First Steps to analyse your system
STEP 1
Make sure you set Windows to see the hidden files and folders
STEP 2
Start Spybot Search&Destroy,
deactivate the "Resident TeaTimer".
(Click onto "Advanced mode" > "YES" > "Tools" Menu > Click
onto "Resident" > take off the checkmark with "Resident TeaTimer"
"activ." Box > exit.)
STEP 3
(Windows 2000 and Windows XP)
The first thing you could do to get rid of malware is: r
estore the operating system to a previous state - have a look
here:
- 1. Log on to Windows as Administrator.
- 2. Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore. System Restore starts.
- 3. On the Welcome to System Restore page, click Restore my computer to an earlier time (if it is not already selected), and then click Next.
- 4. On the Select a Restore Point page, click the most recent system checkpoint in the On this list, click a restore point list, and then click Next. A System Restore message may appear that lists configuration changes that System Restore will make. Click OK.
- 5. On the Confirm Restore Point Selection page, click Next. System Restore restores the previous Windows XP configuration, and then restarts the computer.
- 6. Log on to the computer as Administrator. The System Restore Restoration Complete page appears.
- 7. Click OK.
STEP 4
Download one of these two versions of HijackThis
HijackThis v1.99.1 or HijackThis.v2.02 by TrendMicro.
- Double-Click onto HTJInstall
- Install it
- Use HijackThis with a Double-Click onto its Icon.
(Getting problems, please use: run with administrator rights) > run it.
- Click onto Do a system scan and save a Logfile
- Click OK
- You will get a new window with a textfile copy its content and paste it to your thread.
STEP 5
Due to many malware which is attacking HijackThis by the moment, we need to ask our users to rename HijackThis v1.99.1
Hijackthis.exe -> into -> HJT1991.exe.
Run
HJT1991.exe and let it scan.
Save the fresh HJT logfile and post it.
STEP 6
NOTE:
Please use ONE of these File list Versions !
(NOT Windows Vista) - Download the filelist.zip
(FAQ) to your desktop.
- Unzip this file to your desktop (free Zip-Tools)
- Restart your system
- Doubleclick onto the filelist.bat to run it
- Your editor program will open
- Highlight the content, chose copy & paste it to your following posting
- Please note: we only need the last 30 days of every directory of this file
- Many Thanks to our Moderator Karl83 for creating this new tool.
- Directory of C:\
- Directory of C:\WINDOWS\system32
- Directory of C:\WINDOWS
- Directory of C:\WINDOWS\Prefetch (Windows XP)
- Directory of C:\WINDOWS\tasks
- Directory of C:\WINDOWS\Temp
- Directory of C:\DOCUME~1\Name\LOCALS~1\Temp
->
Please post all wanted information.
(Windows Vista)
- Download VistaFindbat. zip to your desktop
- Unzip the vistafind.zip > extract all...
- Open the new folder VistaFindbat on your desktop.
- Double-Click onto vistafind.bat
(Getting problems, please use: run with administrator rights) > run it.
- You will get a textfile.
- Copy & paste its content to your thread.
- Note: Post the Logfile in [code]
We only need the last 30 days of every directory of this file
Many Thanks to our Moderator Xeranox for creating this new tool.
- These are the directories which can be read using the VistaFind.bat:
- Directory of C:\
- Directory of C:\WINDOWS
- Directory of C:\WINDOWS\system
- Directory of C:\WINDOWS\system32
- Directory of C:\USER\Name\Temp
- Directory of C:\WINDOWS\Prefetch
- Directory of C:\WINDOWS\tasks
- Directory of C:\USER\Name\Temp
- Directory of C:\Program Files\ <--please post all files of this directory
->
Please post all wanted information.- Delete now the vistafind.txt
(Windows All)
- Unzip it to your desktop
(IZArc is free)
- Windows Vista: Rightmouse Click onto the file hjtscanlist.bat > chose (run as an administrator),
- all other Windows: Doubleclick the file hjtscanlist.bat to run it
- Windows XP: "XP"
- Other Windows Versions: "X"
- Windows Vista: "V"
- -> Chose "Q" for Exit > [Enter]
- Chose the selection what was given to you in your thread "1", "2", or "Q" > [Enter]
- Notepad will open, copy&paste the contents of this new text file to your thread
Lots of Thanks to our Team Member Mopao for creating this new tool.
- These are the files, which we want to see:
- Directory of C:\
- C:\Windows
- C:\Windows\System
- C:\Windows\System32
- C:\Windows\Prefetch
- C:\Windows\Tasks
- C:\Windows\Temp
- C:\Users\Name\AppData\Local\Temp
- C:\Program Files
- C:\ProgramData\..
- C:\Windows\system32\drivers\etc\hosts
- Additional Information
->
Please post all wanted information.