Kill Windows Messenger - http://vlaurie.com/computers2/Articles/messenger.htm
* Click here
to download smitRem.exe.
- Save the file to your desktop.
- It is a self extracting file.
- Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
- Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.
* Download the trial version of Ewido Security Suite here
- Install ewido.
- During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
- Launch ewido
- It will prompt you to update click the OK button and it will go to the main screen
- On the left side of the main screen click update
- Click on Start and let it update.
- DO NOT run a scan yet. You will do that later in safe mode.
* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.
* Restart your computer into safe mode now. Perform the following steps in safe mode:
* Open the smitRem
folder, then double click the RunThis.bat
file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
* Run Ewido:
- Click on scanner
- Click Complete System Scan and the scan will begin.
- During the scan it will prompt you to clean files, click OK
- When the scan is finished, look at the bottom of the screen and click the Save report button.
- Save the report to your desktop
* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.
* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.
* Restart back into Windows normally now.
* Run http://www.kaspersky.com/virusscanner
- Online scan
When the scan is finished Save the results from the scan!Post a new HiJackThis log along with the results from Kaspersky and Ewido