Please print out or copy this page to
Notepad in order to assist you when carrying out the following instructions.
To
turn off System Restore Click Start > Right Click My Computer > Properties. Click the System Restore tab and
Check.
"Turn off System Restore" or
"Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.
Go to
My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the
Hide protected operating system files option.
For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).
(Note: If you can not download these files because of the browser problems, you may have to download them on another PC and copy them over.)
Please download
Adaware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it. Go to this
Site to get the plug-in for fixing VX2 variants. Also make sure to
Customize the settings in Adaware for better scan results. Run the scan and fix everything that it finds.
Download Spybot 1.3 from this site
Spybot 1.3. Install the program, update the definitions file and run a scan. Fix all the entries, which are indicated in RED.
Download
CWShredder and click on Fix (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.
Download
WinsockFix and unzip it. Then double-click on it to run it.
If you have a fast internet connection (Broadband), run an online scan at
Trend Micro or
RAV Antivirus.
Please select the “autoclean” option when using Trend Micro.
Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:
(if present)
(Most likely these will not be listed but you should check)
WinTools for Internet Explorer (May be listed as Win-Tools Easy Installer (By Web Search)
Web Search Toolbar
Open Hijack This and click on Scan. Check the following entries
(make sure you do not miss any)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=40
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: HomepageProtector.Protector - {7D6BEC01-15E2-46F0-8ED3-D715DE09A8F9} - C:\HomepageProtector\218\HomepageProtector.dll
O9 - Extra button: (no name) - {7D6BEC01-15E2-46F0-8ED3-D715DE09A8F9} - C:\HomepageProtector\218\HomepageProtector.dll
O9 - Extra 'Tools' menuitem: Homepage Protector - {7D6BEC01-15E2-46F0-8ED3-D715DE09A8F9} - C:\HomepageProtector\218\HomepageProtector.dll
O10 - Broken Internet access because of LSP chain gap (#1 in chain of 10 missing)
O16 - DPF: {0733B8F9-8B52-4693-A9FA-829E12D27F78} (preload control) - http://www.thepaymentcentre.com/build/preload2.cab
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - http://akamai.downloadv3.com/binari...dtc32_EN_XP.cab
O16 - DPF: {2A6BEC01-15E2-46F0-8ED3-D715DE09A8F9} - http://www.homepageprotector.com/da...eproinstall.cab
O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) - http://www.accesoplugin.com/dialerc...oDialerHTML.cab
O16 - DPF: {9076A11F-5EA6-4A67-BDE9-8D3C7C453DAC} – http://www.fizzlewizzle.com/installfiles/popblocker.cab
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
Please remember to close all other windows, including browsers then click Fix checked.
Delete the following Files indicated in
RED and Folders indicated in
BLUE if they still exist.
C:\HomepageProtector
C:\Program Files\Common Files\WinTools
Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and run
KRC HijackThis Analyzer in the same folder to get the
result.txt log. Just post the contents of the result.txt file in the forum.
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. I notice your browser is not up to date and this makes you susceptible to attacks by Trojans and viruses. Please go to
Microsoft and download all the critical updates to help prevent possible re-infection.
4SG