Hello there and welcome to Bleeping Computer's security forum.
My name is David
, I will be helping you with your log today.
It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.
Please set your system to show all
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\lsas.exe
O4 - HKLM\..\Policies\Explorer\Run: [lsas] C:\WINDOWS\lsas.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!
Now reboot into Safe Mode
This can be done tapping the F8
key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.
Using Windows Explorer, please locate the following files/folders, and delete them if still present:
<--(do not delete the legitimate lsass
I want you to clean your cache and cookies from your internet explorer.
There are a few infected files which need to be removed from your system.
° Close all instances of Internet Explorer .
° Go to your control panel and open "Internet Options".
° Click on the "General
° Click the "Delete Cookies" button, then the "Delete Files" button.
° If prompted, place a tick in the "Delete all offline content" box and click OK.
Also, please clean other Temporary files and Empty the Recycle Bin
° Go to start and click on the "run" button.
° Type the following in the box --> cleanmgr
and click ok.
° Let it scan your system for files to remove.
° Make sure only Temporary Files, Temporary Internet Files, and Recycle Bin are checked.
° Press OK
to remove them.
Reboot back into normal mode.
Please download Combofix
to your desktop.
to launch the application.
Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt
Post this log in your next reply together with a new hijackthislog.