View Single Post
Old 04-22-2005, 06:18 PM   #9 (permalink)
greyknight17
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

Yes, that's precisely what we will need to do. Follow the instructions below:

ncase - http://www.pchell.com/support/ncase.shtml
Internet Optimizer - http://www.iamnotageek.com/a/386-p1.php
Power Scan:
Quote:
Powerscan Description
Powerscan may launch pop-up advertisements and monitor your Internet activity while you're browsing the web. This adware may be downloaded through other pop-up advertisements, or it may come packaged with an Internet Explorer toolbar with search functions.

PowerScan Removal Instructions

End the 'cleanup.exe', 'ignorelist.exe', 'patchnow.exe', 'productsupport.exe', 'powerscan.exe', 'sysrestore.exe' process from the Task Manager (ctrl-alt-delete).

Remove these files (if present) with Windows Explorer: cleanup.exe, ignorelist.exe, patchnow.exe, pc powerscan - live update.lnk, pc powerscan.lnk, power scan.lnk, productsupport.exe, programfilesdir+\power scan\powerscan.exe, sysrestore.exe.

Open the registry (Start->Run->regedit) and delete the following keys and values:
HKEY_CURRENT_USER\software\powerscan
HKEY_CURRENT_USER\software\powerscan account_id 126407
HKEY_CURRENT_USER\software\powerscan\{4e7bd74f-2b8d-469e-dbfc-ed1ca787ad2d}
HKEY_CURRENT_USER\software\powerscan\account_id
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion
un power scan
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion
un\power scan
HKEY_LOCAL_MACHINE\software\powerscan
HKEY_LOCAL_MACHINE\software\powerscan loadnum 1

Having successfully done this you should be able to delete the entire 'PowerScan' folder in Program Files.
SideFind:
Quote:
SideFind Description
SideFind is a website search engine that may also be downloaded as an Internet Explorer toolbar with specialized search functions. SideFind may change your home page settings and redirect your search requests and error pages.

SideFind Removal Instructions

Before you can delete files, you must first stop all the SideFind processes that are running in memory.
Do this by ending all processes from the Task Manager.
Press CTRL+ALT+DELETE to open the Windows Task Manager. If you see multiple
"tabs," click on the "Processes" tab. For each process that you would like
to kill, find the process name in the list, click it to select it, and click
the "End Process" button.



Delete registry values Instructions:
Open the Windows Registry Editor by clicking on the Windows "Start" button,
clicking "Run," and typing "regedit" into the box in the Window that appears. Click "OK".
Once the Registry Editor is open, navigate through the registry tree to the
location of the key that you wish to delete. When you find the key or
value to be deleted, click on it to highlight it and press the "DELETE" key.

Delete Registry Values:
SOFTWARE\Microsoft\Side\Find
SOFTWARE\Microsoft\Internet Explorer\Extensions\{10E42047-DEB9-4535-A118-B3F6EC39B807}
BrowserHelperObject.BAHelper
{8CBA1B49-8144-4721-A7B1-64C578C9EED7}
{339D8AFF-0B42-4260-AD82-78CE605A9543}
SideFind.Finder
{58634367-D62B-4C2C-86BE-5AAC45CDB671}


Unregister DLL Instructions:
To un-register a DLL file, first locate the file on your hard drive.
Open a command prompt window by clicking on the Windows "Start" button,
clicking "Run," and typing "cmd" into the box in the Window that appears. Click "OK."
Next type "regsvr32 /u " and press the "ENTER" key.
For example, to un-register a file called "myDll.dll" which is located in
the "C:\windows\system32" folder, your would type
"regsvr32 /u C:\windows\system32\myDll.dll" and press the "ENTER" key.



Delete File Entries:
sfbho13[1].dll
sidefind[1].exe
sfexd001
OK, that should do it. If you have any questions, feel free to ask them here. Before you attempt to edit anything in the registry, make sure to back it up first. Go into the Registry Editor and then click on File->Export and save it somewhere.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline