  TheJoker Premium,VIP,MVM join:2001-04-26 Alexandria, VA
| reply to blusky1 Re: HJT Log Adware.BetterInternet Nail.exe
Please download the trial version of Ewido Security Suite here: »www.ewido.net/en/download/ Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Please run Notepad and copy the following text into a new file:
@ECHO OFF cd %windir% Nail.exe /FULLREMOVE sc config SvcProc start= disabled sc stop SvcProc sc delete SvcProc attrib -s -r -h nail.exe attrib -s -r -h svcproc.exe del nail.exe del svcproc.exe cd %windir%\system32 attrib -s -r -h DrPMon.dll del DrPMon.dll exit Save the file to the desktop as remove.bat and make sure the "Save as type" field says "All files".
Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site: »www.pchell.com/support/safemode.shtml
Once in Safe Mode, please double-click on remove.bat. A window should open and close very quickly --- this is normal.
Then please run Ewido, and run a full scan. Post the log from the scan here for me.
Then please run HijackThis, click Scan, and check:
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O4 - HKLM\..\Run: [xbnuwxa] c:\windows\system32\zpoejid.exe
Close all open windows except for HijackThis and click Fix Checked.
Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
-- TheJoker |