Copy these instructions to notepad and save them on your desktop for easy access. Open the Temp folder and go to Edit>Select All then Edit>Delete to delete the entire contents of the Temp folder.

Check Turn off System Restore. Click the Tools menu, and then click Folder Options.

When it is finished restart your computer. In addition to scan and remove capabilities, HijackThis comes with several useful tools to manually remove malware from your computer.

Wait until it's done fixing, and then close HijackThis.

Restart your computer, turn System Restore back on and create a restore point.

Now to scan just click the Next button.

Then go and read the Viruses/spyware/malware, preliminary removal instructions. Open the System32 folder and right click on an empty space in the window.

  1. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe O4 - HKLM\..\Run:
  2. Click OK DO NOT RUN IT YET Download KillBox here: http://www.downloads.subratam.org/KillBox.zip Save it to your desktop.
  3. If it finds anything that it cannot clean have it delete it or make a note of the file location so you can delete it yourself.
  4. When the scan has completed, click Copy and paste the results (if any) into this topic.
  5. Do not stop those two.
  6. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link
  7. My computer takes about 10 - 15 seconds to open up anything, like Internet or a file.
  8. All Rights Reserved.
  9. Things appear to be working properly so far...
  10. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:45:07, on 9/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe

Wait for it to complete.

Afterwards, I had restarted my computer and the problem still existed.

If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.Give it atleast 20-30 minutes to finish if needed. HJT attached:Logfile of HijackThis v1.99.1Scan saved at 2:44:28 PM, on 6/5/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\savedump.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\sysan32.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\sysoa32.exeC:\PROGRA~1\STOMPS~1\SPYWAR~1\PPControl.exeC:\PROGRA~1\STOMPS~1\SPYWAR~1\PPMemCheck.exeC:\Program Files\Dell\Media Experience\PCMService.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeC:\Program Files\MUSICMATCH\MUSICMATCH Type a description for your new restore point.

Open the program and click on the Rootkit tab. When the scan is complete, click OK, then Show Results to view the results.Be sure that everything is checked, and click Remove Selected .When completed, a log will open in Notepad.

When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized. Click the System Restore tab.

Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box. Exit the Services utility.

Do a file search for ComboFix.txt