AboutBrian Benosky Expertise I will help you in eradicating malware and all forms of virus/trojans/adware. I can answer all PC-related hardware issues. I can also troubleshoot Windows OS errors (including Vista) and other software problems. HijackThis logs are a MUST for virus related help. If you do not know how to do this, I have posted easy-to-follow instructions on the Ask a Question page. Every computer infection is different, so I will give you personal instructions on how to remove the malware, not a 'pat' answer. You can be assured of a prompt, polite, and knowledgeable response in all regards.
Experience I have over 25 years experience in using, building, and repairing computers. I have helped over a thousand people here on AllExperts, with consistent Top Feedback Scores. Please look at my answers here:
http://en.allexperts.com/q/Computer-Security-Viruses-1737/indexExp_84308.htm
I am also a Top Contributer of General Computing answers in Yahoo! Questions.
Education/Credentials College Educated
Self-taught Computer Skills
Expert: Brian Benosky Date: 7/7/2008 Subject: OSEENUS toolbar
Question QUESTION: I am having difficulty getting rid of this OSEENUS toolbar. It is allowing constant popups and resets my privacy button in IE to accept all cookies. I read several of your other postings and was able to get rid of another virus (Vundo)...I think. Here is my HJT logfile. If you see any other potential problems please let me know.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:42 AM, on 7/7/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Please download ComboFix from here and save to your desktop: http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
Please disable your antivirus application for now, as this may interfere with the removal process.
Doubleclick combofix.exe
Follow the prompts.
Note - Your internet connection will be terminated while ComboFix runs. Do Not attempt to re-enable it. Should ComboFix terminate prematurely, restart the computer to restore connectivity.
Don't use your mouse or keyboard while the fix is running, because that will cause your system to hang.
When finished and after reboot (in case it rebooted), combofix will open again to gather the necessary information for the log. This may take a bit. When done, Combofix will close and a log should open, combofix.txt.
Post the contents of this log in your next reply together with a new hijackthis log.
Brian
---------- FOLLOW-UP ----------
QUESTION: Thanks for your prompt response. I read several of your other postings and I downloaded ComboFix but when i click on it i get an error meassage that reads:
C:\Documents and Settings\Darrell Tingle\Desktop\ComboFix.exe is not a valid Win32 application
Also, I do not know how to turn off AVG 8...there is not disable button.
Answer Hi Darrell
Please make sure that you are running as an Administrator. Now let's try this:
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your administrator account.
* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
* Finally paste the contents of the Report.txt and a new HJT log.