siliconman01
Global Moderator
    
 Trojans! Chew 'em Up, Spit 'em Out...
Gender: 
Posts: 5815
|
 |
Re: Unable to Remove Registry Key
« Reply #7 on: Feb 4th, 2007, 2:51am » |
Quote Modify
|
Okay, so the computer in question is now able to boot into normal mode (in a fashion) and is able to connect to the Internet. Let's address the floppy issue a bit later. I'm going to post a series of things to do in an effort to get you back to normal. BE SURE that your Windows XP firewall is set to Active now that you have removed ZoneAlarm. This is done through START>SETTINGS>CONTROL PANEL>WINDOWS FIREWALL. ZoneAlarm is an excellent firewall. Let's address this issue later as well. There is nothing malicious showing up in your HiJackthis log; however, there are some things that need to be fixed. You may wish to print out this post so you can follow it without having IE open. Please do this: 1. Run another Hijackthis scan 2. When the scan is completed, place a checkmark in the box next to each of the red items below. BE SURE these are the only items that are checked. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) 3. Then click on Fix Checked on the lower left of the HiJackthis window. Confirm that you want HJT to fix these items and let it fix them. 4. Close HJT 5. Uninstall Windows Defender via Add or Remove Programs in the control panel. It has apparently become corrupted. We will re-install it later. Reboot your computer at the end of the uninstall. 6. After the reboot, please run a hard drive diagnostic repair. - Go to START>RUN and type in CHKDSK /r /f (Be sure there is a space before the /r and then again before the /f) Click on OK - A CMD window will open and ask you if you want to run CHKDSK on the next reboot. Type in a Y and press ENTER on your keyboard. Then type in EXIT and press ENTER on your keyboard to close the CMD window. - Immediately reboot your computer. As the reboot progress, the disk diagnostic will start to run before Windows loads. The diagnostic will take several minutes depending on the size of your hard drive. Let it fix any problems it finds. 7. You have an outdated version of TrojanHunter. The latest version is V4.6.930. Please follow the procedure in the link below to upgrade to the latest version. http://www.misec.net/forum/board/FAQ/1139255716 - After you have upgraded and set up all the options in TH and run LiveUpdate to obtain the latest rulesets, reboot your computer into SAFE MODE. - Run a full scan with TrojanHunter and let it clean/quarantine what it finds. Please save the scan/cleaning log. This is under the FILE menu item in the top menu bar. - Reboot back into Normal Mode. 8. You have a very outdated version of JAVA (C:\Program Files\Java\jre1.5.0_06). For security reasons you should update to the latest version which is version 1.6.0.b105). - Go to START>SETTINGS>CONTROL PANEL>JAVA>UPDATE tab. This will lead you to the latest version download. - Install the latest version of JAVA. The installer will not remove the old version as it installs the new version. - After the installation of the new version is completed, reboot your computer. - Uninstall the old version (C:\Program Files\Java\jre1.5.0_06) via Add or Remove Programs in the Control Panel. 9. It looks like you have an old version of ewido. I recommend that you uninstall ewido 4 and install the latest AVG AntiSpyware 7.5.0.50. The link below will guide you to the download. http://www.ewido.net - Be sure to download the latest definitions/rulesets - Run a full scan with the new AVG AS V7.5.0.50 10. I recommend that you uninstall SpywareGuard. You have enough security programs on your system....TrojanHunter, AVG Anti-Spyware, Windows Defender, AVG, Spyware Doctor. SpywareGuard is not needed and it has not been upgraded in years. 11. Run a REMOTE Scan with Bit Defender. The link below will guide you to the Bit Defender scanner. You will need to use IE because Bit Defender requires an ActiveX download. http://www.misec.net/forum/board/FAQ/1141894786 12. Re-install Windows Defender. Download the latest version from Microsoft at http://www.microsoft.com/athome/security/spyware/software/default.mspx and install it. Set up the desired options. - Be sure to download the latest rulesets. - Run a full scan 13. Go to Windows Update and install any critical updates for XP. At this point, I will stop with the recommendations. I have more; however, I would like to hear how things are going. - Please post the TrojanHunter scan log - Run a new Hijackthis scan and post a new log. - Please let me know what problems you are experiencing now.
|