Author Topic: Help i haf been hacked by spiderman  (Read 10580 times)

0 Members and 1 Guest are viewing this topic.

donz

  • Guest
Help i haf been hacked by spiderman
« on: February 12, 2008, 10:51:09 AM »
Help i have been "hacked by Spiderman June 10 2007"
It appears ontop of my IE

Attatched are the reports from Mountpoint and hijackthis

Help me ASAP
i have tried:
1: Scanning wif Mcafee
2: Removing using Flash Disinfector
\
thanks for your help and reply ASAP pls!!!

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #1 on: February 12, 2008, 03:05:01 PM »
HI

This should work for the problem you posted about, but you have other problems as well.

http://video.aol.com/video-detail/ayumilove-how-to-remove-hacked-by-spiderman-2007-june-10/1666675518

For your other problems, vundo

Go to add/remove programs and uninstall

Starware 3.3.3.0.

Open HJT, run a system scan only, check mark these lines if present

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcD+LDHhd+DajEeyxFHfiCAFB8IC5Frd47zG8WAI65zPAN5TTGsCmQu/rtF8UaQyZvisVfLcBfh0ggS1uv+npqDZrxilUenrZyKBc8K+j5jbcZrcVSaOrdNjNWLurYUoDhbEY1yuGInr3lK13vN8lwh1bVTkejb+0wO
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://seek.3721.com/srchcust.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by Spiderman 2007-June-10)
R3 - URLSearchHook: CleverHook Class - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\WINDOWS\jeired.dll (file missing)
R3 - URLSearchHook: (no name) -  - (no file)
O2 - BHO: (no name) - {5E9755A1-314A-4ae6-99E1-B9F7DC7C7CF0} - (no file)
O2 - BHO: CleverHook Class - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\WINDOWS\jeired.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [windows auto update] msblast.exe
[O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O4 - HKLM\..\Run: [MemoryMeter] C:\Program Files\MemoryMeter\MemoryMeter.exe
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\Run: [NetService] C:\DOCUME~1\TOHGIM~1\LOCALS~1\Temp\vista.exe /run
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\iiijge.dll",forkonce
O4 - HKCU\..\Run: [checkdisk] rundll32.exe "c:\windows\khefcb.dll",DllRegisterServer
O9 - Extra button: Yahoo 1G mail - {507F9113-CD77-4866-BA92-0E86DA3D0B97} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yahoomail (file missing)
O9 - Extra button: E bazar - {59BC54A2-56B3-44a0-93E5-432D58746E26} - http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://www.taobao.com/vertical/mall/pro.php?allyesPara=816 (file missing)
O9 - Extra button: Yahoo Assistant - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yassist (file missing)
O9 - Extra button: (no name) - {6354ABE6-05F1-49ed-B850-E423120EC338} - http://cn.widget.yahoo.com/index.htm?source=Cns (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clean (file missing)
O20 - AppInit_DLLs: c:\windows\khefcb.dll
O20 - Winlogon Notify: 4 - C:\WINDOWS\4.tmp
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)



Download ComboFix from Here or Here to your Desktop.

Double click combofix.exe and follow the prompts.

When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall.





Close all other browsers/windows, click fix, close HJT.

donz

  • Guest
Re: Help i haf been hacked by spiderman
« Reply #2 on: February 13, 2008, 07:36:06 AM »
Thanks here are the logs

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #3 on: February 13, 2008, 03:00:55 PM »
We have a lot to do, but start wuth this. I'll put more up in awhile.

Download and Install Microsoft's TweakUI: http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx

Obtain and install TweakUI (right hand panel, 147kb in size), and then start TweakUI.

Expand the My Computer branch, then the AutoPlay branch, and then select Drives.

Turn off the checkbox next to every drive letter to disable AutoPlay -- except your CD/DVD drive letters

This will prevent autoruns from running on your computer.


Download this program, Flash Drive Disinfector by sUBs from

http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

Plug in your usb hd

Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.

This utility will do a couple of things. First it will remove any autorun.inf it finds. There shouldn't be one on a fixed HD anyway. There is no need for such a file on any removable storage device -- iPod, USB flash drive, cell phone, .etc as you can open these drives manually.

It will create a SYSTEM protected, read-only, and perfectly harmless Autorun.inf file on any hard drive or removable storage device it finds when run. This file will not only help prevent future autorun infections, it will disable any current Autorun infection its ability to restart.

You can do this with all of your usb devices.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #4 on: February 13, 2008, 09:38:07 PM »
Hi,

Have you completed all the steps, I have posted up until now?

I need to know how many usb devices you have, how many can be plugged in at a time and the drive letters usually assigned to these drives


Open Hijackthis,run a system only, checkmark the following lines if present

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by Spiderman 2007-June-10
4 - HKLM\..\Run: [MicrosoftComboBoxControl] C:\WINDOWS\comboClt.ocx.vbs
O20 - AppInit_DLLs: c:\windows\khefcb.dll




Please download
 OTMoveIt2 by OldTimer.


Save it to your desktop.

Please double-click OTMoveIt2.exe to run it.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


C:\WINDOWS\noqsru.ini
C:\WINDOWS\ursqon.dll
C:\WINDOWS\jkjhed.exe
C:\comboClt.ocx.vbs
C:\WINDOWS\awtsrs.exe
C:\WINDOWS\ddbcbc.exe
C:\WINDOWS\efffeb.exe   
C:\WINDOWS\geeedd.exe
C:\WINDOWS\byvvwu.exe
C:\WINDOWS\awutqn.exe
C:\WINDOWS\gebbyw.exe
C:\WINDOWS\effdaw.exe
C:\WINDOWS\qonklk.exe
C:\WINDOWS\byyaax.exe
C:\WINDOWS\wvvurr.exe
C:\WINDOWS\nnonkj.exe
C:\WINDOWS\rqpqpn.exe
C:\WINDOWS\xxyyyw.exe
C:\WINDOWS\fcbxur.exe
C:\WINDOWS\vtttsr.exe
C:\WINDOWS\opoopm.exe
C:\WINDOWS\iifday.exe
C:\WINDOWS\qonnlj.exe
C:\WINDOWS\dddbcy.exe
C:\WINDOWS\yabbay.exe
C:\WINDOWS\tuvvts.exe
C:\WINDOWS\oponoo.exe
C:\WINDOWS\mlijhe.exe
C:\WINDOWS\awutqq.exe
C:\WINDOWS\nnolkk.exe
C:\WINDOWS\awuron.exe
C:\WINDOWS\pmllkh.exe
C:\WINDOWS\tutspq.exe
C:\WINDOWS\urrsss.exe
C:\WINDOWS\cbbyaw.exe
C:\WINDOWS\iihhhe.exe
C:\WINDOWS\khgghe.exe
C:\WINDOWS\nnkjhe.exe
C:\WINDOWS\comboClt.ocx.vbs
C:\WINDOWS\cbxxuv.exe
C:\WINDOWS\iiihef.dll
c:\WINDOWS\xxywts.exe
C:\WINDOWS\xxxvwx.exe
C:\WINDOWS\urrpqn.dll
C:\WINDOWS\yaxxxw.dll
C:\WINDOWS\urssrp.dll
C:\WINDOWS\ljgdbc.exe
C:\WINDOWS\vttqon.dll
C:\WINDOWS\bywttq.exe
C:\WINDOWS\tutqrr.dll
C:\WINDOWS\pmlkki.exe
C:\WINDOWS\tutuur.exe
C:\WINDOWS\pmklig.dll
C:\WINDOWS\opmlkl.exe
C:\WINDOWS\khgfef.dll
C:\WINDOWS\wvturs.dll
C:\WINDOWS\qopolk.exe
C:\WINDOWS\xxvvtq.dll
C:\WINDOWS\pmlijj.dll
C:\WINDOWS\ddddcd.exe
C:\WINDOWS\byvvtr.exe
C:\WINDOWS\nnklig.dll
C:\WINDOWS\sstron.exe
C:\WINDOWS\tuttus.dll
C:\WINDOWS\hgffgf.exe
C:\WINDOWS\ssropn.exe
C:\WINDOWS\ssqnoo.dll
C:\WINDOWS\khiigd.dll
C:\WINDOWS\nnkkkh.exe
C:\WINDOWS\mliiii.dll
C:\WINDOWS\qopmmj.exe
C:\WINDOWS\bywvus.exe
C:\WINDOWS\efcdba.exe
C:\WINDOWS\ddbxwu.exe
C:\WINDOWS\ssrsst.dll
C:\WINDOWS\cbbaxy.exe
C:\WINDOWS\mlifca.dll
C:\WINDOWS\nnklii.exe
C:\WINDOWS\pmnonn.dll
C:\WINDOWS\tusqnl.exe
C:\WINDOWS\rqrqpm.dll
C:\WINDOWS\xxyxvt.exe
C:\WINDOWS\ljgggd.dll
C:\WINDOWS\vtttuv.dll
C:\WINDOWS\qonllm.exe
C:\WINDOWS\ssqnki.dll
C:\WINDOWS\yaawvs.exe
C:\WINDOWS\ljgddd.dll
C:\WINDOWS\hgdeba.exe
C:\WINDOWS\wvvtrr.dll
C:\WINDOWS\iihebc.exe
C:\WINDOWS\ursrrp.dll
C:\WINDOWS\fcyaxu.exe
C:\WINDOWS\jkheff.exe
C:\WINDOWS\vtusqn.exe
C:\WINDOWS\qonlii.exe
C:\WINDOWS\hgdcbc.exe
C:\WINDOWS\opommn.dll
C:\WINDOWS\qomkll.exe
C:\WINDOWS\urrqop.dll
C:\WINDOWS\qopqol.exe
C:\WINDOWS\xxvsss.dll
C:\WINDOWS\pmnkhi.exe
C:\WINDOWS\tuvvuv.exe
C:\WINDOWS\khebyw.dll
C:\WINDOWS\nnmnmk.dll
C:\WINDOWS\ljkhge.exe
C:\WINDOWS\xxxyxy.exe
C:\WINDOWS\xxyxvu.dll
C:\WINDOWS\ljkifg.exe
C:\WINDOWS\vtrono.exe
C:\WINDOWS\mlmlif.dll
C:\WINDOWS\wvtqol.exe
C:\WINDOWS\urpnlk.dll
C:\WINDOWS\iihefd.exe
C:\WINDOWS\ljgffe.dll
C:\WINDOWS\xxvtqn.exe
C:\WINDOWS\khghig.exe
C:\WINDOWS\ljkkhf.exe
C:\WINDOWS\mlkjji.dll
C:\WINDOWS\qomnnl.dll
C:\WINDOWS\awwwur.exe
C:\WINDOWS\opqrqn.dll
C:\WINDOWS\qomnli.exe
C:\WINDOWS\khgfdb.dll
C:\WINDOWS\efddec.exe
C:\WINDOWS\mlmkkj.dll
C:\WINDOWS\yaxvvv.exe
C:\WINDOWS\mliihf.exe
c:\windows\khefcb.dll



Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.



Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")



Next,



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt  -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
.
I will need the following, answers to the questions above, the OTMOVEIT2 results, and the Deckard's logs.

Thanks






« Last Edit: February 13, 2008, 09:46:17 PM by oldman »

donz

  • Guest
Re: Help i haf been hacked by spiderman
« Reply #5 on: February 16, 2008, 07:16:40 AM »
i haf 2 drives, both can fit into my com.

attached are the logs.

thanks

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #6 on: February 16, 2008, 08:57:49 AM »
In your next post please confirm the following
1. you disabled autoruns
2. you ran flashdrive disinfector
3. mcafee is your current ativirus program and it has an active firewall. If not please turn on the windows firewall
4. the drive letters of your flashdrives


   

We'll use OTMOVEIT2 again, but this time we will use the lower left box under the yellow line. Also, providing you have run Flashdrive Disinfector, we can also clean your flashdrives. Please insert both drives before running OTMOVEIT2. (as image below)


Open HJT, run a system scan only, check mark these lines if present

O4 - HKLM\..\Run: [Windows Control Server] wlmsvcxp.exe
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O20 - AppInit_DLLs: c:\windows\khefcb.dll


Close all other browsers/windows, click fix, close HJT.


Go to add/remove programs and uninstall, if present

Spyware Cleaner




Please double-click OTMoveIt2.exe to run it.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

C:\WINDOWS\iiffda.exe
C:\WINDOWS\mlkhij.exe
C:\WINDOWS\urspmj.exe
C:\WINDOWS\ljgdcy.exe
C:\WINDOWS\ssrppm.exe
C:\WINDOWS\ursrqp.exe
C:\WINDOWS\wvttsr.exe
C:\WINDOWS\yaaxus.dll
C:\WINDOWS\vttrpm.exe
C:\WINDOWS\pmljjg.dll
C:\WINDOWS\awttqo.exe
C:\WINDOWS\rqolkh.dll
C:\WINDOWS\pmljhg.exe
C:\WINDOWS\ursqnn.exe
C:\WINDOWS\wvtrpn.dll
C:\WINDOWS\cbywwu.exe
C:\WINDOWS\jkhigh.dll
C:\WINDOWS\tutqqo.exe
C:\WINDOWS\vtroom.exe
C:\WINDOWS\sstuuu.dll
C:\WINDOWS\ddbbxw.exe
C:\WINDOWS\wvvvwv.exe
C:\WINDOWS\pmkjgg.dll
C:\WINDOWS\xxvwxy.dll
C:\WINDOWS\mlijgg.exe
C:\WINDOWS\iiijjj.dll
C:\WINDOWS\geefff.exe
C:\WINDOWS\urrrsr.exe
C:\WINDOWS\xxxyyv.dll
C:\WINDOWS\ddayax.exe 
C:\WINDOWS\qopmlm.dll
C:\WINDOWS\geebbx.exe
C:\WINDOWS\jkkjhg.dll
C:\WINDOWS\mlklll.exe
C:\WINDOWS\khggdc.dll
C:\WINDOWS\gedbaa.exe
C:\WINDOWS\fccawt.exe
C:\WINDOWS\wvwutt.dll
C:\WINDOWS\mlmmnm.exe
C:\WINDOWS\khghec.dll
C:\WINDOWS\ssrqno.exe
C:\WINDOWS\qomkif.dll
C:\WINDOWS\urrrop.exe
C:\WINDOWS\jkkkhf.dll
C:\WINDOWS\mlkljh.dll
C:\WINDOWS\hgfcdb.exe
C:\WINDOWS\wvwvss.dll
C:\WINDOWS\awurpm.exe
C:\WINDOWS\opqpqq.dll
C:\WINDOWS\efcbcd.exe
C:\WINDOWS\mlkhgg.dll
C:\WINDOWS\nnkijj.dll
C:\WINDOWS\qoppoo.exe
C:\WINDOWS\fccyax.exe
C:\WINDOWS\wvwwxu.exe
C:\WINDOWS\urpnol.exe
C:\WINDOWS\urpmml.dll
C:\WINDOWS\khghhe.exe
C:\WINDOWS\efcaab.exe
C:\WINDOWS\nnmmlm.dll
C:\WINDOWS\hgdbcb.exe
C:\WINDOWS\rqpppp.dll
C:\WINDOWS\vtrqnn.dll
C:\WINDOWS\nnkkih.exe
C:\WINDOWS\tuvurp.exe
C:\WINDOWS\iiighh.dll
C:\WINDOWS\xxyxyw.exe
C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe
C:\Windows\ wlmsvcxp.exe
c:\comboClt.ocx.vbs /s
d:\comboClt.ocx.vbs /s
f:\comboClt.ocx.vbs /s
g:\comboClt.ocx.vbs /s
h:\comboClt.ocx.vbs /s
i:\comboClt.ocx.vbs /s
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{842cd910-b2a2-11dc-a2b3-000bdbb36144}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6887bd70-c7fa-11dc-a2da-000bdbb36144}



Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.


Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the results they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


Please post the OTMOVEIT2 results and a new DSS log.

Thanks

donz

  • Guest
Re: Help i haf been hacked by spiderman
« Reply #7 on: February 18, 2008, 10:22:42 AM »
I have done all the above steps.
The drives are e and f drive.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #8 on: February 18, 2008, 02:46:39 PM »
I went by the DSS log and it said your cd was E:. Ok then run OTmoveit2 with the fix below, use the lower box again with usb devices attached.

Everything else looks good. How's does it look from there?

c:\comboClt.ocx.vbs /s
d:\comboClt.ocx.vbs /s
f:\comboClt.ocx.vbs /s
g:\comboClt.ocx.vbs /s
h:\comboClt.ocx.vbs /s
i:\comboClt.ocx.vbs /s
e:\comboClt.ocx.vbs /s

Just need the results of OTMOVEIT2 this time.
« Last Edit: February 18, 2008, 02:52:07 PM by oldman »

donz

  • Guest
Re: Help i haf been hacked by spiderman
« Reply #9 on: February 19, 2008, 11:08:28 AM »
it looks great my com is running very fast now thanks for the advice.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Help i haf been hacked by spiderman
« Reply #10 on: February 19, 2008, 02:32:43 PM »
Good like to here that. I think we are done.

Yuo can keep FDD, in case you format or but a new usb device.

Delete querymountpoints and any logs or notepads that you have left after the rest of the clean up.

* Click start button, run, then copy and paste the following line into the box and click ok.

ComboFix /u


* Open OTMOVEIT2 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.

* Create a new restore point

You must be logged on to an administrator account
Go to Start - All Programs - Accessories - System Tools - System Restore.
Click Create a restore point, and then click Next.
In the text box labeled Restore Point Description, type a name for this restore point , click create

* Remove old restore points

- Go to Start - All Programs - Accessories - system tools. Launch the Disk Cleanup tool and let it run. When it finishes a box with tabs will appear, select the more options tab. On this tab you will find a section for System Restore. If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.


* Open an Internet Explorer (only) window and go to http://java.sun.com/javase/downloads/index.jsp > Scroll down to "Java Runtime Environment (JRE) 6 Update 4...allows end-users to run Java applications".

Click the download button on the right.

 > If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.

 You do not have to install the Java Web Start ActiveX Control


Accept the license agreement > Click on Windows (XP,Vista, .etc) Offline Installation, Multi-language and Save the file jre-6u4-windows-i586-p.exe to your desktop; do not Run it. Do not install it yet.

When the download is complete, Open Control Panel > Add/Remove Programs:

Uninstall anything that says Sun Java, Java JRE, or similar.

Close Add/Remove Programs.

In Windows Explorer, navigate to C:\Program Files\Java <=this folder, if found. Delete any subfolders it may contain.

Do NOT delete C:\Program Files\JavaVM <=this folder, if found!

Reboot your computer.

Double-click on the saved file to install the update.

Delete the downloaded installation file after completing the above procedure  and reboot if not prompted to do so.



* Download and run this clean up utility. You can use it regularly. When it's first run, it is in demo mode to show you what it will remove. Review it and then rerun in real mode. It is configurable.

CleanUp by Steven Gould

http://www.stevengould.org/downloads/cleanup/


Take care keep safe.