Hello lucameyer , welcome to DaniWeb. My name is Justin and I will be helping you with your computer today. I will be helping clean all the maleware and spyware problems associated with your computer. Throughout my fix if you have any questions on the programs I am having you use don't be afraid to ask me.
Welcome,
Please follow the instructions provided, you may want to print out these instructions and use them as a reference.
Please download ewido anti-malware it is a free version of the program.Install ewido anti-malware
When installing, under "Additional Options" uncheck..Install background guard
Install scan via context menu
Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files.On the left hand side of the main screen click update.
Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates
Once the updates are installed do the following:Click on scanner
Click on Complete System Scan and the scan will begin.
You will be prompted to clean the first infection.
Select "Perform action on all infections", then proceed.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware
Please note their will be more steps
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
I will be here.. Have fun at work! =D
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
Updating Java and Clearing CacheGo to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
It will say "Java Plug-in" under the icon.
Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
If you are unable to update you can manually update by going here:http://www.java.com/en/download/manual.jsp
After the reboot, go back into the Control Panel and double-click the Java Icon.
Under Temporary Internet Files, click the Delete Files button.
There are three options in the window to clear the cache - Leave ALL 3 CheckedDownloaded Applets
Downloaded Applications
Other Files
Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Java Control Panel.
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
Please open HiJackThis and check the following boxes.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.evko.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.evko.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
= http://www.evko.biz
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = http://www.evko.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.evko.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.evko.biz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.evko.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.evko.biz
And click Fix Selected.. How is everything now?
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
Theirs one more thing i would like you to do.
Please submit the following file to one of these online file scanners.
C:\WINNT\system32\kernels8.exe
Jotti File Scan
VirusTotal File Scan
This will produce a report after the scan is complete, please copy and paste those results in your next post.
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
Yes it seems that the file is hidding.
* Make sure you can view hidden files and folders:
1.
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.
Now re-upload C:\WINNT\system32\kernels8.exe.
If you can't find it, just copy the file path and paste it in.
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
[QUOTE=Burton1]
Please download ewido anti-malware it is a free version of the program.
QUOTE]
LOL, I was about to suggest the same thing. That program is awesome. Can clean everything mcafee can and then some. And it's free!
bwjones
Junior Poster in Training
70 posts since Jul 2005
Reputation Points: 10
Solved Threads: 1
Please open HiJackThis, and place a checkmark next to:
O4 - HKLM\..\Run: [System] C:\WINNT\system32\kernels8.exe
Now click "Fix Selected".
Please download the Killbox by Option^Explicit .
Note: In the event you already have Killbox, this is a new version that I need you to download.Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINNT\system32\kernels8.exe
Return to Killbox, go to the File menu, and choose Paste from Clipboard.
Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
Well it has been removed. Is everything running smoothly?
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4
You know ive been looking around and i can't find anything on, but otherwise you are clean.
Burton1
Junior Poster in Training
55 posts since May 2006
Reputation Points: 12
Solved Threads: 4