Hi and Welcome
It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed..These instructions only apply to HJT v1.99.1
Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes..
Please do NOT run Hijack This in a TEMPorary folder or on the Desktop. I recommend c:/program files/HJT/
Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check “Turn off System Restore”, <Apply>, <OK>. Reboot. When we have confirmed that your log file is clean, you may renable System Restore and create a new restore point.
SHOW HIDDEN FILES AND FOLDERS.
To show hidden files instructions (WinXP)
Doubleclick My Computer | Tools | Folder Options | View tab
Select Show Hidden Files and Folders
Uncheck Hide extensions for known file types
Uncheck Hide protected operating system files (Recommended)
Select Apply to All Folders | Yes | Apply | OK
------------------------------------------------------------------
Files highlighted in BLACK will need to be removed from your hard drive.
------------------------------------------------------------------
Please start by putting HJT in SAFE MODE. During reboot, tap the F8 key. Select Safe Mode and then run "Hijack This"
------------------------------------------------------------------
Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following exe file and click End Process for each one if they are listed.
elitewdm32.exe
pokapoka69.exe
pokapoka70.exe
------------------------------------------------------------------
Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.
O4 - HKLM\..\Run: [lsass] C:\windows\system32\elitewdm32.exe
O4 - HKLM\..\Run: [System service69] C:\WINDOWS\\etb\pokapoka69.exe
O4 - HKLM\..\Run: [System service70] C:\WINDOWS\etb\pokapoka70.exe
------------------------------------------------------------------
Open Windows Explorer and delete the following highlighted file/s (or delete the whole (Red) folder if listed).
C:\windows\system32\elitewdm32.exe
C:\WINDOWS\\etb\pokapoka69.exe
C:\WINDOWS\etb\pokapoka70.exe
-------------------------------------------------------------------
Check that you have carried out all the above steps/fixes and then reboot into Normal Mode and download Cleanup This will clean out your tempory files.
When finished please post a new log......
It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed..These instructions only apply to HJT v1.99.1
Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes..
Please do NOT run Hijack This in a TEMPorary folder or on the Desktop. I recommend c:/program files/HJT/
Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check “Turn off System Restore”, <Apply>, <OK>. Reboot. When we have confirmed that your log file is clean, you may renable System Restore and create a new restore point.
SHOW HIDDEN FILES AND FOLDERS.
To show hidden files instructions (WinXP)
Doubleclick My Computer | Tools | Folder Options | View tab
Select Show Hidden Files and Folders
Uncheck Hide extensions for known file types
Uncheck Hide protected operating system files (Recommended)
Select Apply to All Folders | Yes | Apply | OK
------------------------------------------------------------------
Files highlighted in BLACK will need to be removed from your hard drive.
------------------------------------------------------------------
Please start by putting HJT in SAFE MODE. During reboot, tap the F8 key. Select Safe Mode and then run "Hijack This"
------------------------------------------------------------------
Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following exe file and click End Process for each one if they are listed.
elitewdm32.exe
pokapoka69.exe
pokapoka70.exe
------------------------------------------------------------------
Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.
O4 - HKLM\..\Run: [lsass] C:\windows\system32\elitewdm32.exe
O4 - HKLM\..\Run: [System service69] C:\WINDOWS\\etb\pokapoka69.exe
O4 - HKLM\..\Run: [System service70] C:\WINDOWS\etb\pokapoka70.exe
------------------------------------------------------------------
Open Windows Explorer and delete the following highlighted file/s (or delete the whole (Red) folder if listed).
C:\windows\system32\elitewdm32.exe
C:\WINDOWS\\etb\pokapoka69.exe
C:\WINDOWS\etb\pokapoka70.exe
-------------------------------------------------------------------
Check that you have carried out all the above steps/fixes and then reboot into Normal Mode and download Cleanup This will clean out your tempory files.
When finished please post a new log......