i too have winsupdater.exe

Status
Not open for further replies.
Please follow all this advice IN SEQUENCE

C:\DOCUME~2\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
put HijackThis in e.g. C:\Program Files\HJT and NOT in Temp or on the Desktop!.

C:\Program Files\Internet Explorer\iexplore.exe
Go to www.getfirefox.com and STOP using IE, other than for windoze-upates!

C:\Program Files\LimeWire\LimeWire.exe
Uninstall this virus/trojan magnet once and for all and DON'T put anything like this on your PC again!

C:\WINDOWS\system32\winlog.exe
For winlog.exe, see this: http://www.sophos.com/virusinfo/analyses/w32agobotlf.html

Then Read: Only use these HJT-instructions when asked!
/P/
/P/ Process needs to be stopped
/S/ Service needs to be stopped
/U/ UNinstall anything to do with this
The text between the dotted lines underneath goes between the dotted lines of that post.
Make sure to follow ALL instructions, and in HJT tick/fix ALL lines!
...................................................................................................
/P/U/ C:\Program Files\LimeWire\LimeWire.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
/P/ O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
/P/ O4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /auto
/P/ O4 - HKLM\..\Run: [] winlog.exe
/S/ O4 - HKLM\..\RunServices: [] winlog.exe
O4 - Global Startup: RtlWake.lnk = ?
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
Fix ALL your O16 - DPF: entries
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
...................................................................................................
 
Status
Not open for further replies.
Back