Originally Posted by AndiAndi
We'll see to that later , maibe after removing all the malware that prob might be gone.Thanks for your help!
I'm sure I disabled System Restore manually, but will do again.
Not sure how to empty the prefetch folder, but can follow directions if you let me know how. Also, how do I run ChckDsk?
Maybe you run Ewido before disabling sysrestore , and to empty the prefetch folder , just navigate to it and delete the contents. If you dont see the prefetch folder then just copy this in the address bar and press enter:
C:\Windows\prefetch
And to run a diskcheck ,in "my computer" rightckick youre drive , select properties , tools , check now , and reboot.
(BTW, whenever I try and restart, I get a window:
End Program:
"ccAPP" this program is not responding, click End Now to end. Changes will be lost (or something like that). I have to click End Now to get it to restart.
I see that you have "Spyware Cleaner" installed , that is not an recommended app and i would advice to uninstall it.
See here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Then boot in safemode and fix these with hjt:
O4 - HKLM\..\Run: [dmhqz.exe] C:\WINDOWS\system32\dmhqz.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CF5BEA4-7CFB-482F-A702-89AF4D98CC6F}: NameServer = 85.255.115.118,85.255.112.12
C:\WINDOWS\SYSTEM32\ENCODEX.EXE
C:\WINDOWS\SYSTEM32\CSFHF.EXE
C:\WINDOWS\SYSTEM32\IPSEC6.EXE
C:\WINDOWS\SYSTEM32\DMASJ.EXE
C:\WINDOWS\SYSTEM32\DMLOX.EXE
And i would also disable the windows messenger service:
Please download Shoot The Messenger
Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.
If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.
Lets see if you still have any trojan warnings after that.
























Linear Mode


