also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

[Resolved] Google randomly redirecting...logs attached

Discussion in 'Virus and Malware Removal' started by mcIrishgurl, Mar 14, 2011.

Thread Status:
Not open for further replies.
  1. Bobbye Helper on the Fringe

    You can search on the system for C:\WINDOWS\system32\grpconv.exe
    Right click on Taskbar> Explore> My Computer> Double click Local Drive(C)> Windows> System 32> Look for grpconv.exe on right screen> right click Delete.

    If you don't see the file> once in Windows Explorer>
    • Go to Tools > Folder Options.
    • Select the View tab.
    • Scroll down to Hidden files and folders.
    • Select Show hidden files and folders.
    • Uncheck (untick) Hide extensions of known file types.
    • Uncheck (untick) Hide protected operating system files (Recommended).
    • Click Yes when prompted.
    • Click OK.
    • Pick up the directions above beginning with 'Windows'.
    Reset Hidden/System Files & Folders
    ==========================================
    Both Spysweeper and Malwarebytes are okay to keep on system, but Mbam will require you to purchase the program to keep it on the system.
    ==========================================
    Tips for added security and safer browsing: (Links are in Bold Blue)
    1. Browser Security
      [o] Safe Settings
      [o] ZonedOut. This manages the Zones in Internet Explorer. (For IE7 and IE8, Windows 2000 thru Vista. No Windows 7)
      [o] Replace the Host Files
      [o] Google Toolbar Pop Up Blocker
      [o]Web of Trust (WOT) Site Advisor. Traffic-light rating symbols show which rate the site for Trustworthiness, Vendor Reliability, Privacy, Child Safety.
    2. Have layered Security:
      [o]Antivirus :(only one):Both of the following programs are free and known to be good:
      [o]Avira-AntiVir-Personal-Free-Antivirus
      [o]Avast Free Version
      [o]Firewall (only one): Use bi-directional firewall. Both of the following programs are free and known to be good:
      [o]Comodo
      [o]Zone Alarm
    3. Antimalware: I recommend all of the following:
      [o]Spywareblaster: SpywareBlaster protects against bad ActiveX.
      [o]Spybot Search & Destroy
    4. Updates: Stay current:
      [o] the Microsoft Download Sitefrequently. All updates marked Critical and the current SP updates.
      [o]Adobe Reader Install current, uninstall old.
      [o]Java Updates Install current, uninstall old.
    5. Tracking Cookies
      Reset Cookie:
      [o]For Internet Explorer: Internet Options (through Tools or Control Panel) Privacy tab> Advanced button> check 'override automatic Cookie handling'> check 'accept first party Cookies'> check 'Block third party Cookies'> check 'allow per session Cookies'> Apply> OK.
      [o]For Firefox: Tools> Options> Privacy> Cookies> check ‘accept Cookies from Sites’> Uncheck 'accept third party Cookies'> Set Keep until 'they expire'. This will allow you to keep Cookies for registered sites and prevent or remove others. (Note: for Firefox v3.5, after Privacy click on 'use custom settings for History.')
      I suggest using the following two add-on for Firefox. They will prevent the Tracking Cookies that come from ads and banners and other sources:
      AdBlock Plus
      Easy List
      [o]For Chrome: Tools> Options> Under The Hood> Privacy Section> CHECK 'Restrict how third party Cookies can be used'> Close.
    6. Do regular Maintenance
      [o] Temporary File Cleaner
    7. Restore Points:
      [o]See System Restore Guide
    8. Safe Email Handling
      [o] Don't open email from anyone you don't know.
      [o] Don't open Attachments in the email. Safe to your desktop and scan for viruses using a right click
      [o] Don't leave your personal email address on the internet. Have a separate email account at one of the free web-based emails like Yahoo.
    Please let me know if you find any bad link.
  2. mcIrishgurl Newcomer, in training

    i found grpconv.exe but when i delete, it deletes for a few seconds then reappears....as for the other things u suggested, i have pretty much done that except for the restore point, until you advise what to do for grpconv.exe . should i try to delete it's master file grpconv instead?
  3. Bobbye Helper on the Fringe

    How do you mean 'master file'?
  4. mcIrishgurl Newcomer, in training

    please excuse my lack of proper technical terminology...lol...when i click on the folder system 32 and it opens to all its contents, amongst it all is an icon with grpconv beneath it. the grpconv.exe only shows once i elect to show hidden files and such.
  5. mcIrishgurl Newcomer, in training

    just checking in to see what's next bobbye...thanks.
  6. Bobbye Helper on the Fringe

    My internet was down- again.

    Just do a right click on the .exe file.

    Then you are through.
  7. mcIrishgurl Newcomer, in training

    hi bobbye....i already tried right clicking but as i said in an earlier post, when i click delete, it deletes the icon for grpconv.exe for a moment, then the icon reappears which suggests to me that it really didn't delete. that is why i asked if i should try to delete the icon grpconv instead. if i don't need it and it serves no purpose for my version of xp (home), i don't care if it gets deleted.
  8. Bobbye Helper on the Fringe

    Okay, you clean and finished.
Thread Status:
Not open for further replies.