Hi again,
I've got some more instructions for you to follow to try to get to the bottom of this.
Again, before you start, please read through these instructions and make sure that you understand them.
If you are not sure about anything, post a reply in this thread with your questions.
You will be booting into Safe Mode at some point in these instructions, so you should print out these instructions for reference. You will not have internet access in Safe Mode.
Step 1
Download Killbox from http://www.downloads.subratam.org/KillBox.zip. Once it is downloaded extract it to c:\killbox. Do not use it yet
Step 2
Copy the red lines below into a new Notepad file.
Name the file as fix.reg
Change the "Save as Type" to "All Files" and save it on the desktop
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\durptfviqn]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mwsoemon]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MyWebSearch Email Plugin]
Then double-click on the fix.reg file, when it prompts to merge click "Yes".
Reboot back to normal mode
Step 3
Open KillBox
a) Type the full name and path "c:\windows\system32\durptfviqn.exe" (without the quotes) into the box "Full Path of File to Delete"
b) Choose "Delete on Reboot"
c) Click the "Delete File" button (red circle with white cross).
d) Click "Yes" in the "Delete next Reboot" message box.
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
Reboot back as normal.
Step 4
Run Hijack This, "Scan" and post the log as a reply to this thread. I'll check it through, and get back to you. Also, let me know what problems you still appear to be having with your pc.
Thanks,
Bod
I've got some more instructions for you to follow to try to get to the bottom of this.
Again, before you start, please read through these instructions and make sure that you understand them.
If you are not sure about anything, post a reply in this thread with your questions.
You will be booting into Safe Mode at some point in these instructions, so you should print out these instructions for reference. You will not have internet access in Safe Mode.
Step 1
Download Killbox from http://www.downloads.subratam.org/KillBox.zip. Once it is downloaded extract it to c:\killbox. Do not use it yet
Step 2
Copy the red lines below into a new Notepad file.
Name the file as fix.reg
Change the "Save as Type" to "All Files" and save it on the desktop
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\durptfviqn]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mwsoemon]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MyWebSearch Email Plugin]
Then double-click on the fix.reg file, when it prompts to merge click "Yes".
Reboot back to normal mode
Step 3
Open KillBox
a) Type the full name and path "c:\windows\system32\durptfviqn.exe" (without the quotes) into the box "Full Path of File to Delete"
b) Choose "Delete on Reboot"
c) Click the "Delete File" button (red circle with white cross).
d) Click "Yes" in the "Delete next Reboot" message box.
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
Reboot back as normal.
Step 4
Run Hijack This, "Scan" and post the log as a reply to this thread. I'll check it through, and get back to you. Also, let me know what problems you still appear to be having with your pc.
Thanks,
Bod