Please download free Trial of Superantispyware
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it.
close the program
Please download ATF Cleaner:
Download and install DrWebCureit:
to your desktop.
Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked.
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [Microsoft Autorun4] C:\WINDOWS\system32\dllhost32.exe
O4 - HKLM\..\Run: [Microsoft Autorun5] C:\WINDOWS\system32\mosou.exe
O4 - HKLM\..\Run: [QQREST] C:\WINDOWS\system\SMSS.exe
O4 - HKLM\..\Run: [RAVMSMON] C:\WINDOWS\Fonts\RAVMSMON.exe
O4 - HKLM\..\Run: [RAVQJMON] C:\WINDOWS\Fonts\RAVQJMON.exe
O4 - HKCU\..\Run: [NTService] C:\Program Files\Common Files\System\MSOSV.EXE
O23 - Service: A6049A5A - Unknown owner - C:\WINDOWS\system32\113DCAE7.EXE (file missing)
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
Delete the following files or folders (delete item in bold). Please do not be concerned if
any of the items are not found as they may have been automatically removed by actions I had
you take earlier in the cleaning process.
Open Folder Options in Controlpanel >view and check your settings:
Select
Show hidden files and folders
Display the contents of system folders
Uncheck: Hide protected operating system files
Delete:
Files:
C:\WINDOWS\system32\dllhost32.exe
C:\WINDOWS\system32\mosou.exe
C:\WINDOWS\system\SMSS.exe
C:\WINDOWS\Fonts\RAVQJMON.exe
C:\Program Files\Common Files\System\MSOSV.EXE
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch (Windows XP) only.
Java Cache
Recycle Bin
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the green screwdriver-
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select -Delete
Click on the drive(s) you want to scan . A red dot will mark the selected drive(s) . Then hit the green arrow in lower right corner It will now scan your drive(s), say yes to all
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Start Superantispyware/rightclick on the black/yellow bug in tray.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next,
it will scan now. When scan have finished, put a checkmark with all items it found. Next, after cleaning, allow it to Reboot
Start Superantispyware again –
Click Preferences and then click the statistics/logs tab.
Click the dated log and press view log and a text file will appear.
Post this log along with fresh hijackthis log, Dr.Web log and tell how things are running ?
Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention.