View Single Post
Old 03-07-2006, 03:52 PM   #4 (permalink)
Buzz1927
Digaredd
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 6,104
Default

Run Hijackthis and select "Do a system scan only", place a check by the following entries.


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...ge=about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - {1A48170E-D5EF-8032-990D-AE98BE65F0CD} - C:\WINDOWS\system32\prxo.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {1A48170E-D5EF-8032-990D-AE98BE65F0CD} - C:\WINDOWS\system32\prxo.dll (file missing)
O4 - HKCU\..\Run: [Wfec] C:\Documents and Settings\Laurence\My Documents\?racle\spool32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\iakwnwv.exe (file missing)


Close all open windows and browsers, and hit "Fix Checked".

Delete this folder (the ? could be anything)

C:\Documents and Settings\Laurence\My Documents\?racle

Then reboot and post a new Hijackthis log.
__________________
The Grim Reaper - Son of Glyndwr
"To Hell or Connacht" may you burn in Hell tonight!
Buzz1927 is offline   Reply With Quote