View Single Post
Old 11-07-2008, 07:23 AM   #5 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,583
OS: WinXP and Vista


Re: Infected by trojans in pseudo-codec

You're welcome, yst_dfm. : )


Have you installed the Recovery Console yet? You really should have done that before running the tools.

Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.


***************************************************

Close any open browsers.

--------------------------------------------------------------------


Open HijackThis and click on 'Do a System Scan Only'. 'Check' the following entries:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)



Click 'Fix Checked' and close HijackThis.

--------------------------------------------------------------------


Open notepad and copy/paste the entire text in the quote box below: (don't forget to copy and paste REGEDIT4)

Quote:

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{47ef56aa-6010-11dd-bf5c-d22a445c9a20}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ebbc4ec1-d087-11da-b82d-806d6172696f}]

Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:

Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

--------------------------------------------------------------------

What are your I: and D: drives?

Do you know what this scheduled task is for? Is it something you created?
2008-10-31 C:\WINDOWS\Tasks\Temp.job
- C:\WINDOWS\Temp [2008-11-01 04:35]
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline