Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
And the story begins....
A couple days ago, Norton Realtime AV warned me of three instances of the downloader.trojan virus on my machine. (I think they loaded when a pop-up window appeared)
I stopped what I was doing, jumped over to the Symantec site and followed the removal instructions (update virus definitions, disable system restore, start in safe-mode, system scan, delete, then check a couple spots in the registry).
So I did all this. When I went to the registry, I didn't notice anything unusual so I rebooted in normal mode, ticked System Restore, and went about my business.
Long story short, this is the worst hijacker I've ever heard of. It completely takes over my browser. I can't type a URL into the address bar, search, download (even from trusted business sites) without being hijacked. What's more, there's a "Free Mature Porn" link that keeps adding itself to my favorite places no matter how many times I delete it. Needless to say, Symantec's removal instructions didn't work, and now I have no restore points prior to the virus.
I've tried to download HijackThis! and guess what happens....they do!
The web page it keeps bringing me to is www.nkvd.us, so I thought I'd go back to the registry and search. Low and behold, almost EVERY web-related setting I had was set to this site. I changed and/or deleted everything appropriately (here's the kicker) and tried my browser again. NOW, it's got me going to www.Smart-search.us (or something similar).
Next, I tried to remove IE through add/remove programs....however something didn't work right coz it never went away. The only thing missing after I removed it was my history.
I'm about ready to comit an act of hari-kari and FDISK it all!!
Anyone have any suggestions? (keep in mind it's awful hard to get to a page without following a link, and once I get there it's impossible to download)
Fun! Ain't it?

Beeny,
CoolWWWSearch.SmartKiller Direct Download
Spybot S&D 1.2 Direct Download
HijackThis.exe Direct Download
CWShredder.exe Direct Download
Thought I'd see, if these help any. Also, you might want to check your "HOST" file. It might, be causing some problems.
Good Luck

Thanks, but I get hijacked on those links.
How big is the install for HijackThis? Is it something someone could email me? Or meet me on MSN messenger and send the file?
I'm 'Kabeeny' on MSN if anyone would like to try & my email addy is at the top of this post.

OK,
I went to a friend's house and downloaded HijackThis, wrote it to a CD, installed and ran it.
Is there ANYONE that can help me out with my HjT log?
Just tell me where to post/send it.
I would be MOST thankful!

Beeny
Go back to your buddy's computer an download all the files CrazyOne put up.
Run the smartkiller one first.
Reboot
Run the CWShredder one next.
Reboot
Clear out all temporary internet files including all offline content and history.
Reset web settings:Start> settings> control panel> internet options:
Delete files
At the popup check "delete offline content"
Click ok
Click delete history
Yes at the promptClick the programs tab
Click "reset web settings"
On the popup also check "also reset home page"
Yes at the prompt.
Click okInstall the Spybot next then run its update feature (online> search for updates) and install all updates. Click the "unido Europe" down arrow> choose EON Austraillia site.
It will restart itself when done updating.
Disconnect from internet.
Diasable antivirus
Run spybot's scan (check for problems)
Have it remove what it finds.(all in red)Reboot
When spybot asks to run at next start...let it.
When 2nd scan is done let it remove what it finds...then windows will start normal.Once you have done the above and if you still have problems then post a fresh hijack log(it will be different after above cleanouts.) here in reply. I will help with your log.
If you need it...my email is in my name..(ya gotta click it)(also my msn)
You shouldn't display your email addy in plain view like in your #3 response...we have spam bots crawling thru here all the time looking for emails to send their crap to.
When I click your name...I can see your email...that's good enough.
_____________________________________________I never give up!

OH MY!!
YOU DID IT!!!!!!!!!!!!!
Looks like I'm back to my normal life again, instead of all these work-arounds I've been inventing to deal with this problem.
I can't thank you guys enough! Does the site take support donations? Handshakes? Hugs? You name it!
Thanks SO much for your responses.
(The email is my "junk" email address. I use it whenever there might be a risk of getting spam, but it's prolly not good to encourage the spammers by letting them find addresses. And for anyone reading this thread, "don't post the address" IS excellent advise!!)
Thank you again, and thank God there is someone on the internet that believes in people's privacy and protection from those idiots. If I ever found the low-life that was responsible for the loss of productivity over the last 5 days, I would shoot to kill!! I have litterally spent HOURS and HOURS spinning my wheels trying to get rid of this thing.
THANK YOU!!!!!!!!!!!!!!!!

I have the same exact virus but no good buddy with a computer and cd burner. Looks like I'm screwed. :(
Does anyone out there maybe have AIM or MSN where we could hook up direct download of this stuff? I've got a speedy connection. This really really sucks.Shel

Beeny
Glad all is well!
Good idea with the "throw away" email addy. I use those alot too.
Now for future protection...
1. make sure you have all your windows updates...or risk re-infection.
2. Install Spywareblaster, IE-Spyad, SpywareGuard.
All are free and take almost no resorces.
Spywareblaster Basically stops crap from being downloaded to your computer by blocking known bad active x controls.
Spywareguard watches your IE home page and search page settings for IE. If something tries to change it..it alerts you with option to keep or repair the change.
IE-Spyad puts thousands of known crapware sites in your restricted zone of IE where by default java, active x, and anything else potientially dangerous is disabled. If you hit a bad site...chances are they can't do anything.
Spywareblaster/Spywareguard download:
http://www.javacoolsoftware.com/downloads.html
IE-Spyad download:
http://www.staff.uiuc.edu/~ehowes/resource.htm
Take care and surf safe.
If you want to donate somewhere...Do it here:
http://www.spywareinfo.com/~merijn/donate.html
He made that CWShredder prog and can use the help...site is constantly under attack by the crapware makers. That is a mirror site above.
_______________________________________
Shel
Click my name for email addy, email me first to tell me who you are on msn, then I will add you to my list. My email addy here is also my msn. I also have hi speed.
________________________________________
I never give up!

how about spy sweeper (taproot) for removing the nkvd hijacker? i'm giving it a try right now, but don't know if everyone knows something i don't...

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |