Open Task Manager & end process on the following:
[b]zczghsfb.exe[b] Make sure it has ended completely.
Then delete the file manually by going to; C:\WINDOWS\System32
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click
'fix checked':
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.red.clientapps.yahoo.com/...arch.yahoo.com/
O4 - HKLM\..\Run: [oirythcm] C:\WINDOWS\System32\zczghsfb.exe
O9 - Extra button: BT - {03F7A76B-72EE-4071-9BE1-979015A7FFD5} -
http://www.bt.com (file missing) (HKCU)
O9 - Extra button: Homepage - {057E448E-9B00-43F9-933D-73C8AF45F69C} -
http://bt.yahoo.com (file missing) (HKCU)
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_f...1613117fb4ea0f9
-
Blazefind Windupdates Adware
Reboot & see how it is.