Error message with Hitman Pro35

Options
124

Comments

  • Wikikenkey
    Wikikenkey Posts: 268 Forumite
    First Anniversary First Post Combo Breaker
    Options
    Hi aliEnRIK

    I have done all the above apart from stopping the Spyware Doctor bit. Not sure why Spyware Doctor is still in my C drive because I uninstalled it about 2 days ago. I did a search for sdhelp.exe in my C drive and found it. Can I just delete it?

    After that, would you like me to run another hijack or do you think I am good to go. Hoping to replace McAfee with Avast in the very near future.

    Thank you.
  • RussJK
    RussJK Posts: 2,359 Forumite
    Options
    If you go into Start menu and type "services.msc", then look for the entry 'PC Tools Spyware Doctor (SDhelper)', just double click on it and set the startup mode to disabled. The alternative method is to use "msconfig" then the Services tab, 'Hide all Microsoft services' to make it easier, and look for the spyware doctor entry and untick it. Don't restart if it asks.

    To remove McAfee, I find this tool useful to remove it: http://www.appremover.com/. Afterwards, you can run the McAfee Removal tool if you want to be 100% sure it's gone (http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe).

    If you had the Avast installer ready to go, then install it after McAfee is gone.
  • Wikikenkey
    Wikikenkey Posts: 268 Forumite
    First Anniversary First Post Combo Breaker
    Options
    All done. Thank you.

    I have just one last sneaky query.

    If you could recommend a good external drive that I could back-up my computer to (yes, I am one of those who have never made a back-up) and also save my music files to, which would it be?

    Merci beaucoup
  • RussJK
    RussJK Posts: 2,359 Forumite
    Options
    Wikikenkey wrote: »
    All done. Thank you.

    I have just one last sneaky query.

    If you could recommend a good external drive that I could back-up my computer to (yes, I am one of those who have never made a back-up) and also save my music files to, which would it be?

    Merci beaucoup

    No worries, ask anything you want.

    I went with Western Digital elements - I had a £30 off voucher from very.co.uk, and got a 2tb 3.5" external for £52.95. I saw a list from a large retailer which showed that WD had the lowest return rates for hard drives, suggesting that they were more reliable.

    The USB powered 2.5" are more convenient and smaller, but the 3.5" ones are cheaper but mains-powered.

    The one I got is big enough to copy everything over from all my computers, as well as make regular 'clones' using Clonezilla or Redobackup. With a 'clone', it is a 1:1 copy of everything on the hard drive so that you can restore things exactly as they were if you run into trouble.

    Oh by the way, are you now able to run Hitmanpro without it stopping? :D
  • Wikikenkey
    Wikikenkey Posts: 268 Forumite
    First Anniversary First Post Combo Breaker
    Options
    In my excitement, I had totally forgotten all about Hitmanpro.

    I have just tried it again, using breach mode, and it is still giving me an error message (HitmanPro has encountered a problem and needs to end) at ESENTPRFK.dll. The error message comes up in a box but Hitmanpro carries on classifying behind the error message box till 99%. The light green marker is on ESENTPRFK.dll - uploading to Scan Cloud but the marker just sits there. I have left the computer for about 30 mins, come back and the green marker hasn't moved. What to do?
  • RussJK
    RussJK Posts: 2,359 Forumite
    Options
    So the original file is still there. Might need something like oldtimer to get rid of it, but I've not used that yet myself. See what tricks AlienRik has up his sleeve, otherwise the folks at bleepingcomputer could help.

    Go into Malwarebytes, then select the More Tools tab, and run the FileAssassin tool on ESENTPRFK.DLL, and reboot, then try HitManPro again.

    Another method is to try one of the bootable antivirus scanners. This thread has a list and instructions (http://forums.moneysavingexpert.com/showthread.php?p=41653210). Dr Web is a good one, although incredibly slow - fortunately it has a web browser so you can still use the machine! I also like Avira and F-Secure.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    First Anniversary Combo Breaker
    Options
    Unless its disguised, the file is a legit microsoft file

    I think hitmans at fault personally
    :idea:
  • RussJK
    RussJK Posts: 2,359 Forumite
    Options
    aliEnRIK wrote: »
    Unless its disguised, the file is a legit microsoft file

    I think hitmans at fault personally

    It showed up as an inaccessible file in Hijack Hunter as well, and I've found no information on the web after searching, which is why I'm suspicious of it. Perhaps she can instead do the Dr Web scan from a boot disk and see what turns up.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    First Anniversary Combo Breaker
    Options
    Apologies
    I was searching for the file minus the K which is legit (duh)


    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\ESENTPRFK.dll


    Save this as "CFScript" (FULL file will be 'CFScript.txt' EXACTLY as shown)

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
    (If SNAPSHOT is stupidly large, leave that part out)

    Combofix should never take more that 30 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    :idea:
  • Wikikenkey
    Wikikenkey Posts: 268 Forumite
    First Anniversary First Post Combo Breaker
    Options
    Thanks, all. At work at the moment but will definitely try this when I get home. Will get back to you.
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.7K Banking & Borrowing
  • 250.2K Reduce Debt & Boost Income
  • 449.9K Spending & Discounts
  • 235.8K Work, Benefits & Business
  • 608.8K Mortgages, Homes & Bills
  • 173.3K Life & Family
  • 248.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards