
13-03-2007, 03:13 AM
|
 |
Full Member
New Recruit
|
|
Join Date: Mar 2007
Posts: 77
|
|
|
Re: CID Popup problems
OK. Let's see what we can do.
You may want to print out these instructions as you will not be able to access them online during part of the fix.
- Display Hidden Files Please set your system to show
all files; please see here if you're unsure how to do this.
- Please Download NoLop to your desktop from one of the links below...
Link 1
Link 2
Link 3- First close any other programs you have running as this will require a reboot
- Double click NoLop.exe to run it
- Now click the button labelled "Search and Destroy"
<<your computer will now be scanned for infected files>>
- When scanning is finished you will be prompted to reboot only if infected, Click OK
- Now click the "REBOOT" Button.
- A Message should popup from NoLop. If not, double click the program again and it will finish Please
--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.
- Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below being careful to get only these:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [build beep byte bird] C:\Documents and Settings\All Users\Application Data\Cast cash build beep\Phone else.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZU
O16 - DPF: {04CC2CE2-BBC4-43B6-96D6-E1C3E0BA120F} (HMVDownloader Control) - https://www.hmvdigital.com/HMV.Digit...Downloader.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...up1.0.0.15.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n019p/EN/install/gtdownlr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
Now close all windows other than HiJackThis, then click Fix Checked. Exit Hijack This.
- Reboot into safe mode.
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.
- Delete Files/Folders
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):
C:\Documents and Settings\All Users\Application Data\Cast cash build beep
- After that, Reboot.
- Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only- Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser- Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser- Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
- Please download, install, update and scan your system with the free version of AVG Anti-Spyware Scanner: AVG Anti-Spyware 7.5
- Download the AVG Anti-Spyware Scanner installer to your Desktop. Find the icon on your desktop and double click on it to install.
- Let AVG Anti-Spyware Scanner open once it is installed.
- The first thing you need to do is update the detection definition files.
- From the main AVG Anti-Spyware screen, click on UPDATE in the top menu, then click the Start Update link.
- After the update finishes (the status bar near the top will inform you of progress), click on the Scanner button in the top menu, then click on the Settings tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
- Click on the Scan tab. Then click on Complete System Scan. This scan will take a while, please be patient.
- Once the scan is complete, you will be prompted if any items are found that need attention. Select Apply all actions. This will take a moment or two.
- When AVG Anti-Spyware Scanner reports All Actions Have been Applied you can close AVG Anti-Spyware Scanner. The report was automatically saved if the settings were set as instructed. The report will be located at C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
- Please re-open HiJackThis and scan and save a new log file.
- Post Logs
- AVG AS Results
- New Hijack This Log
|