You need to be able to somehow install a few programs on your computer to help get it up & running. Can you download to another computer then save the programs to disk? Hijackthis will fit on a floppy, the others will not. If you can do that, I will give some links for you.
Download & instal Adaware from here
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot
Download & instal Spybot S&D from here. Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot
Download HijackThis from here & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop (in a folder on the desktop is fine) & not directly on your hard drive).
If you have anything disabled in MsConfig, please re-enable it/them.
Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Open Task Manager & end process on the following:
win32x.exe
winmep.exe
windrvl32.exe
Delete them manually now.
C:\WINDOWS\System32\win32x.exe
C:\WINDOWS\System32\winmep.exe
C:\WINDOWS\System32\windrvl32.exe
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R3 - Default URLSearchHook is missing
O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\Program
Files\ClearSearch\IE_ClrSch.DLL (file missing)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -
C:\WINDOWS\System32\nvms.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} -
C:\WINDOWS\System32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} -
C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [SVX Control Service] svxhost.exe
O4 - HKLM\..\Run: [mismo] win32x.exe
O4 - HKLM\..\Run: [Windows Firewall Security] winmep.exe
O4 - HKLM\..\Run: [Windows Update Client Service] windrvl32.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\yshyiwt.exe
O4 - HKLM\..\RunServices: [SVX Control Service] svxhost.exe
O4 - HKLM\..\RunServices: [mismo] win32x.exe
O4 - HKLM\..\RunServices: [Windows Firewall Security] winmep.exe
O4 - HKLM\..\RunServices: [Windows Update Client Service] windrvl32.exe
O4 - HKLM\..\RunOnce: [SVX Control Service] svxhost.exe
O4 - HKCU\..\Run: [SVX Control Service] svxhost.exe
O4 - HKCU\..\RunOnce: [SVX Control Service] svxhost.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
-Netster
Reboot into safe mode following the instructions here & navigate to & delete the following if found:
C:\Program Files\ClearSearch-folder
C:\WINDOWS\System32\yshyiwt.exe-file
Reboot normally after doing the above then post a fresh log please.
Go here for an on-line scan & set it to autoclean for you.
Try this scan as well.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985