FesselAJ,
Hi! and welcome to the [your forum] forums.
===============
Go to www.trendmicro.com , and then:
1. Click "Free Online Scan".
2. Click "Scan now, it's free".
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) "Auto Clean".
3. Click "Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
===============
Now, let's open a command prompt by going to the start menu and then select 'Run'.
In the box that pops up type in 'cmd'. The command prompt will open.
OR
You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u yfxkkxne.dll
regsvr32 /u qgewelnr.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save typing them in.
===============
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
O2 - BHO: (no name) - {01E7D903-F1EB-E2D7-883D-ADCD90AFD7E2} - C:\WINDOWS\system32\yfxkkxne.dll
O2 - BHO: (no name) - {28933B1B-FB04-2726-F639-2605F5CA345F} - C:\WINDOWS\System32\pkeelqcq.dll (file missing)
O2 - BHO: (no name) - {8948B04A-7947-2192-28B5-3B9B67B96AC8} - C:\WINDOWS\System32\oksycjfy.dll (file missing)
O2 - BHO: (no name) - {D6DBE33B-0B69-B08E-878F-D3A57CD4B60D} - C:\WINDOWS\system32\qgewelnr.dll
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [Rwsr] C:\Documents and Settings\Andrew Fessel\Application Data\aeae.exe
O4 - HKCU\..\Run: [Slou] C:\Documents and Settings\Andrew Fessel\Application Data\paae.exe
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Andrew Fessel\Application Data\DownloadPlus.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {A1A961DA-2BA6-4032-859E-01AC35357163} (One2One Viewer) - http://www.one2one.com/static/class/one2one.cab
O23 - Service: ileudoeujjek (MsUpdate6) - Unknown owner - C:\WINDOWS\system32\msupd6.exe (file missing)
Now, with all windows closed except HiJackThis, click "Fix checked".
===============
Locate and delete the following item(s), if present. Make sure your able to " view system and hidden files/ folders: "
files...
C:\WINDOWS\system32\yfxkkxne.dll
C:\WINDOWS\system32\qgewelnr.dll
C:\Documents and Settings\Andrew Fessel\Application Data\aeae.exe
C:\Documents and Settings\Andrew Fessel\Application Data\paae.exe
C:\Documents and Settings\Andrew Fessel\Application Data\DownloadPlus.exe
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in " Safe Mode ".
-
Reboot.
===============
To help protect your system from hostile ActiveX content, or special 'downloadable' files:
Download, install and keep updated, SpywareBlaster . If you've installed it for the first time:
1) Check for any available updates; if present, they'll be automatically downloaded and installed.
2) Next, "Enable all protection".
3) Exit the program.
-
Note: Remember to regularly check for updates.
===============
After rebooting your PC post back a new log, and let me know how everything goes.
-
crunchie.