ChrisRLG
OK - here we go again:-
=======================
OK this is long and involved - It will take me four or five posts - as I will be posting copies of pictures that I copied when I infected this on myself.
With these pictures will be file names from my infection - THAT WILL NOT BE THE SAME AS YOURS - they are provided as examples only. Please read the text for the filenames that you will need to find and delete etc.
My suggestion is so that you can follow all of that to copy all the text to a wordpad file on your computer - along with the pictures if you think they will help you.
Then once you boot to safe mode - DO NOT OPEN INTERNET EXPLORER OR GO TO THE INTERNET WITH ANY OTHER METHOD - until you have completed the last of those tasks.
Please continue with the next step if you run into a problem with the current one. Just be sure to let us know what the problem was when you reply.
Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows
Please download About:Buster from here: http://tools.zerosrealm.com/AboutBuster.zip. Once it is downloaded extract it to
c:\aboutbuster. We will use that program later in this process.
Please download Reg Lite from here:
http://www.resplendence.com/download/reglite.exe
Once it is downloaded double click to install. We will use that program later in this process.
Reboot your computer into Safe Mode and follow these steps:
Step 1:
Click on start, then control panel, then administrative programs, then services. Look for a service called Remote Procedure Call (RPC) Helper. Double click on the that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.
[external image: Posted Image]
[external image: Posted Image]
=======================
OK this is long and involved - It will take me four or five posts - as I will be posting copies of pictures that I copied when I infected this on myself.
With these pictures will be file names from my infection - THAT WILL NOT BE THE SAME AS YOURS - they are provided as examples only. Please read the text for the filenames that you will need to find and delete etc.
My suggestion is so that you can follow all of that to copy all the text to a wordpad file on your computer - along with the pictures if you think they will help you.
Then once you boot to safe mode - DO NOT OPEN INTERNET EXPLORER OR GO TO THE INTERNET WITH ANY OTHER METHOD - until you have completed the last of those tasks.
Please continue with the next step if you run into a problem with the current one. Just be sure to let us know what the problem was when you reply.
Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows
Please download About:Buster from here: http://tools.zerosrealm.com/AboutBuster.zip. Once it is downloaded extract it to
c:\aboutbuster. We will use that program later in this process.
Please download Reg Lite from here:
http://www.resplendence.com/download/reglite.exe
Once it is downloaded double click to install. We will use that program later in this process.
Reboot your computer into Safe Mode and follow these steps:
Step 1:
Click on start, then control panel, then administrative programs, then services. Look for a service called Remote Procedure Call (RPC) Helper. Double click on the that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.
[external image: Posted Image]
[external image: Posted Image]