PC Pals Forum
Technical Help & Discussion => Broadband, Networking, PC Security, Internet & ISPs => Topic started by: daveeb on October 17, 2004, 13:46
-
Grrrrr. Got this highly annoying adware. Got rid of it yesterday with hijack this in safe mode but it has returned and is more intrusive than ever. Anyone got any tips on keeping it at bay. >:(
-
Found this on another forum Dave, may be worth giving it a try :)
First, we need to take care of WebRebates though.
Go to Control Panel, Add/Remove Programs, and uninstall "WebRebates" and "FlashJet", if found.
Next, fire up Task Manager (press CTRL+ALT+DEL), "Processes" tab, and END these processes :
WebRebates1.exe
WebRebates0.exe
Now, locate and delete these two files in bold :
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
Ok, have ONLY HijackThis! running, and check to fix these entries (then click on "Fix checked") :
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - (no file)
O2 - BHO: (no name) - {D1F391B4-EFB2-4EF6-8140-18EAB436F223} - C:\WINDOWS\madopew.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll
O18 - Filter: text/plain - {E75A984A-6D2A-4CAB-AEFF-37BBE4EE7AEC} - C:\WINDOWS\madopew.dll
Now, please Reboot your computer in Safe Mode, then locate and delete the following file and folders, if found :
C:\WINDOWS\digfilt.dll <<< file
C:\Program files\FlashGet <<< entire folder
C:\Program Files\Web_Rebates <<< entire folder
Reboot normally. Scan with HJT, then post a fresh log ;
-
Thanks for that sandra, i'll give it a go. ;)