View Single Post
Old 07-30-2006, 07:44 PM   #8 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,147
OS: 2000 Pro; XP Pro; XP Home


Ok, betty, that's good to hear....we're getting close, but I'd like to run a couple more tools based on what I've seen.

I have attached a file to this post - betty2.zip Download this file to your desktop. Double click on the zip folder, then double click on the reg file within. Click yes to allow it to merge into your registry.

---------------------------------------------------------------------------------------------

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download AproposFix from here:
http://swandog46.geekstogo.com/aproposfix.exe

Save it to your desktop but do NOT run it yet.

Then please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Delete the following if they exist (don't worry if you can't find them):

C:\Program Files\AdTools Service
C:\Program Files\AutoUpdate
C:\Program Files\BullsEye Network
admppp.exe<<<locate via Start>Search
C:\WINDOWS\\system32\gah95on6.exe
C:\Program Files\Internet Optimizer
C:\WINDOWS\mhqhyb.exe
alriscon.exe<<<locate via Start>Search
C:\Program Files\Viewpoint
C:\Program Files\AWS
C:\Program Files\WildTangent
C:\Program Files\Yacy
C:\drwin32.exe
C:\WINDOWS\system32\2-20060511-1.exe
C:\Program Files\ornu
C:\Program Files\Common Files\mzko
C:\msnotify.com


---------------------------------------------------------------------------------------------


Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode, and post the entire contents of the log.txt file in the aproposfix folder in your next reply.

Also please do this:

Go here and do the BitDefender online virus scan.
  • Click "I Agree" to agree to the EULA.
  • Allow the ActiveX control to install when prompted.
  • Leave the scanning options at default and press "Click here to scan" to begin the scan.
  • Please refrain from using the computer until the scan is finished.
  • When the scan is finished, click on "Click here to export the scan results"
  • Save the report to your desktop then come back here and post it in your next reply along with a new Hijack This log
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009

Last edited by tetonbob; 09-19-2006 at 01:53 PM.
tetonbob is offline