Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted.
Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding. Please ensure that there aren't any any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.
* * * * * *
Please disable Ewido's real-time scanner, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable Ewido's real-time scanner:
- Double click on the Ewido icon in system try
- Click on the status button
- Select Remove Guard
* * * * * * ADDITIONAL DOWNLOADS * * * * * * * * * * * * * *
Download & install
CleanUp.exe (not recommended for WinXP64)
Download
KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)
You will need to update Ewido to the latest definition files.
Launch Ewido & click Update from the left pane
Then click on Start Update.
If you are having problems with the updater, you can use this
link to manually update Ewido
When you have finished updating, EXIT Ewido.
Please download & Install -
FixWareout.exe
When you reach the final page of the installation process, make sure
"Run fixit" is checked.
Follow the on-screen prompts & reboot your computer when instructed to do so.
**Do not be alarmed if your computer takes longer than usual to load.
After you have restarted, wait for HijackThis to launch automatically.
With HiJackThis & place a check next to these items and select "Fix checked":
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - URLSearchHook: (no name) - {68319495-C2E5-A012-BE50-F7C617EFA96A} - ExchangeMaster.dll (file missing)
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - c:\windows\system\BHOmod.dll (file missing)
O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll (file missing)
O4 - HKLM\..\Run: [PFO Check Settings] pfochk.exe
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [dmcur.exe] C:\WINDOWS\system32\dmcur.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - HKCU\..\Run: [porka_] srbho.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{18F6633B-4948-41BC-838D-0CE991E73AA0}: NameServer = 85.255.114.62,85.255.112.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{31B69C6E-E283-47CA-867E-D0DF7175EA3A}: NameServer = 85.255.114.62,85.255.112.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1E373C6-121F-48CA-BB35-2EF025CAE285}: NameServer = 85.255.114.62,85.255.112.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{C239E5D9-6D7A-4A20-9BD0-33DCE5EF2931}: NameServer = 85.255.114.62,85.255.112.97
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2CD160F-F680-407A-AE39-62727BB9B3A4}: NameServer = 85.255.114.62,85.255.112.97
O17 - HKLM\System\CS1\Services\Tcpip\..\{18F6633B-4948-41BC-838D-0CE991E73AA0}: NameServer = 85.255.114.62,85.255.112.97
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
Close HijackThis, and click
OK to proceed.
FixWareOut will produce a logfile, report.txt located within the C:\fixwareout folder
* * * * * * KILLBOX * * * * * * * * * * * * * * * * * * * * * * *
Launch KillBox.exe & select the following options:
- delete on Reboot
- All files (if available)
Use your mouse to select all the filenames highlighted in
blue & then right-click & select Copy
- C:\WINDOWS\SYSTEM32\msupdate32.dll
C:\Windows\pfochk.exe
c:\drsmartloadb.exe
C:\WINDOWS\system32\dmcur.exe
* Go to the File menu, and choose
Paste from Clipboard
* Click the
RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.
* * * * * * RESTART WINDOWS IN SAFE MODE * * * * * * * * * *
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the option to run Windows in Safe Mode.
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider initially to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program.
6. Do NOT reboot/logoff if prompted.
* CleanUp! will not create any backups!!
* * * * * * RUNNING ADDITIONAL SCANNERS * * * * * * * * * * *
Run
Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click Complete System Scan to begin scanning.
- Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
- "Perform action on all infections"
- .Choose clean and click OK.
Once finished, click the
Save report button & save the report to your desktop
** Ewido scan would require at least an hour. I suggest that you go grab a cup of coffee & do something else while you wait for it to complete.
* * * * * * REBOOT TO NORMAL MODE * * * * * * * * * * * * * *
Establish an internet connection & perform an online scan with Internet Explorer at
Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
* * * * * * CHECK LIST * * * * * * * * * * * * * * * * * * * * *
In your next post, please include fresh logs from:
- FixWareout's log
- HiJackThis log
- Online Scan
- Ewido
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now