ok you mostly did try it, but did you try spybot search and destroy?Originally Posted by Falconblade
ok you mostly did try it, but did you try spybot search and destroy?Originally Posted by Falconblade
Start in safe mode without networking
Disable system restore
Click Start > Run.
Type regedit
Click OK.
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
In the right pane, delete the value:
"Shell" = "Explorer.exe, msmsgs.exe"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
In the right pane, delete the value:
"MSN Messenger" = "%System%\msmsgs.exe"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion
In the right pane, delete the value:
"uuid" = "[random characters]"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\policies\explorer\Run
In the right pane, delete the value:
"notepad.exe" = "msmsgs.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{724510C 3-F3C8-4FB7-879A-D99F29008A2F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects
\{724510C3-F3C8-4FB7-879A-D99F29008A2F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects
\{724510C3-F3C8-4FB7-879A-D99F29008A2F}
Exit the Registry Editor.
Reset your browser home page, preferably for time being to about:blank
Reset your browser search option
Trojan.Zlob also nests in:
%System%\ld100.tmp
%System%\regperf.exe?
Also the files it can mask itself as when it copies:
hp[X].tmp
msvol.tlb
ncompat.tlb
RSA
Protect
vnp7s.net
zxserv0.com
dumpserv.com
If its running its usually running under these 2 processes (use TaskManager):
nvctrl.exe
msmsgs.exe
bah, it's easier to just wipe. No matter what, you can't be 100% certain that you got all the crap out...
Seriously though, CD-R is cheap. So's an external hard drive. If it's sooooo important you want to muck through the registry and dig through all the files in windows for a virus, why isn't it possible for you to burn a copy on a cd or transfer a copy to an external?
1-866-PC-SAFETY <--- Free Microsoft Virus/Spyware removal service
Step 1) Backup your drivers
Step 2) Download UBCD (make sure you have updated drivers)
Step 3) Boot to UBCD, scan your computer, remove viruses.
Step 4) If all else fails, reformat and use your backed up drivers.
If you're not wanting to reformat because you'd have to reinstall FFXI, check this:
http://www.windower.net/forums/viewtopic.php?t=8434