Home > General > A.doginhispen.com

A.doginhispen.com

This removes all entries from the domain zones. I think this happened when I clicked a picture of a little white dog - then all the problems started. BleepingComputer is being sued by Enigma Software because of a negative post of SpyHunter. There has been no further appearance of "dog, ski, or 88" for 20 hours, but I am monitoring it. navigate here

I have read some of the other posts about this and it seems very difficult to fix. a name, then click "Create". Dismiss Notice TechSpot Forums Forums Software Virus and Malware Removal Today's Posts A.doginhispen.com and hisbrothers Bykingsbishop Jan 8, 2008 Page 1 of 2 1 2 Next > Hello from Italy! Next, close and click Yes to save the changes. http://www.bleepingcomputer.com/forums/t/131025/adoginhispencom/

Jan 9, 2008 #4 kingsbishop TS Rookie Topic Starter Posts: 24 Hello Momok and excuse me for my misunderstanding! As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged This will remove all the remaining nasties from your old restore points.

thanks in advance for any help rebel256, Feb 12, 2008 #1 This thread has been Locked and is not open to further replies. Press 1 then Enter. C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\CAPONN.EXE C:\WINDOWS\system32\dla\bak\tfswctrl.exe C:\WINDOWS\system32\bak\ctfmon.exe C:\Programmi\Toshiba\Windows Utilities\bak\Hotkey.exe C:\Programmi\Toshiba\Touch and Launch\bak\PadExe.exe C:\Programmi\Toshiba\TOSHIBA Zooming Utility\bak\SmoothView.exe C:\Programmi\Toshiba\TOSCDSPD\bak\toscdspd.exe C:\Programmi\Synaptics\SynTP\bak\SynTPLpr.exe C:\Programmi\Synaptics\SynTP\bak\SynTPEnh.exe C:\Programmi\QuickTime\bak\qttask.exe C:\Programmi\Nero\Nero8\Nero BackItUp\bak\NBKeyScan.exe C:\Programmi\Lexmark X1100 Series\bak\lxbkbmgr.exe C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\bak\kav.exe C:\Programmi\iTunes\bak\iTunesHelper.exe C:\Programmi\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe C:\Programmi\File comuni\Nero\Lib\bak\NeroCheck.exe C:\Programmi\ATI Press 2 then Enter.

I found this site by doing a search for these website problems and I am so glad I did. When done, a text file, Find AWF report will be produced. Again, THANK YOU!!! Instead, open a new thread in our Security and The Web forum.

It then moves the original clean executable to \bak\.exe. Regards KsB Jan 14, 2008 #9 momok TS Rookie Posts: 2,265 Hi, Run FindAWF again. Please don't post your own virus/spyware problems in this thread. Also should I keep deleting these sites?

Regards, momok =) This thread is for the use of kingsbishop only. https://otx.alienvault.com/indicator/hostname/a.doginhispen.com/ Please download and run CCleaner via step 9 of the instructions HERE. Regards, momok =) This thread is for the use of kingsbishop only. Zones have been reset".After resetting the domain zones, the program will return to the main menu.Press E then 'Enter' to EXIT.Note: If you had manually added any sites in the trusted

A text file named files.txt will open: Copy and paste the following text from the quote box below into the text file. I thought TrendMicro would stop this; it did block the websites, but not the changes. Privacy Policy Rules · Help Advertise | About Us | User Agreement | Privacy Policy | Sitemap | Chat | RSS Feeds | Contact Us Tech Support Forums | Virus Removal Here is the new file.

This trojan tries to download other malware from various websites and also lowers security settings on the compromised machine. Please run AVG again properly by setting all actions to quarantine; read through the instructions carefully and follow them exactly. C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\CAPONN.EXE C:\WINDOWS\system32\dla\bak\tfswctrl.exe C:\WINDOWS\system32\bak\ctfmon.exe C:\Programmi\Toshiba\Windows Utilities\bak\Hotkey.exe C:\Programmi\Toshiba\Touch and Launch\bak\PadExe.exe C:\Programmi\Toshiba\TOSHIBA Zooming Utility\bak\SmoothView.exe C:\Programmi\Toshiba\TOSCDSPD\bak\toscdspd.exe C:\Programmi\Synaptics\SynTP\bak\SynTPLpr.exe C:\Programmi\Synaptics\SynTP\bak\SynTPEnh.exe C:\Programmi\QuickTime\bak\qttask.exe C:\Programmi\Nero\Nero8\Nero BackItUp\bak\NBKeyScan.exe C:\Programmi\Lexmark X1100 Series\bak\lxbkbmgr.exe C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\bak\kav.exe C:\Programmi\iTunes\bak\iTunesHelper.exe C:\Programmi\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe C:\Programmi\File comuni\Real\Update_OB\bak\realsched.exe C:\Programmi\File comuni\Nero\Lib\bak\NeroCheck.exe C:\Programmi\ATI dz4920 Back to top #9 quietman7 quietman7 Bleepin' Janitor Global Moderator 47,093 posts OFFLINE Gender:Male Location:Virginia, USA Local time:03:05 PM Posted 16 February 2008 - 09:10 AM If there are

Staff Online Now etaf Moderator valis Moderator cwwozniak Trusted Advisor TheShooter93 Malware Specialist Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > When the program returns to the main menu, use the following option: Press E then Enter to EXIT Delete the following folder: C:\QooBox\Quarantine\C\WINDOWS Thereafter, please post fresh HJT and AVG Antispyware Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers.

Login now.

IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) Can the computer be rebooted without those sites reappearing? doginhispen.com also displays excessive pop-up advertisements on the infected systems. A text file named folders.txt will open.

For example, if the following registry entry existed on the affected machine: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Foo ="%Program Files%\foo.exe" the trojan may copy itself to %Program Files%\foo.exe and create a copy of the clean foo.exe Save it on your Desktop. 2. Back to top #4 dz4920 dz4920 Topic Starter Members 7 posts OFFLINE Local time:02:05 PM Posted 14 February 2008 - 10:27 PM Quietman7 I wanted to add something to the Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List

Join the community here. I have Windows XP Home and Trend Micro Internet Security which indicates that it is blocking the website "a.doginhispen.com/favicon.ico" and "a.doginhispen.com/150/in/htmlg" About the time this happened I could not sign in Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe