|
|
Joe_London
HijackThis Helper
Reg'd: Tue
Posts: 10791
Loc: London
|
Re: hijack log - please advise
Fri Mar 28 2008 08:39 PM
|
|
|
Hi ricecakes, Please disable TeaTimer, it can be re-activated once your HijackThis log is clean at the end of this fix.
- Open Spybot Search & Destroy.
- In the Mode menu click "Advanced mode" if not already selected.
- Choose "Yes" at the Warning prompt.
- Expand the "Tools" menu.
- Click "Resident".
- Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
- In the File menu click "Exit" to exit Spybot Search & Destroy.
Uninstall SpywarePro via the add/remove utility in the control panel if present. Alternatively go to start | All programs and use its own uninstaller if present.
Then in any event open Hijackthis, take another scan and place a checkmark next to these entries.
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKCU\..\Run: [SpywareProMFC] C:\Program Files\SpywarePro\SpywarePro.exe O4 - HKUS\S-1-5-21-842925246-299502267-725345543-1003\..\Run: [SpywareProMFC] C:\Program Files\SpywarePro\SpywarePro.exe (User '?')
Close all open Windows except Hijackthis and click on "fix Checked".
Open Windows Explorer, Locate and delete the following item(s), if present. Make sure you're able to view system and hidden files/ folders:
files... C:\Program Files\SpywarePro\SpywarePro.exe
folders... C:\Program Files\SpywarePro
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode". Reboot the computer for the changes to take effect.
Open Hijackthis, Click Config | Misc Tools | Open Unistall Manager. A list of the entries in Add/remove programs will appear. Click on Save List... The list will be saved as 'Uninstall_list.txt' Copy & Paste the contents in your next reply.
Post the following:
- A new Hijackthis log
- The Uninstall List.
This may not remove all the infections present. It is important that you post back and complete the fix.
Please post in this thread for further review and evaluation. Please provide details of any problems you encountered whilst performing the above steps & update us on how the Computer is running.
Joe.
PS. For the benefit of others how did you come by this rogue?
-------------------- If I have helped you in any way, please consider a donation:
Joe's WebSite.
Member of UNITE and ASAP.
Edited by Joe_London (Fri Mar 28 2008 08:40 PM)
|
|
|
|
1 registered and 20 anonymous users are browsing this forum.
Moderator: putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate
Print Thread
|
Forum Permissions
You cannot start new topics
You cannot reply to topics
HTML is disabled
Mark-up is enabled
|
Rating:
Thread views: 0
|
|
|