View Single Post
Old 08-23-2007, 08:21 AM   #5 (permalink)
ECTech
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: Spyware upsetting system

First, disable system restore:

1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes.
7. Click OK.


Next, turn off Norton GoBack:


1) In the Norton GoBack main window, click Options.

2) Click Disable Norton GoBack.
A message informs you that disabling Norton GoBack will clear the history and that you will not be able to run Disk Drive Restore or Advanced Disk Drive Restore until Norton GoBack is turned back on.

3) Click OK.
Your computer automatically restarts and Norton GoBack is turned off.


Remove the Java you have installed and update it to the current version >> java.com: Hot Games, Cool Apps


fix these entires,

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe

O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr357.dll

O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe

O4 - Startup: system.exe

O4 - Global Startup: autorun.exe

O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

09 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (file missing)

O20 - AppInit_DLLs: hanonvt.ini


Then, run ComboFix >> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

post all logs when finished
ECTech is offline