hrdcover,
Please read "ALL" of the instructions before proceeding:
You may want to print out these instructions for a reference or you can
save them by copying and pasting them into notepad and saving the text file to the desktop.
This will take a few steps, if you have any questions along the way please ask...
Download CleanUp
Install the program, dont run it yet, we will later.
Download Pocket Killbox
Click Here to download Pocket Killbox by Option^Explicit.
Unzip the program and save it to your desktop, dont run it just yet.
Next, please reboot your computer in SafeMode by doing the following:
Do not open any new windows.
Now scan with HJT and place a checkmark next to each of the following items:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O17 - HKLM\System\CCS\Services\Tcpip\..\{138BD34C-5FAF-4DAB-BF8A-285D85C5F707}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA575D31-8FC4-407F-9EAB-525AD6A5F096}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CS1\Services\Tcpip\..\{138BD34C-5FAF-4DAB-BF8A-285D85C5F707}: NameServer = 69.50.184.84,195.225.176.37
Within HJT click the Fix Checked button. Close HJT.
Now lets check some settings on your system.
Now lets run Killbox
C:\WINDOWS\system32\nC5594Om3.dll
C:\WINDOWS\system32\epx30104.exe
C:\WINDOWS\system32\epx30105.exe
C:\WINDOWS\system32\yqssr.exe
Once you have rebooted into Normal Mode, please do the following:
Run the CleanUp program you downloaded earlier.
*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folder, please make a backup of these before running CleanUp
Running CleanUp
Reboot once again and post back a new HJT log by using Post Reply
Thanks,
rstones12
Please read "ALL" of the instructions before proceeding:
You may want to print out these instructions for a reference or you can
save them by copying and pasting them into notepad and saving the text file to the desktop.
This will take a few steps, if you have any questions along the way please ask...
Download CleanUp
Install the program, dont run it yet, we will later.
Download Pocket Killbox
Click Here to download Pocket Killbox by Option^Explicit.
Unzip the program and save it to your desktop, dont run it just yet.
Next, please reboot your computer in SafeMode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
Do not open any new windows.
Now scan with HJT and place a checkmark next to each of the following items:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O17 - HKLM\System\CCS\Services\Tcpip\..\{138BD34C-5FAF-4DAB-BF8A-285D85C5F707}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA575D31-8FC4-407F-9EAB-525AD6A5F096}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CS1\Services\Tcpip\..\{138BD34C-5FAF-4DAB-BF8A-285D85C5F707}: NameServer = 69.50.184.84,195.225.176.37
Within HJT click the Fix Checked button. Close HJT.
Now lets check some settings on your system.
- Enter your Control Panel and double-click on Network Connections
- Then right click on your Default Connection
- Usually Local Area Connection for Cable and DSL
- Left click on Properties
- Double-Click on the Internet Protocol (TCP/IP) item
- Select the radio dial that says Obtain DNS Servers Automatically
- Press OK twice to get out of the properties screen, if it asks to reboot select "NO", we will later.
Now lets run Killbox
- Double-click on Killbox.exe to start the program.
- In the killbox program, select the Delete on Reboot option.
- In the field labeled Full Path of File to Delete enter the file paths listed below ONE AT A TIME (EXACTLY as it appears, please double check to make sure!):
C:\WINDOWS\system32\nC5594Om3.dll
C:\WINDOWS\system32\epx30104.exe
C:\WINDOWS\system32\epx30105.exe
C:\WINDOWS\system32\yqssr.exe
- Press the button that looks like a red circle with a white X in it after each one.
- When it asks if you would like to delete on reboot, press the YES button, when it asks if you want to reboot now, press the NO button.
- Do this after each one until you have entered the LAST file path I have listed above.
- After that LAST file path has been entered, press the YES button at both prompts so that your computer restarts.
- If you receive a message and your computer does not restart automatically, please restart it manually.
Once you have rebooted into Normal Mode, please do the following:
Run the CleanUp program you downloaded earlier.
*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folder, please make a backup of these before running CleanUp
Running CleanUp
- Start CleanUp
- When CleanUp starts go to the Options button (right side of CleanUp screen)
Uncheck cookies
This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea. - Click OK
- Then click on the CleanUp button. This will take a short while, let it do its thing.
- When asked to reboot system select No
- Close CleanUp
Reboot once again and post back a new HJT log by using Post Reply
Thanks,
rstones12