stupid, because I know that the thread said that file names will be similar to critical programs. It's just that this NoAdware.net scan is showing me that I'm still critically infected, and I'm having to manually keep my firewall turned on. This is kinda scary.I guess there are a couple things we could check. My brother, a more experience comp person than I am, said it was possible that the NoAdware.net was making up the file so that I would buy their product (it gives a free scan, but you have to purchase it to delete stuff) So if someone could get the scan to verify if it's saying everybody has it, that would help. A safer alternative might be to just check your computer by going to START>RUN> then type in "regedit." From there, you can drop the folders and see if you can't find the file I've found. If someone who has an uninfected computer found this file I guess that would be good news for me.I'm out of ideas at this point, and I really suck with computers. I'm kind of scared to leave my computer because I don't want my firewall to turn off.Thanks in advance for your help. This has been a very tough day for me. Link to post Share on other sites
No_Neck 0 Posted May 15, 2006 Share Posted May 15, 2006 honestly I would back up all your files and format/reinstall everything. or get zonealarmwww.zonelabs.com Link to post Share on other sites
Jerry 0 Posted May 15, 2006 Share Posted May 15, 2006 I am no Internet expert, but if something is turning your firewall off something needs to be done.May I suggest some internet porn to turn it on again.- Jerry Carmichael Link to post Share on other sites
doubleatrain 0 Posted May 15, 2006 Share Posted May 15, 2006 I'd suggest trying a site with a forum that reads/analyzes HijackThis logs. One that I've been to (though tons exist, I'm sure) was http://www.geekstogo.com I had some adware/spyware issues that they got to the bottom of after not too long. The site explains everything that you have to do to get started, but you send in a log of all running processes and they tell you what shouldn't be there and how to get rid of it. It's all people who donate their time and they seem to be trustworthy.Hope that helps! Link to post Share on other sites
L. Ron Hubbard 0 Posted May 15, 2006 Share Posted May 15, 2006 Have you tried a thetan scan yet? Link to post Share on other sites
HangukMiguk 8 Posted May 15, 2006 Share Posted May 15, 2006 Have you tried a thetan scan yet?I heard it's about as useful as a cattle prod up the pooper. Link to post Share on other sites
stevedar 0 Posted May 15, 2006 Share Posted May 15, 2006 try ewido anti-malware...it works before startup so it can remove some things that some others can't...it's found all kinds of stuff other scanners missed for me Link to post Share on other sites
DanielSon 0 Posted May 15, 2006 Share Posted May 15, 2006 Just go into your registry and delete it. Run spyware doctor and it will show you all the infections as well, but won't let you delete unless you purchase. If you don't want to purchase, just delete manually, no biggie Link to post Share on other sites
AlphaOmega 0 Posted May 15, 2006 Author Share Posted May 15, 2006 Just go into your registry and delete it. Run spyware doctor and it will show you all the infections as well, but won't let you delete unless you purchase. If you don't want to purchase, just delete manually, no biggieThe problem is that a whole folder is coming up as the source. I don't think it's a good idea to delete everything in the registry. It's likely the trojan, or whatever, just planted the malicious software in that folder somewhere, along with other things that are useful to the operation of my computer. Link to post Share on other sites
FCP Bob 1,321 Posted May 15, 2006 Share Posted May 15, 2006 The problem is that a whole folder is coming up as the source. I don't think it's a good idea to delete everything in the registry. It's likely the trojan, or whatever, just planted the malicious software in that folder somewhere, along with other things that are useful to the operation of my computer.My advice AlphaOmega is to find a reliable computer services company local to you and bring them your computer for servicing. Link to post Share on other sites
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now