View Single Post
Old 02-08-2008, 08:02 AM   #3 (permalink)
ceewi1
Moderator
 
ceewi1's Avatar
 
Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,305
Default

Please run Notepad and paste the contents of the codebox into a new file. Please do not include the word Code:
Code:
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0000811163604555mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0048841163555854mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0097661163446971mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0128021163879378mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0139371163779382mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0324641163965674mcinstcleanup]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fkzihmt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\irkf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XBHOUB]
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{07CDEFFF-22A7-2DEC-0302-070001080100}]
Save the file to the desktop as fix.reg and make sure the Save as Type field says All Files. Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

Please delete the following files:
C:\Program Files\B.ico
C:\Program Files\A.ico

Please run HijackThis and choose Do a system scan only.

Place a check next to the following entries:
  • R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
  • R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
  • O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
  • O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
  • O3 - Toolbar: (no name) - {70CC76D5-A4EE-4F25-9931-B109A63E298E} - (no file)
  • O4 - HKCU\..\Policies\Explorer\Run: [{08E312F2-0891-1033-1207-010322060001}] "C:\Program Files\Common Files\{08E312F2-0891-1033-1207-010322060001}\Update.exe" mc-110-12-0000140
  • O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
  • O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing)
  • O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
  • O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
  • O22 - SharedTaskScheduler: bonspells - {11853d5f-f894-4cc7-bbc3-fc7a9dcfd896} - (no file)
  • O22 - SharedTaskScheduler: haeckel - {8373a2e0-bdd0-42bd-b4ec-ba5451eb6607} - (no file)
  • O24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com - http://active.intelligentdesktop.com/active/?17908644

Do you recognise this entry?
O24 - Desktop Component 0: (no name) - http://promotions.cecentertainment.c...es/402coup.gif

If not, place a check next to it as well.

Please close all open windows except for HijackThis and choose Fix checked

Please reboot and post a new HijackThis log. How is your system running now?
__________________

CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870
RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W

Cheap PSUs - 2% of system costs, responsible for 28% of system deaths
As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity.
- The "Warranty void if removed" sticker on numerous CoolerMaster PSUs.

ceewi1 is offline   Reply With Quote