Hello Warrell and welcome to Geeks to Go
Before we get underway, you may wish to print these instructions for easy reference during the fix, although please be aware that many of the required URLs are hyperlinks in the red names shown on your screen. Part of the fix will require you to be in Safe Mode
, which may not allow you to access the internet, or my instructions!
The infection you have needs to be disabled before being removed, probably why you haven’t been able to get rid up until now (and if I fail now, I will have egg on my face for sure).
Firstly could you please disable Winpatrol from running during the fix, it may just hinder our attempts to change anything.
To start please download the following programmes, we will run them later. Please save them to a place that you will remember, I suggest the Desktop: Killbox by Option^Explicit CCleanerEwido Security Suite
Go to Start
and type Services.msc
then hit Ok
Scroll down and find the below services: Network Security Service (NSS) or ( 11Fßä #•ºÄÖ`I)
When you find it, double-click on it. In the next window that opens, click the Stop
button, then click on properties
and under the General
Tab, change the Startup Type to Disabled
. Now hit Apply
and then OK
. Click on None of the above, just start the program
. Now, click on the Config
button (bottom right), then click on Misc Tools
, then click on Delete an NT Service
a window will pop up. Enter the below item into that field (copy and paste): Network Security Service
It should pull up information about the service, when it asks if you want to reboot now click YES
Install Ewido Security Suite (it is a 14-day trial version of the programme).
- Launch ewido, there should be an icon on your desktop double-click it.
- The programme will prompt you to update click the OK button
- The programme will now go to the main screen
You will need to update ewido to the latest definition files.
- On the left hand side of the main screen click update
- Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed do the following:
- Click on scanner
- Make sure the following boxes are checked before scanning:
- Click on Start Scan
- Let the programme scan the machine
While the scan is in progress you will be prompted to clean files, click OK
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
- Click Save report
- Save the report to your desktop and include it in your reply.
Please re-open HiJackThis
and scan. Check the boxes next to all the entries listed below.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O23 - Service: Network Security Service (NSS) ( 11Fßä #•ºÄÖ`I) - Unknown owner - C:\WINDOWS\addls32.exe" /s (file missing)
Now close all windows other than HiJackThis
, then click Fix Checked.
Please now reboot into safe mode. Here's how:Restart your computer and as soon as it starts booting up again continuously tap the F8 key. A menu should appear where you will be given the option to enter Safe Mode.
Please remove these entries from Add/Remove Programs
in the Control Panel (if present):(click Start>Settings>Control Panel)
Home Search Assistent
Please notify me of any other programmes that you don’t recognise in that list in your next response
Please install Killbox by Option^Explicit
*Extract the programme to your desktop and double-click on its folder, then double-click on Killbox.exe to start the programme.
*In the Killbox programme, select the Delete on Reboot
*In the field labelled Full Path of File to Delete
enter the file paths listed below (EXACTLY as it appears, please double check to make sure!): C:\WINDOWS\addls32.exe
Press the button that looks like a red circle with a white X in it after each one. When it asks if you would like to delete on reboot
, press the YES
button, when it asks if you want to reboot now
, press the YES
button at both prompts so that your computer restarts. If you receive a message and your computer does not restart automatically, please restart it manually.If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click download and run missingfilesetup.exe. Then try TheKillbox again.
There is almost certainly bound to be some junk (leftover bits and pieces) on your system that is doing nothing but taking up space. I would recommend that you run CCleaner
. Install it, update it, check the default setting in the left-hand pane, Analyze, Run Cleaner.
You may be fairly surprised by how much it finds.
Post back a fresh HijackThis log
and I will take another look."Edit,
As there has been no reply from the original poster this topic is now closed,
Should you have any further problems please create a new Topic,
Edited by Crustyoldbloke, 31 May 2005 - 09:17 AM.