Infected With Outerinfo And Others.

Step 10 Type a file name to backup the registry in the File Name text box of the Save As dialog box, and then click the Save button. Step 2 Click the Internet options menu item. It is far more secure than Internet Explorer. The Windows Advanced Options Menu will appear. Source

Do NOT delete the tasks folder present in your C:\Windows-folder !!!C:\WINDOWS\system32\tmp.reg <== fileC:\VundoFix Backups <== folderC:\Qoobox <== folderIf it's clean, can I now install SP2?Yes, but in case this is a Secure your Internet Explorer by going here and following the instructions there. Unfortunately, OuterInfo Installer is only engaging in information capture or attempting to advertise unwanted products and services. Empty the Recycle Bin.

O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: Search with Wanadoo -

It is an important part of removing the virus. Therefore, only computer users with rich computer knowledge are recommended to implement the process because any errors including deleting important system files and registry entries will crash your computer system. So far so good. Join over 733,556 other people just like you!

If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. Step 9 Click the Yes button when CCleaner prompts you to backup the registry. Step 3 In the installed programs list, locate the listing for OuterInfo Installer. Step 4 On the License Agreement screen that appears, select the I accept the agreement radio button, and then click the Next button.

C:\RECYCLER\S-1-5-18\Dc2\system.dll -> Adware.Softomate : No action taken. find more It will ask if you want to update the program definitions, click Yes, Let it through your firewall!Under Configuration and Preferences, click the Preferences button. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. My computer's been infected with Outerinfo adware - HJT help?

My problem has changed, by the looks of it. http://secondsolution.net/infected-with/infected-with-spyeraser.php Note that all previous restore points will be lost. =============== If you have any more problems, post back. - Happy surfing, crunchie. Anyway I used HijackThis, with the log copy-pasted below. Hi.

Post back an update on that before you do the cleanup, but here are those steps as well. Loading... Please double-click OTMoveIt.exe to run it and click on Cleanup. have a peek here C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : No action taken.

For XP users. Under Scanner Options make sure the following are checked: Close browsers before scanning Scan for tracking cookies Terminate memory threats before quarantining. C:\System Volume Information\_restore{349EF5AA-43EC-41FB-BA13-F317E31AE13B}\RP46\A0002886.vbs -> Trojan.Small : No action taken.

O4 - HKLM\..\Run: [tizeugl.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Daniel Brauer\Local Settings\Application Data\tizeugl.dll",wgbnsigO4 - HKLM\..\Run: [{090E3069-0647-1033-1003-060805060001}] "C:\Program Files\Common Files\{090E3069-0647-1033-1003-060805060001}\Update.exe" mc-110-12-0000272O4 - HKLM\..\Run: [ewmjwc.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Daniel Brauer\Local

After the list has downloaded, you'll be asked if you want to begin cleanup process? C:\System Volume Information\_restore{349EF5AA-43EC-41FB-BA13-F317E31AE13B}\RP45\A0002836.exe -> Adware.PurityScan : No action taken. The right one lists the registry values of the currently selected registry key.To delete each registry key listed in the Registry Keys section, do the following:Locate the key in the left Check This Out Back to top #3 driver8 driver8 Topic Starter Members 3 posts OFFLINE Local time:09:53 PM Posted 04 June 2007 - 08:57 PM This was my sister's old computer and my

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Xyron Wishblade Status Supervisor.lnk = ? Go back in and Turn System Restore Back on. Learn how. Sometimes adware is attached to free software to enable the developers to cover the overhead involved in created the software.

Completion time: 2008-04-21 0:25:51 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-21 04:25:48 Pre-Run: 72,260,870,144 bytes free Post-Run: 73,234,792,448 bytes free 270 --- E O F --- 2008-04-21 04:05:10 Hijack This log: Logfile It is usually bundled with free software or other pirated software from insecure sources, suspicious sites and spam e-mail attachments. C:\System Volume Information\_restore{349EF5AA-43EC-41FB-BA13-F317E31AE13B}\RP46\A0002888.vbs -> Trojan.Small : No action taken.     ::Report end       Logfile of HijackThis v1.99.1 Scan saved at 11:29:35 PM, on 2/12/2007 Platform: Windows XP SP1 Place a check (tick) next to the following entries (if present):   O2 - BHO: (no name) - {A54CEB41-70DB-0A0B-D93C-2D90EFA36FBA} - C:\WINDOWS\System32\odkvqssd.dll (file missing) O4 - HKCU\..\Run: [Kta] "C:\Documents and Settings\Owner\Application Data\?icrosoft.NET\w?auclt.exe"

O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: Search with Wanadoo -

