This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Mleady-MWR

14 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from July 19, 2007, 10:16 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Scotty Retired Graduate
Well, I do believe there is only need for one real-time scanner so I'llmake the suggestion first of uninstalling Defender. I'll take my time with her and just post back when I actually come to do a fix?
askey127 Admin/Teacher
OK.
Scotty Retired Graduate
Hi Askey

Is it something Im doing, or not doing? That 023 just wont go away.
askey127 Admin/Teacher
The batch file is not correct:
@echo off
sc stop "Content Monitoring Tool"
sc delete "Content Monitoring Tool"
del Fixservices.bat
exit


should be:

Open Notepad and choose [b]File, New[/b]
Copy the content of the quote box below into notepad.
[quote]@echo off
sc stop "Content Monitoring Tool"
sc disable "Content Monitoring Tool"
sc delete msCMTSrvc
[/quote]
Use Notepad's [b]File, Save As[/b] and save to your desktop as FileType [b]All Files[/b] and Filename [b]FixService.bat[/b]
Do not save as File Type [b]Text[/b] or it won't work.
Exit Notepad

Then double-click [b]FixService.bat[/b] on your desktop.



sc delete always needs the name in parentheses in the O23 line.
Then the O23 line can be removed in HJT if it's still there.

Post it and get one more HJT log.
Scotty Retired Graduate
Im getting some great replies today! Tried google but cant find a definitive answer. Maybe it's something to do with (file missing)?
Im just guessing now.
askey127 Admin/Teacher
Mistakenly posted this in the real thread instead of here.
Got to stop leaving both open at once!
That's twice in the same month!
I deleted it, but his ref to me is that.
suggested remove the kernel dump O4
and
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
and suggested that he was probably OK after that.
the O23 is only a minor nuisance.

He posted he's still worried about the McAfee malware.j note he's getting.
I don't know if it's just a heuristics catch (that name sounds like it).
No other AV's have noted that one yet.
Can't find out anything else online either.
Maybe you can ask the user if he is able to find out what file is involved and we can upload it to Virustotal or Jotti.


I would run a Kaspersky Online scan and see if it picks up anything.
If nothing, I would give the all clear.
Scotty Retired Graduate
Hi askey

Will do.
Scotty Retired Graduate
I should add, asking this op to id and find a file might be a bit much. :D
askey127 Admin/Teacher
Think I owe you a pint for this one.
Scotty Retired Graduate
OK. I think I can guide her to delete the two temp files and the My Websearch folder. How do you clear out Spysweeper's temp files?
askey127 Admin/Teacher
You don't need to delete the Spysweeper Temp files and they are probably protected. They are no risk to the user.

Go ahead and make up your post for the other stuff.
Scotty Retired Graduate
We have three files we need to delete. First these files:

Go to Start then My Computer and double-click on the Local Drive ( C ) icon.
You should see these two files.

47.tmp/data0002 and 47.tmp NSIS.

Right-click once on each and in the sub-menu that appears select Delete.

Stay in that same location and double-click on the Program Files folder.
Now seek out this file in there

Uninstall My Web Search.dll

right-click on it and select Delete.

Close all open windows then right-click on the Recycle-bin and select Empty Recycle Bin.

Let me know you have done that correctly or if you have any problems.
askey127 Admin/Teacher
47.temp may be a folder. Have User delete it whatever it is.

Post it.
Scotty Retired Graduate
Hello Askey

One more HJT log or All-Clean? She got the files.
askey127 Admin/Teacher
Looks OK.

All-clean
this one needs a few extra protections against the operator
SWBlaster prob a must in this case.

Good job

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.