Home Computer Repair Online
hcrlogo

We provide: Free Computer Support - Device Drivers - Support Forums -
Chat Rooms -Video Game Hints - Cheats and Tips

Search:

Monday, September 06, 2010

User name: Password:









Main Menu


     HOME
     Device Drivers
    Register For Free
    Articles and Tips
    Geek Blog
    Submit Article
    Free Downloads
    Computer Help Forum
    Support Chat Rooms
    Unknown File Lookup
    Virus Alerts
    Internet Traffic Report
    Video Game Arcade
    Favorite Bookmarks
    Reviews
    Member List
    Site FAQs
    Sign/View Guest Book
    Send Donation
     Recommend Us



Who's Online

There are 8 visitors using this site.

You are guest 1619143 since we started counting on August 20th 2002.






Spyware Removal Geek Tip:

WinAntiSpyware Removal Instructions

WinAntiSpyware Removal Instructions

WinAntiSpyware Descriptions: WinAntiSpyware is counterfeit anti-spyware software. WinAntiSpyware usually installed itself onto your PC without your permission, through Trojan and virus. WinAntiSpyware will display fake system alerts or fake security alerts to trick user to buy the Paid Version of WinAntiSpyware. (You could get WinAntiSpyware by opening an infected message in myspace or installing infected or fake video codec)

Stop WinAntiSpyware Processes: (Learn how to stop a process) insthelp.exe updater.exe stera.exe uwasffnt.exe was6.exe winantispyware2006freesetup.exe wasffnt.exe winantispyware2006setup.exe

Remove WinAntiSpyware Registry Values: (Learn how to delete a registry value) HKEY_CLASSES_ROOTclsid{1230649b-b980-44a5-b259-9b09ebea6331} HKEY_CLASSES_ROOTclsid{1236de55-eded-4675-af10-ba15eddb4d7a} HKEY_CLASSES_ROOTclsid{abcd4567-76b5-4bc7-aac5-396d70925b11} HKEY_CLASSES_ROOTclsid{f3ef3329-ccb1-433b-a3ed-6e763665d280} HKEY_CLASSES_ROOTdirectoryshellexcontextmenuhandlersexploreruwas HKEY_CLASSES_ROOTdriveshellexcontextmenuhandlersexploreruwas HKEY_CLASSES_ROOTinterface{4567ab12-a884-4ca6-b739-cedb12fef096} HKEY_CLASSES_ROOTinterface{abcd4567-4d73-43e9-85e5-53a2dbd95411} HKEY_CLASSES_ROOTinterface{abcd4567-d8e8-4df1-a3ea-d0aa72f42611} HKEY_CLASSES_ROOT ypelib{12398a44-7dfc-4c46-bd8f-41259d169a0d} HKEY_CLASSES_ROOT ypelib{4567ab12-ae24-4fd6-b479-e2b464f32da6} HKEY_CLASSES_ROOT ypelib{abcd4567-7437-43ef-ab74-4ab1d3a37411}

Unregister WinAntiSpyware DLL Files: (Learn how to unregister a dll file below) was6chk.dll uwas6chk.dll shellext.dll asagents.dll

Find and Delete these WinAntiSpyware Files: insthelp.exe updater.exe stera.exe uwasffnt.exe was6.exe winantispyware2006freesetup.exe wasffnt.exe winantispyware2006setup.exe was6chk.dll uwas6chk.dll shellext.dll asagents.dll

Unregister DLL in Windows XP or Vista

Sometimes we need to unregister a dll file to troubleshoot a problem in Windows XP or Vista. Heres how to do it:

1. From Start > Run, type cmd then click on Open. (Where is RUN in Windows Vista?) 2. Type regsvr32 /u filename.dll where filename is the name of the file that you like to unregister. regsvr.JPG

Please keep in mind that this involves system modification and can be highly risky. Its always recommended to keep a system backup handy, in case things go wrong.

Posted By thegeek on 2007-06-11 08:24:45.0 | Spyware Removal
comments | Reads: 1478 | printer friendly page

Spyware Removal Article:

How to Remove Trojan.Pakes

Please print out these instructions or copy them into a text file on your Desktop for easy access.

During the fix, u will be asked to fix some entries, delete some files or uninstall some programs. If in case, you do not see those entries / files / programs, please make a note of it. Continue with the fix and in your next post please inform me of all deviations from the fix prescribed.

1. Download Programs

Please download these programs and save them in a new folder on your desktop -

CleanUp
Ewido Security Suite

Install Ewido, and update the definitions to the newest files. Do NOT run a scan yet.

CWShredder

Update CWShredder

* Open CWShredder and click I AGREE
* Click Check For Update
* Close CWShredder

DSRfix.zip

  • Unzip and EXTRACT the files to your Desktop.
  • The program creates and names the new folder to house the files.
  • DO NOT RUN IT YET
2. Remove Infections

Restart the PC in Safe Mode (repeatedly tap the F8 key when the PC is starting up).

Run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about.

Open the folder dsrfix
  • Double click on the dsrfix batch file( the one with the little gear in it )
  • Once dsrfix has completed it will close on its own
Run CleanUp and delete all temp files including temporary internet files

Run Ewido full scan. Let it fix any items it finds.

3. Run Hijack This

Run Hijack This and click on scan. The following items need to be fixed -

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - (no file)
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll (file missing)
O2 - BHO: WinStat - {EE02B99B-1D55-48bc-B8DB-649A42CE45F6} - C:\WINDOWS\System32\WinStat12.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKCU\..\Run: [hwt2RfM9i] ipxcons.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SNInstall] C:\WINDOWS\System32\vxh8jkdq2.exe
O4 - Startup: winupdate65016909[1].exe
O4 - Startup: winupdate92909492[1].exe
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C...bridge-c420.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab


Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

4. Delete Rogue files

Open Add or Remove Programs (click on Start ---> Settings ---> Control panel. This should be the 3rd item). Uninstall or remove the following items -

Surf SideKick 3
Media Access



Open Windows Explorer (right click on Start and then click on explore). Locate and delete the following folders and files -

Folders
C:\Program Files\SurfSideKick 3
C:\Program Files\CxtPls
C:\Program Files\Media Access

Files
C:\WINDOWS\ceres.dll
C:\WINDOWS\dsr.dll
C:\WINDOWS\System32\WinStat12.dll
C:\WINDOWS\System32\kernels32.exe
C:\winstall.exe
C:\WINDOWS\System32\vxh8jkdq2.exe

ipxcons.exe
winupdate65016909[1].exe
winupdate92909492[1].exe

(Search for these files using the Windows Search function)


Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch. It will open the folder Prefetch. Delete all the files in that folder. Dont delete the folder, only the files in it !!!!!!!!


Reboot the PC in Normal Mode.


Posted By thegeek on 2007-05-17 13:32:50.0 | Spyware Removal
comments | Reads: 1060 | printer friendly page

Spyware Removal Geek Tip:

How to Remove Trojan.Pakes

Please print out these instructions or copy them into a text file on your Desktop for easy access.

During the fix, u will be asked to fix some entries, delete some files or uninstall some programs. If in case, you do not see those entries / files / programs, please make a note of it. Continue with the fix and in your next post please inform me of all deviations from the fix prescribed.

1. Download Programs

Please download these programs and save them in a new folder on your desktop -

CleanUp
Ewido Security Suite

Install Ewido, and update the definitions to the newest files. Do NOT run a scan yet.

CWShredder

Update CWShredder

* Open CWShredder and click I AGREE
* Click Check For Update
* Close CWShredder

DSRfix.zip

  • Unzip and EXTRACT the files to your Desktop.
  • The program creates and names the new folder to house the files.
  • DO NOT RUN IT YET
2. Remove Infections

Restart the PC in Safe Mode (repeatedly tap the F8 key when the PC is starting up).

Run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about.

Open the folder dsrfix
  • Double click on the dsrfix batch file( the one with the little gear in it )
  • Once dsrfix has completed it will close on its own
Run CleanUp and delete all temp files including temporary internet files

Run Ewido full scan. Let it fix any items it finds.

3. Run Hijack This

Run Hijack This and click on scan. The following items need to be fixed -

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:Program FilesSurfSideKick 3SskBho.dll
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - (no file)
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:WINDOWSceres.dll
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:WINDOWSdsr.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:Program FilesCxtPlscxtpls.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:WINDOWSSYSTEMLoader.dll (file missing)
O2 - BHO: WinStat - {EE02B99B-1D55-48bc-B8DB-649A42CE45F6} - C:WINDOWSSystem32WinStat12.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM..Run: [Media Access] C:Program FilesMedia AccessMediaAccK.exe
O4 - HKLM..Run: [SurfSideKick 3] C:Program FilesSurfSideKick 3Ssk.exe
O4 - HKLM..Run: [System] C:WINDOWSSystem32kernels32.exe
O4 - HKCU..Run: [hwt2RfM9i] ipxcons.exe
O4 - HKCU..Run: [Windows installer] C:winstall.exe
O4 - HKCU..Run: [SNInstall] C:WINDOWSSystem32vxh8jkdq2.exe
O4 - Startup: winupdate65016909[1].exe
O4 - Startup: winupdate92909492[1].exe
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw3.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C...bridge-c420.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab


Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

4. Delete Rogue files

Open Add or Remove Programs (click on Start ---> Settings ---> Control panel. This should be the 3rd item). Uninstall or remove the following items -

Surf SideKick 3
Media Access



Open Windows Explorer (right click on Start and then click on explore). Locate and delete the following folders and files -

Folders
C:Program FilesSurfSideKick 3
C:Program FilesCxtPls
C:Program FilesMedia Access

Files
C:WINDOWSceres.dll
C:WINDOWSdsr.dll
C:WINDOWSSystem32WinStat12.dll
C:WINDOWSSystem32kernels32.exe
C:winstall.exe
C:WINDOWSSystem32vxh8jkdq2.exe

ipxcons.exe
winupdate65016909[1].exe
winupdate92909492[1].exe

(Search for these files using the Windows Search function)


Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch. It will open the folder Prefetch. Delete all the files in that folder. Dont delete the folder, only the files in it !!!!!!!!


Reboot the PC in Normal Mode.


Posted By thegeek on 2007-05-17 13:13:05.0 | Spyware Removal
comments | Reads: 1294 | printer friendly page

Spyware Removal Article:

Smitfaudfix.exe

How to remove:
AdwarePunisher, AdwareSheriff, AlphaCleaner, Antispyware Soldier, AntiVermeans, AntiVermins, AntiVerminser, AntivirusGolden, AVGold, BraveSentry, MalwareWipe, MalwareWiped, MalwareWipePro, MalwareWiper, PestCapture, PestTrap, PSGuard, quicknavigate.com, Registry Cleaner, Security iGuard, Smitfraud, SpyAxe, SpyCrush, SpyDown, SpyFalcon, SpyGuard, SpyHeal, SpyMarshal, SpySheriff, SpySoldier, Spyware Vanisher, Spyware Soft Stop, SpywareQuake, SpywareKnight, SpywareSheriff, SpywareStrike, Startsearches.net, TitanShield Antispyware, Trust Cleaner, UpdateSearches.com, Virtual Maid, VirusBlast, VirusBurst, Win32.puper, WinHound, Brain Codec, DirectVideo, EliteCodec, eMedia Codec, FreeVideo, Gold Codec, HQ Codec, iCodecPack, iMediaCodec, Image ActiveX Object, IntCodec, iVideoCodec, JPEG Encoder, Key Generator, Media-Codec, MediaCodec, MMediaCodec, MPCODEC, My Pass Generator, PCODEC, Perfect Codec, PowerCodec, PornPass Manager, PornMag Pass, QualityCodec, Silver Codec, SiteTicket, SoftCodec, strCodec, Super Codec, TrueCodec, VideoAccess, VideoBox, VidCodecs, Video Access ActiveX Object, Video ActiveX Object, VideoCompressionCodec, VideoKeyCodec, VideosCodec, WinAntiSpyPro, WinMediaCodec, X Password Generator, X Password Manager, ZipCodec...
Download Smitfraudfix.exe here

Posted By thegeek on 2007-03-05 23:57:44.0 | Spyware Removal
1 comment | Reads: 1407 | printer friendly page

Spyware Removal Article:

Remove Spyware Quake

Use this tool to remove Spyware Quake (spywarequake) SmitfraudFix.zip

Posted By thegeek on 2006-04-21 17:31:20.0 | Spyware Removal
comment? | Reads: 2592 | printer friendly page


Just A few of our super deals. Visit our Ebay store to view hundreds of items at great prices!

Take Our Poll

What O.S. Are You Using Right Now?

Windows
Mac O.S.
Linux

Arcade

Play this game now!

Most Recent Reviews

Hardware: Trendnet TV-IP422W IP Camera 4 Stars Posted By thegeek on

maximumpc.com Posted 09/05/08 at 09:30:51 AM | by Michael Brown

Trendnet’s TV-IP422W wireless IP camera reminds us of the Zonet ZVC7630W    read more ...

Next 1 records

The Geek's Most Popular Articles

Mozilla Announces Firefox Update
Reads (7096)
ShopTheGeek.com Fall 2005 Sale
Reads (5546)
Capacitor Conspiracy!
Reads (5368)
British Intelligence Agency MI5 to Debut Terror E-Mail Alert Service for Public
Reads (5182)

Affiliated Sites

    Shop The Geek
    Device Drivers
    Video Game Cheats
    Computer Humor
    Web Site Hosting

Favorite Quotes

"We have just enough religion to make us hate, but not enough to make us love on another." ~ Jonathan Swift

Copyright 2007 - Home Computer Repair LLC
paid remote support

CLICK HERE TO VIEW OUR SITE MAP