Hello, guys i posted my log on another forum, and didnt get any replies so i hope this is the right place, i got a virus from msn messneger ive tried all the removal methods but it didnt work. ive scanned it with lavasoft it didnt find. please help.
Please post over at techguy that you are already receiving help here so that they don't waste time going through instructions and we don't give conflicting advice.
Remove bad HijackThis entries
Run HijackThis
Click on the System Scan Only button
Put a check beside all of the items listed below (if present):
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [hidebalm] "C:\ProgramData\ListIdleIdle.qy1mu3
O4 - HKCU\..\Run: [SHIM LINK FREE BALL] "C:\ProgramData\REAL JOY SIGN.1szi1xd"
Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code:
[b]C:\ProgramData\ListIdleIdle.qy1mu3
C:\ProgramData\REAL JOY SIGN.1szi1xd[/b]
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
Click the red Moveit! button.
A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Under Main choose: Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
Firefox or Opera:
Click Firefox or Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Thanks ok ill do that, im going to use your technqiues. btw this seems pretty long atm so im going to do it tommorow and give you the response. because the virus is on my sisters pc not mine.
I am positive they are, and there is no 100% garuntee that this will be the end of the instructions, but after you show me the logs I can verify that they are gone and we can run a few more scans to be sure. After I see the requested logs then we can go from there in making sure that it is gone