Now then. What did I tell you??
Open Task Manager & end process on the following:
ns.exe
MiCr0s0ft.exe
Microsoftx.exe
Then go to C:\WINDOWS\System32 and delete them manually.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\Run: [NS] ns.exe
O4 - HKLM\..\Run: [Microsoft Update] Microsoftx.exe
O4 - HKLM\..\Run: [Microsoft Windows Key] rpcxsys.exe
O4 - HKLM\..\RunServices: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\RunServices: [NS] ns.exe
O4 - HKLM\..\RunServices: [Microsoft Update] Microsoftx.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Key] rpcxsys.exe
O4 - HKCU\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
Do not open strange mail! Guess you know that now :).
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Download the Pocket KillBox
Unzip the file to your desktop.
Run KillBox.exe.
Select the Delete on Reboot option.
In the Full Path of File to Delete field paste this path and click the red circle with the white X in it(when it asks you to reboot, click NO.):
C:\WINDOWS\System32\ns.exe
Run KillBox again.
Select the Delete on Reboot option.
In the Full Path of File to Delete field paste this path and click the red circle with the white X in it(when it asks you to reboot, click NO.):
C:\WINDOWS\System32\MiCr0s0ft.exe
Run KillBox again.
Select the Delete on Reboot option.
In the Full Path of File to Delete field paste this path and click the red circle with the white X in it(when it asks you to reboot, click YES.):
C:\WINDOWS\System32\Microsoftx.exe
Your computer should then reboot. Killbox will check to see if the files were deleted.
See if you can get a log from HJT and post it back.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Do you have Winamp?
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
O4 - HKLM\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\Run: [NS] ns.exe
O4 - HKLM\..\Run: [Microsoft Update] Microsoftx.exe
O4 - HKLM\..\Run: [Microsoft Windows Key] rpcxsys.exe
O4 - HKLM\..\RunServices: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\RunServices: [NS] ns.exe
O4 - HKLM\..\RunServices: [Microsoft Update] Microsoftx.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Key] rpcxsys.exe
O4 - HKCU\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKCU\..\Run: [Microsoft Update] Microsoftx.exe
Run a search of your computer and see if you can find any of the above. If you do, you know what to do
Hopefully that will be it :).
Reboot after doing the above, rescan with hijackthis making certain that all instances of Internet Explorer are closed, then post that log here please.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Can you delete it from the prefetch folder, then download sysclean (free) from Trend Micro, allow it to clean up any bad files it finds. It may take a while, so have a cuppa whilst it's running :).
http://www.trendmicro.com/download/dcs.asp
Be sure to download and install the latest pattern file. There's a link to it at the lower left-hand colum of the page. It will not run without the pattern file.
From Trend:
Note that for the Trend Micro Sysclean Package to be effective, you must download and place the latest pattern file in the same folder as the Trend Micro Sysclean Package.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Not buggin' me :). Turn off system restore. You will lose all previous restore points! Go to Start>Run and type msconfig Press enter. When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left. Check the box labeled Turn off System restore.
Clear out your prefetch folder.
Reboot.
Post another hijackthis log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Yes. Just fix these lines and reboot and check to see what is running again :).
O4 - HKLM\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\Run: [Microsoft Windows Key] rpcxsys.exe
O4 - HKLM\..\RunServices: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Key] rpcxsys.exe
O4 - HKCU\..\Run: [MiCr0s0ft Update Machine] MiCr0s0ft.exe
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
You can do that I reckon :). You should be able to recognise it now :).
I responded to another of your threads regarding Messenger Plus that you were going to reinstall. Do not install the 3rd party sponsor with it or you will get infected by LOP.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
briandoc. Thank you very much for posting :).
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985