Hi adalia. The log seems pretty short bu that might just be your setup. Quite minimalist
. Let's get started. Please print these directions and then proceed with the following steps in order.Step #1
and install it but do not run it yet.Important
Your copy of HijackThis needs to be in a folder of it's own. If it is run from Temporary folders the backups and HijackThis itself could be accidentally deleted if the Temporary folders are cleaned. If it is run from the desktop then the backup files and folders can clutter up the desktop and be accidentally deleted. If it is run from inside a compressed file then the backups are not created at all.
Step #2Start in Safe Mode Using the F8 method:
- Please open My Computer
- Double-click on Local Disk (C:)
- Click on the File menu, point to New and then click on Folder. Name the folder 'HijackThis' or 'HJT'.
- Unzip to or copy and paste HijackThis.exe to the new folder.
- Restart the computer.
- As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
- Use the arrow keys to select the Safe Mode menu item.
- Press the Enter key.
Start HijackThis and click the Scan
button to perform a scan. Look for the following items and click in the checkbox in front of each item to select it:F1 - win.ini: run=C:\WINDOWS\SPEEDY.BATc:\windows\speedy.bat,c:\windows\speedy.scr,c:\windows\scrsvr.exe,c:\windows\instit.bat,c:\windows\marco!.scr,c:\windows\alevir.exe,c:\windows\Brasil.pif,c:\windows\natal!.pif
O4 - HKLM\..\Run: [Spees1] C:\WINDOWS\Speedy.scr
O4 - HKLM\..\Run: [ SystemCheck] C:\WINDOWS\Config\system\services.exe
Now close ALL open windows except HijackThis
and click the Fix Checked
button to finish the repair.Step #4We need to make sure all hidden files are showing so please:We need to make sure all hidden files are showing so please:
Find the following files/folders and delete them (don't worry if they are already gone):C:\WINDOWS\Speedy.scr
- Open My Computer.
- Select the View menu and click Folder Options.
- Select the View tab.
- In the Hidden files section select Show all files.
- Click OK.
Start CCleaner and click on the Run Cleaner
button in the lower right-hand corner. When it is finished close CCleaner.Step #6
Reboot normally and run at least 2
of the following on-line virus scans:Trend Micro HousecallBitDefender On-Line Virus ScanPanda ActiveScaneTrust Antivirus Web Scanner
Make sure that you choose "fix" or "clean".Step #7AdAware SEDownload, install, update, configure and run a scan with Ad-aware SE:
- Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
- Close ALL windows except Ad-Aware SE.
- Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
- Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
- In the ‘General’ window make sure the following are selected in green:
- Under Safety:
- Automatically save log-file
- Automatically quarantine objects prior to removal
- Safe Mode (always request confirmation)
- Under Definitions:
- Prompt to update outdated definitions - set the number of days
- Click on the ‘Scanning’ button on the left and select in green:
- Under Driver, Folders & Files:
- Under Select drives & folders to scan:
- Under Memory & Registry: all green
- Scan Active Processes
- Scan Registry
- Deep Scan Registry
- Scan my IE favorites for banned URL’s
- Scan my Hosts file
- Click on the ‘Advanced’ button on the left and select in green:
- Under Shell Integration:
- Move deleted files to recycle bin
- Under Logfile Detail Level: all green
- include addtional object information
- DESELECT - include negligible objects information
- include environment information
- Under Alternate Data Streams:
- Don't log streams smaller than 0 bytes
- Don't log ADS with the following names: CA_INOCULATEIT
- Click the ‘Tweak’ button and select in green:
- Under ‘Scanning Engine’:
- Unload recognized processes during scanning
- Scan registry for all users instead of current user only
- Under ‘Cleaning Engine’:
- Let Windows remove files in use at next reboot
- Under Log Files:
- Include basic Ad-aware SE settings in logfile
- Include additional Ad-aware SE settings in logfile
- Please do not check: Include Module list in logfile
- Click on ‘Proceed’ to save the settings.
- Click ‘Start’
- Choose 'Perform Full System Scan'
- DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
- Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
- If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
- Save the log file when it asks and then click ‘Finish’
- REBOOT to complete the removal of what Ad-Aware SE found.
OK. Reboot your computer normally, start HijackThis and perform a new scan. Use the Add Reply
button to post your new log file back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.