Thread: Infected Laptop
View Single Post
Old 03-08-2006, 01:09 AM   #8 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,494
OS: N/A


Please disable Webroot SpySweeper & Spywareguard, as they hinder the removal of some entries. You can re-enable them after you're clean.
To disable Webroot SpySweeper:
  • Go to the Options>Program Options
  • Uncheck Load at Windows Startup
  • Click Shields & uncheck all items there
  • Uncheck Home page shield.
  • Automaticly restore default without notification
To disable Spywareguard:
  • Right click the running icon of Spywareguard located in the system tray
  • Go to Menu > File > Exit and confirm the programs close.


Have Hijackthis fix these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com




Delete the Viewpoint folder & relaunch Hijackthis again.
to Config > Misc Tools - Open Uninstall Manager
From the box on the left, select Viewpoint & hit the "Delete this entry" button located on the right



Then do another Kaspersky scan. Instead of scanning the 'My Computer', direct it to scan this folder only - C:\Windows\system32\


In your next reply, I'll require these logs

1. Kaspersky
2. Hijackthis
__________________

Question - what have you done for the community today?
sUBs is offline