View Full Version : NetHunter?
Tugela
Jul 30, 2005, 04:26 AM
My PC is behaving very strangely. I cannot do any spyware removal as it seems to freeze on C:\ProgramFIles\NetHunter Group\ProBotSE\InstView - now I cannot find this anywhere on my PC to delete it.
Please helpppppppppppp someone
Thanks
fredg
Jul 31, 2005, 05:33 AM
Hi,
Try running in Safe Mode as follows:
If you think you already have Spyware/Advertising Ware in your computer, run these as follows:
http://www.security-related.com/download2.htm
Download: SpyBot Search & Destroy; 1.3
(If you use the Spyware Blaster free program, then don't set SpyBot to the Immunization feature)
AdAware at:
http://www.lavasoftusa.com
Download: AdAware_SE V 1.06
CWShredder at:
http://www.intermute.com/products/cwshredder.html
(CWShredder is intended only for removal of CoolWebSearch files; placed as spyware on the harddrive). It is not a "stand alone" scan, but needs to be run. Download the free version by clicking on "Download stand alone version of CW Shredder".
All 3 of the above programs run better and much faster when run in SafeMode.
To get into SafeMode:
Re-boot the computer, and immediately after starting up, Press and hold down, F8, at top of keypad.
When the options show on the screen, use the up and down arrow keys on the keyboard to select
"Safe Mode".
Press Enter
It's best to run the AdAware scan first; 3 times; then re-boot.
Then, run the AdAware scan again 3 times; then run the SpyBot. Then, run CWShredder.
Re- Boot.
Reason for running so many times:
Some of these trojans' files can be deleted the first time; leaving some others; but on re-boot, they re-write the files that were deleted.
Running multiple times deletes most of it the first
Time.
If you wish to have a great program, after you clean out Spyware/Advertising Ware:
This program stops this stuff from getting into the computer in the first place, by placing URL's in the browser, stopping them instantly. Best free program anyone can download!
SpyWare Blaster 3.3
http://www.javacoolsoftware.com/sbdownload.html
If Safe Mode doesn't solve it, then the next thing to do would be to Edit the Registry, and delete this stuff from there.
Best wishes,
fredg
NeedKarma
Jul 31, 2005, 12:00 PM
Check this out: http://www.2-spyware.com/remove-probot.html and this: http://inet-mates.com/articles/3_rm_probot.html
"Remove Probot, description and removal instructions"
Press2Esc
Aug 1, 2005, 06:45 AM
Check out the specifics of this new keylogger at http://64.233.161.104/search?q=cache:rlbKo64HXGkC:www.pestpatrol.com/PestInfo/P/ProBot_Activity_Monitor.asp+%22probot+se%22&hl=nl&ie=UTF-8
Read thoroughly.. removal info is listed at the same.
Good Luck
P2E
My pc is behaving very strangely. I cannot do any spyware removal as it seems to freeze on C:\ProgramFIles\NetHunter Group\ProBotSE\InstView - now i cannot find this anywhere on my pc to delete it.
Please helpppppppppppp someone
Thanks
Tugela
Aug 10, 2005, 12:32 PM
Thanks - did all what was suggested - running adaware 3 times etc but when it comes time to run spybot my PC freezes on "BackOrifice.B - now what is this??
Seems adaware runs fine now - in safe mode and normal mode.
Im sorry for all these questions but I'm just a little old lady lol
THANKS
NeedKarma
Aug 10, 2005, 04:38 PM
Having backorifice detected on your PC is not good. I believe thatb you've reached the stage where you should get a local PC technician to do the removal and cleaning of your PC.
Basically BackOrifice.Trojan is an older variant of BackOrifice2K.Trojan. It gives a remote attacker full control over your computer.
Press2Esc
Aug 11, 2005, 05:47 AM
FreddyG... class-act with the How2z instructions.
P2E
Hi,
Try running in Safe Mode as follows:
If you think you already have Spyware/Advertising Ware in your computer, run these as follows:
http://www.security-related.com/download2.htm
Download: SpyBot Search & Destroy; 1.3
(If you use the Spyware Blaster free program, then don't set SpyBot to the Immunization feature)
AdAware at:
http://www.lavasoftusa.com
Download: AdAware_SE V 1.06
CWShredder at:
http://www.intermute.com/products/cwshredder.html
(CWShredder is intended only for removal of CoolWebSearch files; placed as spyware on the harddrive). It is not a "stand alone" scan, but needs to be run. Download the free version by clicking on "Download stand alone version of CW Shredder".
All 3 of the above programs run better and much faster when run in SafeMode.
To get into SafeMode:
Re-boot the computer, and immediately after starting up, Press and hold down, F8, at top of keypad.
When the options show on the screen, use the up and down arrow keys on the keyboard to select
"Safe Mode".
Press Enter
It's best to run the AdAware scan first; 3 times; then re-boot.
Then, run the AdAware scan again 3 times; then run the SpyBot. Then, run CWShredder.
Re- Boot.
Reason for running so many times:
Some of these trojans' files can be deleted the first time; leaving some others; but on re-boot, they re-write the files that were deleted.
Running multiple times deletes most of it the first
time.
If you wish to have a great program, after you clean out Spyware/Advertising Ware:
This program stops this stuff from getting into the computer in the first place, by placing URL's in the browser, stopping them instantly. Best free program anyone can download!
SpyWare Blaster 3.3
http://www.javacoolsoftware.com/sbdownload.html
If Safe Mode doesn't solve it, then the next thing to do would be to Edit the Registry, and delete this stuff from there.
Best wishes,
fredg
ScottGem
Aug 11, 2005, 07:38 AM
FreddyG... class-act with the How2z instructions.
P2E
I have to also disagree to some extent. Fred is by no means a class act as he has proven time and again. His use of a second ID, his hypocrisy, his plagiarism and other things that have been documented are not the actiuons of a "class act".
However, he does have some good canned step by step answers that are often helpful. The problem is he posts them even when they may not apply to the question.
Tugela
Aug 14, 2005, 01:03 PM
Thanks Fredg for your help
Seems if I left spybot running for a long time it got over the "frozen" stage and did a complete scan and came up with nothing.
Thanks