View Single Post
Old 02-14-2007, 09:39 PM   #4 (permalink)
Sempurna
Analyst, Security Team
 
Sempurna's Avatar
 
Join Date: Sep 2006
Posts: 1,302
OS: Windows XP SP2


Hi ct456568,

You’re most welcome, ct456568. Glad to be of some help.

Quote:
I have regularly used CCleaner since I got this computer, and I have almost always done the "Issues" function every time I run it, fixing all issues found by CCleaner - mostly uninstaller references and the such. I haven't noticed any problems with the function and I backup all the changes. Do I need to worry about this at all or stop using the Issues function?
Since you know what it is all about, then it is safe for you to use it. The caution is only for those who don’t understand what it’s for, and might screw up their registry. I still go over every line whenever I use any registry cleaners to clean up the entries in my registry.


Quote:
IE7 seems to start faster, but I still have a problem with it "Not Responding" on occasion when I start it up (Sorry I forgot to tell you about this before). Ending and restarting IE usually works though.
Did you try uninstalling and reinstalling IE7? That might cure the problem. If not we might have to do a system scan and see what’s wrong.


NEXT:

I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes. So please disable TeaTimer by doing the following:

To disable Spybot’s TeaTimer function:
  • Run Spybot-S&D.
  • Go to the Mode menu, and make sure "Advanced Mode" is selected.
  • On the left hand side, choose Tools -> Resident.
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Please download ResetTeaTimer.bat and save it to your desktop.
  • Double-click ResetTeaTimer.bat to remove all entries set by TeaTimer.


NEXT:

Please run HijackThis and click "Scan". Place a check (tick) next to the following entries (if present):

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - (no file)
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} –
O20 - Winlogon Notify: winjgf32 - C:\WINDOWS\



Close ALL programs and browsers (including this one), leaving ONLY HijackThis open, then click "Fix checked".

Then please exit HijackThis.


NEXT:

Please download the Killbox by Option^Explicit and save it to your desktop.

NOTE: In the event you already have Killbox, this is a new version that I need you to download.
  • Please double-click Killbox.exe to run it.
  • From the main Killbox window, select:
    • "Delete on Reboot".
    • "All Files".
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C:

    C:\WINDOWS\system32\1164403324.exe
    C:\Program Files\Morpheus


  • Return to Killbox, go to the "File" menu, and choose "Paste from Clipboard".
  • This is pasted into the "Full Path of File to Delete" field.
  • There’s a little arrow (drop-down arrow) next to that field. If you expand it, the lines that you pasted must be there together (if the files are present!).
  • Click the button with the red circle and white X ("Delete File" button). Click "Yes" at the "Delete on Reboot" prompt. Click "No" at the "Pending Operations" prompt.

If your computer does not reboot automatically, please reboot it manually.

NOTE: If you receive a message such as, "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, CLICK HERE to download and run missingfilesetup.exe. Then try Killbox again.


NEXT:

Let's run another diagnostic scan to make sure we're not leaving anything behind.

Please download ComboFix by sUBs:
  • Save it to your desktop.
  • Double-click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION : Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT:

Please reboot your computer normally into Windows, and then please post the ComboFix log and a new HijackThis log.

How are things running now?
__________________

Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support.

Donation link for Tech Support Forum
Sempurna is offline