startpage.eq

Status
Not open for further replies.
Infections startpage.eq - SMSSU.exe etc

Hello!
I have a sly infection - startpage.eq that Notrton call Trojan.startpage.O.
Removal instructions from Trend Micro and Symantec have not result, and I am very glad to be found this site!

Please, advise me to clean this atrful program!

After day: My bad English makes me misunderstood :mad:
 
Go here first: Read: How to remove Trojans and its ilk!

For PSGUARD, go here: either pay for the program or do it manually:
http://labs.paretologic.com/spyware.aspx?remove=PSGuard

Then Read: Only use these HJT-instructions when asked!
/P/ Process needs to be stopped
/U/ UNinstall anything to do with this
/R/ unRegister the xxx.DLL in that line
The text between the dotted lines underneath goes between the dotted lines of that post.
Make sure to follow ALL instructions, and in HJT tick/fix ALL lines!
...................................................................................................
/P/ C:\WINDOWS\TEMP\IQ461E.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home/
/R/ O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINDOWS\xml2lib.dll
/P/U/ O4 - HKLM\..\Run: [P.S.Guard] C:\Program Files\P.S.Guard\PSGuard.exe
/P/U/ O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
/P/ O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\system32\SMSSU.EXE
/P/ O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\system32\Tmntsrv32.EXE
/P/ O4 - HKCU\..\Run: [Win32res] C:\WINDOWS\win32res.exe
/P/U/ O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\adwarefilter.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Phone Connection Monitor.lnk = ?
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
Fix ALL your O16 - DPF: entries
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
...................................................................................................

Then post a fresh log if you still have problems.
 
Status
Not open for further replies.
Back