![]() |
Help Removing Zedo Hi, Can anyone help me? I've tried everything I could find on how to remove Zedo from this box, but nothing's working. I've pasted a Hijack This log file below. Thanks in advance!!!!! Andrew Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 9:16:42 PM, on 9/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\MozyHome\mozybackup.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\PRISMSVC.EXE C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\PRISMSVR.EXE C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Hello\Hello.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Eset\nod32kui.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\GetModule\GetModule21.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\GetPack\GetPack20.exe C:\Program Files\MozyHome\mozystat.exe C:\Program Files\Dell Wireless\PRISMCFG.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\System32\Rundll32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Jason\Desktop\HiJackThis_v2.exe C:\WINDOWS\system32\wbem\wmiprvse.exe |
Reboot your computer in safe mode run HijackThis and delete the following entries C:\Program Files\GetModule\GetModule21.exe C:\Program Files\GetPack\GetPack20.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = CNN. com - Breaking News, U.S., World, Weather, Entertainment & Video News R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Learn about Dell's laptops, desktops, monitors, printers plus PC electronics & accessories. R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O2 - BHO: Helper Class - {3670A914-63C2-4E67-8C9B-370AE1922143} - C:\Program Files\BChanger\bchanger.dll O2 - BHO: bannerstyles15 browser enhancer - {72336a1a-bafb-e607-a0ad-218e19796665} - C:\WINDOWS\system32\dbjxznhhtocz.dll O2 - BHO: (no name) - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - (no file) |
All times are GMT -4. The time now is 07:33 AM. |
Copyright © 2005-2013 SysChat.com