Quote:
|
Originally Posted by bojang1es
Ok, I could only find one file for Kaspersky Anti-Virus v7.0.1.321 so Im not sure what to remove.
|
If only one entry is installed then that is ok.
-----------
Please follow all instructions and in which order they come, if you have any questions, please ask before proceeding. Its important that you follow this through until i give you the all clear, a lack of symptoms does not mean that it is no longer present.
==========
Open HijackThis and click on 'Do a System Scan Only'. Check the following entries
(If they still exist, make sure you do not miss any)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Please remember to close all other windows, including browsers then click Fix checked.
==========
Go to
My Computer >Tools >Folder Options >View tab and
select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside
Hide file extensions for known file types. Click OK.
============
Delete the following Files indicated in
RED and Folders indicated in
BLUE if they still exist.
C:\Documents and Settings\All Users\Application Data\Browse Dent Win Base
C:\Documents and Settings\All Users\Application Data\Viewpoint
If they resist, boot into safe mode and delete there.
===========
JAVA OUTDATED
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.- Download the latest version of Java Runtime Environment (JRE) 6 Update 5 and save it to your desktop.
- Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
- Click the "Download" button to the right.
- Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.
- Click on the link to download Windows Offline Installation and save the file to your desktop.
- Close any programs you may have running - especially your web browser.
- Go to Start > (Settings) > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
- Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java versions.
- Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-6u5-windows-i586-p.exe to install the newest version.
- After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
- On the General tab, under Temporary Internet Files, click the Settings button.
- Next, click on the Delete Files button
- There are two options in the window to clear the cache - Leave BOTH Checked
- Applications and Applets
Trace and Log Files
- Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
- Click OK to leave the Temporary Files Window
- Click OK to leave the Java Control Panel.
==========
BitDefender Online Scan
Go
here and do the BitDefender online virus scan.
* Click "I Agree" to agree to the EULA.
* Allow the ActiveX control to install when prompted.
* Leave the scanning options at default and press "Click here to scan" to begin the scan.
* Please refrain from using the computer until the scan is finished.
* When the scan is finished, click on "Click here to export the scan results"
* Save the report to your desktop then come back here and post it in your next reply along with the required logs.
============
Run Deckard System Scanner(DSS) again
=============
Logs Required
Bitdefender Scan Results
Main.txt
How is your system running now.
__________________
Member of ASAP since 2007
Member of UNITE since 2008
**Notice to BT customers**
Trial of BT-Phorm spyware to start 30th September, 2008- for more information please visit
No DPI website for more information.
Phorm, previously known as 121Media were responsible for the Apropos rootkit, see
Here for more information on said rootkit.
If we have helped you in anyway,please consider Donating