Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below. Also if you have any programs that may prevent system changes (like Spybot's TeaTimer program, Ad-aware's Ad-Watch, and others), make sure you disable them before doing any of the fixes (or accept the changes for the fix we give you when asked by the programs).
Download CleanUp!
http://cleanup.stevengould.org/ (Alternate Link if main link don't work -
http://www.greyknight17.com/spy/CleanUp.exe ) and install it. CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.
Reboot into Safe Mode.(tapping F8 or F5)
Copy the file names below to the clipboard by highlighting them and pressing Ctrl-C:
C:\WINDOWS\teller2.chk
C:\WINDOWS\secure32.html
Start KillBox.
Go to the
File menu, and choose
Paste from Clipboard.
*Verify that you've done this properly by clicking the dropdown-arrow next to the Full Path of File to Delete field. The filenames you pasted will be found in there.
Select/tick the following:
*
Delete on Reboot
*
End Explorer Shell While Killing File
*
Unregister.dll Before Deleting" if it's not grayed out.
Click the RED X button.
Click [
Yes] at the
'Delete on Reboot' prompt. Click [
Yes] at the
Pending Operations prompt.
Reboot and run another Panda Scan. Post the log and another HijackThis log.
__________________
I won a nobel prize too!!