>
>Soon or later this crap will destroy your system...
>
Let me repeat it all to make sure you are not miss some procedure :
>
>First turn off System Restore , empty Temp , Temporary Internet Files and
>Recycle bin folders
>
>Second Run hijackthis -> scan -> and give a check mark in front of every
>items below -> click "fix checked"
>O4 - HKLM\..\Run: [Automatic Microsoft Windows Updater] SUCHOST.EXE
>O4 - HKLM\..\RunServices: [Microsoft Updater Resources] Win32Fixer.exe
>O4 - HKLM\..\RunServices: [Automatic Microsoft Windows Updater] SUCHOST.EXE
>O4 - HKLM\..\RunServices: [Windows System Manager] winsystem.exe
>O4 - Startup: PowerReg Scheduler V3.exe
>O4 - Startup: PowerReg SchedulerV2.exe
>O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4)
>-
>http://www.drivershq.com/DD_v4.CAB
>O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) -
>
>https://www.birdville.k12.tx.us/CFIDE/classes/CFJava.cab
>
>Third search in C:\ for every files above (suchost.exe ; win32fixer.exe ;
>winsystem.exe; powerreg scheduler v3.exe ; powerreg schedulerv2.exe ;
>dd_v4.cab ; cfjava.cab) and delete them all
>
>Fourth follow every removal instruction for files and registry key from below
>site
>
>http://securityresponse.symantec.com/avcenter/venc/data/trojan.treb.html
>
>http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.EU
>
>http://www.pestpatrol.com/PestInfo/b/blaire.asp
>
>http://nl.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=65604&VName=TROJ_BANCOS.CR&VSect=O
>
>http://www.pestpatrol.com/pestinfo/p/powerreg_scheduler.asp
>Then restart computer.
>
>Fifth follow every step below instruction from the first to the end, do not
>forget to get the very last version of below software... click the link will
>bring you to download the latest software
>Common Steps of Virus - Trojan
>- Spyware - Mallware - Adware
>Removal
>1. Turn off system restore, empty Temp and Temporary Internet Files folders,
>also Recycle Bin...
>2. Run online virus scan at Trendmicro
>or
> Panda site
>3. Update your virus definition and scan the system...
> ◊ Download, install and update
>AVG or
>AntiVir in case you don't have anti virus
>software
> ◊ Download last version of
>Stinger stand alone virus scanner
>4. Download, install and update and run the fixer of
>CWShredder and
>
>CoolWWWSearch.SmartKiller removal
>5. Download install and update
>Spybot,
>Ad-aware, and
>VX2cleaner
>plug-in for ad-aware
>6. Run full system scan in
>safe
>mode with Stinger, Spybot and Ad-aware (run the VX2cleaner scan
>first)
>7. Download install and update
>Spywareblaster, one
>of firewall
>
>Zonealarm / Kerio and
>DCOMbobulator for extra
>protection
>8. If the problem persist download
>HijackThis and
>send the report log back to this forum
>9. Turn on system restore
>Note:
>All above software are free for personal use
>When email address needed for registration some site not explicitly but deny
>hotmail account probably occur to all free base email addresses
>It is also necessary to run cwshredder v.2.0 and coolwwwsearch.smartkiller
>removal tool in safe mode
>
>
>