Reboot into Safe Mode (you can get to the Safe Mode boot option by hitting the F8 key as your computer is starting up)
Open Windows Explorer, and in the Folder Options, Tools, View, select "show hidden files and folders," and uncheck "Hide protected operating system files."
For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
1. Local Settings\Temp
2. Cookies
3. History
4. Local Settings\Temporary Internet Files\Content.IE5
Delete the entire contents of your
C:\Windows\Temp folder
C:\Temp folder
(If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll automatically be regenerated by Windows if they're needed.
Empty your Recycle Bin, and then reboot normally.
Download Killbox from here:
http://www.downloads.subratam.org/KillBox.exe
and put it on your desktop. Open Killbox and select the option Delete on Reboot.
One at a time, copy & paste the full path of these files into Killbox's topmost box.
C:\Program Files\Admilli Service\AdmilliKeep.exe
C:\Program Files\Admilli Service\AdmilliServ.exe
With the full path to the file name in the topmost textbox, click the Red X, for the confirmation message that will appear, you will need to click Yes; A second message will ask to Reboot now? Click No after the first entry (since you are not finished yet), and after the last one, click Yes and let the system reboot.
Whenever you scan with HJT, be sure all browser windows are closed. Now, close all browser windows, scan with HJT, and have it fix the following entries:
O4 - HKLM\..\Run: [Admilli Service] C:\Program Files\Admilli Service\AdmilliServ.exe
(May no longer be in the log)
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
(May no longer be in the log, more info here: http://www.liutilities.com/products/wintaskspro/processlibrary/salm/ )
O4 - HKLM\..\Run: [hmrcxuz] C:\WINDOWS\hmrcxuz.exe
(Have HJT fix this unless you know what it's for)
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
(More info here: http://www.liutilities.com/products/wintaskspro/processlibrary/tsm2/ )
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/C.../bridge-c17.cab
(Blazefind Windupdates Adware)
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe
(BargainBuddy)
Reboot into Safe Mode again
Go to
C:\Program Files and delete the Admilli Service folder, if found
c:\temp and delete salm.exe, if found
You need to delete this one, but you'll have to do a search for it -- tsm2.exe
Same with this one -- ts2.exe
(More info here: http://www.liutilities.com/products/wintaskspro/processlibrary/ts2/ , both of those files are in the same folder, tsa, and you may want to delete the entire folder)
Reboot normally, close all browser windows, scan with HJT, and post a new log please.
You may wish to set seticon to start manually instead of automatically as it is known to be a resource hog ( http://startup.iamnotageek.com/srch-SetIcon.exe.html )