Run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"
O4 - HKLM\..\Run: [scvhost] scvhost.exe
heb ik niet ertussen staan
O4 - HKLM\..\RunServices: [scvhost] scvhost.exe
heb ik niet ertussen staan
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
heb ik niet ertussen staan
Restart to safe mode.
Now find and delete:
The C:\WINDOWS\System32\scvhost.exe file
Deze file heb ik niet
The C:\Program Files\Common Files\GMT folder
Deze map heb ik niet
Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
OK
Now navigate to the C:\Windows\System32\drivers\etc folder. Locate the HOSTS file. Open the HOSTS file in notepad by clicking on it to open it. It will ask you what program you want to use to open it. Tick "Select the program from a list" and click OK. In the menu of programs that opens find and select notepad and click OK. The HOSTS file will open in notepad. Look for a list like this:
127.0.0.1
www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1
www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 sophos.com
127.0.0.1
www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1
www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1
www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1
www.avp.com
127.0.0.1
www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1
www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1
www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1
www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1
www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1
www.trendmicro.com
Delete all those lines leaving only this one:
127.0.0.1 localhost
Now close the file and answer Yes to confirm the changes.
OK
Empty the Recycle Bin.
Turn off System Restore:
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.
When you are sure you are clean turn it back on and create a restore point.
Go here and do an online virus scan:
http://housecall.trendmicro.com/