Yikes!!
You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on.
For a tutorial on how to use HijackThis please see the following link:
Using HijackThis to Remove Spyware, Browser Hijackers, and DialersThis is going to take a while, so grab a drink

You may want to print out these directions as the Internet will not be available. Please continue with the next step if you run into a problem with the current one. Just be sure to let us know what the problem was when you reply.
Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in WindowsPlease download About:Buster from here:
About:Buster Download. Once it is downloaded extract it to
c:\aboutbuster. We will use that program later in this process.
Reboot your computer into
Safe Mode and follow these steps:
Step 1:SKIP THIS STEP
Step 2:Press control-alt-delete to get into the task manager and end the follow processes if they exist:
C:\WINDOWS\NETGP32.EXE
Step 3:Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and press the fix button when ready:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\furiq.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {E2EFAFF5-340E-A0DE-D25A-7AF4C9F82536} - C:\WINDOWS\SDKKP32.DLL
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\BXXS5.DLL,DllRun
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [ClrSchLoader] \Progra~1\Lycos\IEagent\Loader.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe
O4 - HKLM\..\Run: [VVSN] C:\PROGRAM FILES\VVSN\VVSN.EXE
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\RunServices: [NETGP32.EXE] C:\WINDOWS\NETGP32.EXE
O4 - HKLM\..\RunServices: [NTQG32.EXE] C:\WINDOWS\NTQG32.EXE
O4 - HKLM\..\RunServices: [NETGQ32.EXE] C:\WINDOWS\SYSTEM\NETGQ32.EXE
O4 - HKLM\..\RunServices: [MSVF.EXE] C:\WINDOWS\SYSTEM\MSVF.EXE
O4 - HKLM\..\RunServices: [NTNK32.EXE] C:\WINDOWS\NTNK32.EXE
O4 - HKLM\..\RunServices: [CRFV32.EXE] C:\WINDOWS\SYSTEM\CRFV32.EXE
O4 - HKLM\..\RunServices: [IPQG32.EXE] C:\WINDOWS\SYSTEM\IPQG32.EXE
O4 - HKLM\..\RunServices: [D3MA.EXE] C:\WINDOWS\D3MA.EXE
O4 - HKLM\..\RunServices: [SYSRC.EXE] C:\WINDOWS\SYSRC.EXE
O4 - HKLM\..\RunServices: [D3TF.EXE] C:\WINDOWS\D3TF.EXE
O4 - HKLM\..\RunServices: [IERJ32.EXE] C:\WINDOWS\IERJ32.EXE
O4 - HKLM\..\RunServices: [WINVA.EXE] C:\WINDOWS\WINVA.EXE
O4 - HKLM\..\RunServices: [JAVABW.EXE] C:\WINDOWS\SYSTEM\JAVABW.EXE
O4 - HKLM\..\RunServices: [APPWG.EXE] C:\WINDOWS\APPWG.EXE
O4 - HKLM\..\RunServices: [NTMT32.EXE] C:\WINDOWS\SYSTEM\NTMT32.EXE
O4 - HKLM\..\RunServices: [D3QX32.EXE] C:\WINDOWS\D3QX32.EXE
O4 - HKLM\..\RunServices: [IEHE32.EXE] C:\WINDOWS\IEHE32.EXE
O4 - HKLM\..\RunServices: [APPDI.EXE] C:\WINDOWS\APPDI.EXE
O4 - HKLM\..\RunServices: [SYSCE.EXE] C:\WINDOWS\SYSTEM\SYSCE.EXE
O4 - HKLM\..\RunServices: [ADDMR32.EXE] C:\WINDOWS\SYSTEM\ADDMR32.EXE
O4 - HKLM\..\RunServices: [IEXV.EXE] C:\WINDOWS\SYSTEM\IEXV.EXE
O4 - HKLM\..\RunServices: [WINLP32.EXE] C:\WINDOWS\SYSTEM\WINLP32.EXE
O4 - HKLM\..\RunServices: [ATLYP32.EXE] C:\WINDOWS\ATLYP32.EXE
O4 - HKLM\..\RunServices: [WINEF32.EXE] C:\WINDOWS\WINEF32.EXE
O4 - HKLM\..\RunServices: [ATLUP32.EXE] C:\WINDOWS\ATLUP32.EXE
O4 - HKLM\..\RunServices: [IENS.EXE] C:\WINDOWS\SYSTEM\IENS.EXE
O4 - HKLM\..\RunServices: [CRBX.EXE] C:\WINDOWS\SYSTEM\CRBX.EXE
O4 - HKLM\..\RunServices: [SYSJX.EXE] C:\WINDOWS\SYSTEM\SYSJX.EXE
O4 - HKLM\..\RunServices: [SDKMS.EXE] C:\WINDOWS\SYSTEM\SDKMS.EXE
O4 - HKLM\..\RunServices: [APPWZ32.EXE] C:\WINDOWS\APPWZ32.EXE
O4 - HKLM\..\RunServices: [SDKQV.EXE] C:\WINDOWS\SDKQV.EXE
O4 - HKLM\..\RunServices: [ADDYD32.EXE] C:\WINDOWS\ADDYD32.EXE
O4 - HKLM\..\RunServices: [SYSTG32.EXE] C:\WINDOWS\SYSTEM\SYSTG32.EXE
O4 - HKLM\..\RunServices: [SYSUB32.EXE] C:\WINDOWS\SYSTEM\SYSUB32.EXE
O4 - HKLM\..\RunServices: [NTXY.EXE] C:\WINDOWS\SYSTEM\NTXY.EXE
O4 - HKLM\..\RunServices: [IPCU.EXE] C:\WINDOWS\IPCU.EXE
O4 - HKLM\..\RunServices: [NETAK.EXE] C:\WINDOWS\NETAK.EXE
O4 - HKLM\..\RunServices: [NETBR32.EXE] C:\WINDOWS\NETBR32.EXE
O4 - HKLM\..\RunServices: [APPSF32.EXE] C:\WINDOWS\SYSTEM\APPSF32.EXE
O4 - HKLM\..\RunServices: [SDKWO32.EXE] C:\WINDOWS\SDKWO32.EXE
O4 - HKLM\..\RunServices: [APIQQ.EXE] C:\WINDOWS\SYSTEM\APIQQ.EXE
O4 - HKLM\..\RunServices: [D3JG.EXE] C:\WINDOWS\SYSTEM\D3JG.EXE
O4 - HKLM\..\RunServices: [CRSW32.EXE] C:\WINDOWS\CRSW32.EXE
O4 - HKLM\..\RunServices: [D3BK32.EXE] C:\WINDOWS\D3BK32.EXE
O4 - HKLM\..\RunServices: [MSGJ32.EXE] C:\WINDOWS\MSGJ32.EXE
O4 - HKLM\..\RunServices: [MSND.EXE] C:\WINDOWS\SYSTEM\MSND.EXE
O4 - HKLM\..\RunServices: [MFCRD.EXE] C:\WINDOWS\MFCRD.EXE
O4 - HKLM\..\RunServices: [ADDXO32.EXE] C:\WINDOWS\ADDXO32.EXE
O4 - HKLM\..\RunServices: [SDKZJ.EXE] C:\WINDOWS\SYSTEM\SDKZJ.EXE
O4 - HKLM\..\RunServices: [D3DA.EXE] C:\WINDOWS\SYSTEM\D3DA.EXE
O4 - HKLM\..\RunServices: [SYSRF32.EXE] C:\WINDOWS\SYSRF32.EXE
O4 - HKLM\..\RunServices: [APPLM32.EXE] C:\WINDOWS\SYSTEM\APPLM32.EXE
O4 - HKLM\..\RunServices: [ADDOQ32.EXE] C:\WINDOWS\SYSTEM\ADDOQ32.EXE
O4 - HKLM\..\RunServices: [IEVC.EXE] C:\WINDOWS\SYSTEM\IEVC.EXE
O4 - HKLM\..\RunServices: [APIFY.EXE] C:\WINDOWS\SYSTEM\APIFY.EXE
O4 - HKLM\..\RunServices: [MSSH.EXE] C:\WINDOWS\MSSH.EXE
O4 - HKLM\..\RunServices: [SDKLQ.EXE] C:\WINDOWS\SYSTEM\SDKLQ.EXE
O4 - HKLM\..\RunServices: [JAVALQ32.EXE] C:\WINDOWS\JAVALQ32.EXE
O4 - HKLM\..\RunServices: [CRFH32.EXE] C:\WINDOWS\SYSTEM\CRFH32.EXE
O4 - HKLM\..\RunServices: [APPAH.EXE] C:\WINDOWS\APPAH.EXE
O4 - HKLM\..\RunServices: [ADDRE32.EXE] C:\WINDOWS\SYSTEM\ADDRE32.EXE
O4 - HKLM\..\RunServices: [IPEK32.EXE] C:\WINDOWS\SYSTEM\IPEK32.EXE
O4 - HKLM\..\RunServices: [SDKYX32.EXE] C:\WINDOWS\SDKYX32.EXE
O4 - HKLM\..\RunServices: [IESJ32.EXE] C:\WINDOWS\SYSTEM\IESJ32.EXE
O4 - HKLM\..\RunServices: [SYSUQ.EXE] C:\WINDOWS\SYSTEM\SYSUQ.EXE
O4 - HKLM\..\RunServices: [NETAH32.EXE] C:\WINDOWS\SYSTEM\NETAH32.EXE
O4 - HKLM\..\RunServices: [ADDFE32.EXE] C:\WINDOWS\SYSTEM\ADDFE32.EXE
O4 - HKLM\..\RunServices: [APIZW.EXE] C:\WINDOWS\SYSTEM\APIZW.EXE
O4 - HKLM\..\RunServices: [IPVO.EXE] C:\WINDOWS\SYSTEM\IPVO.EXE
O4 - HKLM\..\RunServices: [SYSQI.EXE] C:\WINDOWS\SYSQI.EXE
O4 - HKLM\..\RunServices: [D3CE.EXE] C:\WINDOWS\SYSTEM\D3CE.EXE
O4 - HKLM\..\RunServices: [ATLVE32.EXE] C:\WINDOWS\ATLVE32.EXE
O4 - HKLM\..\RunServices: [SYSOL.EXE] C:\WINDOWS\SYSOL.EXE
O4 - HKLM\..\RunServices: [CRBO32.EXE] C:\WINDOWS\SYSTEM\CRBO32.EXE
O4 - HKLM\..\RunServices: [ATLJU.EXE] C:\WINDOWS\ATLJU.EXE
O4 - HKLM\..\RunServices: [WINXZ32.EXE] C:\WINDOWS\WINXZ32.EXE
O4 - HKLM\..\RunServices: [D3GE.EXE] C:\WINDOWS\D3GE.EXE
O4 - HKLM\..\RunServices: [APPYB32.EXE] C:\WINDOWS\APPYB32.EXE
O4 - HKLM\..\RunServices: [IPZW32.EXE] C:\WINDOWS\SYSTEM\IPZW32.EXE
O4 - HKLM\..\RunServices: [JAVAAC32.EXE] C:\WINDOWS\SYSTEM\JAVAAC32.EXE
O4 - HKLM\..\RunServices: [APIBJ.EXE] C:\WINDOWS\SYSTEM\APIBJ.EXE
O4 - HKLM\..\RunServices: [IPUY32.EXE] C:\WINDOWS\SYSTEM\IPUY32.EXE
O4 - HKLM\..\RunServices: [NETLV32.EXE] C:\WINDOWS\SYSTEM\NETLV32.EXE
O4 - HKLM\..\RunServices: [IPOK.EXE] C:\WINDOWS\SYSTEM\IPOK.EXE
O4 - HKLM\..\RunServices: [NETXI32.EXE] C:\WINDOWS\NETXI32.EXE
O4 - HKLM\..\RunServices: [ADDCF32.EXE] C:\WINDOWS\SYSTEM\ADDCF32.EXE
O4 - HKLM\..\RunServices: [APPKN.EXE] C:\WINDOWS\SYSTEM\APPKN.EXE
O4 - HKLM\..\RunServices: [SDKJE.EXE] C:\WINDOWS\SDKJE.EXE
O4 - HKLM\..\RunServices: [WINLI32.EXE] C:\WINDOWS\SYSTEM\WINLI32.EXE
O4 - HKLM\..\RunServices: [D3YH.EXE] C:\WINDOWS\D3YH.EXE
O4 - HKLM\..\RunServices: [WINIA.EXE] C:\WINDOWS\WINIA.EXE
O4 - HKLM\..\RunServices: [MFCDH.EXE] C:\WINDOWS\MFCDH.EXE
O4 - HKLM\..\RunServices: [ATLUU.EXE] C:\WINDOWS\SYSTEM\ATLUU.EXE
O4 - HKLM\..\RunServices: [SDKOC.EXE] C:\WINDOWS\SYSTEM\SDKOC.EXE
O4 - HKLM\..\RunServices: [APPIG32.EXE] C:\WINDOWS\APPIG32.EXE
O4 - HKLM\..\RunServices: [MFCLT.EXE] C:\WINDOWS\MFCLT.EXE
O4 - HKLM\..\RunServices: [IEKI32.EXE] C:\WINDOWS\SYSTEM\IEKI32.EXE
O4 - HKLM\..\RunServices: [APPSO32.EXE] C:\WINDOWS\APPSO32.EXE
O4 - HKLM\..\RunServices: [SDKHS.EXE] C:\WINDOWS\SDKHS.EXE
O4 - HKLM\..\RunServices: [APIVI32.EXE] C:\WINDOWS\SYSTEM\APIVI32.EXE
O4 - HKLM\..\RunServices: [ATLHI32.EXE] C:\WINDOWS\ATLHI32.EXE
O4 - HKLM\..\RunServices: [MSPM.EXE] C:\WINDOWS\MSPM.EXE
O4 - HKLM\..\RunServices: [SDKCB32.EXE] C:\WINDOWS\SYSTEM\SDKCB32.EXE
O4 - HKLM\..\RunServices: [APIPB.EXE] C:\WINDOWS\APIPB.EXE
O4 - HKLM\..\RunServices: [WINWX.EXE] C:\WINDOWS\WINWX.EXE
O4 - HKLM\..\RunServices: [SDKDD.EXE] C:\WINDOWS\SDKDD.EXE
O4 - HKLM\..\RunServices: [MFCTK32.EXE] C:\WINDOWS\SYSTEM\MFCTK32.EXE
O4 - HKLM\..\RunServices: [WINEJ32.EXE] C:\WINDOWS\WINEJ32.EXE
O4 - HKLM\..\RunServices: [MFCOX.EXE] C:\WINDOWS\MFCOX.EXE
O4 - HKLM\..\RunServices: [NETFF.EXE] C:\WINDOWS\SYSTEM\NETFF.EXE
O4 - HKLM\..\RunServices: [ATLSZ32.EXE] C:\WINDOWS\ATLSZ32.EXE
O4 - HKLM\..\RunServices: [D3GT32.EXE] C:\WINDOWS\SYSTEM\D3GT32.EXE
O4 - HKLM\..\RunServices: [JAVAPW.EXE] C:\WINDOWS\SYSTEM\JAVAPW.EXE
O4 - HKLM\..\RunServices: [MSBD.EXE] C:\WINDOWS\SYSTEM\MSBD.EXE
O4 - HKLM\..\RunServices: [IPCR32.EXE] C:\WINDOWS\SYSTEM\IPCR32.EXE
O4 - HKLM\..\RunServices: [SYSSZ32.EXE] C:\WINDOWS\SYSTEM\SYSSZ32.EXE
O4 - HKLM\..\RunServices: [IEAC.EXE] C:\WINDOWS\IEAC.EXE
O4 - HKLM\..\RunServices: [APIAT.EXE] C:\WINDOWS\APIAT.EXE
O4 - HKLM\..\RunServices: [WINOV.EXE] C:\WINDOWS\SYSTEM\WINOV.EXE
O4 - HKLM\..\RunServices: [JAVANW.EXE] C:\WINDOWS\SYSTEM\JAVANW.EXE
O4 - HKLM\..\RunServices: [MSUC.EXE] C:\WINDOWS\SYSTEM\MSUC.EXE
O4 - HKLM\..\RunServices: [NTIL.EXE] C:\WINDOWS\SYSTEM\NTIL.EXE
O4 - HKLM\..\RunServices: [NTOK.EXE] C:\WINDOWS\SYSTEM\NTOK.EXE
O4 - HKLM\..\RunServices: [ADDOD.EXE] C:\WINDOWS\SYSTEM\ADDOD.EXE
O4 - HKLM\..\RunServices: [NTXO32.EXE] C:\WINDOWS\SYSTEM\NTXO32.EXE
O4 - HKLM\..\RunServices: [APILT32.EXE] C:\WINDOWS\SYSTEM\APILT32.EXE
O4 - HKLM\..\RunServices: [MFCDD32.EXE] C:\WINDOWS\SYSTEM\MFCDD32.EXE
O4 - HKLM\..\RunServices: [APPWC32.EXE] C:\WINDOWS\APPWC32.EXE
O4 - HKLM\..\RunServices: [MSBL32.EXE] C:\WINDOWS\SYSTEM\MSBL32.EXE
O4 - HKLM\..\RunServices: [APIFE.EXE] C:\WINDOWS\SYSTEM\APIFE.EXE
O4 - HKLM\..\RunServices: [JAVAKT.EXE] C:\WINDOWS\JAVAKT.EXE
O4 - HKLM\..\RunServices: [NETYB.EXE] C:\WINDOWS\NETYB.EXE
O4 - HKLM\..\RunServices: [IEVE32.EXE] C:\WINDOWS\IEVE32.EXE
O4 - HKLM\..\RunServices: [NTBK32.EXE] C:\WINDOWS\SYSTEM\NTBK32.EXE
O4 - HKLM\..\RunServices: [ADDZB32.EXE] C:\WINDOWS\ADDZB32.EXE
O4 - HKLM\..\RunServices: [IEJJ.EXE] C:\WINDOWS\IEJJ.EXE
O4 - HKLM\..\RunServices: [CRAL32.EXE] C:\WINDOWS\SYSTEM\CRAL32.EXE
O4 - HKLM\..\RunServices: [APPTB32.EXE] C:\WINDOWS\APPTB32.EXE
O4 - HKLM\..\RunServices: [NETIP32.EXE] C:\WINDOWS\NETIP32.EXE
O4 - HKLM\..\RunServices: [SYSXL.EXE] C:\WINDOWS\SYSXL.EXE
O4 - HKLM\..\RunServices: [APIJG.EXE] C:\WINDOWS\SYSTEM\APIJG.EXE
O4 - HKLM\..\RunServices: [D3QR.EXE] C:\WINDOWS\D3QR.EXE
O4 - HKLM\..\RunServices: [NETBF32.EXE] C:\WINDOWS\NETBF32.EXE
O4 - HKLM\..\RunServices: [IETQ32.EXE] C:\WINDOWS\SYSTEM\IETQ32.EXE
O4 - HKLM\..\RunServices: [MSBL.EXE] C:\WINDOWS\SYSTEM\MSBL.EXE
O4 - HKLM\..\RunServices: [MFCGO32.EXE] C:\WINDOWS\MFCGO32.EXE
O4 - HKLM\..\RunServices: [APPSS.EXE] C:\WINDOWS\SYSTEM\APPSS.EXE
O4 - HKLM\..\RunServices: [IENS32.EXE] C:\WINDOWS\SYSTEM\IENS32.EXE
O4 - HKLM\..\RunServices: [ADDCQ.EXE] C:\WINDOWS\ADDCQ.EXE
O4 - HKLM\..\RunServices: [MSZL.EXE] C:\WINDOWS\MSZL.EXE
O4 - HKLM\..\RunServices: [NETAS32.EXE] C:\WINDOWS\SYSTEM\NETAS32.EXE
O4 - HKLM\..\RunServices: [NTID32.EXE] C:\WINDOWS\NTID32.EXE
O4 - HKLM\..\RunServices: [SDKQU.EXE] C:\WINDOWS\SDKQU.EXE
O4 - HKLM\..\RunServices: [APPCP.EXE] C:\WINDOWS\SYSTEM\APPCP.EXE
O4 - HKLM\..\RunServices: [JAVALT.EXE] C:\WINDOWS\JAVALT.EXE
O4 - HKLM\..\RunServices: [JAVAGC32.EXE] C:\WINDOWS\SYSTEM\JAVAGC32.EXE
O4 - HKLM\..\RunServices: [SYSQD.EXE] C:\WINDOWS\SYSQD.EXE
O4 - HKLM\..\RunServices: [APPGN.EXE] C:\WINDOWS\APPGN.EXE
O4 - HKLM\..\RunServices: [D3WH32.EXE] C:\WINDOWS\D3WH32.EXE
O4 - HKLM\..\RunServices: [ADDQY.EXE] C:\WINDOWS\SYSTEM\ADDQY.EXE
O4 - HKLM\..\RunServices: [JAVAMT32.EXE] C:\WINDOWS\JAVAMT32.EXE
O4 - HKLM\..\RunServices: [ADDVC32.EXE] C:\WINDOWS\SYSTEM\ADDVC32.EXE
O4 - HKLM\..\RunServices: [IEWN32.EXE] C:\WINDOWS\SYSTEM\IEWN32.EXE
O4 - HKLM\..\RunServices: [D3MQ32.EXE] C:\WINDOWS\D3MQ32.EXE
O4 - HKLM\..\RunServices: [MSWY32.EXE] C:\WINDOWS\MSWY32.EXE
O4 - HKLM\..\RunServices: [ADDJQ.EXE] C:\WINDOWS\SYSTEM\ADDJQ.EXE
O4 - HKLM\..\RunServices: [NETDQ32.EXE] C:\WINDOWS\NETDQ32.EXE
O4 - HKLM\..\RunServices: [SDKJQ32.EXE] C:\WINDOWS\SDKJQ32.EXE
O4 - HKLM\..\RunServices: [IEQL32.EXE] C:\WINDOWS\IEQL32.EXE
O4 - HKLM\..\RunServices: [IEDF.EXE] C:\WINDOWS\SYSTEM\IEDF.EXE
O4 - HKLM\..\RunServices: [MSMB32.EXE] C:\WINDOWS\SYSTEM\MSMB32.EXE
O4 - HKLM\..\RunServices: [MSHU.EXE] C:\WINDOWS\MSHU.EXE
O4 - HKLM\..\RunServices: [CRPP32.EXE] C:\WINDOWS\CRPP32.EXE
O4 - HKLM\..\RunServices: [CRNG32.EXE] C:\WINDOWS\SYSTEM\CRNG32.EXE
O4 - HKLM\..\RunServices: [SDKOP.EXE] C:\WINDOWS\SDKOP.EXE
O4 - HKLM\..\RunServices: [MSNT32.EXE] C:\WINDOWS\MSNT32.EXE
O4 - HKLM\..\RunServices: [MSTC32.EXE] C:\WINDOWS\SYSTEM\MSTC32.EXE
O4 - HKLM\..\RunServices: [SYSPU32.EXE] C:\WINDOWS\SYSPU32.EXE
O4 - HKLM\..\RunServices: [NTKO32.EXE] C:\WINDOWS\SYSTEM\NTKO32.EXE
O4 - HKLM\..\RunServices: [APIIO32.EXE] C:\WINDOWS\SYSTEM\APIIO32.EXE
O4 - HKLM\..\RunServices: [APIZO32.EXE] C:\WINDOWS\APIZO32.EXE
O4 - HKLM\..\RunServices: [NETRD.EXE] C:\WINDOWS\SYSTEM\NETRD.EXE
O4 - HKLM\..\RunServices: [SDKXG.EXE] C:\WINDOWS\SYSTEM\SDKXG.EXE
O4 - HKLM\..\RunServices: [IETP.EXE] C:\WINDOWS\IETP.EXE
O4 - HKLM\..\RunServices: [WINFS32.EXE] C:\WINDOWS\WINFS32.EXE
O4 - HKLM\..\RunServices: [ADDUF32.EXE] C:\WINDOWS\ADDUF32.EXE
O4 - HKLM\..\RunServices: [JAVAAZ.EXE] C:\WINDOWS\JAVAAZ.EXE
O4 - HKLM\..\RunServices: [APIFA32.EXE] C:\WINDOWS\SYSTEM\APIFA32.EXE
O4 - HKLM\..\RunServices: [JAVAEJ32.EXE] C:\WINDOWS\SYSTEM\JAVAEJ32.EXE
O4 - HKLM\..\RunServices: [APIBZ.EXE] C:\WINDOWS\SYSTEM\APIBZ.EXE
O4 - HKLM\..\RunServices: [SYSES32.EXE] C:\WINDOWS\SYSTEM\SYSES32.EXE
O4 - HKLM\..\RunServices: [NTYV.EXE] C:\WINDOWS\SYSTEM\NTYV.EXE
O4 - HKLM\..\RunServices: [CRVB.EXE] C:\WINDOWS\CRVB.EXE
O4 - HKLM\..\RunServices: [MFCQI.EXE] C:\WINDOWS\SYSTEM\MFCQI.EXE
O4 - HKLM\..\RunServices: [MFCMN.EXE] C:\WINDOWS\MFCMN.EXE
O4 - HKLM\..\RunServices: [MFCEH.EXE] C:\WINDOWS\SYSTEM\MFCEH.EXE
O4 - HKLM\..\RunServices: [APPHQ32.EXE] C:\WINDOWS\APPHQ32.EXE
O4 - HKLM\..\RunServices: [JAVAJO.EXE] C:\WINDOWS\SYSTEM\JAVAJO.EXE
O4 - HKLM\..\RunServices: [NTTH.EXE] C:\WINDOWS\SYSTEM\NTTH.EXE
O4 - HKLM\..\RunServices: [CRDC32.EXE] C:\WINDOWS\CRDC32.EXE
O4 - HKLM\..\RunServices: [MSWA32.EXE] C:\WINDOWS\SYSTEM\MSWA32.EXE
O4 - HKLM\..\RunServices: [MSNE32.EXE] C:\WINDOWS\MSNE32.EXE
O4 - HKLM\..\RunServices: [IEWO32.EXE] C:\WINDOWS\IEWO32.EXE
O4 - HKLM\..\RunServices: [NETOX.EXE] C:\WINDOWS\NETOX.EXE
O4 - HKLM\..\RunServices: [APPEU32.EXE] C:\WINDOWS\APPEU32.EXE
O4 - HKLM\..\RunServices: [CRRQ32.EXE] C:\WINDOWS\SYSTEM\CRRQ32.EXE
O4 - HKLM\..\RunServices: [ADDZG32.EXE] C:\WINDOWS\ADDZG32.EXE
O4 - HKLM\..\RunServices: [MFCMN32.EXE] C:\WINDOWS\MFCMN32.EXE
O4 - HKLM\..\RunServices: [WINBJ32.EXE] C:\WINDOWS\SYSTEM\WINBJ32.EXE
O4 - HKLM\..\RunServices: [APPVM.EXE] C:\WINDOWS\SYSTEM\APPVM.EXE
O4 - HKLM\..\RunServices: [NETRU.EXE] C:\WINDOWS\SYSTEM\NETRU.EXE
O4 - HKLM\..\RunServices: [ADDGI32.EXE] C:\WINDOWS\ADDGI32.EXE
O4 - HKLM\..\RunServices: [JAVASZ32.EXE] C:\WINDOWS\JAVASZ32.EXE
O4 - HKCU\..\Run: [Iwm] C:\WINDOWS\SYSTEM\mibbdqr.exe
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
Step 6:This is the step where we will use About:Buster that you had downloaded previously.
Navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the
OK button, then the
Start button, then the
OK button, and then finally the
Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so.
When it completed move on to step 5.
Step 5:Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
Save this file on the desktop
QUOTE
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]
Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
Step 6:I now need you to delete the following files. Alot of these are probably gone now, but search for them if you can. I couldnt format the the O4 entries, so you want to look for the files after the ]
C:\WINDOWS\system\furiq.dll
C:\WINDOWS\SDKKP32.DLL
C:\WINDOWS\BXXS5.DLL
C:\Program Files\DownloadWare\dw.exe
c:\PrograM FILES\Lycos\
C:\Program Files\Common files\updater\
C:\Program Files\Web_Rebates\
C:\PROGRAM FILES\VVSN\
C:\WINDOWS\SYSTEM\mibbdqr.exe
O4 - HKLM\..\RunServices: [NETGP32.EXE] C:\WINDOWS\NETGP32.EXE
O4 - HKLM\..\RunServices: [NTQG32.EXE] C:\WINDOWS\NTQG32.EXE
O4 - HKLM\..\RunServices: [NETGQ32.EXE] C:\WINDOWS\SYSTEM\NETGQ32.EXE
O4 - HKLM\..\RunServices: [MSVF.EXE] C:\WINDOWS\SYSTEM\MSVF.EXE
O4 - HKLM\..\RunServices: [NTNK32.EXE] C:\WINDOWS\NTNK32.EXE
O4 - HKLM\..\RunServices: [CRFV32.EXE] C:\WINDOWS\SYSTEM\CRFV32.EXE
O4 - HKLM\..\RunServices: [IPQG32.EXE] C:\WINDOWS\SYSTEM\IPQG32.EXE
O4 - HKLM\..\RunServices: [D3MA.EXE] C:\WINDOWS\D3MA.EXE
O4 - HKLM\..\RunServices: [SYSRC.EXE] C:\WINDOWS\SYSRC.EXE
O4 - HKLM\..\RunServices: [D3TF.EXE] C:\WINDOWS\D3TF.EXE
O4 - HKLM\..\RunServices: [IERJ32.EXE] C:\WINDOWS\IERJ32.EXE
O4 - HKLM\..\RunServices: [WINVA.EXE] C:\WINDOWS\WINVA.EXE
O4 - HKLM\..\RunServices: [JAVABW.EXE] C:\WINDOWS\SYSTEM\JAVABW.EXE
O4 - HKLM\..\RunServices: [APPWG.EXE] C:\WINDOWS\APPWG.EXE
O4 - HKLM\..\RunServices: [NTMT32.EXE] C:\WINDOWS\SYSTEM\NTMT32.EXE
O4 - HKLM\..\RunServices: [D3QX32.EXE] C:\WINDOWS\D3QX32.EXE
O4 - HKLM\..\RunServices: [IEHE32.EXE] C:\WINDOWS\IEHE32.EXE
O4 - HKLM\..\RunServices: [APPDI.EXE] C:\WINDOWS\APPDI.EXE
O4 - HKLM\..\RunServices: [SYSCE.EXE] C:\WINDOWS\SYSTEM\SYSCE.EXE
O4 - HKLM\..\RunServices: [ADDMR32.EXE] C:\WINDOWS\SYSTEM\ADDMR32.EXE
O4 - HKLM\..\RunServices: [IEXV.EXE] C:\WINDOWS\SYSTEM\IEXV.EXE
O4 - HKLM\..\RunServices: [WINLP32.EXE] C:\WINDOWS\SYSTEM\WINLP32.EXE
O4 - HKLM\..\RunServices: [ATLYP32.EXE] C:\WINDOWS\ATLYP32.EXE
O4 - HKLM\..\RunServices: [WINEF32.EXE] C:\WINDOWS\WINEF32.EXE
O4 - HKLM\..\RunServices: [ATLUP32.EXE] C:\WINDOWS\ATLUP32.EXE
O4 - HKLM\..\RunServices: [IENS.EXE] C:\WINDOWS\SYSTEM\IENS.EXE
O4 - HKLM\..\RunServices: [CRBX.EXE] C:\WINDOWS\SYSTEM\CRBX.EXE
O4 - HKLM\..\RunServices: [SYSJX.EXE] C:\WINDOWS\SYSTEM\SYSJX.EXE
O4 - HKLM\..\RunServices: [SDKMS.EXE] C:\WINDOWS\SYSTEM\SDKMS.EXE
O4 - HKLM\..\RunServices: [APPWZ32.EXE] C:\WINDOWS\APPWZ32.EXE
O4 - HKLM\..\RunServices: [SDKQV.EXE] C:\WINDOWS\SDKQV.EXE
O4 - HKLM\..\RunServices: [ADDYD32.EXE] C:\WINDOWS\ADDYD32.EXE
O4 - HKLM\..\RunServices: [SYSTG32.EXE] C:\WINDOWS\SYSTEM\SYSTG32.EXE
O4 - HKLM\..\RunServices: [SYSUB32.EXE] C:\WINDOWS\SYSTEM\SYSUB32.EXE
O4 - HKLM\..\RunServices: [NTXY.EXE] C:\WINDOWS\SYSTEM\NTXY.EXE
O4 - HKLM\..\RunServices: [IPCU.EXE] C:\WINDOWS\IPCU.EXE
O4 - HKLM\..\RunServices: [NETAK.EXE] C:\WINDOWS\NETAK.EXE
O4 - HKLM\..\RunServices: [NETBR32.EXE] C:\WINDOWS\NETBR32.EXE
O4 - HKLM\..\RunServices: [APPSF32.EXE] C:\WINDOWS\SYSTEM\APPSF32.EXE
O4 - HKLM\..\RunServices: [SDKWO32.EXE] C:\WINDOWS\SDKWO32.EXE
O4 - HKLM\..\RunServices: [APIQQ.EXE] C:\WINDOWS\SYSTEM\APIQQ.EXE
O4 - HKLM\..\RunServices: [D3JG.EXE] C:\WINDOWS\SYSTEM\D3JG.EXE
O4 - HKLM\..\RunServices: [CRSW32.EXE] C:\WINDOWS\CRSW32.EXE
O4 - HKLM\..\RunServices: [D3BK32.EXE] C:\WINDOWS\D3BK32.EXE
O4 - HKLM\..\RunServices: [MSGJ32.EXE] C:\WINDOWS\MSGJ32.EXE
O4 - HKLM\..\RunServices: [MSND.EXE] C:\WINDOWS\SYSTEM\MSND.EXE
O4 - HKLM\..\RunServices: [MFCRD.EXE] C:\WINDOWS\MFCRD.EXE
O4 - HKLM\..\RunServices: [ADDXO32.EXE] C:\WINDOWS\ADDXO32.EXE
O4 - HKLM\..\RunServices: [SDKZJ.EXE] C:\WINDOWS\SYSTEM\SDKZJ.EXE
O4 - HKLM\..\RunServices: [D3DA.EXE] C:\WINDOWS\SYSTEM\D3DA.EXE
O4 - HKLM\..\RunServices: [SYSRF32.EXE] C:\WINDOWS\SYSRF32.EXE
O4 - HKLM\..\RunServices: [APPLM32.EXE] C:\WINDOWS\SYSTEM\APPLM32.EXE
O4 - HKLM\..\RunServices: [ADDOQ32.EXE] C:\WINDOWS\SYSTEM\ADDOQ32.EXE
O4 - HKLM\..\RunServices: [IEVC.EXE] C:\WINDOWS\SYSTEM\IEVC.EXE
O4 - HKLM\..\RunServices: [APIFY.EXE] C:\WINDOWS\SYSTEM\APIFY.EXE
O4 - HKLM\..\RunServices: [MSSH.EXE] C:\WINDOWS\MSSH.EXE
O4 - HKLM\..\RunServices: [SDKLQ.EXE] C:\WINDOWS\SYSTEM\SDKLQ.EXE
O4 - HKLM\..\RunServices: [JAVALQ32.EXE] C:\WINDOWS\JAVALQ32.EXE
O4 - HKLM\..\RunServices: [CRFH32.EXE] C:\WINDOWS\SYSTEM\CRFH32.EXE
O4 - HKLM\..\RunServices: [APPAH.EXE] C:\WINDOWS\APPAH.EXE
O4 - HKLM\..\RunServices: [ADDRE32.EXE] C:\WINDOWS\SYSTEM\ADDRE32.EXE
O4 - HKLM\..\RunServices: [IPEK32.EXE] C:\WINDOWS\SYSTEM\IPEK32.EXE
O4 - HKLM\..\RunServices: [SDKYX32.EXE] C:\WINDOWS\SDKYX32.EXE
O4 - HKLM\..\RunServices: [IESJ32.EXE] C:\WINDOWS\SYSTEM\IESJ32.EXE
O4 - HKLM\..\RunServices: [SYSUQ.EXE] C:\WINDOWS\SYSTEM\SYSUQ.EXE
O4 - HKLM\..\RunServices: [NETAH32.EXE] C:\WINDOWS\SYSTEM\NETAH32.EXE
O4 - HKLM\..\RunServices: [ADDFE32.EXE] C:\WINDOWS\SYSTEM\ADDFE32.EXE
O4 - HKLM\..\RunServices: [APIZW.EXE] C:\WINDOWS\SYSTEM\APIZW.EXE
O4 - HKLM\..\RunServices: [IPVO.EXE] C:\WINDOWS\SYSTEM\IPVO.EXE
O4 - HKLM\..\RunServices: [SYSQI.EXE] C:\WINDOWS\SYSQI.EXE
O4 - HKLM\..\RunServices: [D3CE.EXE] C:\WINDOWS\SYSTEM\D3CE.EXE
O4 - HKLM\..\RunServices: [ATLVE32.EXE] C:\WINDOWS\ATLVE32.EXE
O4 - HKLM\..\RunServices: [SYSOL.EXE] C:\WINDOWS\SYSOL.EXE
O4 - HKLM\..\RunServices: [CRBO32.EXE] C:\WINDOWS\SYSTEM\CRBO32.EXE
O4 - HKLM\..\RunServices: [ATLJU.EXE] C:\WINDOWS\ATLJU.EXE
O4 - HKLM\..\RunServices: [WINXZ32.EXE] C:\WINDOWS\WINXZ32.EXE
O4 - HKLM\..\RunServices: [D3GE.EXE] C:\WINDOWS\D3GE.EXE
O4 - HKLM\..\RunServices: [APPYB32.EXE] C:\WINDOWS\APPYB32.EXE
O4 - HKLM\..\RunServices: [IPZW32.EXE] C:\WINDOWS\SYSTEM\IPZW32.EXE
O4 - HKLM\..\RunServices: [JAVAAC32.EXE] C:\WINDOWS\SYSTEM\JAVAAC32.EXE
O4 - HKLM\..\RunServices: [APIBJ.EXE] C:\WINDOWS\SYSTEM\APIBJ.EXE
O4 - HKLM\..\RunServices: [IPUY32.EXE] C:\WINDOWS\SYSTEM\IPUY32.EXE
O4 - HKLM\..\RunServices: [NETLV32.EXE] C:\WINDOWS\SYSTEM\NETLV32.EXE
O4 - HKLM\..\RunServices: [IPOK.EXE] C:\WINDOWS\SYSTEM\IPOK.EXE
O4 - HKLM\..\RunServices: [NETXI32.EXE] C:\WINDOWS\NETXI32.EXE
O4 - HKLM\..\RunServices: [ADDCF32.EXE] C:\WINDOWS\SYSTEM\ADDCF32.EXE
O4 - HKLM\..\RunServices: [APPKN.EXE] C:\WINDOWS\SYSTEM\APPKN.EXE
O4 - HKLM\..\RunServices: [SDKJE.EXE] C:\WINDOWS\SDKJE.EXE
O4 - HKLM\..\RunServices: [WINLI32.EXE] C:\WINDOWS\SYSTEM\WINLI32.EXE
O4 - HKLM\..\RunServices: [D3YH.EXE] C:\WINDOWS\D3YH.EXE
O4 - HKLM\..\RunServices: [WINIA.EXE] C:\WINDOWS\WINIA.EXE
O4 - HKLM\..\RunServices: [MFCDH.EXE] C:\WINDOWS\MFCDH.EXE
O4 - HKLM\..\RunServices: [ATLUU.EXE] C:\WINDOWS\SYSTEM\ATLUU.EXE
O4 - HKLM\..\RunServices: [SDKOC.EXE] C:\WINDOWS\SYSTEM\SDKOC.EXE
O4 - HKLM\..\RunServices: [APPIG32.EXE] C:\WINDOWS\APPIG32.EXE
O4 - HKLM\..\RunServices: [MFCLT.EXE] C:\WINDOWS\MFCLT.EXE
O4 - HKLM\..\RunServices: [IEKI32.EXE] C:\WINDOWS\SYSTEM\IEKI32.EXE
O4 - HKLM\..\RunServices: [APPSO32.EXE] C:\WINDOWS\APPSO32.EXE
O4 - HKLM\..\RunServices: [SDKHS.EXE] C:\WINDOWS\SDKHS.EXE
O4 - HKLM\..\RunServices: [APIVI32.EXE] C:\WINDOWS\SYSTEM\APIVI32.EXE
O4 - HKLM\..\RunServices: [ATLHI32.EXE] C:\WINDOWS\ATLHI32.EXE
O4 - HKLM\..\RunServices: [MSPM.EXE] C:\WINDOWS\MSPM.EXE
O4 - HKLM\..\RunServices: [SDKCB32.EXE] C:\WINDOWS\SYSTEM\SDKCB32.EXE
O4 - HKLM\..\RunServices: [APIPB.EXE] C:\WINDOWS\APIPB.EXE
O4 - HKLM\..\RunServices: [WINWX.EXE] C:\WINDOWS\WINWX.EXE
O4 - HKLM\..\RunServices: [SDKDD.EXE] C:\WINDOWS\SDKDD.EXE
O4 - HKLM\..\RunServices: [MFCTK32.EXE] C:\WINDOWS\SYSTEM\MFCTK32.EXE
O4 - HKLM\..\RunServices: [WINEJ32.EXE] C:\WINDOWS\WINEJ32.EXE
O4 - HKLM\..\RunServices: [MFCOX.EXE] C:\WINDOWS\MFCOX.EXE
O4 - HKLM\..\RunServices: [NETFF.EXE] C:\WINDOWS\SYSTEM\NETFF.EXE
O4 - HKLM\..\RunServices: [ATLSZ32.EXE] C:\WINDOWS\ATLSZ32.EXE
O4 - HKLM\..\RunServices: [D3GT32.EXE] C:\WINDOWS\SYSTEM\D3GT32.EXE
O4 - HKLM\..\RunServices: [JAVAPW.EXE] C:\WINDOWS\SYSTEM\JAVAPW.EXE
O4 - HKLM\..\RunServices: [MSBD.EXE] C:\WINDOWS\SYSTEM\MSBD.EXE
O4 - HKLM\..\RunServices: [IPCR32.EXE] C:\WINDOWS\SYSTEM\IPCR32.EXE
O4 - HKLM\..\RunServices: [SYSSZ32.EXE] C:\WINDOWS\SYSTEM\SYSSZ32.EXE
O4 - HKLM\..\RunServices: [IEAC.EXE] C:\WINDOWS\IEAC.EXE
O4 - HKLM\..\RunServices: [APIAT.EXE] C:\WINDOWS\APIAT.EXE
O4 - HKLM\..\RunServices: [WINOV.EXE] C:\WINDOWS\SYSTEM\WINOV.EXE
O4 - HKLM\..\RunServices: [JAVANW.EXE] C:\WINDOWS\SYSTEM\JAVANW.EXE
O4 - HKLM\..\RunServices: [MSUC.EXE] C:\WINDOWS\SYSTEM\MSUC.EXE
O4 - HKLM\..\RunServices: [NTIL.EXE] C:\WINDOWS\SYSTEM\NTIL.EXE
O4 - HKLM\..\RunServices: [NTOK.EXE] C:\WINDOWS\SYSTEM\NTOK.EXE
O4 - HKLM\..\RunServices: [ADDOD.EXE] C:\WINDOWS\SYSTEM\ADDOD.EXE
O4 - HKLM\..\RunServices: [NTXO32.EXE] C:\WINDOWS\SYSTEM\NTXO32.EXE
O4 - HKLM\..\RunServices: [APILT32.EXE] C:\WINDOWS\SYSTEM\APILT32.EXE
O4 - HKLM\..\RunServices: [MFCDD32.EXE] C:\WINDOWS\SYSTEM\MFCDD32.EXE
O4 - HKLM\..\RunServices: [APPWC32.EXE] C:\WINDOWS\APPWC32.EXE
O4 - HKLM\..\RunServices: [MSBL32.EXE] C:\WINDOWS\SYSTEM\MSBL32.EXE
O4 - HKLM\..\RunServices: [APIFE.EXE] C:\WINDOWS\SYSTEM\APIFE.EXE
O4 - HKLM\..\RunServices: [JAVAKT.EXE] C:\WINDOWS\JAVAKT.EXE
O4 - HKLM\..\RunServices: [NETYB.EXE] C:\WINDOWS\NETYB.EXE
O4 - HKLM\..\RunServices: [IEVE32.EXE] C:\WINDOWS\IEVE32.EXE
O4 - HKLM\..\RunServices: [NTBK32.EXE] C:\WINDOWS\SYSTEM\NTBK32.EXE
O4 - HKLM\..\RunServices: [ADDZB32.EXE] C:\WINDOWS\ADDZB32.EXE
O4 - HKLM\..\RunServices: [IEJJ.EXE] C:\WINDOWS\IEJJ.EXE
O4 - HKLM\..\RunServices: [CRAL32.EXE] C:\WINDOWS\SYSTEM\CRAL32.EXE
O4 - HKLM\..\RunServices: [APPTB32.EXE] C:\WINDOWS\APPTB32.EXE
O4 - HKLM\..\RunServices: [NETIP32.EXE] C:\WINDOWS\NETIP32.EXE
O4 - HKLM\..\RunServices: [SYSXL.EXE] C:\WINDOWS\SYSXL.EXE
O4 - HKLM\..\RunServices: [APIJG.EXE] C:\WINDOWS\SYSTEM\APIJG.EXE
O4 - HKLM\..\RunServices: [D3QR.EXE] C:\WINDOWS\D3QR.EXE
O4 - HKLM\..\RunServices: [NETBF32.EXE] C:\WINDOWS\NETBF32.EXE
O4 - HKLM\..\RunServices: [IETQ32.EXE] C:\WINDOWS\SYSTEM\IETQ32.EXE
O4 - HKLM\..\RunServices: [MSBL.EXE] C:\WINDOWS\SYSTEM\MSBL.EXE
O4 - HKLM\..\RunServices: [MFCGO32.EXE] C:\WINDOWS\MFCGO32.EXE
O4 - HKLM\..\RunServices: [APPSS.EXE] C:\WINDOWS\SYSTEM\APPSS.EXE
O4 - HKLM\..\RunServices: [IENS32.EXE] C:\WINDOWS\SYSTEM\IENS32.EXE
O4 - HKLM\..\RunServices: [ADDCQ.EXE] C:\WINDOWS\ADDCQ.EXE
O4 - HKLM\..\RunServices: [MSZL.EXE] C:\WINDOWS\MSZL.EXE
O4 - HKLM\..\RunServices: [NETAS32.EXE] C:\WINDOWS\SYSTEM\NETAS32.EXE
O4 - HKLM\..\RunServices: [NTID32.EXE] C:\WINDOWS\NTID32.EXE
O4 - HKLM\..\RunServices: [SDKQU.EXE] C:\WINDOWS\SDKQU.EXE
O4 - HKLM\..\RunServices: [APPCP.EXE] C:\WINDOWS\SYSTEM\APPCP.EXE
O4 - HKLM\..\RunServices: [JAVALT.EXE] C:\WINDOWS\JAVALT.EXE
O4 - HKLM\..\RunServices: [JAVAGC32.EXE] C:\WINDOWS\SYSTEM\JAVAGC32.EXE
O4 - HKLM\..\RunServices: [SYSQD.EXE] C:\WINDOWS\SYSQD.EXE
O4 - HKLM\..\RunServices: [APPGN.EXE] C:\WINDOWS\APPGN.EXE
O4 - HKLM\..\RunServices: [D3WH32.EXE] C:\WINDOWS\D3WH32.EXE
O4 - HKLM\..\RunServices: [ADDQY.EXE] C:\WINDOWS\SYSTEM\ADDQY.EXE
O4 - HKLM\..\RunServices: [JAVAMT32.EXE] C:\WINDOWS\JAVAMT32.EXE
O4 - HKLM\..\RunServices: [ADDVC32.EXE] C:\WINDOWS\SYSTEM\ADDVC32.EXE
O4 - HKLM\..\RunServices: [IEWN32.EXE] C:\WINDOWS\SYSTEM\IEWN32.EXE
O4 - HKLM\..\RunServices: [D3MQ32.EXE] C:\WINDOWS\D3MQ32.EXE
O4 - HKLM\..\RunServices: [MSWY32.EXE] C:\WINDOWS\MSWY32.EXE
O4 - HKLM\..\RunServices: [ADDJQ.EXE] C:\WINDOWS\SYSTEM\ADDJQ.EXE
O4 - HKLM\..\RunServices: [NETDQ32.EXE] C:\WINDOWS\NETDQ32.EXE
O4 - HKLM\..\RunServices: [SDKJQ32.EXE] C:\WINDOWS\SDKJQ32.EXE
O4 - HKLM\..\RunServices: [IEQL32.EXE] C:\WINDOWS\IEQL32.EXE
O4 - HKLM\..\RunServices: [IEDF.EXE] C:\WINDOWS\SYSTEM\IEDF.EXE
O4 - HKLM\..\RunServices: [MSMB32.EXE] C:\WINDOWS\SYSTEM\MSMB32.EXE
O4 - HKLM\..\RunServices: [MSHU.EXE] C:\WINDOWS\MSHU.EXE
O4 - HKLM\..\RunServices: [CRPP32.EXE] C:\WINDOWS\CRPP32.EXE
O4 - HKLM\..\RunServices: [CRNG32.EXE] C:\WINDOWS\SYSTEM\CRNG32.EXE
O4 - HKLM\..\RunServices: [SDKOP.EXE] C:\WINDOWS\SDKOP.EXE
O4 - HKLM\..\RunServices: [MSNT32.EXE] C:\WINDOWS\MSNT32.EXE
O4 - HKLM\..\RunServices: [MSTC32.EXE] C:\WINDOWS\SYSTEM\MSTC32.EXE
O4 - HKLM\..\RunServices: [SYSPU32.EXE] C:\WINDOWS\SYSPU32.EXE
O4 - HKLM\..\RunServices: [NTKO32.EXE] C:\WINDOWS\SYSTEM\NTKO32.EXE
O4 - HKLM\..\RunServices: [APIIO32.EXE] C:\WINDOWS\SYSTEM\APIIO32.EXE
O4 - HKLM\..\RunServices: [APIZO32.EXE] C:\WINDOWS\APIZO32.EXE
O4 - HKLM\..\RunServices: [NETRD.EXE] C:\WINDOWS\SYSTEM\NETRD.EXE
O4 - HKLM\..\RunServices: [SDKXG.EXE] C:\WINDOWS\SYSTEM\SDKXG.EXE
O4 - HKLM\..\RunServices: [IETP.EXE] C:\WINDOWS\IETP.EXE
O4 - HKLM\..\RunServices: [WINFS32.EXE] C:\WINDOWS\WINFS32.EXE
O4 - HKLM\..\RunServices: [ADDUF32.EXE] C:\WINDOWS\ADDUF32.EXE
O4 - HKLM\..\RunServices: [JAVAAZ.EXE] C:\WINDOWS\JAVAAZ.EXE
O4 - HKLM\..\RunServices: [APIFA32.EXE] C:\WINDOWS\SYSTEM\APIFA32.EXE
O4 - HKLM\..\RunServices: [JAVAEJ32.EXE] C:\WINDOWS\SYSTEM\JAVAEJ32.EXE
O4 - HKLM\..\RunServices: [APIBZ.EXE] C:\WINDOWS\SYSTEM\APIBZ.EXE
O4 - HKLM\..\RunServices: [SYSES32.EXE] C:\WINDOWS\SYSTEM\SYSES32.EXE
O4 - HKLM\..\RunServices: [NTYV.EXE] C:\WINDOWS\SYSTEM\NTYV.EXE
O4 - HKLM\..\RunServices: [CRVB.EXE] C:\WINDOWS\CRVB.EXE
O4 - HKLM\..\RunServices: [MFCQI.EXE] C:\WINDOWS\SYSTEM\MFCQI.EXE
O4 - HKLM\..\RunServices: [MFCMN.EXE] C:\WINDOWS\MFCMN.EXE
O4 - HKLM\..\RunServices: [MFCEH.EXE] C:\WINDOWS\SYSTEM\MFCEH.EXE
O4 - HKLM\..\RunServices: [APPHQ32.EXE] C:\WINDOWS\APPHQ32.EXE
O4 - HKLM\..\RunServices: [JAVAJO.EXE] C:\WINDOWS\SYSTEM\JAVAJO.EXE
O4 - HKLM\..\RunServices: [NTTH.EXE] C:\WINDOWS\SYSTEM\NTTH.EXE
O4 - HKLM\..\RunServices: [CRDC32.EXE] C:\WINDOWS\CRDC32.EXE
O4 - HKLM\..\RunServices: [MSWA32.EXE] C:\WINDOWS\SYSTEM\MSWA32.EXE
O4 - HKLM\..\RunServices: [MSNE32.EXE] C:\WINDOWS\MSNE32.EXE
O4 - HKLM\..\RunServices: [IEWO32.EXE] C:\WINDOWS\IEWO32.EXE
O4 - HKLM\..\RunServices: [NETOX.EXE] C:\WINDOWS\NETOX.EXE
O4 - HKLM\..\RunServices: [APPEU32.EXE] C:\WINDOWS\APPEU32.EXE
O4 - HKLM\..\RunServices: [CRRQ32.EXE] C:\WINDOWS\SYSTEM\CRRQ32.EXE
O4 - HKLM\..\RunServices: [ADDZG32.EXE] C:\WINDOWS\ADDZG32.EXE
O4 - HKLM\..\RunServices: [MFCMN32.EXE] C:\WINDOWS\MFCMN32.EXE
O4 - HKLM\..\RunServices: [WINBJ32.EXE] C:\WINDOWS\SYSTEM\WINBJ32.EXE
O4 - HKLM\..\RunServices: [APPVM.EXE] C:\WINDOWS\SYSTEM\APPVM.EXE
O4 - HKLM\..\RunServices: [NETRU.EXE] C:\WINDOWS\SYSTEM\NETRU.EXE
O4 - HKLM\..\RunServices: [ADDGI32.EXE] C:\WINDOWS\ADDGI32.EXE
O4 - HKLM\..\RunServices: [JAVASZ32.EXE] C:\WINDOWS\JAVASZ32.EXE
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Step 7:Reboot your computer back to normal mode so that we can restore files that were deleted by this infection:
- This infection deletes the windows file, shell.dll.
If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):
%windir%\system32
%windir%\system
If you are using Windows 98 please download shell.dll from here: shell-dll98.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):
%windir%\system
If you are using Windows ME please download shell.dll from here: shell-dll98.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations (%windir% being the windows or winnt directory):
%windir%\system
- Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
- If you have Spybot S&D installed you will also need to replace one file. Go here: SDHelper.zip and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
- If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
Step 8:Run an online antivirus scan at:
http://housecall.antivirus.com/Reboot and post a last log