Hi and welcome to TSF.
Apologies for any delay in replying, but we have been rather busy lately, and, of course, all our helpers are volunteers.
You may wish to
Subscribe to this thread
(Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply.
Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix. You should not have any open browsers or live internet connections when you are following the procedures below.
Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your log is clean. Remember that although your symptoms may vanish, this does NOT mean that your system is clean.
If there is anything you don't understand, please ask BEFORE proceeding with the fixes.
Please ensure that you follow the instructions in the order I have them listed.
Combofix
Download
ComboFix and save it to your desktop.
**Note: It is important that it is saved directly to your desktop**
CAUTION! Combofix should not be run without supervision - we cannot be held responsible if you end up re-installing Windows!
1. Close any open browsers and
physically disconnect from the Internet.
2. Close/disable
all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
See here for a guide to disabling AV, Firewall and Anti-malware programmes.
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the log C:\ComboFix.txt along with a fresh HijackThis Log for further review.
NOTE: ComboFix should not take more than
20 minutes to run - this includes the reboot if malware is found. If it does:
- Open Task Manager (Ctrl+Alt+Del) and go to the Processes Tab
- End any processes called indstr, find, sed or swreg,
- ComboFix should now contimue.
Please advise me if you had to end any Processes in this way, and let me know the Process Names.
Do not mouseclick combofix's window whilst it's running. This may cause it to stall.