Set Windows To Show Hidden Files and Folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Uncheck the Hide Extensions for known file types
* Click Yes to confirm.
* Click OK.
==Download and UNZIP to a folder
HSFIX.zipHSFix directory will be created
We'll need this later
==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows CleanupGive the link time to load or try it twice, it may be busy
Install for now, don't run a scan yet
==Download and then Install
Ewido Trojan ScannerWhen installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We'll fix that later
From the main ewido screen, click on update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido
We'll need it later
Please Print this out or save these instructions to a Notepad file and save it to your Desktop
RESTART your Computer in
SAFE MODEYou can do this by tapping the F8 key as the system is restarting, after the single post beep, or use the link
I supplied for a more detailed explanation
Find and delete these files or folders if found, in the Exact folders and right file name
C:\WINDOWS\system32\
netdc.exe <-file
C:\Documents and Settings\Peter\Start Menu\Programs\Startup\
netdb.exe <-file
C:\WINDOWS\
farmmext.exe <-file
C:\WINDOWS\system32\
gah95on6.exe <-file
C:\WINDOWS\system32\
pd14.exe <-file
C:\WINDOWS\
svchost.exe <-file, svchost.exe ONLY in the Windows folder, don't try and delete the legit file in the System32 folder
C:\WINDOWS\
zeta.exe <-file
wmediautil.exe <-search for this one and remove it, may be in the C:\WINDOWS\system32 folder
C:\Program Files\
WebSiteViewer <-this folder
Stay in safe mode
==Open Ewido trojan scanner
Click on the Scanner button in the left menu, then click on the Start button. This scan can take a while, so give it time to run
If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
When the scan finishes, click on "Save Report". This will create a text file.
Save the report
When that's done
==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
DECLINE to Log off when scan is done
Afterwards
Do another scan with Hijackthis and put a check next to these entries:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\winxp\system32\blank.htm
F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\netdc.exe
O2 - BHO: (no name) - {00000000-DD60-0064-6EC2-6E0100000000} - (no file)
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [Windows Service] C:\WINDOWS\system32\pd14.exe
O4 - HKLM\..\Run: [Setup experation] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [Windows Media Utility] wmediautil.exe
O4 - HKLM\..\RunServices: [Windows Media Utility] wmediautil.exe
O4 - Startup: netdb.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing)After you have ticked the above entries, close
All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
==Navigate to the
HSFix directory>>Open the folder, ensure you unzipped this
and double-click on HSFix.bat.
* It will produce a log file, located here: C:\
hslog.txt <--we'll need this later
Restart back to Normal mode
Download and Install the free version of
Ad-Aware SE Personal 1.05Ensure you have this version or the paid version
Open Ad-Aware, ensure to click the
check for updates now link and
Connect to download the latest updates
Perform a Full system scan
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button
RESTART your computer to finish the cleaning process
Back in Windows
Post back a fresh Hijackthis log and the Report from Ewidos
Also the log from hsfix.bat
C:\
hslog.txt <-this log