Welcome to HijackThis.de @ Steve


Remember that Hijackthis must be run in an own folder.
C:\Program Files\HJT\HijackThis.exe or C:\HJT\HijackThis.exe
Only if Hijackthis runs in an own folder it will create backups!

Please change that: C:\Documents and Settings\Stevex.Nxxxx\Desktop\HijackThis.exe

Follow the numbers.

1
Using Windows XP: turn off System Restore.

2
Make sure you set windows to see the hidden files and folders.

3
Download and Instructions of Use

A. Download
one of these programs:
WinsockXPFix.exe,
Follow the instructions to use it.

B. Download
New Version: Ad-Aware SE
Ad-Aware SE: install and update it

C. Download
New Version: Spybot Search & Destroy
Spybot Search & Destroy: install and update it

D. Download
CWShredder.

E. Download
about:Buster,
unzip to C:\aboutbuster, run it, and then:

1. Click “Update”.
2. Click “Check For Update”

(If no new version is available, skip that.)
3. Click “Download Update”, and wait for it to be installed.

F. Download
If you don’t have a zip-tool we suggest zipgenius (It is free).

G. Download
host.zip
Press ‘Restore Original Hosts’ and press ‘OK’
Take a look to the instructions

H. Download
CCleaner

I. Download
Disk Cleaner

J. Download
RegClean 4.1a

4
Don’t use the programs now.

5
Disconnect to the Internet.

6
Turn to safe mode. Stay in safe mode until you read that you may turn to normal mode!

7
Close down all windows including Internet Explorer.
Run Hijackthis, click scan, and put a checkmark next to each of these items.
Then click the Fix Checked button:

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hzzp://www.dell4me.com/myway
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hzzp://bfc.myway.com/search/de_srchlft.html
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hzzp://www.dell4me.com/myway
R1 – HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = hzzp://us.mcafee.com/apps/vso/en-us/redir.asp?affid=105-36&installtype=force&dtag=byk7771&systempopup=true
R3 – URLSearchHook: (no name) – {4D25F926-B9FE-4682-BF72-8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 – BHO: (no name) – {4D25F921-B9FE-4682-BF72-8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

Click on Fix Checked and exit HijackThis.

8
Stay in safe mode
run Ad-Aware SE (Adaware SE 1.05 Tutorial)

Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Take a full system scan.
Delete the content of all Ad-aware SE folders and the Quarantine box when the scan is finished.
Safe the logfile.

9
Stay in safe mode
Run Spybot Search & Destroy
Turn on Advanced Mode. Go to “Tools” and put a checkmark into the box of ActiveX.
Scan your system. Let Spybot Search & Setroy delete everything it finds.
Take the immunication for your system.

10
Stay in safe mode
Run CWShredder
press the *fix,* not the scan button
allow it to clean the infection.
Close all browser and explorer windows before hitting the fix button.

11
Stay in safe mode
Run about:Buster
4. Click “Start”.
(Wait for the initial ADS scan to complete.)
5. Click “Exit”.

12
Reboot your system into normal mode.

13
Run the CCleaner
Put a Checkmark next to all items
under “Windows”, “Applications” and “Issues”.
Have a look to the screenshots.
Press the button “Run Cleaner”.

14
Empty your “Recycle Bin”
Go to START > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.

15
Run the Disk Cleaner
Set a checkmark to every item you want to clean.
Temporary Internet Files and Temporary System Files, Cache, History and Prefetch must be cleaned.
Clean as much folders as you can clean.

16
Run RegClean
Allow the program to delete all it finds.

17
Run a Full System Scan with Panda ActiveScan.
It will last 2-3 hours. You will have to allow ActiveX.
Save the logfile.
Reboot the system when the scan is finished.

18
Configure then the IE with these Settings.

19
Run HijackThis once more.
Have it save a new Logfile.

-> Post the Ad Aware SE Logfile
-> Post the About:Buster Logfile
-> Post the Panda ActiveScan Logfile
-> Please post the new HJT-Logfile.