Hi Pat here is it again
You may need to enable hidden files & folders to find the
file as its in the system32 folder,you could use killbox
and paste the C\Windows\System32\sysdebug32.exe line in
then press delete on reboot or search for it manually,
To make it easier enable hidden files and folders if your
searching for the file.
Go to Start then search > goto tools on the top bar> then
click Folder Options-> then goto the View tab .
make sure that 'Show hidden files and folders' is
enabled. 'Display the contents of system folders' is
checked & 'Hide extentions for known file types ' is not
checked then press apply
You can set this back later by opening the same page and
pressing 'restore defaults' then pressing apply,
Windows XP's search feature is a little different. When
searching you click on 'All files and folders' on the
left pane,
click on the 'More advanced options' at the bottom. Make
sure that Search system folders, Search hidden files and
folders, and Search subfolders are checked.
Once you have done this you can then goto search,then all
files & folders and search for :
sysdebug32.exe
Or follow the path to the file.click start > then my
computer > then WINDOWS > then System32 > and check for
sysdebug32 (they are all listed in order in the folder so
it should be easy to find if it still exists)
If found delete,again if you have problems deleting it
goto Task Manager(Control,alt & delete) then check the
processes tab for the file (press name to sort them into
order)and end process if found,then try delete again
If you still have problems deleting it right click the
file and choose properties check the Attributes part at
the bottom for any restrictions.Uncheck both 'hidden'
& 'read only' if found then apply and try delete again
If its still refusing to go you could rename it but i
think using Killbox would be easier,Its a great tool for
files that dont want to quit
Hijack this is good to show whats on your pc,it makes it
alot easier when your trying to fix malware as you can
see whats really going on,There's a few sites where you
can copy & paste your hijack this logs to which gives you
some info on each entry (because some malware uses
genuine filenames ive seen the scanner give false results
in the past but they are very usefull as a starting point)
get advise about anything your unsure about though.
http://www.hijackthis.de/en
http://hjt.iamnotageek.com/
http://www.help2go.com/modules.php?name=HJTDetective
With the prefetch folder it is suprising how fast it
builds up in there but generally they are all harmless
and are there to help programs open faster but if you get
malware clearing the prefetch folder always helps and any
genuine programs will use the folder again when its
needed.Ccleaner is usefull for that i use it myself
everyday before shutting the pc down and its suprising
how much junk it removes.
If you feel the problems still exist or think there may
be other problems then you can send me the hijack log and
id check all the entries,either post it on here or email
it,But if all your scanners are now showing clean it may
not be needed,its up to you though,Let me know if your
hijack logs contain any 015 or 01 entries as they are
added as a result of malware . If you are clean again
you can re-enable system restore.
Here's two other free downloads that might help you keep
clean :
Spyware Blaster
http://downloads.net-
integration.net/spywareblastersetup34.exe
Prevent's the installation of ActiveX-based spyware,
adware, browser hijackers, dialers, and other potentially
unwanted pests.
Block spyware/tracking cookies in Internet Explorer and
Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in
Internet Explorer.And unlike other programs,
SpywareBlaster does not have to remain running in the
background.SpywareBlaster is freeware for personal and
educational use
Spyware Guard
http://www.javacoolsoftware.net/downloads/spywareguardsetu
p.exe
SpywareGuard provides a real-time protection solution
against spyware that is a great addition to
SpywareBlaster's protection method.
Download Protection - prevent spyware from being download
in Internet Explorer
Browser Hijacking Protection - stop browser hijacking
activity in real-time
Regards
Andy Manc
..