Thank you, can you do the following please
I don't want interference with any of your protection programs
They may, and probably will get in the way
Can you open SpyCatcher please and disable it's realtime protections
Did you pay for SpyCatcher? It's not on the bogus list, but I don't usually recommend it
If you didn't pay for it, I would uninstall it
Can you open SpySweeper and do the following
Disable any of the below found
click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck "automatically restore default without notification".
Afterwards, I see you have 2 AV's installed, AVG and BitDefender
It's not a good idea running more than one in the background
This can cause conflict's
But, I think you knew that, can you go back and disable ONLY BitDefender from running on startup please
Don't reboot yet
I see an entry in your log, most of the bad files may be gone, but I want to make sure
Also we'll try and deal with your desktop issue too
Can you do the following please
==Download
CWShredder.exe and save to your desktop
Don't run it yet
Download
Hoster.zip and save it to your Desktop.
UNZIP the contents to your desktop or folder
==Download and Install
Windows Cleanup! 4.0Don't run it yet
==Open Ewido
From the main ewido screen, click on
Update in the left menu, then click the
Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
I don't want Ewido's guard interfering either
Under the Status button>>Under Additional, can you Uninstall the GUARD please
Don't reboot the computer yet
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link
http://www.ewido.net/en/download/updates/==Download
SmitRem.exe by Noahdfear and save the file to your desktop.
Don't run it yet
Download and save Cwsserviceremove.zip
UNZIP to your desktop so you now have Cwsserviceremove.reg extracted
We'll need it later
[attachment=431:attachment]
==Create a New folder on your desktop, call it Aboutbuster
(Right click an empty spot on the desktop and select NEW>>FOLDER)
Download to desktop
About:Buster 5.1by RubbeR Ducky
Unzip it to that new folder
Open the Aboutbuster folder and Run
About:buster.exeClick the
Update button
Allow to update
After it's updated, please close it as we'll need it later
==
Please print the next set of instructions or save them too a notepad file on your desktop for referenceClose all unnecessary programs running including this window
Double click on
CWShredder.exeRun the FIX part of it, let it fix what it finds
Access your Add/Remove programs and remove if found, and if you can
WinHoundRESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Select Safe mode from the Startup menu
Once in safe mode
Go to START>>>RUN>>>type in
services.mscHit OK
In the next window, look on the right hand side for this service
name----
Remote Procedure Call (RPC) Helper <<--There are others that looks similiar, look for the one with "Helper" at the end of it
Double click on it---
STOP the service--If running
In the drop down menu, change the startup type to
Disabled==Open the Aboutbuster folder and Run About:buster.exe
Click the Begin Removal button
Can you please run this scan twice
When it's done it will produce a log in the Aboutbuster folder called
Ab logfile.txt
I'll need to see the log later
==Double click on
cwserviceremove.reg and allow to add or merge to the registry
==Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
* Empty Recycle Bins
* Delete Cookies
* Delete Prefetch files
* Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.
When it's done, decline to log off or restart the computer
==Double click on
SmitRem.exe to extract it to it's own folder on the desktop.
Open the smitRem folder, then double click the
RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
Find and delete this folder if found
C:\Program Files\
WinHound <-this folder
==Open Ewido Security Suite
Give it time to load
Click on the
Scanner button on the left menu
Click on the
Settings button on the right
Select "Scan Every File"
OK it and then click on the "Complete System Scan"
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
*1. Perform Action = Remove
*2. Create Encrypted Backup in Quarantine (Recommended)
*3. Perform action with all infections
Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido
Do another scan with Hijackthis and put a check next to these entries:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
After you have ticked the above entries, close
All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
Reboot back to Normal mode
Locate the
Hoster folder , open it and double click on Hoster.exe
Click on Restore Original Hosts
In the confirmation window, click on OK.
==Access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the Security tab | Custom Level
Check ActiveX security settings:
Make sure that the following settings are correct:
o Download signed ActiveX controls (Prompt)
o Download unsigned ActiveX controls (Disable)
o Initialize and script ActiveX controls not marked as safe (Disable)
o Script ActiveX controls marked safe for scripting (Prompt)
Look for a file called
shell.dll in your C:\Windows\system32 folder
If it is not there, let me know, we'll have too replace it
==From my signature below, use Internet Explorer and run an Online Virus scan at Panda's
It's safe to supply them with an email address and additional info needed
When it's loaded
Choose to scan "Local Disks"
When the scan is done, if anything is found
Click the See Report
Save this report to your desktop
I need to see a few logs please, we'll still have a little more work to do
1. Post a fresh hijackthis log
2. Post the Report from Ewido's
3. Post the log in the About:Buster folder>>
Ab logfile.txt4. Post the report from Panda's