Nibble Guru - Computing queries demystified Friday, August 29, 2008
Home
My Account / Register
Login / Logout
Post your Problem!
Search

About Us
Contact Us



List Home > Spam Alerts / Anti-Spam >   [ Post New Problem ]

Welcome back !
TrackingID : 4806
Posted : Tuesday, July 26th, 2005 10:31:33 AM
By : derick2
adwareConfiguration:
Is ADW.BADBITOR.A adware? TRendMicro dtects it all the time. I delete but keeps coming back.

Additional Comments:
Details on TRendMicro web page but did not find any of these files on my machine
Operating System : microsoft xp
CPU/Processor : PentiumR4 2400 MHz
RAM : 512
Motherboard : asusP4PE
Hard Disk : WD1200JB-00FUAO, Space: 150 GB, RPM:7200
Partition Details : 2 drives
Monitor : dell
Video Card : nvidia
Sound Card : sound max
CD Drive : sony
Mouse : micro optical
Keyboard : dell

Related Problems :
Comments :
Re: Yes ADW.BADBITOR.A is a spyware by Anonymous Ghost on July 28th, 2005 06:27:10 AM
Yes ADW.BADBITOR.A is a spyware. This is nothing but Lop.com spyware.

Follow the following steps:-

Boot in Safe Mode.
Switch System restore OFF.
In folder options, select show all files/folders including OS protected folders.


Delete Files/Folders:
%Favorites%\Adult Entertainment
%Favorites%\Adult Items
%Favorites%\Antivirus.url
%Favorites%\Casino Online.url
%Favorites%\Computers.url
%Favorites%\Computers
%Favorites%\Cool Stuff
%Favorites%\Games.url
%Favorites%\Home
%Favorites%\Instant Messaging.url
%Favorites%\Internet.url
%Favorites%\Internet
%Favorites%\Movie.url
%Favorites%\Online Gaming
%Favorites%\Online Pharmacy
%Favorites%\Shopping Gifts
%Favorites%\Travel
%Favorites%\Web Hosting.url
%Program Files%\BitTorrent\70000016.exe
%Program Files%\BitTorrent\_socket.pyd
%Program Files%\BitTorrent\_sre.pyd
%Program Files%\BitTorrent\_ssl.pyd
%Program Files%\BitTorrent\_winreg.pyd
%Program Files%\BitTorrent\bittorrent-3.3.exe
%Program Files%\BitTorrent\btdownloadgui.exe
%Program Files%\BitTorrent\python23.dll
%Program Files%\BitTorrent\redirdonate.html
%Program Files%\BitTorrent\select.pyd
%Program Files%\BitTorrent\uninstall.exe
%Program Files%\BitTorrent\wxc.pyd
%Program Files%\BitTorrent\wxmsw24h.dll
%Program Files%\BitTorrent\zlib.pyd
%Program Files%\bone balm
%Program Files%\Knob test\Soft Live Wave.exe
%Program Files%\manager burn 16\20023.exe
%Program Files%\manager burn 16\draw keep.dll
%Program Files%\manager burn 16\Fork Coal.dll
%Program Files%\manager burn 16\Part up soap.bin
%Program Files%\that dale

(Note: %Favorites% refers to the current user's Favorites folder, which is usually C:\Documents and Settings\[User name]\Favorites. %Program Files% refers to the Program Files folder, which is usually C:\Program Files.)

Delete registry enteries:
HKEY_LOCAL_MACHINE\Software\Classes\DRIVE.OwnsDefy

HKEY_LOCAL_MACHINE\Software\Classes\FRAG.elseChin

HKEY_LOCAL_MACHINE\Software\Classes\FRAG.elseChin.1

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://ecmh.com/searchbar.html"

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://search200.com/searchbar.html"

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Page = "http://ecmh.com/searchbar.html"

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Search Page = "http://search200.com/searchbar.html"

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Start Page = "ecmh.com"

HKEY_CURRENT_USER\Software\Microsoft
Internet Explorer\Main
Start Page = "search200.com"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://ecmh.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Bar = "http://search200.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Page = "://ecmh.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Search Page = "http://search200.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Start Page = "ecmh.com"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Main
Start Page = "search200.com"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Search
SearchAssistant = "http://search200.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Search
SearchAssistant =" http://ecmh.com/searchbar.html"

HKEY_LOCAL_MACHINE\Software\Microsoft
Internet Explorer\Toolbar\{D1286418-B823-DB08-4CAE-1814A2E2149D}

HKEY_LOCAL_MACHINE\Software\Microsoft
Windows\CurrentVersion\Uninstall\BitTorrent

HKEY_LOCAL_MACHINE\Software\Microsoft
Windows\CurrentVersion\Uninstall\move great trans

HKEY_LOCAL_MACHINE\%Registry Run Key%
creative dead
Re: adware by derick2 on July 29th, 2005 10:04:46 PM
Followed all steps but did not find any of the files listed. This item is only identified by PCcillin not by Spy Bot.or strangely trend micro Spyware which used to be Spysubstract nor PC Doctor. It only appears when I run Azureus? My computer seems to be running OK. Thanks for help.
The same problem... by Anonymous Ghost on August 23rd, 2005 06:53:19 AM
I've got the same problem but this procedure didn't work...
Re: adware by derick2 on August 23rd, 2005 09:22:56 AM
As said previously my computer seems to run OK whether I choose to delete this or not. It seems to me that some of the files identified as problems by various programs can be marginal in their detremental effect. The thing thet concerns me is that there is so much rubbish getting into our machines. It is almost essential to format and reinstall after a few months.
Re: adware by Anonymous Ghost on August 27th, 2005 11:24:31 AM
comes with bittorrent or bittornado etc. little effect to your pc. remove this torrent downloader then it will clean and not return.

Related Problems :
Post a Note :
UserName (not required in anonymous posts)
Password (not required in anonymous posts)
Post Anonymous (check this only if you wish to post anonymously.)
Subject
Comment (limited HTML allowed)



List Home > Spam Alerts / Anti-Spam >   [ Post New Problem ]
Copyright © 2001-2008, Nibble Guru