Kim,
Please read this post completely before begining the fix.
Right click on this & choose "Save As..." DelO15Domains.inf -
DelO15Domains.inf
Right click on
DelO15Domains.inf and choose Install. It will run immediately (you won't be able to see anything happen). You may delete the file afterwards.
SpywareBlaster 3.5.1 - Install & update SpywareBlaster with the latest definitions.
After you have updated, click the button -
enable protection for all unprotected items
IE-SpyAD - Extract the contents to a new folder
From within the folder, double-click
install.bat
Select Option #2 -
Install the new IE-SPYAD list.
Then return to the main menu.
Select option #4 -
Add the old porn sites domain
* * * * * * FIXING ENTRIES WITH HIJACKTHIS * * * * * * * * * *
Do a HijackThis scan & place a check next to these items and select "Fix checked":
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
* * * * * * RESTART WINDOWS IN SAFE MODE * * * * * * * * * *
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the option to run Windows in Safe Mode.
* * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * *
If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools -> Folder Options -> View tab.
- Tick - 'Show hidden files and folder'
- Untick - 'Hide file extensions for known types'
- Untick - 'Hide protected operating system files'
- Click Yes to confirm & then click OK
Locate and delete the following files/folders: (make sure you get everyone of them)
- C:\WINDOWS\system32\geecc.dll
C:\WINDOWS\system32\hgagyfh.vxd
C:\WINDOWS\system32\hoapyee.sys
C:\WINDOWS\system32\hrakeec.sys
C:\WINDOWS\system32\htipyfr.vxd
C:\WINDOWS\system32\in2bS.dll
C:\WINDOWS\system32\Installer.exe
C:\WINDOWS\system32\jiak.exe
C:\WINDOWS\system32\jiakndw30102lib.dll
C:\WINDOWS\system32\Mservice.dll
C:\WINDOWS\system32\ndw-enc-af9.exe
C:\WINDOWS\system32\s_win32.exe
Delete the contents of this folder, leaving it empty:
- C:\Documents and Settings\Kim\.housecall\Quarantine\
C:\HJT\backups\
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider initially to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program.
Reboot to normal mode to post another HJT log. Tell me how your machine is behaving now.
__________________
Question - what have you done for the community today?