Hello HoAfCr and welcome,
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out these instructions.
****************************************************
Download
Ewido Security Suite- Install Ewido Security Suite
- When installing, under "Additional Options" uncheck..
- Install background guard
- Install scan via context menu
- Double-click the icon on Desktop to launch Ewido
You will need to update Ewido to the latest definition files.
- On the left hand side of the main screen click update.
- Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to
manually update Ewido
When you have finished updating,
EXIT Ewido.
Please
download and install CleanUp! but
do not run it yet. (Not Recommended for XP64).
Download
CWShredder and run it. Click on 'I Agree' button if you agree and check for updates. Close CWShredder. Click on 'Fix' (it will automatically fix anything it finds for you) and then click OK. If it asks if you want to delete a certain random file, choose No and post that filename here. Let it finish the scan and then hit Next and Exit.
---------------------------
Click Start->Run - type
services.msc & then click on the OK button
*Locate the service -
System Startup Service
*Double-click on it to open the Properties dialog.
*Under the General tab:
*Stop the service by using the
Stop button.
*Change the Startup type to
Disabled & then click on the OK button
Next, start HiJackThis & go to Config>Misc.Tools...>
Delete an NT service...
*In the popup box that appears, type in the
SvcProc Click OK and allow reboot.
Go directly to Safe Mode.
---------------------------
Reboot your computer in
Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Use the up arrow key to highlight Safe Mode and press Enter.
Go to
My Computer->
Tools->
Folder Options->
View tab:
* Under the Hidden files and folders heading:
*
select Show hidden files and folders.
*
Uncheck Hide protected operating system files (recommended) option.
*Also, make sure there is no checkmark beside
Hide file extensions for known file types.
* Click OK.
---------------------------
Run a scan in HijackThis. 'Check' each of the following if they still exist
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - Default URLSearchHook is missing
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
Click
'Fix Checked' and close HijackThis.
---------------------------
Delete the following
File
C:\WINDOWS\svcproc.exe
---------------------------
*WARNING* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! or move them to a permanent location.
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "
Options..."
*Move the arrow down to "
Custom CleanUp!"
*Put a check next to the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
- Click on the "Temporary Files" and uncheck the box for "Scan drives for file matching" if it's checked.
Click
OK
Press the
CleanUp! button to start the program.
Do NOT reboot/logoff when prompted.
------------------------------------------------
Run Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click Complete System Scan to begin scanning.
- Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
- "Perform action on all infections"
- Choose clean and click OK.
Once finished, click the
Save report button & save the report to your desktop
** Ewido scan would require at least an hour. Ewido is compatible with most AV and anti-spyware products, and the free version will continue to be useful as a second anti-malware scanner.
------------------------------------------------
I see that you have MSCONFIG enabled. This may prevent us from seeing everything on your system. Please go to Start>Run type
msconfig press Enter and enable all startups by selecting
Normal Startup - Load all Device Drivers and Services.
---------------------------
Reboot into Normal Mode.
---------------------------
Perform an online scan using Internet Explorer with
Panda ActiveScan
**
click on "Free use ActiveScan" located on the top right hand corner - Click Check Now & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
- Enter your e-mail address, country, and state & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting
My Computer- If it finds any malware, it will offer you a report.
- Please ignore any entry it finds and wants you to buy the program for removal as we will address this later.
- Click on see report. Then click Save report
In your next reply, I'll need the following:
Ewido results
Panda results
New HijackThis log