sgtfoo said:
I followed the load of instruction to clean my computer..
I'm attaching a HJT txt into this reply...
There`s quite a lot to do here, so take your time and follow these instructions exactly.
Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
Turn off system restore.(XP/ME only) See how HERE.
http://www.bleepingcomputer.com/forums/tutorial56.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Go to add remove programmes in your control panel and uninstall anything to do with(if there).
D:\Program Files\Network
D:\PROGRA~1\Toolbar
Close control panel.
Click start/run and type services.msc into the run box and press the enter key. When the window appears, maximise it and locate these services(if there).
Double click on them and if they are running select stop. Set the startup type to disabled.
demm386.exe
Microsoft Update
$WindowsRegKey%update
virtual
TBPS
IDriverT
Click apply/ok.
Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.
Click on the processes tab and end process for(if there).
ipnetwork.exe
demm386.exe
winfix3.exe
IEXPLORE.EXE
winit.exe
TBPS.exe
Close task manager.
Click start/run and type regsvr32 /u D:\WINXP\System32\sjwmhui.dll Into the run box and press the enter key. Note the spaces between the 32 and the forward slash and again between the U and D.
do this for this entry as well.
D:\WINXP\System32\uhs.dll
Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://home.microsoft.com/access/autosearch.asp?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - D:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: (no name) - {6BC43D2B-F6E8-A86C-9E3D-DCEF3D0AA6BF} - D:\WINXP\System32\sjwmhui.dll
O2 - BHO: (no name) - {6BC43F2B-F6E8-A86C-9E3D-DCEF3D0AA6BF} - D:\WINXP\System32\sjwmhui.dll
O2 - BHO: (no name) - {CC005144-C682-970B-F2B5-E12CF16600B2} - D:\WINXP\System32\uhs.dll
O4 - HKLM\..\Run: [IpNetwork] D:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\RunServices: [demm386.exe] demm386.exe
O4 - HKLM\..\RunServices: [Microsoft Update] winfix3.exe
O4 - HKLM\..\RunServices: [$WindowsRegKey%update] IEXPLORE.EXE
O4 - HKLM\..\RunServices: [virtual] winit.exe
O4 - HKLM\..\RunServicesOnce: [TBPS] D:\PROGRA~1\Toolbar\TBPS.exe /boot
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
Click on the fix checked button.
Close HJT.
Locate and delete the following bold files(if there).
D:\WINXP\System32\
sjwmhui.dll
D:\WINXP\System32\
uhs.dll
D:\Program Files\
Network\ipnetwork.exe
demm386.exe
winfix3.exe
winit.exe
D:\PROGRA~1\
Toolbar\TBPS.exe
Reboot into normal mode and turn system restore back on.
Regards Howard
