jung7311,
Hi. Let's see what we can do :).
-
Download, then unzip to "C:\HJT", the newest version of HiJackThis ; version 1.99.1. Then repost your log, either now, or after following the steps in the solution (if provided in this post). This version has features that might be more helpful in 'cleaning' up your system.
===============
Go to Add/Remove programs and remove(uninstall) the following, if present:
TSA
The above could appear anywhere within the entry. Be careful not to remove any personal or system software.
===============
Next, we need to remove(uninstall) the 'lop' infection by going to here , then downloading and running the uninstaller(s) that relate to the application(s) your wanting to remove. The following selections are available: "Start page", "Search engine", "Accessories Toolbar".
After uninstalling any (or all) of the above, let's see if we have anything in "Scheduled Tasks":
Download, unzip and run ScheduledTasks.bat (courtesy of ddeerrff), and when notepad comes up, post the contents back to this thread.
===============
Now, let's open a command prompt by going to the start menu and then select 'Run'.
In the box that pops up type in 'cmd'. The command prompt will open.
OR
You can go to Start -> Programs -> Accessories -> Command Prompt. Unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u font.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save typing them in.
===============
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {03C00552-9A0B-9DB1-4456-0F4E33B8983F} - C:\DOCUME~1\Owner\APPLIC~1\SENDSO~1\BLAH SIZE.exe
O2 - BHO: CFilter Object - {2A7B720A-7A28-4e99-80A0-2DF985EC93D0} - C:\WINDOWS\system32\font.dll
O4 - HKLM\..\Run: [Drive title dent clock] C:\Documents and Settings\All Users\Application Data\Meow dead drive title\Loud 2.exe
O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe
O4 - HKCU\..\Run: [jump bore] C:\DOCUME~1\Owner\APPLIC~1\StoreMp3\DateMpegDart.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
Now, with all windows closed except HiJackThis, click "Fix checked".
===============
Locate and delete the following item(s), if present. Make sure your able to " view system and hidden files/ folders: "
folders...
C:\PROGRA~1\COMMON~1\tsa
C:\DOCUME~1\Owner\APPLIC~1\SENDSO~1
C:\Documents and Settings\All Users\Application Data\ Meow dead drive title
C:\DOCUME~1\Owner\APPLIC~1\StoreMp3
files...
C:\WINDOWS\system32\font.dll
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in " Safe Mode ".
-
Reboot.
===============
To help protect your system from hostile ActiveX content, or special 'downloadable' files:
Download, install and keep updated, SpywareBlaster . If you've installed it for the first time:
1) Check for any available updates; if present, they'll be automatically downloaded and installed.
2) Next, "Enable all protection".
3) Exit the program.
-
Note: Remember to regularly check for updates.
===============
After rebooting your PC, rescan with hijackthis and post a new log.
Let me know how things are now.