WizYo Blog ! WizYo Sytes Net Tech Support
What a great place to share :) Here you will find flashes of brilliance caught for all the world to enjoy. .. Actually, these are brief articles describing how I fixed a problem. Every day, I find information online that helps me solve a mystery. So this is me giving back to the community. Thanks for stopping by.. and don't forget to tell your friends!

Adware and auto-run registry key (notes)

Process Explorer from SysInternals is a great tool. HiJack This can remove a file during boot process. Use the two to disable and remove "SmitFraud-C" trojan and stubborn items: "MSSearchnet.exe" "nvctrl.exe" and "mscornet.exe" all located in the Windows\System32 folder. Also notice and correct entries in the registry at HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run

watch out for cmdService nesting itself in a long named directory. i just happened to make note of this file name:
n353tqcWtqk0prh5w0.vbs
this file had all special file attributes: hidden, system, read only

 

 

( )

Wednesday, December 21, 2005


0 Comments:

Post a Comment

Back to top.

Home
WizYo
Sytes Net

Links
~hot~ Links


this site !

GuestBook
Guests

Free Hit Counter

Blog!

Tell a friend about Tech Support available here !

Free Phone with iTunes
- Previous -
 
- Veritas 9.0 handy Reinstallation Patches
 
- Windows XP wouldn't allow network access
 
- Cheap website domain hosting
 
- Server 2003 Backup at your own risk !
 
- Norton Internet Security may go *bump* in the night
 
- unsolved emachine
 
- System(don't)Works with WinXP and Zip100
 
- iOmega, USB and Win98.. a winning combination!
 
- LinkSys firmware always an adventure
 
- Exchange server refusing to play nicely
 
- Search -
 

 


it's private

 

This page is powered by Blogger. Isn't yours?