View Single Post
Old 11-30-2005, 06:43 AM   #5 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,030
OS: WinXP and Vista


Hello,

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! (Alternate Link if main link doesn't work) and install it. Do not run it yet.

Reboot into Safe Mode.

Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.

Click on Start->Settings->Control Panel->Java Plug-in and click on the Cache tab. Then click on the Clear button and hit OK.

Delete this file:

C:\WINNT\SYSTEM32\DRIVERS\ETC\hosts.bho

Follow these entire paths and empty the Inbox and Deleted Items:

C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{FCA073A6-0508-482E-A374-FCD3D7E88BB5}\Microsoft\Outlook Express\Inbox.dbx <--Empty this folder

C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{FCA073A6-0508-482E-A374-FCD3D7E88BB5}\Microsoft\Outlook Express\Deleted Items.dbx <--Empty this folder

---------------------------

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Standard CleanUp!"
*Uncheck the following:
-Delete Newsgroup cache
-Delete Newsgroup Subscriptions
-Scan local drives for temporary files
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.
Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility

Reboot into Normal Mode.

Run another scan with Kaspersky and post the results here along with a new HijackThis log.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline