Open NotePad, and copy the contents of the below "Code" box:-
cd %windir%
attrib -s -r -h Nail.exe
attrib -s -r -h svcproc.exe
attrib -s -r -h wupdt.exe
del Nail.exe
del svcproc.exe
del wupdt.exe
cd system32
attrib -s -r -h mhqabb.exe
del mhqabb.exeGo to File Menu >Save As, and save the file with the name Test.bat and exit from NotePad.
Download the Nail Fix tool from NoIdea.Us.
Download CCleaner and install it. Click "Options" button and here go to "Settings" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options.Then exit from CCLeaner.
Run Ewido, and in the main screen, click on "Update" in the left menu, then click the "Start update" button. After the update finishes (the status bar at the bottom will display "Update successful"), exit Ewido. DO NOT scan yet.
Reboot in Safe Mode, restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Double-click on the nailfix.cmd file, a DOS type window opens up and closes automatically, and the Desktop icons may disappear and appear back.
Run Ewido, Click on the "Scanner" button in the left menu, then click on the "Start" button. If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK. When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [frttdx] c:\windows\system32\mhqabb.exe r
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Double-Click on the file Test.bat, a small DOS type window should open and close immediately.
Next, run CCleaner, and click "Run Cleaner" and click "OK" to the warning message.
After this, go to Start > Run and type services.msc and press ENTER. Here navigate to the service and right-click on it. Choose "Properties", and here click "Stop" in the Service Status option. And in the Startup Type option box, choose "Disabled". Click "Apply" and "OK". Exit from Services.
Restart your PC to Normal mode, and run HijackThis again to get a new log. Post the new HijackThis log, and also the log created by Ewido