Please print out or copy this page to
Notepad in order to assist you when carrying out the following instructions.
Viewing Hidden Files
Go to
My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the
Hide protected operating system files option.
Downloads(make sure to save these in a permanent location)
Cleanup! (
Alternate Link)- Install it. You will use this later.
*NOTE* Cleanup deletes EVERYTHING out of temporary folders and does not make backups.
Ewido Security Suite- Install Ewido Security Suite
- When installing, under "Additional Options" uncheck..
- Install background guard
- Install scan via context menu
- Double-click the icon on Desktop to launch Ewido
You will need to update Ewido to the latest definition files.
- On the left hand side of the main screen click update.
- Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to
manually update Ewido
When you have finished updating,
EXIT Ewido.
Services
Click Start->Run - type
SERVICES.MSC & then click on the OK button
- Locate the service - Command Service (cmdService)
- Double-click on it to open the Properties dialog.
- Under the General tab, note down the name of "Service name". We shall need it later.
- Stop the service by using the Stop button.
- Change the Startup type to Disabled & then click on the OK button
- Then start HiJackThis & go to Config>Misc.Tools...> Delete an NT service...
- In the popup box that appears, type in cmdService & then click on the OK button
Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).
Add/Remove
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:
Freeprod Toolbar
HijackThis!
Open Hijack This and click on Scan. Check the following entries
(make sure you do not miss any)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: LinkTracker Class - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - C:\Program Files\QL\qlink32.dll
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe"
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - C:\Program Files\QL\qlink32.dll
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\q0nula591d.dll (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\am9uIGV1\command.exe (file missing)
Please remember to close all other windows, including browsers then click Fix checked.
File and Folder Deletions
Delete the following Files indicated in
RED and Folders indicated in
BLUE if they still exist.
C:\Program Files\QL
C:\WINDOWS\am9uIGV1
C:\WINDOWS\isrvs
C:\WINDOWS\system32\igps.exe
Tools
Open
Cleanup! by double-clicking the icon on your desktop (or from Start > All Programs). Set the program up as follows:
Click
Options
Move the slider button down to
Custom CleanUp!
Check the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
Uncheck the following :
- Scan local drives for temporary files
Click
OK, Press the
CleanUp! button to start the program. If prompted to reboot, click
No.
Run
Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click Complete System Scan to begin scanning.
- Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
- "Perform action on all infections"
- Choose clean and click OK.
Once finished, click the
Save report button & save the report to your desktop
** This scan may take over an hour, after choosing the action for the first item you do not need to stay at the PC.
Reboot your system in Normal Mode.
Open HijackThis, click Config, then click Misc Tools.
Click "
Open Uninstall Manager"
Click "Save List" (generates
uninstall_list.txt)
Click Save, copy and paste the results in your next post.
Online Scans
Perform an online scan with Internet Explorer with
Panda ActiveScan
**
click on "Free use ActiveScan" located on the top right hand corner - Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
- Click Scan Now
- Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting
My Computer- If it finds any malware, it will offer you a report.
- Click on see report. Then click Save report
Post the contents of the report in your next reply
*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
*Turn off the real time scanner of any existing antivirus program while performing the online scan
In your next post please include:
- Ewido Log
- Uninstall List
- Panda Activescan Log
- A new Hijackthis! Log