Please read this post completely before begining the fix.
Right click on this & choose "Save As..." DelO15Domains.inf -
DelO15Domains.inf
Right click on
DelO15Domains.inf and choose Install. It will run immediately (you won't be able to see anything happen). You may delete the file afterwards.
Host.zip - From within Host.zip, double click on
MVPS.bat & allow it to run.
Right click on this & select 'Save As' -
DNSManual.bat
Doubleclick on
DNSManual.bat & allow it to run.
SpywareBlaster 3.5.1
Install & update SpywareBlaster with the latest definitions.
After you have updated, click the button -
enable protection for all unprotected items
IE-SpyAD - Extract the contents to a new folder
From within the folder, double-click
install.bat
Select Option #2 -
Install the new IE-SPYAD list.
Then return to the main menu.
Select option #4 -
Add the old porn sites domain
* * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * *
If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools -> Folder Options -> View tab.
- Tick - 'Show hidden files and folder'
- Untick - 'Hide file extensions for known types'
- Untick - 'Hide protected operating system files'
- Click Yes to confirm & then click OK
Locate and delete the following files/folders: (let me know if you fail to find/delete any)
- C:\Documents and Settings\Quincy Vagell\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-5fa77070.zip
C:\Documents and Settings\Quincy Vagell\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-1dbf9af3-7da7d147.zip
C:\Documents and Settings\Quincy Vagell\My Documents\progs, etc\CooolSoft.Power.MP3.WMA.Converter.2006.v3.42b. WinALL.Cracked-ViRiLiTY\crack-inf.exe
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider initially to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program.
6. Do NOT reboot/logoff if prompted.
* * * * * * USING HIJACKTHIS' DELETE ON REBOOT * * * * * *
Start HiJackThis & go to Config>Misc.Tools>
Delete a file on reboot... - In the popup box that appears, copy/paste in:
- C:\WINDOWS\SYSTEM32\ursst.dll
- Click the Open button.
- Click YES when prompted to restart your computer.
This will clear the System Volume Information folder
Go to Start >> Run - type
control sysdm.cpl,,4 & press Enter
- Tick on the checkbox - Turn off System Restore on all drives
- Click Apply
Turn it back 'On' by unticking the same checkbox & click OK
Once you have completed the above, please post a fresh HJT log & let me know how the machine is behaving now.
__________________
Question - what have you done for the community today?