WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


Trojan: SHeur2.gnw

3 posters

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Thanks.
Open the CD as a folder, is there an i386 folder on the CD?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Aye

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
That is "yes" in auld english, or so I've been taught.. Smile...

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Hello.
Haha, yeah. I'm from good ole England, the land of sheep and dirt.
Just seen your edit, yes it's bogus. AVG have detected a second tool now, I got it too.
Trojan.Downloader.Banload

Alittle while ago, it detected OTMoveIt as generic backdoor. AVG is going down the drain.

Now lets fix this problem.

Press Start > Run
Type in cmd and press enter.
Once the command opens, type this in:

expand H:\i386\userinit.ex_ c:\windows\system32\userinit.exe

Press enter.

Now delete the avenger.exe from your Desktop, along with DDS.
Delete this folder:
C:\avenger

What problems remain?

Last edited by Belahzur on 20th January 2009, 12:19 am; edited 1 time in total

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Done.
cmd says: "no destination secified for H:\i386\userinit.ex_ c:\windows\system32\userinit.exe

is that good or bad?

and the infection is still there according to avg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Did you put a space between _ and C?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
nope. ill try again. (btw that space is alomst impossible to see for the naked eye)

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
copied

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Okay, everything should be fine now. The malware is gone and userinit is replaced.

Any problems remaining?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
now; this file is used to log on to windows am i right? we dont really know if this was a success until i reboott and see if i can still log onto the system?

1,5 min 'til scan is complete

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Yes, hopefully it won't lock you out. Indifferent or Blank

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
0/0 - you did it man! Hooray!

heres hoping my computer will start..

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
that bleak smiley of yours didnt fill me with confidence?!

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
I'm confident, just hoping. LOL Banner

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
wtf?!
yeah yeah, might as well try it at once.
if im not posting backwithin 5 minutes ive jumped from the balcony..

any pointers to what i do if it crashes?

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Put this image onto a CD buying writing to a blank disc.
http://home.eunet.no/pnordahl/ntpasswd/cd080802.zip

If your locked out, we can use that to recover it.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
memory stick sufficient? i need to make a image cd?

Last edited by ronsonol on 20th January 2009, 12:27 am; edited 1 time in total

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
CD image, not memory stick.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
done.
but how do i use it?

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
We can boot from it.

Try rebooting now we have something to recover from.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Heureka!
Bless your cotton socks, Im back!

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Thanks god for that. Hooray!

You may be able to help me now, and save a few hundred machine.
Is your OS normal XP SP3 or SP3 Media Centre?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
normal

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Okay.
Please upload this file:
C:\windows\system32\userinit.exe
To here for me.
www.savefile.com

If you can't access that, upload it to rapidshare or some other upload site.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
will try
a few things:
i will do a thorough scan tomorow, after work, checking everything.
i will not declare victory until then. need to get up i 5 hours.

i notice i cant turn on automatic updates on avg, looks suspicious. gut feeling?

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Trust be told - I would prefer you uninstall AVG, as you see the false positive of picking up the avenger.

I would prefer you use avast! or avira, but we'll talk about that later if you need sleep, now go sleep. LMBO or ROFL

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
god knows i need my beautysleep.. :crazy:

trying to upload at the mo, sent my firefox crashing.. (using ie now)
ill try again tomorrow, ok?

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Okay. Smile...

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
ok, thanks mate
c ya tomorrow

descriptionTrojan: SHeur2.gnw - Page 1 EmptyI think we are ok

more_horiz
Hi again B.
Been doing checks and scans today and it looks as though Im in the clear.

AVG is still not able to sustain automatic updates though, a bit worried by that. Ive downloaded Avast! though, will install it later, if that is what you recomend.

Ive also downloaded spywareblaster and superantispyware to give them a test. I understand the fist one is good to prevent attacks?!

The file you wanted is uploaded at userinit.exe (the one you suggested just kept crashing on me).
Please scan it to make sure its safe, cos Marlwarebytes claimed the file was infected. Not the original file, but I copied to my desktop to .rar it and Malware meant the copy was corrupt.


Ive been doing a few reboots as well, that works just fine.

I thought maybe I could ask you to look at my HJT log again, so you can see if you find any threats?

HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:22:26, on 20.01.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Geir\Desktop\Hijack(GP)This.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.db.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230037788250
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7546 bytes

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Thanks for the file.
Log looks good, all that is left is the AV issue, feel free to take your time, but please remember to do this as AVG maybe corrupt and you aren't safe.
Do not surf the net between uninstall/install new AV as you will not be protected.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
I wont. I think I'll try it at once, as my skiing plans just went down the drain.
I wish I was in your land of sheep and dirt right now, over here its a land of snow and slush. Recieved 3 feet in one night, the whole country came to a standstill. and now its raining on top of it. i bet that is a problem youre not used to...

I used to live in Leeds btw. (and London) I remember when Leeds had half an inch of snow the whole place collapsed on itself. And I, in my renault 5, was the king of the road, the only person with the guts to go out and face the white menace of the heavens..

Anyways; Feel free to hit the "solved" button if youd like, I imagine you take pride in it. Thank You!
I cant thank you enough for taking the time and effort, it is greatly appreciated.

I understand geekpolice would like feedback/review as a token of appreciation?

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Can we switch places? pretty please? I love the snow. LMBO or ROFL
I WANT it to snow heavy here, I hate getting up early for college. LOL Banner

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
https://addons.mozilla.org/en-US/firefox/addon/722
https://addons.mozilla.org/en-US/firefox/addon/1865
https://addons.mozilla.org/en-US/firefox/addon/433

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

To help you keep your software updated, please considering using this free software program that will check for program updates.
Update Checker

5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

If you would take a moment to fill out our feedback form, we would appreciate it.
The link can be found here.

Hopefully this should take care of your problems! Good luck. Big Grin

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Ill switch places only if you live close to Anfield (or at least a bloody good pub). Love the snow myself, but not the slush..

Btw; College is for partying not studiyng. You country is not of sheep and dirt (that would be New Zealand) but rather beer and skimply clad chicks..

I turned of system restore before I even came here for help, time to turn it on again now, thanks for reminding me.

Read through the articles allready, good reading. Now to make my girlfriend. read them... (and to convert her to firefox)

Feedback submitted. Pretty much told you off Goofy
Cheers mate!

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
LOL Banner Your welcome.
Solved.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Trojan: SHeur2.gnw - Page 1 DXwU4
Trojan: SHeur2.gnw - Page 1 VvYDg

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

............................................................................................

Please be a GeekPolice fan on Facebook!

Trojan: SHeur2.gnw - Page 1 Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

............................................................................................

Please be a GeekPolice fan on Facebook!

Trojan: SHeur2.gnw - Page 1 Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionTrojan: SHeur2.gnw - Page 1 EmptyRe: Trojan: SHeur2.gnw

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum