View Single Post
Old 06-16-2008, 10:13 PM   #9 (permalink)
chemist
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,228
OS: XP SP3


Re: Virus, Constant Popups, Rundll32.exe error, userinit.exe error

Hello again, greenoznic.

Please save this page to Notepad in order to assist you when carrying out the following instructions.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding.
Ensure that there aren't any opened browsers when you are carrying out the procedures below.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

------------------------------------------------------

You have installed Messenger Plus! 3. This program is known to install malware. If the program is a must have, reinstall it and decline when asked to install the sponsor's software.

------------------------------------------------------
  • Please download fl.zip and Save it to your Desktop.
  • Extract the contents to a new folder on your Desktop.
  • Within the folder, locate & double-click fl.bat
  • It should produce a report at C:\findlop.txt. Post the contents of the report in your next reply.
------------------------------------------------------

Delete dss.exe from your desktop if it still exists.

Delete the following Folder if it still exists:

C:\Deckard

------------------------------------------------------

You have old versions of Java still installed. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components.
  • Close any programs you may have running - especially your web browser.
  • Go to Start(or My Computer) > Control Panel and click on Add or Remove Programs
  • Click (highlight) the following items:
    • J2SE Runtime Environment 5.0 Update 10
    • J2SE Runtime Environment 5.0 Update 7
    • J2SE Runtime Environment 5.0 Update 9
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Restart your computer once all Java components are removed.
------------------------------------------------------

Please download Deckard's System Scanner (DSS) and Save it to your Desktop. Note: You must be logged onto an account with administrator privileges.
  1. Close all applications and windows.
  2. Double-click on dss.exe to run it, and follow the prompts.
  3. When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
  4. Copy (Ctrl+A then Ctrl+C) and Paste (Ctrl+V) the contents of main.txt here.
  5. Please attach extra.txt to your post.
To attach a file to a new post, simply
  1. Click the Manage Attachments button under Additional Options > Attach Files on the post composition page, and
  2. Copy and Paste the following into the Upload File from your Computer box:
    C:\Deckard\System Scanner\extra.txt
  3. Click Upload
What DSS will do:
  • create a new System Restore point in Windows XP and Vista.
  • clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
  • check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
------------------------------------------------------

Please post the following in your next reply:

C:\findlop.txt
main.txt
an attached extra.txt
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline