Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help


  • This topic is locked This topic is locked
3 replies to this topic

#1 lockdown

lockdown

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 20 August 2005 - 11:41 PM

Sup guys I have a big problem to day i was looking for a key for nero I know i should but just being honest so I go to the site I usually do and never ever had a problem. Well all of a sudden while im trying to connect to the site it turns into a big popup window and and my internet expoler gets a error and closes down on me.

After that I bring up IE again and my homepage is not google and i have things that are installed on my computer that I didn't agree to or it accept on the site. I know what to whatch on for on sites and never had this problem this is the first.

So the steps i took was installed search & destory rebooted my computer into safe mode and ran the program and it found stuff did all the steps to remove it. Then I rebooted and it was still installed and getting popups when I bring up my system.

Is this even LEGAL since I didn't agree or it accept on any kind of button. I really feel that they just ruined my os and need help to get ride of this. So here is the log file.

Logfile of HijackThis v1.99.1
Scan saved at 11:29:00 PM, on 8/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ntlw.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Adam\Desktop\HijackThis1991.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {4982D30C-67C2-4EDC-B9FB-50B7DB64D84D} - C:\WINDOWS\system32\mfcij32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ntlw.exe] C:\WINDOWS\system32\ntlw.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\RunOnce: [msyu32.exe] C:\WINDOWS\msyu32.exe
O4 - HKLM\..\RunOnce: [javaft32.exe] C:\WINDOWS\javaft32.exe
O4 - HKLM\..\RunOnce: [apisd.exe] C:\WINDOWS\system32\apisd.exe
O4 - HKLM\..\RunOnce: [d3dh32.exe] C:\WINDOWS\d3dh32.exe
O4 - HKLM\..\RunOnce: [netga.exe] C:\WINDOWS\system32\netga.exe
O4 - HKLM\..\RunOnce: [apisf32.exe] C:\WINDOWS\system32\apisf32.exe
O4 - HKLM\..\RunOnce: [sdkuy32.exe] C:\WINDOWS\system32\sdkuy32.exe
O4 - HKLM\..\RunOnce: [iebj32.exe] C:\WINDOWS\iebj32.exe
O4 - HKLM\..\RunOnce: [msqc32.exe] C:\WINDOWS\system32\msqc32.exe
O4 - HKLM\..\RunOnce: [msoa32.exe] C:\WINDOWS\msoa32.exe
O4 - HKLM\..\RunOnce: [d3yw.exe] C:\WINDOWS\system32\d3yw.exe
O4 - HKLM\..\RunOnce: [netzf32.exe] C:\WINDOWS\netzf32.exe
O4 - HKLM\..\RunOnce: [appia32.exe] C:\WINDOWS\appia32.exe
O4 - HKLM\..\RunOnce: [atlsk32.exe] C:\WINDOWS\atlsk32.exe
O4 - HKLM\..\RunOnce: [javauq.exe] C:\WINDOWS\system32\javauq.exe
O4 - HKLM\..\RunOnce: [sdkdm32.exe] C:\WINDOWS\system32\sdkdm32.exe
O4 - HKLM\..\RunOnce: [cras32.exe] C:\WINDOWS\cras32.exe
O4 - HKLM\..\RunOnce: [winkl32.exe] C:\WINDOWS\winkl32.exe
O4 - HKLM\..\RunOnce: [sdkrt.exe] C:\WINDOWS\sdkrt.exe
O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
O4 - HKLM\..\RunOnce: [apigr32.exe] C:\WINDOWS\system32\apigr32.exe
O4 - HKLM\..\RunOnce: [addfe32.exe] C:\WINDOWS\addfe32.exe
O4 - HKLM\..\RunOnce: [netpu.exe] C:\WINDOWS\netpu.exe
O4 - HKLM\..\RunOnce: [d3tm32.exe] C:\WINDOWS\system32\d3tm32.exe
O4 - HKLM\..\RunOnce: [sdkaw.exe] C:\WINDOWS\system32\sdkaw.exe
O4 - HKLM\..\RunOnce: [iefx.exe] C:\WINDOWS\iefx.exe
O4 - HKLM\..\RunOnce: [sysnd.exe] C:\WINDOWS\sysnd.exe
O4 - HKLM\..\RunOnce: [nethp.exe] C:\WINDOWS\nethp.exe
O4 - HKLM\..\RunOnce: [iecy32.exe] C:\WINDOWS\system32\iecy32.exe
O4 - HKLM\..\RunOnce: [sdkmr.exe] C:\WINDOWS\system32\sdkmr.exe
O4 - HKLM\..\RunOnce: [atlbt.exe] C:\WINDOWS\system32\atlbt.exe
O4 - HKLM\..\RunOnce: [javaka32.exe] C:\WINDOWS\javaka32.exe
O4 - HKLM\..\RunOnce: [crsf32.exe] C:\WINDOWS\crsf32.exe
O4 - HKLM\..\RunOnce: [atlnf.exe] C:\WINDOWS\system32\atlnf.exe
O4 - HKLM\..\RunOnce: [d3vf.exe] C:\WINDOWS\d3vf.exe
O4 - HKLM\..\RunOnce: [sysek.exe] C:\WINDOWS\system32\sysek.exe
O4 - HKLM\..\RunOnce: [d3er32.exe] C:\WINDOWS\d3er32.exe
O4 - HKLM\..\RunOnce: [netyi.exe] C:\WINDOWS\netyi.exe
O4 - HKLM\..\RunOnce: [ntyv32.exe] C:\WINDOWS\system32\ntyv32.exe
O4 - HKLM\..\RunOnce: [msqu32.exe] C:\WINDOWS\msqu32.exe
O4 - HKLM\..\RunOnce: [apifp32.exe] C:\WINDOWS\apifp32.exe
O4 - HKLM\..\RunOnce: [msnv32.exe] C:\WINDOWS\system32\msnv32.exe
O4 - HKLM\..\RunOnce: [appre.exe] C:\WINDOWS\system32\appre.exe
O4 - HKLM\..\RunOnce: [apivd32.exe] C:\WINDOWS\system32\apivd32.exe
O4 - HKLM\..\RunOnce: [apiwj32.exe] C:\WINDOWS\apiwj32.exe
O4 - HKLM\..\RunOnce: [javavc32.exe] C:\WINDOWS\javavc32.exe
O4 - HKLM\..\RunOnce: [iepz.exe] C:\WINDOWS\iepz.exe
O4 - HKLM\..\RunOnce: [sysdj32.exe] C:\WINDOWS\sysdj32.exe
O4 - HKLM\..\RunOnce: [mfcva.exe] C:\WINDOWS\system32\mfcva.exe
O4 - HKLM\..\RunOnce: [atlkv.exe] C:\WINDOWS\system32\atlkv.exe
O4 - HKLM\..\RunOnce: [iedt32.exe] C:\WINDOWS\system32\iedt32.exe
O4 - HKLM\..\RunOnce: [sysmz.exe] C:\WINDOWS\system32\sysmz.exe
O4 - HKLM\..\RunOnce: [sdkln32.exe] C:\WINDOWS\system32\sdkln32.exe
O4 - HKLM\..\RunOnce: [javael32.exe] C:\WINDOWS\javael32.exe
O4 - HKLM\..\RunOnce: [ieip.exe] C:\WINDOWS\ieip.exe
O4 - HKLM\..\RunOnce: [mfcmz.exe] C:\WINDOWS\mfcmz.exe
O4 - HKLM\..\RunOnce: [ipfx.exe] C:\WINDOWS\ipfx.exe
O4 - HKLM\..\RunOnce: [cryu32.exe] C:\WINDOWS\system32\cryu32.exe
O4 - HKLM\..\RunOnce: [mspo.exe] C:\WINDOWS\system32\mspo.exe
O4 - HKLM\..\RunOnce: [iesl.exe] C:\WINDOWS\iesl.exe
O4 - HKLM\..\RunOnce: [ienc32.exe] C:\WINDOWS\ienc32.exe
O4 - HKLM\..\RunOnce: [sysst32.exe] C:\WINDOWS\sysst32.exe
O4 - HKLM\..\RunOnce: [mfcwl32.exe] C:\WINDOWS\mfcwl32.exe
O4 - HKLM\..\RunOnce: [apier32.exe] C:\WINDOWS\apier32.exe
O4 - HKLM\..\RunOnce: [ieho.exe] C:\WINDOWS\system32\ieho.exe
O4 - HKLM\..\RunOnce: [netcx32.exe] C:\WINDOWS\system32\netcx32.exe
O4 - HKLM\..\RunOnce: [ntbf32.exe] C:\WINDOWS\ntbf32.exe
O4 - HKLM\..\RunOnce: [atlop.exe] C:\WINDOWS\atlop.exe
O4 - HKLM\..\RunOnce: [wintz32.exe] C:\WINDOWS\wintz32.exe
O4 - HKLM\..\RunOnce: [crgj32.exe] C:\WINDOWS\crgj32.exe
O4 - HKLM\..\RunOnce: [mfcgh.exe] C:\WINDOWS\system32\mfcgh.exe
O4 - HKLM\..\RunOnce: [d3xd32.exe] C:\WINDOWS\d3xd32.exe
O4 - HKLM\..\RunOnce: [javawu32.exe] C:\WINDOWS\system32\javawu32.exe
O4 - HKLM\..\RunOnce: [sdkhc32.exe] C:\WINDOWS\sdkhc32.exe
O4 - HKLM\..\RunOnce: [apifl.exe] C:\WINDOWS\apifl.exe
O4 - HKLM\..\RunOnce: [addcn32.exe] C:\WINDOWS\system32\addcn32.exe
O4 - HKLM\..\RunOnce: [ipvv32.exe] C:\WINDOWS\system32\ipvv32.exe
O4 - HKLM\..\RunOnce: [javadb.exe] C:\WINDOWS\javadb.exe
O4 - HKLM\..\RunOnce: [iehd.exe] C:\WINDOWS\iehd.exe
O4 - HKLM\..\RunOnce: [ipsq.exe] C:\WINDOWS\ipsq.exe
O4 - HKLM\..\RunOnce: [mfcjj32.exe] C:\WINDOWS\system32\mfcjj32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Network Security Service ( 11F#`I) - Unknown owner - C:\WINDOWS\msyu32.exe"  /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



BC AdBot (Login to Remove)

 


m

#2 lockdown

lockdown
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 20 August 2005 - 11:42 PM

What do i need to do with hijack to get ride of this stuff?
forgot to ask sorry.

#3 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,717 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:01:19 AM

Posted 23 August 2005 - 09:50 AM

Hello lockdown and welcome to BleepingComputer.


Please read through the instructions before you start (you may want to print this out or copy it into a word program).


Download and install the trial version of Ewido Security Suite.
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
- Launch Ewido, there should be an icon on your desktop double-click it.
- When you run Ewido for the first time, you will get a warning "Database could not be found!".
- The program will prompt you to update; click the OK button.
- The program will now go to the main screen.
- On the left hand side of the main screen click update.
- Click on Start.

The update will start and a progress bar will show the updates being installed.
Once the updates are installed, close Ewido. Tutorial if needed


Download AboutBuster.zip.
- Unzip the contents of AboutBuster.zip to it's own folder.
- Navigate to the AboutBuster folder and double-click on AboutBuster.exe.
- Click Update to begin the update process.
- If any updates exist please install them.
- Close AboutBuster by clicking on Exit. AboutBuster will be used later.


Download HSfix.zip.
- Unzip it to your desktop.
- It will be used later.


Download CWShredder.exe.
- Save it to your desktop.
- It will be used later.


Open Windows Explorer (Windows key +e):
- From the top menu, click on Tools, then Folder Options.
- Open the View tab.
- Check "Show hidden files and folders".
- UNCheck "Hide protected operating system files" and "hide extensions for known file types".
- Click on "Apply to all folders", Apply, then OK.


+++++++++++++++++++++++++++++++++++++++++++++++++

Boot into Safe Mode.


Click on Start, Run, type in services.msc and click the Ok button.
- Locate the Network Security Service service and double click on it.
- Click the Stop button.
- In the Startup type dropdown select Disabled.
- Click the Apply button and then the Ok button.

Close the Services window.


Start HJT and click on the SCAN button. Put a check mark in front of the following lines if they still show:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\wjifm.dll/sp.html#17702
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {4982D30C-67C2-4EDC-B9FB-50B7DB64D84D} - C:\WINDOWS\system32\mfcij32.dll

O4 - HKLM\..\Run: [ntlw.exe] C:\WINDOWS\system32\ntlw.exe

O4 - HKLM\..\RunOnce: Check for removal ALL of these 'RunOnce' entries.

O23 - Service: Network Security Service ( 11F#`I) - Unknown owner - C:\WINDOWS\msyu32.exe" /s (file missing)

With ALL OTHER WINDOWS CLOSED, click on Fix Checked.


Open Windows Explorer (Windows key+e), navigate to and delete the following files (Don't be concerned if they can not be found):

C:\WINDOWS\system32\wjifm.dll
C:\WINDOWS\system32\mfcij32.dll
C:\WINDOWS\system32\ntlw.exe
C:\WINDOWS\msyu32.exe


Double-click on the HSfix.reg file previously saved to the desktop.
- When it prompts to add or merge, say yes.


Open CWShredder.
- Run CWShredder by clicking on the FIX button, and allow it to complete.


Browse to where you saved AboutBuster and double click AboutBuster.exe.
- Click Begin removal to allow AboutBuster to scan.
- When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK.
- Another information window will open. Click on Exit.
- AboutBuster will inform you that a log has been created. Click OK.


Run Ewido Security Suite:
- Click on scanner.
- Click on Complete System Scan.
- Let the program scan the machine.

We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
- Click Save report.
- Save the report to your desktop.


Run Disk Cleanup
- Click on the Start button and then on Run.
- Type in cleanmgr then click on OK.
- Be sure the (C:) drive is selected and click OK.
It may take a bit for "Compress old files" to complete.
- Check all the boxes and click on OK, then OK again.


Reboot into normal mode.


Open Internet Explorer and do an online virus scan at the following site:
TrendMicro Housecall
- Select 'Complete Scan', then check 'My Computer'.


Reboot and post a fresh HJT log back here by using the add reply button below, and lets see how we did. (Note: Please do not put your HJT login a quote box - it makes it harder to read.)
Derfram
~~~~~~

#4 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,717 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:01:19 AM

Posted 07 September 2005 - 09:48 AM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
Derfram
~~~~~~




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users