RSS Forums RSS
Please support our Viruses, Spyware and other Nasties advertiser: 64-bit Windows Community

Trojan.Cachecachekit Help!!

Join Date: Jan 2007
Posts: 538
Reputation: TT4Titans is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 21
TT4Titans's Avatar
TT4Titans TT4Titans is offline Offline
Posting Pro

Re: Trojan.Cachecachekit Help!!

  #2  
Mar 18th, 2007
Fix these:

O4 - HKLM\..\Run: [SpywareBot] "C:\Program Files (x86)\SpywareBot\SpywareBot.exe" -boot

I am gonna tell you from looking at this it isn't a easy one to get out.

you will have to:

MANUAL REMOVAL INSTRUCTIONS
Note: Systems affected by this malware are also usually infected by a BOT worm. Be sure to scan your system for any related malware and to follow the corresponding removal instructions.
Restarting in Safe Mode



• On Windows XP
  1. Restart your computer.
  2. Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
  3. Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
Editing the Registry
This malware modifies the system's registry. Users affected by this malware may need to modify or delete specific registry keys or entries.





Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware from executing at startup.
If the registry entries below are not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.
  1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
  2. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>Services
  3. In the left panel, locate and delete the key:
    rdriv
  4. Close Registry Editor.
Enabling Show All Files
This procedure allows you to access hidden malware files using Windows Explorer.




• On Windows 2000, XP, and Server 2003
  1. Open Windows Explorer. Right-click Start then click Explore.
  2. On the Tools menu, click Folder Options.
  3. Click the View tab.
  4. Select Show hidden files and folders, then click OK.
  5. Uncheck the Hide protected operating system files check box (if found).
  6. Click Yes when prompted.
  7. Uncheck the Hide file extension for known file types check box.
  8. Click OK.
Deleting Malware File
  1. Right-click Start then click Search or Find, depending on the version of Windows you are running.
  2. In the Named input box, type:
    RDRIV.SYS
  3. In the Look In drop-down list, select the drive that contains Windows, then press Enter.
  4. Once located, select the file then press Delete.
Important Windows ME/XP Cleaning Instructions
Users running Windows ME and XP must disable System Restore to allow full scanning of infected systems.
Users running other Windows versions can proceed with the succeeding procedure set(s).





Running Trend Micro Antivirus
If you are currently running in safe mode, please restart your system normally before performing the following solution.



Scan your system with Trend Micro antivirus and delete files detected as TROJ_ROOTKIT.E. To do this,use HouseCall, the Trend Micro online virus scanner.

http://housecall.antivirus.com/

After you are done Download and run the CWShredder from there.

Good luck.
Reply With Quote  
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 4:25 pm.
Newsletter Archive - Sitemap - Privacy Statement - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC