Hi and Welcome to TSF
Before attacking an adware/spyware problem with hijackthis make sure you have already run the following tools. Download and update the databases on each program before running.
Also make sure you are using the the latest version (1.99.1) of
HijackThis and it's installed in it's own folder on the root drive.
(C:\HJT)
Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible.
Please make sure system restore is enabled by right clicking on My Computer and go to Properties->System Restore and check the box for Turn OFF System Restore and make sure it’s
NOT checked. We want system restore
ON and monitoring your current hard drive. Once your clean we will turn this off and then back on to remove the infection from the restore folder and create a clean restore point.
Download and install
CleanUp! but
do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.
Download
KillBox http://www.bleepingcomputer.com/file...re/KillBox.zip
Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "
Options..."
*Move the arrow down to "
Custom CleanUp!"
*Put a check next to the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
[X]Scan local drives for temporary files (Please uncheck this option)
- Cleanup! All Users
Click
OK
Press the
CleanUp! button to start the program. Reboot/logoff when prompted.
Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Now navigate to the following file and open it with wordpad. C:\Windows\
Wininit.ini
Delete this entry and then save the file.
PendingFileRenameOperations: C:\DOCUME~1\MORPHE~1\LOCALS~1\Temp\A~NSISu_.exe||| C
Run KILL box. Paste the following locations into KILL BOX one at a time. Checkmark the box that says
"Delete on Reboot" and checkmark the box
"Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say
YES and when the next box opens prompting you to reboot now...click
NO...and proceed with the next file. Once you get to the last one click
YES and it will reboot.
C:\WINDOWS\nxstinst.exe
C:\WINDOWS\mgrsts.exe
C:\WINDOWS\remover.dll
C:\WINDOWS\xlz.exe
Once you reboot..run another Panda scan and post it's log.