View Single Post
Old 03-06-2006, 09:00 PM   #10 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,498
OS: N/A


Good work. Let's hit it when it's down

Please read this post completely before begining the fix.


Right click on this & choose "Save As..." DelO15Domains.inf - DelO15Domains.inf
Right click on DelO15Domains.inf and choose Install. It will run immediately (you won't be able to see anything happen). You may delete the file afterwards.

SpywareBlaster 3.5.1 - Install & update SpywareBlaster with the latest definitions.
After you have updated, click the button - enable protection for all unprotected items

IE-SpyAD - Extract the contents to a new folder
From within the folder, double-click install.bat
Select Option #2 - Install the new IE-SPYAD list.
Then return to the main menu.
Select option #4 - Add the old porn sites domain

Download KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)


* * * * * * KILLBOX * * * * * * * * * * * * * * * * * * * * * * *


Launch KillBox.exe & select the following options:
  • delete on Reboot
  • All files (if available)
Use your mouse to select all the filenames highlighted in blue & then right-click & select Copy
  • c:\WINDOWS\Downloaded Program Files\turbo.inf
    c:\WINDOWS\Downloaded Program Files\WUInst.dll
    c:\WINDOWS\Downloaded Program Files\ashton.inf
    c:\WINDOWS\SYSTEM\bk.exe
    c:\WINDOWS\SYSTEM\RFSAPI32.DLL
    c:\WINDOWS\SYSTEM\qodsregk.exe
    c:\WINDOWS\SYSTEM\SVROBJ.DLL
    c:\WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\RegistryCleaner.zip
    c:\WINDOWS\pf78.exe
    c:\My Documents\My Deliveries\cnet\setupmp3towav.exe
    c:\My Documents\ssbuilder3.exe
    c:\My Documents\BSINSTALL.exe
    c:\Program Files\Support.com\backup\ho\hosts\3397_50ca3e631_
    c:\NNSCAA638.EXE
    c:\ZICORN001.exe
    c:\ventfe1.exe
* Go to the File menu, and choose Paste from Clipboard
* Click the RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.


* * * * * * RESTART WINDOWS IN SAFE MODE * * * * * * * * * *


1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the option to run Windows in Safe Mode.


* * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * *


Locate and delete the following files/folders: (let me know if you fail to find/delete any)
  • c:\WINDOWS\browserxtras\
Delete the contents of this folder, leaving it empty:
  • c:\WINDOWS\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\

* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *


Run Cleanup! using the following configuration:

1. Click Options...
2. Set the slider initially to Standard CleanUp!
3. Uncheck the following:
  • Delete Newsgroup cache
  • Delete Newsgroup Subscriptions
4. Click OK
5. Press the CleanUp! button to start the program.


* * * * * * REBOOT TO NORMAL MODE * * * * * * * * * * * * * *


Perform an online scan with Internet Explorer with Panda ActiveScan
  1. Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Click Scan Now
  3. Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on see report. Then click Save report
Post the contents of the report in your next reply

*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
*Turn off the real time scanner of any existing antivirus program while performing the online scan



* * * * * * CHECK LIST * * * * * * * * * * * * * * * * * * * * *


In your next post, please include fresh logs from:
  1. HiJackThis
  2. Online scan
Please update us on how the computer behaves now
__________________

Question - what have you done for the community today?
sUBs is offline