Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
Turn off system restore.(XP/ME only) See how HERE.
http://www.bleepingcomputer.com/forums/tutorial56.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Go to add remove programmes in your control panel. Uninstall anything to do with(if there).
DIRECWAY
support.com
AdwareAlert
ISTsvc
Close Control panel.
Click start/run and type services.msc into the run box and press the enter key.
When the window appears, maximise it.
Locate the following services(if there) and double click on them. If they are running, select stop. Set the startup type to disabled.
DIRECWAY Webcast (DPC_SRV_WEBCAST)
Lookout Citadel Server (LkCitadelServer)
Lookout Classified Ads (LkClassAds)
Lookout Time Synchronization (LkTimeSync)
Click apply/ok.
Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.
Click on the processes tab and end process for(if there).
server.vbs
cmsspu.exe
tractrs.exe
AdwareAlert.Exe
teltes40.exe
pDPCDIAPI (7).exe
dpcproxy.exe
lkcitdl.exe
lkads.exe
lktsrv.exe
Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.techspot.com/vb/topic47462.html
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [¢‰¸u0Ô@ÔÁß]*ú"ü‰üžiC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\cmsspu.exe
O4 - HKLM\..\Run: [¢‰¸u0–4C
}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\cmsspu.exe
O4 - HKLM\..\Run: [p34P3qW] tractrs.exe
O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKCU\..\Run: [Y0vFRka6S] teltes40.exe
O4 - Global Startup: Dpcstart.lnk = C:\Program Files\DIRECWAY\BIN\pDPCDIAPI (7).exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{B6ECBF43-57B7-4615-B4CB-80AE2DE8461A}: NameServer = 198.77.116.8
Only fix this, if it doesn`t belong to your ISP.
O23 - Service: DIRECWAY Webcast (DPC_SRV_WEBCAST) - Unknown owner - C:\PROGRA~1\DIRECWAY\bin\dpcproxy.exe (file missing)
O23 - Service: Lookout Citadel Server (LkCitadelServer) - Unknown owner - C:\WINDOWS\System32\lkcitdl.exe (file missing)
O23 - Service: Lookout Classified Ads (LkClassAds) - Unknown owner - C:\WINDOWS\System32\lkads.exe (file missing)
O23 - Service: Lookout Time Synchronization (LkTimeSync) - Unknown owner - C:\WINDOWS\System32\lktsrv.exe (file missing)
Click on the fix checked button.
Locate and delete the following
bold files(if there).
C:\WINDOWS\System32\
lktsrv.exe
C:\WINDOWS\System32\
lkads.exe
C:\WINDOWS\System32\
lkcitdl.exe
C:\PROGRA~1\
DIRECWAY\bin\dpcproxy.exe
C:\Program Files\
DIRECWAY\BIN\pDPCDIAPI (7).exe
teltes40.exe
C:\Program Files\
AdwareAlert\AdwareAlert.Exe -boot
tractrs.exe
C:\Program Files\
ISTsvc\istsvc.exe] C:\WINDOWS\cmsspu.exe
c:\program files\
support.com\client\lserver\server.vbs
Reboot into normal mode and turn system restore back on.
Regards Howard
