Author Topic: Win32:Onlinegames-CAZ [Trj]  (Read 3451 times)

0 Members and 1 Guest are viewing this topic.

dotweb

  • Guest
Win32:Onlinegames-CAZ [Trj]
« on: February 11, 2008, 01:55:48 AM »
hi all
plz help me with Win32:Onlinegames-CAZ [trj] as i have tried all possible ways to remove it
thanks

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Win32:Onlinegames-CAZ [Trj]
« Reply #1 on: February 11, 2008, 02:03:54 AM »
Hi dotweb,

A cleansing routine for reference can be found here:
http://www.elektroda.pl/rtvforum/topic936066.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

dotweb

  • Guest
Re: Win32:Onlinegames-CAZ [Trj]
« Reply #2 on: February 13, 2008, 10:57:24 PM »
to polonus plz translate your advice in english
Hi
Thanks for your reply but plz tel me in english as i cant understand the link u send me and im still using my PC along with this virus
many thanks

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Win32:Onlinegames-CAZ [Trj]
« Reply #3 on: February 13, 2008, 11:20:58 PM »
Hi dotweb,

We will start to try and handle this, maybe with an assist from essexboy or oldman,
our combofix specialists in this section of the forum.
The essentials of the cleansing routine were: to download SP2 if your system is XP,
To change for an alternate browser like Firefox with NoScript add-on or to Opera,
To attach a HJT log to see what we have to delete, in the case described in the link I quoted
there were two 02 BHO Global Search Bar entries and a 03 entry fixed.
 Also to be deleted were 188qsm.bat files on various disks,
and a 188 etc.BAT.pf file, then a ComboFix scan was run, and a log file posted, installed and run was
ATF Cleaner, to be downloaded from here: http://www.atribune.org/ccount/click.php?id=1
furthermore the following was removed:  various cmd files & an executable in C:\ a particular
windows system32 uninst.exe

This were the essentials translated from the Polish removal instruction,

How to run and post the logs of HijackThis and Combofix, you read and see here:
http://forum.avast.com/index.php?topic=33222.msg277260#msg277260

Waiting for your logs being attached to your next posting,

polonus aka Damian
« Last Edit: February 13, 2008, 11:22:32 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!