Thanks, it looks Good to me, but I'm a novice at these logs, I have asked the other staff members to take a look for other stuff, but for now:
Ensure that spybot search and destroy resident helper/teatimer is not running, then
ensure that NONE of these applications are running in the background, by either exiting out of them, closing all open windows, and or killing their processes via task manager; if exiting the applications and closing the windows still will not allow you to uninstall and you need help figuring out how to kill their processes via task manager, let us know.
If you don't use google toolbar, open "start menu" "settings" "Control Panel" then open "add remove programs"
look for google toolbar and click add/remove, check the "uninstall" or "remove" not sure what it is.
Same goes for Uniblue registry booster, if you don't have the full version, all it does is make recommendations on what you can change, in order to change anything using the program you need the "full" version = buy it.. If you don't like what you see and don't plan on buying the full version; To un-install this application, you have to kill it's process, or turn it off, if it has a tray icon next to the clock/speaker icon in your start bar, click on this and look for an "exit" option, then go to the control panel, add remove programs and use it's uninstaller, as mentioned previously for google toolbar.
If you do not use synchronization software; to work offline, you can disable the mobsync.exe /boot synchronization manager!
To do this; open the start menu, programs, accessories, then run "synchronize" open the "setup" menu and uncheck the synchronization options,
Then deselect the option to synchronize your home page. Open internet explorer, in the top bar of internet explorer you should see a set of options, this is the toolbar, on the internet explorer toolbar select Tools, then select Folder Options, and offline files, deselect the "enable offline files" option. You will have to reboot for the changes to take effect. Once rebooted, you should no longer see the following entry in your hijack this log:
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
_________
There may be some residual "file missing" entries caused by the uninstal processes, but we'll get to those later.
You can have hijack this fix the following by checking the box next to their entries and clicking the "FIX CHECKED" button:
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O24 - Desktop Component 0: Privacy Protection - (no file) !!~see if you have a file folder on your drive C in C:\windows named "privacy danger" If you find the "privacy danger" folder, delete it! this is related to a malware infection.
The internet settings "restrictions" is probly created by spybot search and destroy's
Resident helper. The other thing I noticed in your logs is that teatimer is enabled.
Teatimer protects your registry from changes by asking you "allow" "deny" changes that applications want to make to the registry, this is good if you know what you are installing, and will pop up if something that you were un-aware of is trying to make changes to the registry, alerting you of possilbe changes that would cause issues
It can also cause any malware or anti-virus application to not be able to remove registry problems when they find them.
it's recommended to turn off Teatimer, or even the whole spybot search and destroy application, before running the anti-virus/anti-malware applications.
To temporarily disable teatimer; run spybod search and destroy in "advanced mode". In the spybot search and destroy side bar, there's a "TOOLS" menu, in the tools menu there is an icon that says "resident", click on "resident" and you will find a couple of check boxes, one is to enable/disable "teatimer" the other is for internet explorer and is probly what creates the "restrictions" entry showing in your hijackthis log. Nothing to worry about. Turn them both off, but take good measure by disconnecting from the internet prior to disabling the internet explorer SDHELPER? Run your anti-virus/anti-malware, and hijack this without spybot search and destroy running. Then save the logs, and re-enable the resident settings and have spybot search and destroy running before you reconnect your internet connection. Compare the hijackthis logs, or post the logs for comparison.
There are some other things that I am unsure of just yet, but this is a good middle ground, once you have completed the above mentioned suggestions, run hijack this and repost another log and we can take a look at it to see how it's going, make further suggestions etc.



Reply With Quote