Please re-open HijackThis and click
Do a System Scan only. Check the boxes to the left of all the entries listed below.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8074
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O4 - HKCU\..\Run: [aaskwwlh] "C:\DOCUME~1\Owner\LOCALS~1\Temp\wrkvmvvyx\imvsjeflajb.exe"
O8 - Extra context menu item: Crawler Search - tbr:iemenu
Then, please
exit all programs except for HijackThis, and then click Fix Checked.
After it completes its process, please close HijackThis and reboot your computer.
Please
download OTM - Save it to your desktop.
- Please double-click OTM to run it. (Note for Vista: Right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL C (or, after highlighting, right-click and choose Copy):
:files
C:\Documents and Settings\Owner\Local Settings\Temp\wrkvmvvyx
:Commands
[emptytemp]
[purity]
[Reboot]
- Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter
*.log and press the Enter key, navigate to the
C:\_OTMoveIt\MovedFiles folder, and
open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Post a new HijackThis log here in your next reply along with the OTM log.