We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

What can I get rid of?

Options
13»

Comments

  • dogmaryxx wrote: »
    Also remove

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

    If other people using the computer used Limewire would I still remove 03?
  • Donnie
    Donnie Posts: 9,862 Forumite
    Where is the Malwarebytes' log?
  • x.nukke.x
    x.nukke.x Posts: 122 Forumite
    Part of the Furniture Combo Breaker
    Yes, that is simply a toolbar. You can still run LimeWire if needed via Start -> All Programs -> LimeWire
  • Just doing it now!:)
  • Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4451
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13
    20/08/2010 15:24:47
    mbam-log-2010-08-20 (15-24-47).txt
    Scan type: Quick scan
    Objects scanned: 241518
    Time elapsed: 1 hour(s), 48 minute(s), 18 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\WINDOWS\SYSTEM32\DRIVERS\RKHit.sys (Rogue.BestSpywareScanner) -> Quarantined and deleted


    Now rebooted.
  • and latest hijack this....
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 15:33:20, on 20/08/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.17080)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\system32\CSHelper.exe
    C:\WINDOWS\system32\FsUsbExService.Exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\Program Files\WinPcap\rpcapd.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\svchost.exe
  • bat999
    bat999 Posts: 1,947 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 20 August 2010 at 4:50PM
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    This is still running.
    Never interrupt your enemy when he is making a mistake.
  • Donnie
    Donnie Posts: 9,862 Forumite
    Yes, we are waiting for the rest of the HijackThis log.

    If the Search Enhancement Pack is not listed in Add/Remove options for un-instalation in the usual way, you can remove it this way:
    Launch regedit (you only search and copy-no changes)
    Click on "My computer" at the top of the key structure
    Hit F3 (or Cntrl-F for "Find")
    Select the checkbox for "Values" only and search for "uninstallstring" (without quotes)

    As you find these values in your registry you will see in the right pane a value called DisplayName (the name of the program to be uninstalled)
    After you find the name of the program you want to uninstall (in this popups case "ChoiceGuard" or "Search Enhancement Pack")
    Double-click the uninstallstring value for that program and copy the string data to your clipboard (should look like "msiexec /x ........")

    close regedit

    click on start-then Run then paste in your clipboard
    click ok

    answer Yes to the prompts and it is gone.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 599K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.