Instrucitons follow:
=== Get File Info ===
Download Beta-Fix.exe from here: Beta-Fix The isn't working for some reason so ,Right click on Beta-Fix and copy shortcut and past it
into you address bar and hit enter to activate the download .
Double Click on the Beta-Fix.exe and it will install the batch file in
its own folder in the same location as the file you downloaded.
Open the Beta-Fix folder and double click on !LOG!.bat
IMPORTANT! Before you run this tool please close ALL running programs
and ALL Windows except Find-All.
Relax, sit back and wait a few minutes while the program collects the
necessary information.
*NOTE:If your AntiVirus is running a scriptblocker, when you run this
tool, you will probably receive an alert warning you that the script is
running. "Allow" the script to run.
When the program is finished:
Open the Beta-Fix folder.
1. Post the contents of Log.txt in this thread.
2. Attach file Win.txt to the same post. (Please attach, do not post)
(If this board does not provide the ability to attach documents to your
post, then please post the Win.txt file in this thread)
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
See if you can delete this file .
fileC:\Documents and Settings\owner\Local Settings\Temp\sp.html
Also try running the free online virus scan in my signature .
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
The download link in my first post has been fixed please download from here instead of the zip i added
=== Get File Info ===
Download Beta-Fix.exe from :
HERE
Link isn't working for some reason Right click and copy shortcut and past it into you address bar and hit enter to activate the download .
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
These need to be deleted:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
and, I'd remove these, to see if it makes a difference:
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
I couldn't figure out what these do, but you can try removing them. If it doesn't work, run System restore or something, so you get these reg keys back.
alc6379
Cookie... That's it
2,820 posts since Dec 2003
Reputation Points: 186
Solved Threads: 147
i tried to remove them and they were still there when i immediately ran hjt again.
Even the second two I suggested?
If those are still showing up, you may want to consider backing up your data, reformatting your hard drive, and reinstalling Windows. There are occasions where you will run into pesky spyware like this that is just that difficult to fix...
alc6379
Cookie... That's it
2,820 posts since Dec 2003
Reputation Points: 186
Solved Threads: 147
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\WINDOWS\ALCXMNTR.EXE< file
Reboot normally after doing the above then post a fresh log plz.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Nothing in that log. Next time it comes back, do not fix it but scan with HJT & post that log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985