|

List Home > Spam Alerts / Anti-Spam > [ Post New Problem ]
Welcome back !
| TrackingID : | 4806 |
| Posted : | Tuesday, July 26th, 2005 10:31:33 AM |
| By : | derick2 |
| adware | Configuration: |
Is ADW.BADBITOR.A adware? TRendMicro dtects it all the time. I delete but keeps coming back.
Additional Comments: Details on TRendMicro web page but did not find any of these files on my machine
| Operating System : microsoft xp
CPU/Processor : PentiumR4 2400 MHz
RAM : 512
Motherboard : asusP4PE
Hard Disk : WD1200JB-00FUAO, Space: 150 GB, RPM:7200
Partition Details : 2 drives
Monitor : dell
Video Card : nvidia
Sound Card : sound max
CD Drive : sony
Mouse : micro optical
Keyboard : dell
|
Related Problems : Comments :
Re: Yes ADW.BADBITOR.A is a spyware by Anonymous Ghost on July 28th, 2005 06:27:10 AM Yes ADW.BADBITOR.A is a spyware. This is nothing but Lop.com spyware.
Follow the following steps:-
Boot in Safe Mode.
Switch System restore OFF.
In folder options, select show all files/folders including OS protected folders.
Delete Files/Folders:
%Favorites%\Adult Entertainment
%Favorites%\Adult Items
%Favorites%\Antivirus.url
%Favorites%\Casino Online.url
%Favorites%\Computers.url
%Favorites%\Computers
%Favorites%\Cool Stuff
%Favorites%\Games.url
%Favorites%\Home
%Favorites%\Instant Messaging.url
%Favorites%\Internet.url
%Favorites%\Internet
%Favorites%\Movie.url
%Favorites%\Online Gaming
%Favorites%\Online Pharmacy
%Favorites%\Shopping Gifts
%Favorites%\Travel
%Favorites%\Web Hosting.url
%Program Files%\BitTorrent\70000016.exe
%Program Files%\BitTorrent\_socket.pyd
%Program Files%\BitTorrent\_sre.pyd
%Program Files%\BitTorrent\_ssl.pyd
%Program Files%\BitTorrent\_winreg.pyd
%Program Files%\BitTorrent\bittorrent-3.3.exe
%Program Files%\BitTorrent\btdownloadgui.exe
%Program Files%\BitTorrent\python23.dll
%Program Files%\BitTorrent\redirdonate.html
%Program Files%\BitTorrent\select.pyd
%Program Files%\BitTorrent\uninstall.exe
%Program Files%\BitTorrent\wxc.pyd
%Program Files%\BitTorrent\wxmsw24h.dll
%Program Files%\BitTorrent\zlib.pyd
%Program Files%\bone balm
%Program Files%\Knob test\Soft Live Wave.exe
%Program Files%\manager burn 16\20023.exe
%Program Files%\manager burn 16\draw keep.dll
%Program Files%\manager burn 16\Fork Coal.dll
%Program Files%\manager burn 16\Part up soap.bin
%Program Files%\that dale
(Note: %Favorites% refers to the current user's Favorites folder, which is usually C:\Documents and Settings\[User name]\Favorites. %Program Files% refers to the Program Files folder, which is usually C:\Program Files.)
Delete registry enteries:
HKEY_LOCAL_MACHINE\Software\Classes\DRIVE.OwnsDefy
HKEY_LOCAL_MACHINE\Software\Classes\FRAG.elseChin
HKEY_LOCAL_MACHINE\Software\Classes\FRAG.elseChin.1
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://ecmh.com/searchbar.html"
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://search200.com/searchbar.html"
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Page = "http://ecmh.com/searchbar.html"
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Page = "http://search200.com/searchbar.html"
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Start Page = "ecmh.com"
HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Start Page = "search200.com"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://ecmh.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://search200.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Page = "://ecmh.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Page = "http://search200.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Start Page = "ecmh.com"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Start Page = "search200.com"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Search
SearchAssistant = "http://search200.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Search
SearchAssistant =" http://ecmh.com/searchbar.html"
HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Toolbar\{D1286418-B823-DB08-4CAE-1814A2E2149D}
HKEY_LOCAL_MACHINE\Software\Microsoft
Windows\CurrentVersion\Uninstall\BitTorrent
HKEY_LOCAL_MACHINE\Software\Microsoft
Windows\CurrentVersion\Uninstall\move great trans
HKEY_LOCAL_MACHINE\%Registry Run Key%
creative dead |
Re: adware by derick2 on July 29th, 2005 10:04:46 PM Followed all steps but did not find any of the files listed. This item is only identified by PCcillin not by Spy Bot.or strangely trend micro Spyware which used to be Spysubstract nor PC Doctor. It only appears when I run Azureus? My computer seems to be running OK. Thanks for help. |
The same problem... by Anonymous Ghost on August 23rd, 2005 06:53:19 AM I've got the same problem but this procedure didn't work... |
Re: adware by derick2 on August 23rd, 2005 09:22:56 AM As said previously my computer seems to run OK whether I choose to delete this or not. It seems to me that some of the files identified as problems by various programs can be marginal in their detremental effect. The thing thet concerns me is that there is so much rubbish getting into our machines. It is almost essential to format and reinstall after a few months. |
Re: adware by Anonymous Ghost on August 27th, 2005 11:24:31 AM comes with bittorrent or bittornado etc. little effect to your pc. remove this torrent downloader then it will clean and not return. |
Related Problems :
List Home > Spam Alerts / Anti-Spam > [ Post New Problem ] |
|