PDA

View Full Version : Adware issue-can't remove


frateman
June 12th, 2006, 07:06 AM
I was scanning and found E:\I386\Apps\APP20386\src\HPSummer2005.exe »WISE »s4Setp.exe - a variant of Win32/AdInstaller application
i read the thread that someone else that found this and I tried the removel tool someone linked to. It doesn't work I get error msg. This spyware is in my partition that holds my windows restore info. I can't reformat that area to rid myself of this. How can I get rid of this???HELP!!

pc-support
June 12th, 2006, 07:25 AM
Judging by the path to the file I would say that this is a false positive. The HPSummer2005 file appears to be a bit of advertising by HP.

Anyone else think this?

ASpace
June 12th, 2006, 07:55 AM
Yes , can be a false positive however I have seen real threats hiding in this folder/path .

Frateman , open NOD32's Control Center -> NOD32 System Tools -> Quarantine and add this file there . Then submit it for analyze to ESET and write it can be a false positive . Also write them the path .

When it is in the quarantine , please boot in Safe Mode and remove it manually (HPSummer2005.exe)
To boot in Safe Mode , you need to continuously hit F8 while Windows is starting , after the BIOS loads and before the Windows logo appears . Then you'll open Windows Advanced Menu and you choose Safe Mode . Wait for a second and go ahead

Download Ad-Aware SE Personal (www.lavasoftusa.com)
Install , update and perform full scan with it and remove all the threats found.Again scan with NOD32 and that's it ;D

Because of the fact the file is in the quarantine you can restore it in future if something goes wrong

:)