Download
KillBox http://www.greyknight17.com/spy/KillBox.exe.
Reboot into
Safe Mode
Go into
Add/Remove and uninstall the following if they exist:
MyWay
TVMedia
RXToolbar
SideSearch
Run KillBox and check the box that says '
End Explorer Shell While Killing File'. Next click on '
Delete on Reboot'. For each of the following files below, check the box that says '
Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file -
Choose YES when informs you the file will be deleted on Reboot.
Choose NO when it asks if you want to reboot):
C:\WINDOWS\System32\hookdump.exe
C:\WINDOWS\cdmxtras
C:\Program Files\MyWay
C:\Program Files\Common Files\Totem Shared
C:\Program Files\Common Files\SearchUpgrader
C:\WINDOWS\wupdsnff.exe
C:\Documents and Settings\Owner\Application Data\tvm*.dll
C:\Documents and Settings\Owner\Application Data\Lycos
C:\WINDOWS\alchem.???
C:\WINDOWS\smdat32m.sys
C:\Program Files\Windows Media Player\wmplayer.exe.tmp
No disinfected C:\Program Files\RXToolBar
C:\Documents and Settings\Default User\Local Settings\Temp\obie.exe
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\ODAVG5YR\dd[1].exe
C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
C:\Documents and Settings\Owner\Application Data\tvmknwrd.dll
C:\Program Files\Common Files\SearchUpgrader\system.cfg
C:\Program Files\Windows Media Player\wmplayer.exe.tmp
C:\WINDOWS\alchem.ini
C:\WINDOWS\browserxtras\pn\remove.exe
C:\WINDOWS\inf\alchem.inf
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\wupdsnff.exe
Return the
Normal Mode and run a New Panda Scan and a new HJT scan and post the results from both in your next post.