Open up HiJackthis and do a scan. Check off the following items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50245
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
Click FIX CHECKED then close HiJackThis.
Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg (make sure that Save as Type is set at "All Files") on your Desktop. Ensure there is no space at above REGEDIT 4.
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\MODULEUSAGE\C:/WINDOWS/DOWNLOADED PROGRAM FILES/M67M.OCX]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RECOMMENDED HOTFIX - 421701D]
[-HKEY_CURRENT_USER\SOFTWARE\AURORA]
[-HKEY_CURRENT_USER\SOFTWARE\IN3RD]
[-HKEY_CURRENT_USER\SOFTWARE\PROGRAM INFO]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TOPSEARCH.TSLINK]
[-HKEY_CLASSES_ROOT\WEBCOM.WEBBAR.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ACTIVEX COMPATIBILITY\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\ISTSVC]
[-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\BANDREST]
[-HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]
[-HKEY_CLASSES_ROOT\Interface\{00ada225-ea6c-4fb3-82e8-68189201ccb9}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{6685509E-B47B-4f47-8E16-9A5F3A62F683}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page]
Locate fixme.reg on your Desktop and double-click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer "Yes" and wait for a message to appear similar to "Merged Successfully".
Just a few random bad files and folders to clean up.
Please remove the following folders using Windows Explorer (if present):
C:\PROGRAM FILES\joystick networks
C:\PROGRAM FILES\COMMON FILES\Slmss
C:\WINDOWS\SYSTEM32\nsvsvc
C:\WINDOWS\bsx32
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\nsv
- Open HiJackThis
- Click on the configure button on the bottom right
- Click on the tab "Misc Tools"
- Click on "Delete File on Reboot"
- Navigate to this file - C:\WINDOWS\unstall.exe
- Double click on that file.
- HJT asks you if you want to reboot, now. Click "no".
Do that for the following files also, until you get to the last one, then click "yes" when HJT asks you to reboot.
C:\WINDOWS\SYSTEM32\commcoss.dll
C:\WINDOWS\SYSTEM32\ide21201.vxd
C:\WINDOWS\SYSTEM32\saie.log
C:\WINDOWS\SYSTEM32\setup_incred_8.exe
C:\WINDOWS\SYSTEM32\TBPS.ini
C:\WINDOWS\INF\alchem.inf
C:\WINDOWS\INF\localNrd.inf
C:\WINDOWS\INF\twaintec.inf
C:\WINDOWS\optimize.exe
C:\Documents and Settings\Owner\Desktop\backups\backup-20050730-004645-791.dll
- Open HiJackThis
- Click on the configure button on the bottom right
- Click on the tab "Misc Tools"
- click on "delete an NT service"
- Copy and paste this in the box: SvcProc
- Click "ok", then reboot