Hey
Just unzip to Desktop.
Leave the programs.
Disable System Restore
Please print out the remainder of these directions, as you'll have to proceed in Safe Mode. Now, disconnect to the net.
Reboot into Safe Mode (hit F8 key until menu shows up).
Start-run, type:regedit Find- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main check for a key called-HOMEOldsp, if present- delete it. And if you have some files in searchpage/searchbar which end with …\sp delete them Go to Edit in registry and type - HOMEOldsp. Click-Find Next, delete it-if present. Use F3 for search more, if you find more- delete them. Same procedure with-About:blank Close Registry.
Scan with HijackThis , close all other windows and browsers, and place a checkmark next to these items, and fix: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\wrpjy.dll/sp.html#33111 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\wrpjy.dll/sp.html#33111 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = Double click the AboutBuster.exe file. Click OK, then click Start, then click OK.
This will scan your computer for the bad files and delete them. Save the report it creates (copy and paste it into notepad and save as a .txt file).
Run Adware
we need to configure Ad-aware SE for a full scan. Some of them should be enabled by default, while others you will need to set yourself (see below).
Click on the Gear icon (second from the left) to access the preferences/settings window
1. In the General window make sure the following are selected: Automatically save logfile Automatically quarantine objects prior to removal Safe Mode (always request confirmation) Click on the Scanning button on the left and select : Scan within archives Scan active processes Scan registry -Deep-scan registry Scan my IE Favorites for banned URLs Scan my Hosts file Under Select drives & folders to scan, choose: Select all of your hard drives that are not selected already Click on the Advanced button on the left and select: Include additional object information Include negligible objects information Include environment information Click the Tweak button and select: Under the Scanning Engine:
2. Unload recognized processes & modules during scan Under the Cleaning Engine:Let Windows remove files in use at next reboot Click on Proceed to save the settings.
Click Start and on the next screen choose: Use custom scanning options Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.
Save the log file when it asks and then click Finish. When finished, mark everything for removal and get rid of it. (Right-click on any of the entries and choose Select All from the drop down menu and click Next).
Now run the Scanner, you downloaded from Microworld. Activate all in settings
Delete files/folder from the following directories (But not the directory itself, for example delete all files/folder IN temp. C:\Windows\Temp\ C:\Documents and Settings\<Your Profile>\Local Settings\Temp\ C:\Documents and Settings\<All other users Profile>\Local Settings\Temp\ C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <<<This will delete your files in your internet cache--including cookies. C:\Documents and Settings\<All other users Profile>\Local Settings\Temporary Internet Files\ Empty your "Recycle Bin"
There are usally a couple of files that you will not be able to delete..this is normal.
Install the files from Spyware info, if needed
post new log, with AboutBuster log ---------------------------------------------------------------------------
|