I recently downloaded WinRAR and along with it came a virus, the one that has a box pop up every minute saying "intervalhehehe". On another thread I saw how to get rid of it. So far I've done this:
1. open task manager, kill the process "explore.exe."
2. deleted "explore.exe" out of the windows directory
3. ran comand regedit, navigated to HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\SYSTEMPROGRAMS and deleted the entry for "explore.exe"
4.Ran HostsXpert 3.7 and clicked "Restore Microsoft's Host File"
I still get redirected to the fake Microsoft page when I go to google or yahoo but dont have any other trouble with the popup.
I ran OTScanit, scanned all users, selected rootkit check, selected additional scans(file - lop check, file- purity scan, evnt- eventviewer errors/warnings) i attached the txt file.
What am I missing?