View Single Post
Old 01-08-2006, 01:48 PM   #5 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,341
OS: N/A


Reboot to Safe Mode


Once in Safe Mode,, Go to Start->Run and type in regsvr32 /u occache.dll and hit OK.


If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools -> Folder Options -> View tab.
  • Tick - 'Show hidden files and folder'
  • Untick - 'Hide file extensions for known types'
  • Untick - 'Hide protected operating system files'
  • Click Yes to confirm & then click OK
Locate and delete the following files/folders: (let me know if you fail to find/delete any)
  • C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc hive1213.jar-353c96ce-69408b8b.zip
    C:\Documents and Settings\Matthew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc hive1213.jar-61c76c7d-15f16422.zip
    C:\Program Files\Internet Explorer\BTOW Shared Files\btwebcontrol.dll
    C:\WINDOWS\Downloaded Program Files\240044__.exe511
    C:\WINDOWS\Downloaded Program Files\240240__.exe333

Go to Start->Run and type in regsvr32 occache.dll and hit OK.


This will clear the System Volume Information folder
Go to Start >> Run - type control sysdm.cpl,,4 & press Enter
  • Tick on the checkbox - Turn off System Restore on all drives
  • Click Apply
Turn it back 'On' by unticking the same checkbox & click OK


Post a new HJT log. Tell me if Counterspy still finds those severe risks.
__________________

Question - what have you done for the community today?
sUBs is offline