Hi,
Please download The Avenger by Swandog46 to your Desktop. Do not run it now!
Download CCleaner and install it.
Reboot in Safe Mode:-
Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O4 - HKLM\..\Run: [funk] funk.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Exit from HijackThis.
Run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally click "Run Cleaner" and click "OK" to continue cleaning.
Reboot to Normal Mode. Double click on Avenger.zip to open the file and extract avenger.exe to your Desktop.Copy the below quoted text (which is a script for Avenger) into your clipboard by highlighting it and pressing CTRL C keys:-
Files to delete:
c:\nj.exe
C:\winstall.exe
C:\WINDOWS\System32\funk.exeNow, run The Avenger program by double clicking its icon on your Desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the text copied to clipboard into this window by pressing Ctrl V keys.
Click Done.
Now click on the Green Light to begin execution of the script.
Answer "Yes" twice when prompted.
The Avenger will automatically do the following:-It will Restart your computer.
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the reboot, it creates a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
Perform an online virus scan at Kaspersky Online Scanner (Click the "Kaspersky Online Scanner" button). Save the log it gives after the scan.
Run HijackThis again, click Do a System scan and save log, and post the fresh log along with the Kaspersky log and Avenger log.