I'm not an expert, but I can help you get started. First of all, if you haven't already done so, you should follow the suggestions in this thread:
http://www.daniweb.com/techtalkforums/thread5690.html
(SpywareBlaster will help prevent this from happening again)
Empty all Temp and Temporary Internet folders for all users (if anything won't delete, try booting into Safe Mode and deleting them). Also do a search for *.tmp and delete all those as well.
Next, download sysclean from http://www.trendmicro.com/download/dcs.asp making sure to download and install the latest pattern file. There's a link to it at the lower left-hand colum of the page. Note that it will not work without the pattern file which must be unzipped into the same folder as sysclean.
Then, update your HJT, it has an Update feature within it or you can get it from here:
http://www.softpedia.com/progDownload/x-Download-5034.html
Close all windows, scan with HJT and have it fix the following entries:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz
O16 - DPF: v2cab - http://searchmiracle.com/cab/v2cab.cab
Reboot, close all windows, scan with HJT and post a new log so one of the pro's can finish cleaning it up.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
The only temp folder i could find was C:\Windows\Temp. I'm assuming there are more. And is there a way to clear my temp internet files without opening IE? I never plan to use it again. Also should I do everything in that order, and when I download sysclean should I run it before running hjt again?
Go toC:\documents and settings\{each individual user}\local settings and empty each Temp folder and Temporary Internet folder (this will clear it without opening IE), like this:
C:\documents and settings\john\local settings\temp\ <-- Remove everything inside this folder.
Order shouldn't matter, just run sysclean before you post your next log and allow it to clean up any bad files it finds... it may take a while.
And don't forget to update HJT.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Best to wait for one of the pro's to finish this up; I see a couple of suspect things and there's still something running from your temp folder. You may also need lsp_fix but I can't help with that either.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
One of the experts told me what you need to do, so here it is:
Go to Add/Remove Programs and uninstall Windows SyncroAd and EliteToolBar.
Close all windows, scan with HJT, and have it fix this entry:
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/296c21b...ip/RdxIE601.cab
and these if they're still showing:
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
I think you should also do this:
Open Task Manager and end the process of pAuwru9.exe, if it's running.
Empty the contents of this Temp folder: C:\documents and settings\john\local settings\temp
That should fix your problem; to help keep it from happening again, get SpywareBlaster from here:
http://www.javacoolsoftware.com/spywareblaster.html
Update it and have it enable all protection -- keep it updated too!
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Empty the contents of this Temp folder: C:\documents and settings\john\local settings\temp
Note: You will need to haveHidden Files and Folders showing in order to see the local settings folder.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214