Hi girloutside,
You may wish to print out a copy of these instructions to follow while you complete this procedure.
Step One:
Please scan your system with Ad-aware:
Ad-aware SE - Download - Home Page If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to uninstall the previous version.
After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run.
Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".
Once the definitions have been updated:
Reconfigure Ad-Aware for Full Scan as per the following instructions:Launch the program, and click on the Gear at the top of the start screen.
Under General Settings the following boxes should all be checked off: (Checked will be indicated by a green circle with a check mark in it, Un-Checked is a red circle with an X in it. If it is greyed out, those features are only available in the retail version.)"Automatically save logfile"
Automatically quarantine objects prior to removal"
Safe Mode (always request confirmation)
Prompt to update outdated confirmation) - Change to 7 days.
Click the "Scanning" button (On the left side).
Under Drives & Folders, select "Scan within Archives"
Click "Click here to select Drives + folders" and select your installed hard drives.
Under Memory & Registry, select all options.
Click the "Advanced" button (On the left hand side).
Under "Shell Integration", select "Move deleted files to Recycle Bin".
Under "Log-file detail", select all options.
Click on the "Defaults" button on the left.
Type in the full url of what you want as your default homepage and searchpage e.g. http://www.google.com .
Click the "Tweak" button (Again, on the left hand side).
Expand "Scanning Engine" by clicking on the "+" (Plus) symbol and select the following:"Unload recognized processes during scanning."
"Obtain command line of scanned processes"
"Scan registry for all users instead of current user only"
Under "Cleaning Engine", select the following:"Automatically try to unregister objects prior to deletion."
"During removal, unload explorer and IE if necessary"
"Let Windows remove files in use at next reboot."
"Delete quarrantined objects after restoring"
Click on "Safety Settings" and select "Write-protect system files after repair (Hosts file, etc)"
Click on "Proceed" to save these Preferences.
Click on the "Scan Now" button on the left.
Under "Select Scan Mode, be sure to select "Use Custom Scanning Options".
Close all programs except ad-aware.
Click on "Next" in the bottom right corner to start the scan.
Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT - Even if not prompted to.
After you log back in, Ad-Aware may run to finalize the scan and remove any locked files that it may of found. Allow it to finish.
Step Two:
Download and Install Spybot S&D, accepting the Default Settings
Home - The home of Spybot-S&D!: http://www.safer-networking.org/
Here is a nice Tutorial http://www.safer-networking.org/index.php?page=tutorial Go to Start > Programs >Spybot Search & Destroy and choose 'Spybot S&D'
Close ALL windows except Spybot S&D
Click the button 'Search for Updates' and download and install the Updates.
Next click the button 'Check for Problems'
When Spybot is complete, it will be showing 'RED' entries BLACK entries and GREEN entries in the window
Make sure there is a check mark beside the RED entries ONLY.
Choose Fix Selected Problems and allow Spybot to fix the RED entries.
REBOOT
Step Three:
Please download and install Trojan Hunter, free trial . Check for updates, scan and let it clean what it finds.
Step Four:
Download, install, and run CleanUp!
Step Five:
Run this online virus scan: ActiveScan - Save the results from the scan!
Step Six
Please re-open HiJackThis and scan. Check the boxes
next to all the entries listed below.
O4 - HKLM\..\Run: [Timer] C:\WINDOWS\timer.exe /i
O4 - HKLM\..\Run: [Microsoft Update Machine] clpbrd.exe
Now close all windows other than
HiJackThis, then click Fix Checked. Reboot into
safe mode.
Restart your computer and as soon as it starts booting
up again continuously tap F8. A menu should come up
where you will be given the option to enter Safe Mode.
Please delete these files using Windows
Explorer(if present):
C:\WINDOWS\timer.exe
And
clpbrd.exe
Step Seven:
Reboot and post a new HiJackThis log along with the results from ActiveScan. :cool: