Delete's unremovable O15 entries in Hijack This.
Warning: Deletes all entries in the Restricted & Trusted Zone list
Download and save file -- Unzip. To execute this file: in Explorer - right-click (this file). Select Install from the Menu.
Download here: http://www.geekstogo...=download&id=40
I followed the directions and the two items were removed from my Hijack this file. Now I cannot access anything in my Amazon seller account that would cause the page to be redirected to another page and when I try to bid on Ebay I get "If you are seeing this page your browser settings prevent you from automatically redirecting to a new URL". It has a button to click if that page is showing but it will not do anything. I checked my security settings and the are on default. I uninstalled and reinstalled IE. I went to Internet options and clicked on the button to set the browser to default. I uninstalled Spysubstract and deleted the zip file from above. I spent two hours on the phone with Dell and she helped me to delete BFO files, among other things. After that two hours she said there was nothing else she knew to do and I had to pay $40.00 to talk to someone that dealt with that kind of stuff. I am at a loss to what to do now. When I go to the the Trusted Site under internet options it says that there is nothing there and everything is grayed out so I cannot add anything. I do not know what else to do. Please Help.
This is a copy of the Hijack this file. I thought that maybe something happened with my DSL but when I plugged in my laptop to the DSL the accounts looked fine. I am able to access these accounts, but I have to click on the properties of the site that I am trying to be redirected to and cut and paste the address into the address bar, which makes for very slow going.
ogfile of HijackThis v1.98.2
Scan saved at 7:27:17 PM, on 12/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\edith\My Documents\hijackthis\HijackThis.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [d3im32.exe] C:\WINDOWS\d3im32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O16 - DPF: cpcScanner - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1104092059937
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D8F7BB9-8630-466B-BA7C-21D96CE53717}: NameServer = 216.165.129.157 216.170.153.146
Thank you for all your help.