| not-a-virus:Adware.Win32.Cinmus.d removal process |
|
| Author:admin CopyFrom:web Hits: UpdateTime:2008-3-20 14:48:15 |
1.DownloadGoogle recommend safer browser Web browser, For more safe , Stay Secure on the Web and stay far away virus,Download URL http://www.oral8.net/firefox/firefox.htm
2. Temporarily Disable System Restore (Windows Me/XP).
3. Update the virus definitions. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all not-a-virus:Adware.Win32.Cinmus.d infected files and Delete/Modify any values added to the registry.
Navigate to the subkey and delete the valuesas following:
C:\Documents and Settings\All Users\Application Data\Microsoft\pctools\pctools.dll C:\WINDOWS\system32\FreezeScreenSaver.exe C:\Program Files\MSEB\smss.exe
O2 - BHO: BHO Class - {BCBD80C9-6AD7-48ed-8DF1-6963414B3649} - C:\WINDOWS\system32\flym.dll (file missing) {FFB3D068-F8DA-4370-A71E-83B1C959CDD6} - C:\WINDOWS\system32951.dll HKLM\..\Policies\Explorer\Run: [bv75mc6k] rundll32 "C:\WINDOWS\Downlo~1\bv75mc6k.dll",start HKLM\..\Policies\Explorer\Run: [vham6] rundll32 "C:\WINDOWS\Downlo~1\vham6.dll",Run
5. Exit registry editor .
6.delete the IE temp files or you may download ATF temp files cleaner to run a full cleaning.and restart the computer.
8. Now you may remove not-a-virus:Adware.Win32.Cinmus.d successfully.
send these files for analysis (i advise quarantining them): C:\WINDOWS\system32\FreezeScreenSaver.exe C:\Program Files\MSEB\smss.exe how to send/quarantine http://forum.kaspersky.com/index.php?showtopic=13881
|
| howtoremoveInputer:admin Editor:admin |
| End Of The Article how to remove not-a-virus:Adware.Win32.Cinmus.d |
|
Back 个howtoremove:Backdoor.Win32.Rbot.cqi
Next 个howtoremove: OSO.exe |