could you please help with Iefeats but at the end could you please list other problems that i should look into later? Reinstall your Symantec antivirus program As this adware may attempt to remove the files and registry subkeys that your Symantec antivirus program uses, you may need to reinstall the program. Start about:buster and hit start.

Sophos Home Free protection for home computers. However two deletions could not be completed in the safe mode as they were not there.O2 - BHO: Class - {40061BD6-2058-A80E-76F6-493801F6BBD3} - C:\WINNT\ntde32.dllO2 - BHO: Class - {B11827DC-EDAD-9543-292B-E0A80432EE07} - C:\WINNT\winwk32.dllNew Hijackthis C:\WINNT\winamp.ini:ymdewnRemoved Stream! For additional information, or if this procedure does not work, read the Microsoft® Knowledge Base article: Home Page Setting Changes Unexpectedly, or You Cannot Change Your Home Page Setting, Article ID https://www.symantec.com/security_response/writeup.jsp?docid=2004-030417-3501-99

Intercept X A completely new approach to endpoint security. The next time you open it, it will again use the Search Companion. C:\WINNT\aucfg.ini:iuqcvoRemoved Stream!

Replaces Internet Explorer search functionality by removing the following registry subkeys: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks and adds the value: "[BHO CLSID]" = "0x00 [38 MEANINGLESS BYTES]" to the recreated subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Internet

This Cancel option tells the scanner to ignore the risk for this scan only, and thus, the risk will be detected again the next time that you run a scan. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000). Adware.Iefeats Started by ::SHArP:: , Jun 27 2004 10:37 PM #1 ::SHArP:: ::SHArP:: Members 16 posts OFFLINE Local time:04:13 PM Start AboutBuster.exe.

Downloads encrypted service and Browser Helper Object from one or more of following domains: u47.cc u45.cx u48.cc u46.cx Decrypts the files, merges them with up to 1024 random bytes and saves Please re-enable javascript to access full functionality. Live Sales Chat Have questions? To learn more and to read the lawsuit, click here.

Note: The date and time displayed will be adjusted to your time zone, if your computer is not set to the Pacific time zone. C:\WINNT\videoimp.ini:tynajeRemoved Stream! C:\WINNT\KB840315.log:nedpbgRemoved Stream!

Unzip AboutBuster in an own folder such as C:\AboutBuster. Close Reply To This Thread i have used search to search my whole computer, hidden files and everything for this .dll file but it won't turn up. Click Tools > Internet Options.

Click OK. Do NOT run a scan yet.°First, we will make your hidden files and folders visible. * Click Start. * Open My Computer. * Select the Tools menu and click Folder Options.

C:\WINNT\Blue Lace 16.bmp:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}Removed Stream! Follow the prompts on screen.Wait for the tool to complete and disk cleanup to finish.* Run Ewido:* Click on scanner* Click Complete System Scan and the scan will begin.* During the Because the algorithm used by this adware lacks the capability for proper detection of Security Risks, it may also damage legitimate processes and files.

Symantec sees it but doenst seem to be cleaning it.

Click Reset. Click on the Programs tab then click the "Reset Web Settings" button. Click the Search button on the toolbar. Adds the value: "[NAME OF THE INSTALLER FILE]" = "[LOCATION AND NAME OF THE INSTALLER FILE]" to the registry subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run so that the installer runs every time Windows starts.

Adds the value: "[NAME OF THE SERVICE FILE]" = "[LOCATION AND NAME OF THE SERVICE FILE]" for downloaded service to the registry subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce so that the service could be run CONTRIBUTE TO OUR LEGAL DEFENSE All unused funds will be donated to the Electronic Frontier Foundation (EFF). Any feedback on the latest HijackThis log? have a peek at these guys C:\WINNT\$_hpcst$.hpc:taufwqRemoved Stream!

If you want to go back to the "Search Companion" search (it usually has an animated character at the button), proceed with step n. Restart the computer in Safe mode or VGA mode Shut down the computer and turn off the power. Click OK. I have pop-ups, browser hijacked, even one mouse button behaves differently on IE Explorer pages.

Adware.Iefeats CoolWWWSearch Started by daybud, Sep 05 2005 08:19 AM #1 daybud daybud Member Full Member 2 posts Posted 05 September 2005 Once this occurs, when Internet Explorer is opened, the Browser Helper Object does the following: Downloads encrypted configuration and data files from one or more of following domains: u47.cc u45.cx u48.cc