Reboot into safe mode following the instructions here & Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.allcybersearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.allcybersearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://prosearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://prosearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://prosearching.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
N2 - Netscape 6: user_pref("browser.startup.homepage", "prosearching.com");\n (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\2475klod.slt\prefs.js)
O1 - Hosts: 66.40.16.234 auto.search.msn.com
O1 - Hosts: 204.244.184.143 SafeWeb.com
O1 - Hosts: 204.244.184.143 WWW.SafeWeb.com
O2 - BHO: (no name) - {4F3C5BAE-F9A1-2136-2D8F-0832A17E99A2} - C:\PROGRA~1\CREATI~1\Dent size.dll
O2 - BHO: (no name) - {5DAFD089-24B1-4c5e-BD42-8CA72550717B} - C:\Program Files\SurfAssistant.com\saiemod.dll
O3 - Toolbar: (no name) - {69550BE2-9A78-11d2-BA91-00600827878D} - C:\WINDOWS\system\shdocvw.dll (file missing)
O3 - Toolbar: Balloption - {B4C1852D-9D9A-D1A3-3721-3DD017323D74} - C:\PROGRA~1\CREATI~1\Dent size.dll
O4 - HKLM\..\Run: [explore] C:\WINDOWS\System32\explore.exe
O4 - HKLM\..\Run: [about move] C:\PROGRA~1\Rdr bash\SPAM WMA.exe
O4 - Startup: PowerReg Scheduler V3.exe
Delete the following:
C:\PROGRA~1\CREATI~1< folder
C:\Program Files\SurfAssistant.com< folder
C:\PROGRA~1\Rdr bash< folder
C:\WINDOWS\System32\explore.exe< file
Reboot normally after doing the above then post a fresh log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
That comes up as google for me. If you know nothing about it have HJT fix it the same way as the others.
You should also consider uninstalling Wild Tangent from add/remove, unless you need it for gaming.
Apart from that your log is good.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Jim,
We ask that members not "tag" their questions onto a thread started by another member- please post your question in its own separate thread. It just gets too confusing when multiple questions are being asked and answered in a single thread.
For more info on our general posting guidelines, please read the following:
http://www.daniweb.com/techtalkforums/announcement.php?f=64&announcementid=1
Thanks,
-DMR
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Hi warren. 1st of all it is important to start your own thread in order for you to get the best possible help. B4 doing so, follow these instructions:
Download & instal Adaware from here
& update it B4 scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot
Download & instal Spybot S&D from here Update it B4 scanning. Go into settings & have it check for Beta releases also & download if available.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot
Download HijackThis from here & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop & not directly on your hard drive). Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is harmless & even necessary to the running of your system.
B4 posting your log, boot into safe mode (here's how) Scan with HJT & place a check in the boxes next to the entries for prosearching.com & hit the fix checked box. Reboot normally, rescan with HJT & post that log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I am having the same problem, can some one please be so kind and give me some advice to rid myself of this prosearching problem.
Mr.Furious.
We ask that members not "tag" their questions onto a thread started by another member- please post your question in its own separate thread. It just gets too confusing when multiple questions are being asked and answered in a single thread.
For more info on our general posting guidelines, please read the following: http://www.daniweb.com/techtalkforu...nnouncementid=1
Thanks,
-DMR
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985