Click Start/Run and type in
msconfig, then hit enter.
See if you can UNcheck: RunOnce: [18btul.exe] C:\WINDOWS\System32\18btul.exe /k
Reboot in Safe Mode
UNinstall anything to do with (if you can):
C:\Program Files\
Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\
AutoUpdate\AutoUpdate.exe
C:\Program Files\
CxtPls\CxtPls.exe
C:\PROGRA~1\
Web Offer\wo.exe
Next, go into Task Manager (ctrl-alt-del) and try to STOP these processes (if still there):
quoycv.exe
ViewMgr.exe
packager.exe
tibs3.exe
AutoUpdate.exe
umdbk32.exe
lmrredir.exe
CxtPls.exe
wo.exe
satmat.exe
farmmext.exe
enhupdt.exe
18btul.exe
Next, run HJT on its own, and let it 'fix' (if still there):
C:\WINDOWS\System32\quoycv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\packager.exe
C:\WINDOWS\System32\tibs3.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\umdbk32.exe
C:\WINDOWS\System32\lmrredir.exe
C:\Program Files\CxtPls\CxtPls.exe
O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\WINDOWS\
ZServ.dll
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINDOWS\
enhtb.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [bspftoyxyfntn] C:\WINDOWS\System32\quoycv.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINDOWS\enhupdt.exe
O4 - HKLM\..\Run: [t3FT33S] umdbk32.exe
O4 - HKLM\..\RunOnce: [18btul.exe] C:\WINDOWS\System32\18btul.exe /k
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [c0w3RTeEW] lmrredir.exe
O4 - HKCU\..\RunOnce: [18btul.exe] C:\WINDOWS\System32\18btul.exe /k
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} -
https://www.spydeleter.com/order2.php?KBID=1062 (file missing)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52....apple.com/saba/us/win/QuickTimeInstaller.exe
Delete the
bold files, except MSCONFIG. When a
directory is also
bold, delete everything in it, including that directory itself.