Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google Search Redirected [RESOLVED]


  • This topic is locked This topic is locked

#16
Samyew

Samyew

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\1580.tmp Infected: Worm.Win32.AutoRun.onp 1
C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\15A0.tmp Infected: Worm.Win32.AutoRun.oni 1
C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\2B0016D4-00000047.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\759A2350-00000008.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Users\Samuel\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Users\Samuel\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Users\Samuel\Downloads\install.exe Infected: Trojan-Downloader.Win32.Tiny.ach 1
C:\Users\Samuel\Downloads\install.exe~ Infected: Trojan-Downloader.Win32.Tiny.ach 1
C:\WINDOWS\System32\omvjks.exe~ Infected: Backdoor.Win32.Rbot.enq 1
D:\Old Documents\My Downloads\susetup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.6105 1
D:\Old Documents\My Downloads\susetup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.gen 1
D:\Old Documents\My Downloads\susetup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.5201 2
D:\Old Documents\My Downloads\WarezP2P_TDL.exe Infected: not-a-virus:Downloader.Win32.Agent.h 1
  • 0

Advertisements


#17
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
firstly, could you delete the mail in your Junk E-mail folder, it has some infections in it.

and then:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
"C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\2B0016D4-00000047.eml"
"C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\759A2350-00000008.eml"
"C:\Users\Samuel\Downloads\install.exe"
"C:\Users\Samuel\Downloads\install.exe~"
"C:\WINDOWS\System32\omvjks.exe~"
"D:\Old Documents\My Downloads\susetup.exe"
"D:\Old Documents\My Downloads\WarezP2P_TDL.exe"


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#18
Samyew

Samyew

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
where do I get combofix?
  • 0

#19
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts

where do I get combofix?

oops, that was embarrassing......

try this:

Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\2B0016D4-00000047.eml
    C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\759A2350-00000008.eml
    C:\Users\Samuel\Downloads\install.exe
    C:\Users\Samuel\Downloads\install.exe~
    C:\WINDOWS\System32\omvjks.exe~
    D:\Old Documents\My Downloads\susetup.exe
    D:\Old Documents\My Downloads\WarezP2P_TDL.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

and some idea of how your machine is running now

andrewuk
  • 0

#20
Samyew

Samyew

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\2B0016D4-00000047.eml moved successfully.
C:\Users\Samuel\AppData\Local\Microsoft\Windows Mail\Local Folders\Junk E-mail\759A2350-00000008.eml moved successfully.
C:\Users\Samuel\Downloads\install.exe moved successfully.
C:\Users\Samuel\Downloads\install.exe~ moved successfully.
C:\WINDOWS\System32\omvjks.exe~ moved successfully.
D:\Old Documents\My Downloads\susetup.exe moved successfully.
D:\Old Documents\My Downloads\WarezP2P_TDL.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Arj.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\avlib.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Avp1.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\btimages.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\CAB.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\dmap.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\dtreg.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FSSync.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HashCont.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HashMD5.PPL scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HCCMP.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\ichk2.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\iChkSA.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Inflate.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\IWGen.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kave.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\lha.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\L_llio.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\mdb.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MDMAP.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MemModSc.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MemScan.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\minizip.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MKavIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\msoe.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\nfio.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\NTFSstrm.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prKernel.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prLoader.dll scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prseqio.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\PrUtil.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Quantum.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\rar.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\sfdb.PPL scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\TempFile.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\thpimpl.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UniArc.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UnLZX.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UnStored.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\hsperfdata_Samuel\4428 scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\ehmsas.txt scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\~DF7BCE.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\~DF7D75.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\~DFB37F.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Temp\~DFB392.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
File delete failed. C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12012008_130058

Files moved on Reboot...
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Arj.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\avlib.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Avp1.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\AvpMgr.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\btimages.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\CAB.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\dmap.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\dtreg.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FsDrvPlg.ppl moved successfully.
DllUnregisterServer procedure not found in C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FSSync.dll
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FSSync.dll NOT unregistered.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\FSSync.dll moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HashCont.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HashMD5.PPL moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\HCCMP.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\ichk2.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\iChkSA.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Inflate.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\IWGen.ppl moved successfully.
DllUnregisterServer procedure not found in C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kave.dll
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kave.dll NOT unregistered.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kave.dll moved successfully.
DllUnregisterServer procedure not found in C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kosglue-7.0.25.0.dll
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kosglue-7.0.25.0.dll NOT unregistered.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\kosglue-7.0.25.0.dll moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\lha.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\L_llio.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\mdb.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MDMAP.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MemModSc.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MemScan.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\minizip.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\MKavIO.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\msoe.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\nfio.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\NTFSstrm.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prKernel.ppl moved successfully.
DllUnregisterServer procedure not found in C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prLoader.dll
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prLoader.dll NOT unregistered.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prLoader.dll moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\prseqio.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\PrUtil.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\Quantum.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\rar.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\ScanningProcess.exe moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\sfdb.PPL moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\TempFile.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\thpimpl.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UniArc.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UnLZX.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\UnStored.ppl moved successfully.
C:\Users\Samuel\AppData\Local\Temp\jkos-Samuel\binaries\WDiskIO.ppl moved successfully.
File C:\Users\Samuel\AppData\Local\Temp\hsperfdata_Samuel\4428 not found!
C:\Users\Samuel\AppData\Local\Temp\ehmsas.txt moved successfully.
File C:\Users\Samuel\AppData\Local\Temp\~DF7BCE.tmp not found!
File C:\Users\Samuel\AppData\Local\Temp\~DF7D75.tmp not found!
File C:\Users\Samuel\AppData\Local\Temp\~DFB37F.tmp not found!
File C:\Users\Samuel\AppData\Local\Temp\~DFB392.tmp not found!
C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_001_ moved successfully.
C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_002_ moved successfully.
C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_003_ moved successfully.
C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\Samuel\AppData\Local\Mozilla\Firefox\Profiles\rmpcvgxu.default\XUL.mfl moved successfully.

My computer is running as it always has, no major difference
  • 0

#21
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
redirects still gone?
  • 0

#22
Samyew

Samyew

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
no redirects since the first fix.
  • 0

#23
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hello Samyew

congratulations, your logs are clean and another fix is in the can :)

looks like you had other infections as well as the google redirect - but they are gone now.

out of interest, i assume you are using an antivirus program, i could see one on your initial log, but not the later ones. if you are not using an antivirus program, let me know and we can easily get a free one on your machine.

in this post we will clear away the fix tools (this is so that should you ever be re-infected, you will download updated versions and it will also remove the quarantined Malware from your computer), reset your restore points (there will be infections lurking in there) and i will leave you with some ideas on how to enhance the protection of your machine against future infection.

====STEP 1====
  • Double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
====STEP 2====
Resetting your restore points (which is about turning system restore off, rebooting, and then turning it back on again).

1. Open System by clicking the Start button, clicking Control Panel, clicking System and Maintenance, and then clicking System.

2. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

3. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK.

reboot

1. Open System by clicking the Start button, clicking Control Panel, clicking System and Maintenance, and then clicking System.

2. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

3. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.

How to Turn On and Turn Off System Restore in Vista
http://windowshelp.m...6fb3f01033.mspx



====IDEAS TO SPEED UP YOUR MACHINE====
this page http://users.telenet...owcomputer.html gives some good ideas on how to improve the efficiency of your machine and has one or two useful links to help your further.


====AND FINALLY====
The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

best wishes

andrewuk
  • 0

#24
Samyew

Samyew

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Thanks for the help I really appreciate it.
  • 0

#25
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP