Originally Posted by philmydinger
for some reason i cannot run the setup applications for the two programs that the instructions say to run. i ran hijack this again here is the log:
Thats not very nice from them is it? lol. Oh well.
Make sure you still have system restore disabled , and hidden files set to show.
Please download
Process Explorer by Systernals from
HERE.
Also download
KillBox by Option^Explicit from
HERE.
Then uninstall these in add/remove programs if present:
Red Swoosh/rssoft
SoftwareOnline
SpySheriff
After that boot in safe mode (hit f8 when booting up)
Unzip
Process Explorer and double click on
procexp.exe
In the top section of the Process Exlporer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
avpe32.dll once and then click the
kill button.
After you have killed all of the
avpe32.dll's under winlogon click
OK.
Next In the top section of the Process Exlporer screen again , double click on
explorer.exe and again click once on each instance of
avpe32.dll then click the
kill button.
Once you have done that click
OK again.
And then fix these with
hjt:
(if still present)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about
:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about
:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} - (no file)
O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\
DH.dll
O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\
igps.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SOProc_DAP] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\
SOFTWAREONLINE\soproc.exe -pack DAP
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\
RSSoft\RSEDNClient.exe
O4 - HKCU\..\Run: [Windows installer] C:\
winstall.exe
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\
sywsvcs.exe
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - (no file)
O20 - Winlogon Notify: avpe32 - C:\WINDOWS\SYSTEM32\avpe32.dll
Then delete the files in bold , and see if you can run ccleaner now.
Then manually delete these files if present from youre pc:
C:\WINDOWS\System32\avpe32.dll
C:\WINDOWS\System32\avpe64.sys
C:\WINDOWS\System32\klgcptini.dat
C:\WINDOWS\System32\qz.dll
C:\WINDOWS\System32\qz.sys
C:\WINDOWS\System32\stt82.ini
C:\WINDOWS\Web\wallpaper.html
C:\WINDOWS\Web\desktop.html
C:\Windows\Desktop.html
C:\wp.exe
C:\wp.bmp
C:\Program Files\SpySheriff <--- the whole folder
C:\Documents and Settings\username\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\username\Application Data\Install.dat
Double click on
Killbox.exe and then check the
delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box:
C:\WINDOWS\SYSTEM32\avpe32.dll
Click the
red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)
After your computer has rebooted please Download this reg fix:
unzip and dubbel click on it and enter it to the registry.
http://users.telenet.be/marcvn/regfi...desktopfix.zip
Then run Hijackthis again and post a new Hijackthis log please.