View Single Post
  #2  
Old February 22nd, 2006, 07:25 PM
WhatYouWant WhatYouWant is offline
CTH Subscriber
 
Join Date: Jul 2004
Location: France
Posts: 2,776
Welcome to CTH, schwa75.

Before we start working with your log, you are running Hijack This from a temporary location. If we leave it where it is, backups will not be saved so lets move the file to it's own folder in C:\Program Files.

To do this, go here:
http://www.cybertechhelp.com/download/file/move-hijack-this

and download Move_HijackThis.vbs to your Desktop.

Doubleclick on Move_hijackthis.vbs to run it. If you get a warning about a malicious script, please ignore that and allow this to run. This file was written by Mosaic1. She is a Hijack Advisor here and an expert in malware removal.

When the script has finished running, it will start Hijackthis from its new location in C:\Program Files\Hijackthis\hijackthis.exe. To run Hijack This next time, please go to C:\Programs Files or use the Run box.

----------------------------------------------

Download the trial version of Ewido Security Suite from here.

When installing, under "Additional Options" uncheck "Install Background Guard" and "Install scan via context menu".

Launch Ewido (there should be an icon on your desktop doubleclick it). The program will now go to the main screen. You will need to update ewido to the latest definition files.

On the left hand side of the main screen click update and then click on Start Update. The update will start and a progress bar will show the updates being installed. If you have problems with the updater, you can use this link to manually update ewido.
ewido manual updates http://www.ewido.net/en/download/updates/. Do not run a scan yet.

Close Internet Explorer and any open windows and run Hijack This again. Check the below entries and click on Fix Checked:


O2 - BHO: (no name) - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - (no file)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\system32\nsh70.dll

O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

Close HijackThis and navigate to C:\Windows\Downloaded Program Files and delete all you dont need.

When you have done this, boot into Safe Mode (restart your PC and tap F8 as it restarts).

Run Ewido now. Click on Scanner and click Complete System Scan and the scan will begin. During the scan it will prompt you to clean files, click OK. When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK. When the scan is finished, click the Save report button at the bottom of the screen. Save the report to your desktop and close Ewido.

Post back a new HijackThis log as well as the Ewido one, please.
Reply With Quote