Forum Home
Press F1
 
Thread ID: 92701 2008-08-19 07:38:00 Browser Hijacked Blam (54) Press F1
Post ID Timestamp Content User
698650 2008-08-21 23:01:00 Remove whatever Avast / NOD 32 picks up

If Avast picks anything up delete them.

Have you disabled system restore yet?
Speedy Gonzales (78)
698651 2008-08-22 00:00:00 As speedy asked - Have you turned off Restore ?

Also does it tell you exactly where the rootkits are and their names ?
wainuitech (129)
698652 2008-08-22 02:17:00 www.imagef1.net.nz Blam (54)
698653 2008-08-22 02:20:00 So did you click on delete now?

And for the 3rd-4th time is system restore disabled now, or not?

If it isnt there's no point in us helping you
Speedy Gonzales (78)
698654 2008-08-22 07:47:00 Yes, I have disabled system restore
www.imagef1.net.nz
and yes, I did click delete
Blam (54)
698655 2008-08-22 08:08:00 Hmmm OK try this ----


Open Hijack This
Click on the button “ Open The mics Tool Section”

Click on the “Select A file On reboot” Button

Navigate to where the file/root kit file is located, select it.If there is more than one, select them all. BUT only the files that are listed as rootkits/infections.

Reboot the PC.


Note: if its not showing in the window,

Vista Extra, Make sure you are in Classic view in the control panel first - top Left , select classic View.

For Vista :: Click on the start Orb/ Control Panel / Folder options / View, Under Hidden files and folder, click “ Show Hidden Files and Folders”

For XP ::: open My Computer, up top go to tools/Folder options/View, Under Hidden files and folder, click “ Show Hidden Files and Folders”


WARNING:

If they are still not showing ( and be VERY CAREFUL here) in the View, scroll down till you locate “Hide protected operating system Files(recommended)” untick it, then go looking for the infection. BE VERY CAREFUL not to select anything apart from the infections, system files are hidden for a good reason, delete the wrong thing and it may stop your PC from working correctly..

After rebooting try rescanning the PC.
wainuitech (129)
698656 2008-08-22 10:04:00 just to add to the above post - If that doesn't work, go to This site here (www.bleepingcomputer.com) - download Blacklight and read the instructions on the page as to how to operate it - make sure you read it all. wainuitech (129)
698657 2008-08-22 21:16:00 Thanks, did another boot time scan, now it picked up 4 nasties.
Another warning message from avast has come up with another rootkit, will follow your instructions ASAP.
Blam (54)
698658 2008-08-22 21:47:00 Easier way to fix it = format it Speedy Gonzales (78)
698659 2008-08-22 22:18:00 Easier way to fix it = format it

Sounds a bit drastic,do you reckon he is over infested?
Cicero (40)
1 2 3 4 5 6 7 8