Cant even type without interuption through cid

Status
Not open for further replies.
At the risk of spreading FUD [Fear, Uncertainty, Doubt], I duplicate my post here.

Have you considered a System Restore save point created before this began?

Malware removal is best handled by following 15-step Procedure

A non-expert view of HJT - verify that the following file is not part of the Realtek AC97 driver package

C:\WINDOWS\SOUNDMAN.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

While HJT can zap this entry, this does not fully address the infection.
The quote was posted here

My findings at castlecops & symantec rule in a possible infection. I did not pursue disqualifying the 'soundman' symptom.
 
his is the legitimate version. you can tell by looking at the running processes then the directory. However there are other infections.

You appear to have a LOP infection that often comes together with Messenger Plus.

1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove)

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important).

While in add/remove programs also uninstalled any of the following:
Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer
Netpumper
BitRoll
CiD Help
CiD Manager
Download Plugin for Internet Explorer
Zone Media


When this is complete, restart your computer.
--------------------------------------------------------------------------------------------------
Your computer should become functional after removing the offending program from add/remove. Then please proceed to follow the preliminary removal instructions found HERE
 
Status
Not open for further replies.
Back