Download deldomains:
http://www.mvps.org/winhelp2002/DelDomains.inf
To use: right-click and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.
Note: Because this will remove all entries in both the Trusted Zone and the Restricted Zone, any program, tool, or settings that were previously used to set restrictions will need to be reset:
Examples: (if these are being used),
- Spybot's "Immunize" feature is affected, you will need to re-immunize
- SpywareBlaster's "Enable all protection" feature will have to be re-enabled
- IE-SPYADS will have to be reinstalled
Get hoster here:
http://www.funkytoad.com/download/hoster.zip
Unzip it to a convenient place and open the program.
Choose "Restore Original Hosts" and press "OK".
Close the program.
Read over the following directions. Ask if anything appears unclear to you.
Download Clean.bat to your desktop: for later use to clean out your TEMPORARY and PREFETCH files.
http://www.thatcomputerguy.us/downloads/clean.bat
We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.
SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:
O4 - HKLM\..\RunServices: [MICROSOFT CONFIGURE 32] msgconfigre.exe
O4 - HKCU\..\Run: [MICROSOFT CONFIGURE 32] msgconfigre.exe
O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Mpbniaej.dll (file missing)
Make sure that all browser windows and internet links are closed, even this one!
CLICK ’FIX CHECKED’ with HijackThis.
HIDDEN FILES: To make sure you can see all hidden files, please follow the directions
here
SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained
here if needed).
Delete TEMPORARY FILES: Now, hunt down the most common temporary file locations and the temporary file clutter contained therein (and of possible malware hiding places):
Go to Start > Run and type:
CLEANMGR.EXE and hit enter.
When prompted select the C: drive and click ok.
Check the boxes for: - Temporary Internet Files
- Downloaded Program Files
- Recycle Bin
- Temporary Files
Click OK or Enter
For additional, more thorough cleaning and for multi-profile user configurations:
(*) Run Clean.bat to clean up your TEMPorary files.
***** Clean out the
Recycle Bin for items removed below,
ONLY once you have regained the full functional use of your PC.
Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):
DELETE FILES:
C:\WINDOWS\System32\msgconfigre.exe
POST A REVISED HIJACKTHIS LOG for review:
Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.