Hello and welcome to TSF
I recommend you Subscribe to this thread so you are notified of any replies via email. To do this click
Thread Tools, then click
Subscribe to this Thread. Make sure it is set to
Instant Notification, then click
Subscribe.
Please print out or copy this page to
Notepad in order to assist you when carrying out the following instructions.
Downloads(make sure to save these in a permanent location)
Cleanup!- Install it. You will use this later.
*NOTE* Cleanup deletes EVERYTHING out of temporary folders and does not make backups.
Ewido Anti-Malware- Install Ewido Anti-Malware
- Double-click the icon on Desktop to launch Ewido
You will need to update Ewido to the latest definition files.
- On the top of the main screen click Shield
- Click the word active to change it to inactive
- On the top of the main screen click Update.
- Then click on Start Update. The update will start and a progress bar will show the updates being installed.
- I also recommend changing the "Update interval" to something more reasonable like 12 hours.
If you are having problems with the updater, you can use this link to
manually update Ewido
When you have finished updating,
EXIT Ewido.
CWShredder- Run CWShredder and click on Fix (it will automatically fix anything it finds for you). If it asks if you want to delete a certain random file, choose No and post that filename here.
Next, please reboot your computer in Safe Mode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
HijackThis!
Open Hijack This and click on Scan. Check the following entries
(make sure you do not miss any)
1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://minisearch.startnow.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {27EDDE35-6D90-43D3-A96A-241FD86AF0BB} - (no file)
O2 - BHO: (no name) - {34B65A51-7B7B-228B-A275-90764A72E096} - C:\WINDOWS\System32\pioapef.dll
O4 - HKLM\..\Run: [glv] C:\WINDOWS\glv.exe
O4 - HKLM\..\RunServices: [Microsoft System Checkup] ntsysmgr.exe
Please remember to close all other windows, including browsers then click Fix checked.
File and Folder Deletions
Delete the following Files indicated in
RED and Folders indicated in
BLUE if they still exist.
C:\WINDOWS\System32\pioapef.dll
C:\WINDOWS\glv.exe
ntsysmgr.exe <<Find via Start>Search
Tools
Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "
Options..."
*Move the arrow down to "
Custom CleanUp!"
*Put a check next to the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
- Click on the "Temporary Files" and uncheck the box for "Scan drives for file matching" if it’s checked.
Click
OK
Press the
CleanUp! button to start the program. If prompted to reboot, click No.
Run
Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click on the Scan tab
- Click Complete System Scan to begin scanning.
- When the scan is complete click Recommended Action and change it to Quarantine
- Then click Apply all actions
Once finished, click the
Save report button, then click
Save Report As and save it to your desktop.
Reboot your system in Normal Mode.
Online Scans
Perform an online scan with Internet Explorer with
Panda ActiveScan
**
click on "Free use ActiveScan" located on the top right hand corner- Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
- Click Scan Now
- Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting
My Computer- If it finds any malware, it may ask you to purchase the program, this is not necessary we will take care of the entries manually.
- At the end of the scan click on see report. Then click Save report
Please post that log in your next reply.
In your next post please include:
- Ewido log
- Panda Activescan Log
- A new Hijackthis! Log