Jump to content

autorun.inf virus problem


Recommended Posts

Hi yesterday I borrowed my friends usb drive and when I tried to open it all the folders had been replaced with shortcuts. I didnt realise this and clicked one only to find out later the shortcut had been running an exe file with random letters along with opening the folder. I used mbam and it found like 4 of these exe files within the drive and deleted them but it didnt get rid of the autorun file. I tried restarting in safe mode to delete this but when I restart normally the autorun file will come back to the root directory of the usb drive along with either a pif or exe file with random letters for the name about 100kB.It seems to constantly alternate between a pif and exe file everytime I try to delete it. mbam can detect this and shows it as Trojan.Malpack.Gen. I also found that around the time the autorun and random exe or pif file is created another 2 exe files are created in c:\users\username\appdata\local\temp but it says these files are 0bytes. There was another file called pktier.exe which was 120kB created in the c:\users\username folder at the same time I first used the drive which was one of the exe files contained on the drive. I deleted that and it hasnt come back but I havent been able to get rid of the virus completely. I've tried alot of what ive seen on the internet but havent had anyluck so far. Also to view the files I'm talking about I had to change the settings in the folder options to show hidden system files but anytime I do something within the folders that contain the files like deleting one the setting will immediately go back to do not display hidden files and folders everytime except for when I'm in safe mode.

I moved all the data from the original folders into new ones on the drive and deleted the shortcuts and so far it hasnt changed the new folders into shortcuts and within the large amount of movies on the drive I noticed 5 files that were named the same as another video within the same folder but like x.MOVIENAME.avi that were also around 100kB but they havent returned after deleting them.

[AutoRun]

;dgVljgsMvemV LkBdGifGxXyTIuuISnEwUAwpePtgqfhxgtRao

;

shEll\ExpLore\coMmAnD=pbxp.pif

;aAJLAT knMb UQmKsfHVy YpeYjMukmlA FEeEV

sHell\opEn\COMmanD= pbxp.pif

open=pbxp.pif

;iynTbxgdcpOy uuYeufHBMpJhXuI

shEll\opEN\DEFAult=1

;muxiq

Shell\aUtoplAY\comMAnd= pbxp.pif

;RnNtQn rKEsrCoMjydjYGjJARVxfsjkmf seshRidd

Thats the autorun.inf as it is now.

Anyhelp would be appreciated

heres the logs from the dds tool

DDS (Ver_2012-11-20.01) - NTFS_x86

Internet Explorer: 9.0.8112.16421

Run by JULIE at 15:54:06 on 2013-08-12

Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.64.1033.18.3454.2428 [GMT 12:00]

.

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ================

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\SLsvc.exe

c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

c:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Windows\system32\WUDFHost.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

C:\hp\support\hpsysdrv.exe

C:\Windows\System32\mobsync.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Common Files\Java\Java Update\jusched.exe

C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\Windows\system32\schtasks.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

C:\hp\kbd\kbd.exe

C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

C:\Windows\system32\taskeng.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\svchost.exe -k hpdevmgmt

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\System32\svchost.exe -k HPZ12

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

.

============== Pseudo HJT Report ===============

.

uProxyOverride = <local>

BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: <No Name>: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBHO.dll

BHO: IE to GetRight Helper: {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - c:\program files\getright\xx2gr.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: &Google: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

TB: Show Norton Toolbar: {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll

TB: &Google: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun

uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet

mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide

mRun: [sunJavaUpdateReg] "c:\windows\system32\jureg.exe"

mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe

mRun: [symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"

mRun: [RtHDVCpl] RtHDVCpl.exe

mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"

mRun: [KBD] c:\hp\kbd\KbdStub.EXE

mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe

mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe

mRun: [DPService] "c:\program files\hp\dvdplay\DPService.exe"

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto

mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup

mRun: [AutorunRemover.exe] c:\program files\autorunremover\AutorunRemover.exe -Hide

uPolicies-Explorer: NoDriveAutoRun = dword:3

uPolicies-Explorer: NoDriveTypeAutoRun = dword:0

mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0

mPolicies-Explorer: NoDriveAutoRun = dword:3

mPolicies-Explorer: NoDriveTypeAutoRun = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Download with GetRight - c:\program files\getright\GRdownload.htm

IE: Open with GetRight Browser - c:\program files\getright\GRbrowse.htm

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll

IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe

TCP: NameServer = 192.168.42.129

TCP: Interfaces\{C867532A-2C97-4ADF-8E10-E46435B2547D} : DHCPNameServer = 192.168.42.129

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll

LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\28.0.1500.95\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

.

============= SERVICES / DRIVERS ===============

.

R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2007-1-1 232512]

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20071220.001\IDSvix86.sys [2007-12-22 180272]

R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-10-11 21504]

R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2011-3-31 80896]

R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2007-1-10 38200]

S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-3-1 161384]

S3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [2013-1-9 12288]

S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-6-9 24576]

S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040]

S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-9-4 1252232]

.

=============== File Associations ===============

.

FileExt: .inf: inffile=c:\windows\system32\NOTEPAD.EXE %1 [userChoice]

FileExt: .js: Applications\notepad.exe=c:\windows\system32\NOTEPAD.EXE %1 [userChoice]

.

=============== Created Last 30 ================

.

2013-08-25 01:48:07 -------- d-----w- c:\users\julie\appdata\local\{7311B2C7-F89F-4F3A-AD46-B17B95F13019}

2013-08-11 19:39:04 -------- d-----w- C:\UsbFix

2013-08-11 18:26:21 -------- d-----w- c:\programdata\Autorun Eater

2013-08-11 02:39:47 -------- d-----w- C:\a

2013-08-09 13:54:33 60872 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{cd20605d-57cb-4f4b-9313-580b82be0241}\offreg.dll

2013-08-09 13:44:43 7143960 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{cd20605d-57cb-4f4b-9313-580b82be0241}\mpengine.dll

2013-07-31 12:37:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2013-07-31 12:37:40 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe

2013-07-24 07:28:39 -------- d-----w- c:\program files\THQ

2013-07-24 06:59:21 -------- d-----w- C:\comp

2013-07-19 09:20:08 -------- d-----w- c:\programdata\APN

2013-07-15 21:45:24 -------- d-----r- c:\program files\Skype

2013-07-15 21:39:55 -------- d-----w- c:\users\julie\appdata\local\{BC509C8E-1E3B-4A93-BA6A-AC7E082C3F62}

.

==================== Find3M ====================

.

.

============= FINISH: 15:55:19.52 ===============

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft® Windows Vista™ Home Basic

Boot Device: \Device\HarddiskVolume1

Install Date: 10/09/2007 8:14:56 p.m.

System Uptime: 12/08/2013 2:37:24 p.m. (1 hours ago)

.

Motherboard: ECS | | Nettle2

Processor: AMD Sempron Processor 3800+ | Socket M2 | 2200/201mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 67 GiB total, 2.154 GiB free.

D: is FIXED (NTFS) - 7 GiB total, 0.998 GiB free.

E: is CDROM (UDF)

G: is Removable

H: is Removable

I: is Removable

J: is Removable

K: is CDROM ()

L: is FIXED (NTFS) - 75 GiB total, 4.603 GiB free.

.

==== Disabled Device Manager Items =============

.

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0003

Manufacturer: Microsoft

Name: 6TO4 Adapter

PNP Device ID: ROOT\*6TO4MP\0003

Service: tunnel

.

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0007

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter #4

PNP Device ID: ROOT\*6TO4MP\0007

Service: tunnel

.

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}

Description: Microsoft 6to4 Adapter

Device ID: ROOT\*6TO4MP\0011

Manufacturer: Microsoft

Name: Microsoft 6to4 Adapter #7

PNP Device ID: ROOT\*6TO4MP\0011

Service: tunnel

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

32 Bit HP CIO Components Installer

Activation Assistant for the 2007 Microsoft Office suites

Adobe Flash Player 11 ActiveX

Adobe Reader 8.1.0

AIO_Scan

Alarm Clock version 1.0

AppCore

Atlantis Quest

µTorrent

Auslogics Disk Defrag

AV

Bejeweled 2 Deluxe

Big Kahuna Reef 2

Bricks of Egypt

BufferChm

ccCommon

Chuzzle

Company of Heroes

Continuum 0.40

Copy

Cradle of Rome

CustomerResearchQFolder

D3DX10

DAEMON Tools Lite

Destinations

DeviceManagementQFolder

DJ_AIO_ProductContext

DJ_AIO_Software

DJ_AIO_Software_min

DVD Play

Dynasty

Emperor of the Fading Suns

Enhanced Multimedia Keyboard Solution

eSupportQFolder

F2100

F2100_Help

File Shredder 2.0

Fish Tycoon

Four Houses

Galapago

GetRight

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper

Greenshot

Hardware Diagnostic Tools

Hewlett-Packard Active Check

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

HP Active Support Library

HP Active Support Library 32 bit components

HP Customer Experience Enhancements

HP Customer Feedback

HP Customer Participation Program 8.0

HP Deskjet All-In-One Software 8.0

HP Easy Setup - Frontend

HP Imaging Device Functions 8.0

HP On-Screen Cap/Num/Scroll Lock Indicator

HP Photosmart Essential

HP Photosmart Essential 2.01

HP Photosmart Essential2.01

HP Picasso Media Center Add-In

HP Solution Center 8.0

HP Update

HPAsset component for HP Active Support Library

HPProductAssistant

HPSSupply

HTC BMP USB Driver

HTC Driver Installer

HTC Sync

Insaniquarium Deluxe

Java Auto Updater

Java 6 Update 31

Java SE Runtime Environment 6 Update 1

Jewel Match

Jewel Quest

LightScribe 1.8.15.1

LiveUpdate 3.2 (Symantec Corporation)

LiveUpdate Notice (Symantec Corporation)

LucasArts' TIE Fighter

Luxor

Luxor - Amun Rising

Luxor 2

Magic Match 2

Mah Jong Quest

Mahjong Escape Ancient China

Mahjong Match

Malwarebytes Anti-Malware version 1.75.0.1300

MarketResearch

Mask Playable Demo

Master of Orion II

MediaRing Talk

Microsoft .NET Framework 3.5 SP1

Microsoft Application Error Reporting

Microsoft Office Excel MUI (English) 2007

Microsoft Office Home and Student 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Silverlight

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Works

Mp3tag v2.48

MSRedist

MSVCRT

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB941833)

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP3 Parser

muvee autoProducer 6.0

Mystery Case Files - Prime Suspects

Mystic Inn

Norton Confidential Browser Component

Norton Confidential Web Protection Component

Norton Internet Security

Norton Internet Security (Symantec Corporation)

Norton Protection Center

NVIDIA Drivers

OpenAL

PokerStars

PSSWCORE

Python 2.5

Rainbow Mystery

Realtek High Definition Audio Driver

Roxio Activation Module

Roxio Creator Audio

Roxio Creator Basic v9

Roxio Creator Copy

Roxio Creator Data

Roxio Creator EasyArchive

Roxio Creator Tools

Roxio Express Labeler 3

Roxio MyDVD Basic v9

Scan

Scrubbles

Security Update for 2007 Microsoft Office System (KB951550)

Security Update for 2007 Microsoft Office System (KB951944)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Segoe UI

Sid Meier's Civilization 4

Skype™ 6.3

Slingo Quest

Soft Data Fax Modem with SmartCP

SolutionCenter

Spin & Win

Spin and Play

Star Defender 3

Status

SymNet

Teddy Factory

Toolbox

TrayApp

Treasures of the Deep

UnloadSupport

Update for 2007 Microsoft Office System (KB967642)

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft Office 2007 Help for Common Features (KB963673)

Update for Microsoft Office OneNote 2007 Help (KB963670)

Update for Microsoft Office Script Editor Help (KB963671)

Update for Office System 2007 Setup (KB929722)

UsbFix By El Desaparecido

VideoToolkit01

Virtual Villagers The Lost Children

WebReg

Windows Live Communications Platform

Windows Live Essentials

Windows Live ID Sign-in Assistant

Windows Live Installer

Windows Live Messenger

Windows Live Photo Common

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live UX Platform

Windows Live UX Platform Language Pack

WinRAR archiver

Wisdom-soft ScreenHunter 5.0 Pro

Wonderful Wizard of Oz

Wonderland - Secret Worlds

World of Tanks

XChat 2 (remove only)

Yahoo! Messenger

Zen of Sudoku

Zuma Deluxe

.

==== End Of File ===========================

Link to post
Share on other sites

  • Root Admin

Hello and :welcome:

Sorry for the delay.  If you still need assistance with this please read the following and reply back letting me know that you still want help with this.

 

 

If you've not already done so please start here and post back the 2 log files DDS.txt and Attach.txt

P2P/Piracy Warning:
 

 

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.
Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.
If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 



Before we proceed further, please read all of the following instructions carefully.
If there is anything that you do not understand kindly ask before proceeding.
If needed please print out these instructions.

  • Please do not post logs using CODE, QUOTE, or FONT tags. Just paste them as direct text.
  • If the log is too large then you can use attachments by clicking on the More Reply Options button.
  • Please enable your system to show hidden files: How to see hidden files in Windows
  • Make sure you're subscribed to this topic:
    • Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly
  • Removing malware can be unpredictable...It is unlikely but things can go very wrong! Please make sure you Backup all files that cannot be replaced if something were to happen. You can copy them to a CD/DVD, external drive or a pen drive
  • Please don't run any other scans, download, install or uninstall any programs unless requested by me while I'm working with you.
  • The removal of malware is not instantaneous, please be patient. Often we are also on a different Time Zone.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of the issue.
  • When we are done, I'll give you instructions on how to cleanup all the tools and logs
  • Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.
  • Your topic will be closed if you haven't replied within 3 days
  • (If I have not responded within 24 hours, please send me a Private Message as a reminder)

 

 

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.