afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > newbie ;guys really need ur help to fix my pc...
Newbie ;Guys really need ur help to fix my pc...
duday
Newbie
2. September 2007 @ 17:09
Link to this message
hi guys really need ur help to fix my pc. it automatically shutdown 60 sec after boot up..heres the log thanks...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:22 PM, on 9/2/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\HpMmKbd.exe
C:\PROGRAM FILES\MOUSEWAREPRO\MWProEng.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\DMI\Win32\Bin\HPTrayIcon.exe
C:\WINDOWS\System32\Promon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\cassandra\My Documents\background\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defa...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\windows\SYSTEM\blank.htm
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn2\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper -
{02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F}
- C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
O2 - BHO: (no name) - {2DA29024-7E86-4B28-B96C-3D17F356EE30} -
C:\WINDOWS\Speech\rcc.dll (file missing)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} -
C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} -
C:\WINDOWS\System32\umohelxv.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}
- C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HpMmKbd] HpMmKbd.exe
O4 - HKLM\..\Run: [MWProEng] C:\PROGRAM FILES\MOUSEWAREPRO\MWProEng.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI
Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program
Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [sysems] C:\WINDOWS\system32\syslem.exe
O4 - HKLM\..\Run: [stack12] C:\WINDOWS\system32\mfee.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program
Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [ServiceLayer] C:\Program Files\Common
Files\Nokia\Services\ServiceLayer.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite
5\DataLayer\Application\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common
Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Virtual Drive] "C:\Program
Files\FarStone\VirtualDrive\vdtask.exe"
O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\MCAFEE\MCAFEE
VIRUSSCAN\WebScanX.Exe
O4 - HKLM\..\Run: [HP Tray Icon] C:\DMI\Win32\Bin\HPTrayIcon.exe
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\MCAFEE\MCAFEE
VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\SYSTEM32\PDESK.EXE /Autolaunch
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM32\STIMON.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run:
[MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User
'?')
O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run:
[QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
(User '?')
O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run: [Yahoo!
Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User '?')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft WinMax Player] winvrn.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunServices: [Microsoft WinMax Player]
winvrn.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft WinMax Player] winvrn.exe (User
'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Microsoft WinMax Player]
winvrn.exe (User 'Default user')
O4 - Global Startup: Reality Fusion GameCam SE.lnk = C:\Program
Files\Intel\Createshare\program\PC Camera Games\Program\RFTray.exe
O4 - Global Startup: Quick Shelf.lnk = C:\Program Files\Microsoft
Encarta\Encarta World English Dictionary 2001\QSHLFED.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: Event Reminder.lnk = C:\Program
Files\Broderbund\PrintMaster\PMremind.exe
O8 - Extra context menu item: &Define - c:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - c:\Program
Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - c:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - c:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Common\yiesrvc.dll
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} -
c:\Program Files\Common Files\Microsoft Shared\Reference
2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define -
{5DA9DE80-097A-11D4-A92E-006097DBED37} - c:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50}
- C:\Program Files\Common Files\Microsoft Shared\Encarta
Researcher\EROPROJ.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .ivs: C:\PROGRA~1\INTERN~1\PLUGINS\Npriff.dll
O16 - DPF: Win32 Classes -
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation
Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image
Uploader Control) -
http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
- http://update.microsoft.com/windowsupdat...b?1136508759610
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI
Utility Class) -
http://security.symantec.com/sscv6/Share...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
- http://update.microsoft.com/microsoftupd...b?1136510132354
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer
Class) - http://a532.g.akamai.net/f/532/6712/5m/v...0/installer.exe
O20 - Winlogon Notify: ddcaxwu - ddcaxwu.dll (file missing)
O20 - Winlogon Notify: rcc - C:\WINDOWS\Speech\rcc.dll (file missing)
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\rvipxmib.dll
(file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program
Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5
(AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program
Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Advanced Windows Tray - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Client Debug Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Client Disk Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Config Debug Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Debug Config System - Unknown owner -
C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: DNS Client Service - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: DNS FPHost Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: DNS Support Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program
Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Local Debug Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Logon Task Manager - Unknown owner -
C:\WINDOWS\system32\symon.exe (file missing)
O23 - Service: Logon Terminal Manager - Unknown owner -
C:\WINDOWS\system32\spoolsc.exe (file missing)
O23 - Service: Microsoft BIOS Drivers - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Microsoft Client Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Microsoft DLL System - Unknown owner -
C:\WINDOWS\system32\smsc.exe (file missing)
O23 - Service: Microsoft Windows System32 - Unknown owner -
C:\WINDOWS\zaber.exe (file missing)
O23 - Service: Monitor Disk Manager - Unknown owner -
C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Net Logon Engine - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Net Logon Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Network Location Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Network Logon Engine - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Remote Auther Service - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Crypt Services - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote FTPD Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Header Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Logon Manager - Unknown owner -
C:\WINDOWS\system32\smcs.exe (file missing)
O23 - Service: Remote Map Manager - Unknown owner -
C:\WINDOWS\system32\lssc.exe (file missing)
O23 - Service: Remote PEpng Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Plesk Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Print Spooler - Unknown owner -
C:\WINDOWS\system32\spoolsc.exe (file missing)
O23 - Service: Remote Process Manager - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Remote Public Services - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Storage Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote TCP Services - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Remote Transfer Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote Usage Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote vShell Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Remote ZWare Service - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Security Access Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Security Task Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: ServiceLayer - Nokia . - C:\Program Files\PC
Connectivity Solution\ServiceLayer.exe
O23 - Service: Shell Code Services - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Shell Plugin Services - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Storage Shell Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: System Restore Manager - Unknown owner -
C:\WINDOWS\system32\symon.exe (file missing)
O23 - Service: System Restore Services - Unknown owner -
C:\WINDOWS\system32\lsiss.exe (file missing)
O23 - Service: Task Client Manager - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Task Restore Service - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: TCP Monitor Manager - Unknown owner -
C:\WINDOWS\system32\symon.exe (file missing)
O23 - Service: Terminal Device Services - Unknown owner -
C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Web Client Supply - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Win32Sr - Unknown owner - C:\WINDOWS\win32ssr.exe (file missing)
O23 - Service: Window Boot Services - Unknown owner -
C:\WINDOWS\system32\lsiss.exe (file missing)
O23 - Service: Window Configs Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows Access Services - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows Browser Application - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows Live Config - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows Monitor Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows PE Debugger - Unknown owner -
C:\WINDOWS\system32\lviss.exe (file missing)
O23 - Service: Windows Process Manager - Unknown owner -
C:\WINDOWS\system32\spoolsc.exe (file missing)
O23 - Service: Windows Reg Service - Unknown owner -
C:\WINDOWS\system32\lsyss.exe (file missing)
O23 - Service: Windows Regedit Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows Remote Manager - Unknown owner -
C:\WINDOWS\system32\lsiss.exe (file missing)
O23 - Service: Windows Restore Service - Unknown owner -
C:\WINDOWS\system32\spoolcs.exe (file missing)
O23 - Service: Windows Security Manager - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Windows SFTP System - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Windows System Host - Unknown owner -
C:\WINDOWS\sychost32.exe (file missing)
O23 - Service: Windows System Tray - Unknown owner -
C:\WINDOWS\systay.exe (file missing)
O23 - Service: Windows Task Manager - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Windows Terminal Services - Unknown owner -
C:\WINDOWS\system32\vcmon.exe (file missing)
O23 - Service: Wireless Task Manager - Unknown owner -
C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc.
- C:\WINDOWS\System32\wwSecure.exe
--
End of file - 17465 bytes
~rezelle~
duday
Newbie
2. September 2007 @ 21:31
Link to this message
anyone who wants to help me?? pleaseee..
~rezelle~
bluecoal
Suspended due to non-functional email address
4. September 2007 @ 07:01
Link to this message
I am not sure if I can help you completely clean your machine. Here are some things you can try to do some cleanup:
You can try steps 8,9,11,and 14 here:
http://www.malwarebytes.org/forums/index...5&showtopic=692
Using atf cleaner and superantispyware.
----------------------------
Then you can run a program called sdfix. Here are instructions I copied from another site:
Then, please download SDFix by AndyManchesta and save it to your Desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process, then display "Finished"; press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
(prior to using hijackthis , please rename it from hijackthis.exe to scanner.exe, then run it as scanner.exe and create and post the log. Some malware is now programmed to hide from hijackthis.exe.)
This message has been edited since posting. Last time this message was edited on 4. September 2007 @ 08:16
Advertisement
duday
Newbie
8. September 2007 @ 15:59
Link to this message
thanks..
~rezelle~
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > newbie ;guys really need ur help to fix my pc...