View Single Post
Join Date: Jul 2008
Posts: 2,809
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 160
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Maven

Re: Browser Redirects to "go.google.com" (or nowhere at all)

 
0
  #10
Sep 13th, 2008
First of all please disable the Spybot TeaTimer;
To do this can you start Spybot and go to the Mode button and select Advanced. Go to Tools > Resident and uncheck the box next to Tea-Timer.
Reboot.
Next go back to the ESET Scanner, run the scan again and have it FIX or REMOVE everything found.
Reboot.
Then run a NEW full system scan with HiJackThis.
Place checkmarks next to the following entries if they still remain;
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)

O4 - Startup: PowerReg Scheduler V3.exe

Once you have placed the checkmarks then click the Fix Checked button. Exit HJT and reboot.
You also need to do a search for that PowerReg program, it is most definitely malware. It would most likely be located in
UserProfile (this would be you so substitute your name)\Start Menu\Programs\Startup
If you find it, delete it.
Run a new HJT scan after doing all the above, INCLUDING the fixes with the ESET scanner and post those logs here.
Reply With Quote