Hey Hammy, long time no see.
In the future, remember to close any open browser windows before scanning with HJT.
I believe 'pokapoka' is your main problem. Scan with HJT and have it fix the following entries:
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [checkrun] E:\windows\system32\elitecla32.exe
O4 - HKLM\..\Run: [System service62] E:\WINDOWS\etb\pokapoka62.exe
Close any open windows, other then HijackThis, and hit Fix checked.
Go to the following locations and delete the highlighted file and folder:
E:\windows\system32\elitecla32.exe
E:\WINDOWS\etb
If either cannot be deleted, try booting into Safe Mode and deleting it from there.
Do you know what this file is for? duperealpure.exe If not, do a search for it, right-click on it, go to Properties, and get whatever information you can from there (Company, version, etc.)
Reboot (normally), close any open browser windows, scan with HJT, and post a new log please.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
It was supposed to go away, but it's being stubborn :(
Make sure your system is set up to 'Show hidden files and folders' -- Open Windows Explorer, go to Tools, and in Folder Options, select Show hidden files and folders, and deselect (uncheck) Hide protected operating system files.
Reboot into Safe Mode.
Scan with HJT and have it fix the following entries:
O4 - HKLM\..\Run: [checkrun] E:\windows\system32\elitecla32.exe
O4 - HKLM\..\Run: [System service62] E:\WINDOWS\etb\pokapoka62.exe
Close any open windows, other then HijackThis, and hit Fix checked.
Go to the following locations and delete the highlighted file and folder:
E:\windows\system32\elitecla32.exe <-- File
E:\WINDOWS\etb <-- Folder
If you still can't find or delete these, open HijackThis again and click on the Config... button in the lower right corner of the main window. In the next window, click on the Misc Tools button at the top, and then click the Delete a file on reboot... button. Copy and paste E:\windows\system32\elitecla32.exe into the box, and click Open. A new window will pop up asking if you want to restart your computer now; click Yes.
Repeat the delete on reboot instructions for E:\WINDOWS\etb\pokapoka62.exe.
Do a search for drawbend and duperealpure and see if you can find out anything about these now. It's no longer in your log, but if it's something bad we should make sure it's actually gone.
Back in normal mode, scan with HijackThis and post a new log.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Sorry, I missed a step. Open Windows Explorer, go to Tools, and then Folder Options; when the Folder Options window opens, click on the View tab. You should find these entries in the list under Advanced settings. Select Show hidden files and folders, and deselect (uncheck) Hide protected operating system files.
For any of the popup messages you're getting, don't click on any of them, not even to close them; either right-click and select Close, or use Task Manager (Ctrl-Alt-Del) and End Task.
Post a new HJT log with you're next reply (after you've fixed/deleted the bad entries).
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Good- the main "nasties" are no longer present in your latest log.
A couple of things, though:
1. MessengerPlus! 3 has a "Sponsored" installation mode, and if installed in this mode, the program will install adware on your system. If you are unsure of which installation mode you chose, you should uninstall the program and then reinstall it without the Sponsor option.
2. The following log entry is a loose end which should be taken care of:
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
To do this:
A) Open the Services utility in your Administrative Tools control panel.
- In the list of services, locate the service named "Remote Packet Capture Protocol" or "rpcapd" and double-click on it.
- In the General tab of the Properties window that opens, click the Stop button if the service is not already stopped.
- Once the service is stopped, choose Disabled in the "Startup Type" drop-down menu and then click OK. Close the Services utility after that.
B) Run HijackThis again, do another scan, and put a check in the box to the left of the O23 - Service: Remote Packet Capture Protocol v.0 entry, and then click "Fix Checked".
C) Once HJT finishes the fix, click on the "Config" button in the lower right corner of HijackThis' main window. In the next window click on the "Misc Tools" button at the top then click the "Delete an NT service" button. Type the following in the box and click OK:
rpcapd
3. Reboot and then run another HJT scan to make sure the rpcapd entry no longer exists.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
All looks good; your latest log is clean. :)
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Can you still give people good rep? I would like to do so with the both of you if possible :) Let me know how if we can.
Just click on the little 'scales' symbol next to the post number.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214