Hi,
Download Sysclean Pacakge , create a folder named Sysclean on Desktop, and put the downloaded file to that folder. Next download the pattern file for Windows OS (pattern file will have a name like lpt915.zip ) and extract the contents of the ZIP file to the same Sysclean folder.
Download CleanUp and install it. Do not run it now.
Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options.
Uncheck Hide protected operating system files.
Then, click to select the option Show hidden files and folders.
Click Apply and then click OK to exit.
Reboot in Safe Mode:-
Restart (or switch ON) the PC.
Then, keep tapping the F8 Key.
From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Go to Start > Run and type services.msc and press ENTER. Here, navigate to the service named Microsoft Path Finder Service (MSpath) and right-click on it. Then click "Properties". Here, in the "Status" dialog box, select "Stop". Then, under "Startup type" dialog box, select "Disabled". Click "Apply" and then "OK".
Run HijackThis and click Do only a System scan. Then put a check mark infront of below listed entries:-
F2 - REG:system.ini: UserInit=userinit.exe,xpjava.exe
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: Activater - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\Program Files\CommonName\Toolbar\CNBarIE.dll
O2 - BHO: (no name) - {999A06FF-10EF-4A29-8640-69E99882C26B} - (no file)
O3 - Toolbar: (no name) - {A3E3F04C-F98C-4295-95EF-41C57425B077} - (no file)
O4 - HKLM\..\RunServices: [internet service] wmsmgs.exe
O4 - HKLM\..\RunServices: [Micros0ft Updote] FmMPacK32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O20 - Winlogon Notify: pswave - C:\WINDOWS\
O20 - Winlogon Notify: utilcmd - C:\WINDOWS\
O23 - Service: Microsoft Path Finder Service (MSpath) - Unknown owner - C:\WINDOWS\mspath.exe (file missing)
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Exit from HijackThis. Delete these files, if found:-
C:\WINDOWS\System32\xpjava.exe
C:\WINDOWS\mspath.exe
Delete this folder:-
C:\Program Files\CommonName
Go to Start > Search. Here click "All files and folders" in the left pane. Next, click on "More advanced options". Here select the options "Search system folders", "Search hidden files and folders" and "Search subfolders". Next, type/copy the below mentioned filename and search for it, if you find it, right-click on it and click delete:-
wmsmgs.exe
FmMPacK32.exe
Run CleanUp! and click "Options.." button. Here move the "Quick Setup" slider to "Thorough Cleanup" position. Uncheck the option "Delete Favorites Palces/Bookmarks", if you have any bookmarks. Click "OK" to return to main window, and click "CleanUp!" to start cleaning. After it completes, click "Close" and click "No" to avoid logging off.
Next, double-click on the sysclean.com file, and after few seconds, the Sysclean window appears. Here make sure that "Automatically clean or delete infected files" option is selected. Then click "Scan". After the scan is complete it gives a log, save the log file.
After this, reboot the PC. Run HijackThis again to get a new log and post back the same along with the Sysclean log.