Disable Windows DefenderWe need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
- Open Windows Defender
- Click on Tools > Option
- Scroll down and uncheck Use real-time protection (recommended)
- After you uncheck this, click on the Save button and then exit Windows Defender
- Now on your keyboard press and hold Ctrl+Alt and then press the Delete key tow times to bring up the Task Manager.
- Locate MSASCui.exe then right click on it and choose End Process. Click Yes on the Task Manager Security Warning.
After all of the fixes are complete it is very important that you enable real-time protection again.
.
----------
Open HijackThis and select
Do a system scan only.
Place a check mark next to the following entries: (if there)
- R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
- O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
- O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
- O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1Important: Close all windows except for HijackThis and then click
Fix checked.
Exit HijackThis.
----------
Download the
OTMoveIt3 by OldTimer
Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose
Run As Administrator.
*
Save it to your
Desktop.
* Double-click
OTMoveIt3.exe to run it.
*
Copy the lines in the codebox below to the clipboard by highlighting
ALL of them and
pressing CTRL + C (or, after highlighting, right-click and choose
Copy)
:Processes
explorer.exe
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}]
:files
C:\Program Files\AskTBar
C:\rsit
C:\lopR.txt
C:\Lop SD
C:\ComboFix.txt
C:\WINDOWS\zip.exe
C:\WINDOWS\VFIND.exe
C:\WINDOWS\SWXCACLS.exe
C:\WINDOWS\SWSC.exe
C:\WINDOWS\SWREG.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\NIRCMD.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\fdsv.exe
C:\Qoobox
C:\SDFix
C:\VundoFix.txt
C:\VundoFix Backups
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
* Return to OTMoveIt3, right click in the
"Paste Instructions for Items to be Moved" window
(under the yellow bar) and choose
Paste.
* Click the red
Moveit! button.
*
Copy everything in the Results window (under the green bar) to the clipboard by highlighting
ALL of them and
pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close
OTMoveIt3Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose
Yes.If not, reboot anyway.
Is everything back to normal now?