Hi again --
Closer still.. the log is almost clean.
It's pretty important that we get CleanUp! to run, because that's going to take out any lingering installers in your Temp folders and various other locales. Here's a more direct link -- see if you can get it from
here. If you have problems downloading it from here, please let me know and we'll figure out some other way to get it to you.
Also, did you run rkfiles last time around? I didn't see its logfile in the last post, only the rem.bat file. We need to take a look at that as well.
So, assuming you can get CleanUp!, here's your next set of instructions. As always, you should print them so you can access them during your fix:
Go to
Start > Run and type
Services.msc, then click
OK. In the list that appears, scroll down to find a service called
System Startup Service (SvcProc) and double-click on it. In the next window, click
Stop, then click
Properties, and under the General tab, change the Startup Type to Disabled. Click
Apply, then
OK, then close any open windows.
Run CleanUp! and click the
CleanUp! button. When it asks whether you want to log off, click
Yes.
Reboot your system into Safe Mode once more (again, this means repeatedly tapping F8 until the menu appears, then selecting
Safe Mode).
This is very important, as the following must be done in Safe Mode!
Make sure any open programs, especially Web browsers, are closed.
Open Hijack This and click
Scan. If they still exist -- and some might not -- check all of the following entries
(make sure you do not miss any):
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe (file missing)
Please close all other windows, including browsers, then click Fix checked.
Check whether
c:\windows\SvcProc.exe exists; if it does, delete it.
Again, clear out your old rkfiles and rem.bat logs to make way for these new ones, then:
Double-click rkfiles.bat. It will scan for a while, so please be patient. It'll save as C:\log.txt.
Run CleanUp! and click the
CleanUp! button. When it asks whether you want to log off, click
Yes.
Reboot back into normal mode.
In your next post, please include a fresh HijackThis log and the contents of the rkfiles log.
__________________
Have TSF volunteers helped you? Please consider helping TSF by
subscribing or
donating. Thanks!