To make things bigger in your browser, you may press "Ctrl" and "+" together. This will make your browser Zoom In, and make text bigger.
NOTE:
I will explain everything I said previously after we finish these steps to eliminate confusion.
Lets start fresh!
INSTRUCTIONS:
Part 1
- Turn on your other computer that you copied you files to.
- Download these files to your desktop :
PROCEXP LINK> http://download.sysinternals.com/files/ProcessExplorer.zip
AUTORUNS LINK> http://download.sysinternals.com/files/Autoruns.zip
CPORTS LINK> http://www.nirsoft.net/utils/cports.zip
- The files you downloaded are zip archives. Double click Processexplorer and extract the contents to the desktop using the wizard OR if you have winrar, right click the archive and click extract here.
- Now that you extracted procexp from the archive, copy it to your usb thumb drive. You probably can see two procexp files. You need the one with the windows logo.
- Repeat steps 3&4 for the autoruns and cports archives so that in the end you have copied 3 files to your usb thumb drive.
.
- Turn on your infected computer.
- Plug in the usb thumb drive and copy the 3 files to your desktop.
Part 2
- Double click procexp. If it does not open or you receive an error similar to what you get when you try to open taskmanager, rename procexp to "sunnyday" (or anything you wish).
- When procexp opens, click on "View" > click on "Select Columns"
- Make sure that the boxes for "Image Path" and "Command Line"
are checked.
- Click "Ok"
- Click "File" > Click "Save as"
- Save this text log file to your usb thumb drive.
Part 3
- Double click autoruns. If it does not open or you receive an error similar to what you get when you try to open taskmanager, rename autoruns to "blaze" (or anything you wish).
- Click on "Options" > Click on "Filter Options..."
- Clear all of the checkboxes.
- Click "Ok"
- The program will begin scanning. When "Ready" is displayed in the lower left corner.
Click "File" > Click "Save..."
- Save the autoruns log file to the usb thumb drive.
Part 4
- Double click cports. If it does not open or you receive an error similar to what you get when you try to open taskmanager, rename cports to "wind" (or anything you wish).
- Press " Ctrl + A " on your keyboard. (the ctrl key and the A key at the same time)
This should select all of the rows in cports.
OR
Alternatively, Click "Edit" > Click "Select All"
- Click on the floppy disk icon on the toolbar just under "File Edit View (etc)"
- Save the log file as a text file to the usb thumb drive.
Part 5
- Remove the usb thumb drive from your infected computer.
- On your other computer, come back to this post and click this link to my profile.
- On my profile, find my email address beside the words "Contact me:"
- Using that email, send me an email with the 3 log files that you got from
Parts 2-4 attatched.
I will review the log files and create a script for you that you will only need to double click in order to remove any infections. I will post the script here in this forum for you to copy and paste when completed.
If there is anything you find confusing please don't hesitate to ask, I tried to make this guide as clear as possible and spent lots of time on it.
-Alex