Hi. You've picked up some malware, all the way from Indonesia. Try this:
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or: http://www.besttechie.net/tools/mbam-setup.exe
=Dclick that file, mbam-setup.exe, to install the application,
-ensure that it is set to update and start, else start it via the icon, and UPDATE it.
Select "Perform QUICK Scan", then click Scan; the application will guide you through the remaining steps.
ENSURE that EVERYTHING found has a CHECKMARK against it, then click Remove Selected.
If malware has been found [and removed] MBAM will automatically produce a log for you when it completes... do not click the Save Logfile button.
Examine the log: if some files are listed as Delete on Reboot then restart your machine before continuing.
Copy and post that log [it is also saved under Logs tab in MBAM].
And do try to avoid registry repair software. They only remove some...some... orphaned entries. Anything "legitimately" there, ie keys linked to malware... won't be removed! The bulk of the entries they proudly remove are those which would be cycled out over time, such as pointers to recently used files, or data placed by M$ for links that you don't have the software for and so do not use.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
We can use this tool to identify the actual startup entries and delete them:
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then...
-in that folder start HijackThis by dclicking the .exe
-CLOSE ALL OTHER APPLICATIONS and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Thanks, dilwar,
start hijackthis again, click Scan.
- place checkmarks against all the entries listed below that still exist, and then press Fix Checked.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\Run: [PersonalPC] C:\WINDOWS\DroModule.exe
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\system32\windupdates\windupdates.exe
O4 - HKCU\..\Run: [PersonalPC] C:\WINDOWS\DroModule.exe
O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\system32\windupdates\windupdates.exe
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\windupdates\windupdates.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\WINDOWS\system32\windupdates\windupdates.ex
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O15 - Trusted Zone: http://download.windowsupdate.com
Good. Now delete these files:
C:\WINDOWS\DroModule.exe
C:\WINDOWS\system32\windupdates\windupdates.exe
C:\APPS\IE\offline\uk.htm
and this folder:
C:\APPS\IE\offline\
Run Hijackthis again. If any of the above entries exist please post the new log.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Good-oh, dilwar. don't worry about not finding the files, at least the starting emtries are now gone.
IE... I don't set any homepage [how often do you wish to go there?].In IE go Tools, Internet options, General, and click Use Blank.
You can uninstall Google Toolbar. Same with Vuze Remote toolbar, I imagine, although because I do not know it, there is a chance that it is a required add-on for some software you have installed.
Windows Desktop Search. You can uninstall that too... it a is a file indexer. For fast searching. Whoopee.
And that is about it for speeding things up. I don't run any antispyware service.... if I ever caught anything I would run it then as a cleaner.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Yes, you can delete those two entries. They are malware. I guess I did not see them ion the ht log because you had them stopped.
And I modified my previous post... re Windows Desktop Search.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Delete services?
==Go Start, run, type services.msc -and press Enter. Maximise the window and at foot select Extended tab, scroll to the specific service, rclick it, select properties. Write down the exact Service Name. Press Stop if it is highlighted [you may have to set the service Startup Type to Disable first]. Close Services, now type this line into the run text box and press Enter:
sc delete "exact Service Name" - don't be silly now....
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
Ah, not services, but under the startup tab. Okay, recheck them in msconfig. Then run Hijackthis again, press Scan, and search for them under O2 and O4 and possibly O20 [they may appear multiple times]. Check them, press Fix checked.
The actual files would once have been in system32, but are now not there, hence the intial error messages you posted about.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300
You're quite welcome, Dilwar.
gerbil
Industrious Poster
4,206 posts since May 2005
Reputation Points: 239
Solved Threads: 300