Okay, I'm back, so let's go to work. Print this out, cos you are going offline soon.
This is all the stuff we are gunning for:-
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
..this one pops up every time you start, right? Do you want it?
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
...this tries to update you every time you start up. If you like Real Player, fine, keep that, but you should get rid of this thing...
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\spywarebot\SpywareBot.exe -boot
- this is a dubious bit of software... I would remove it from programs via uninstall.... anyway it serves no purpose running all the time as it shows here to be booting from startup: a waste of resources.
O2 - BHO: (no name) - {3A9D5790-8C7D-4A58-A5C6-9645FF5D78E1} - C:\WINDOWS\system32\msac850.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O20 - AppInit_DLLs: c:\windows\system32\pmkjkhf.dll
O20 - Winlogon Notify: msac850 - C:\WINDOWS\SYSTEM32\msac850.dll
Time to get some free stuff....
First off I would like you to download CCleaner from http://www.majorgeeks.com/download4191.html and put it in a new folder.
Then download RootKitRevealer from http://www.sysinternals.com/Utilities/RootkitRevealer.html [the link is at the bottom of the page] and place in a folder next to CCleaner. Read that webpage.
Thirdly go get Ewido 4.0 [free], install it alongside your other regular applications in Program Files, because you should keep it for scanning once a week or so - put an icon on your desktop. McAfee is letting you down. I'm not sure it's wise to have more than one AV product installed and running, but I'd like you to go to AVG site and download AVG Free, install it, update and run it to see what it finds. Then it's up to you whether you keep it....
==== Get ewido and AVG free both via this link.. http://free.grisoft.com/doc/2/lng/us/tpl/v5 ====
Now, Ewido:- start it; the main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Click on update tab and then Update Now. When it finishes click on scanner tab and then Settings:- How to act- click on recommended action and set Quarantine. For reports, set to generate after every scan and untick only if threats found. Finally down on the tray right click the Ewido icon and untick Start with windows, an then Exit it. Don't scan yet
.
Ok, you're done with the net. Shut it down. Disconnect..... whatever...
Open a window and go to tools tab > folder options > view. Set to show hidden files and folders, and untick hide protected operating system files and folders, Apply and OK. We want our tools to see evrything, right?
Now rclick your recycle bin and run CCleaner. [or go to its folder and dclick ccleaner.exe] You will lose a lot of handy stuff like histories etc... but there is a job to do...
Close all open windows, shut all applications, and then open a Windows explorer and Run RootKit Revealer from its folder...[dclick the .exe file]. Do not touch anything, even mouse, until it completes its scan.
Now go into safe mode [Restart, F8 and select Safe Mode and Enter.... You'll get a dark desktop with icons etc...]
Start Ewido, do the full system scan. Click "Apply all actions" to place any infected files into Quarantine, and only then click on "Save Report" to view all completed scans; click on the scan you just performed and select "Save report."
Note: Close all open windows, programs, and DO NOT USE the computer while Ewido is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper Ewido's ability to clean properly and may result in reinfection.
And now, still in Safe Mode and with nothing else open, run Hijack This , check the eight items i listed above and Fix them. Or at the very least the bottom four!!
Qttask and Realsched....If you want to remove them and HijackThis does not complete the job, you may have to stop qttask.exe and realsched.exe in Task Manager as processes first, then delete realsched.exe in C:\Program Files\Common Files\Real\Update_OB. and qttask from C:\Program Files\QuickTime\qttask.exe.
Right. Restart into Windows as per normal and see what happens. Run Hijack This...., and set System Restore to ON for all drives. Make a restore point!!!!!!!!! Let me know if you're clean.
Finally, if all is ok, remove earlier restore points, cos they may be bugged!
Go back and hide those operating system files and folders if you wish. Prob safer to do so...
PS... that msg u got above about contacting Merijn after trying a fix with HT, ignore it.... sometimes it has trouble doing backups, but it still fixes things...