All home pages are set to google.co.uk.
You have the about:blank malware. All of the following processes should be checked for removal. An additional cleaning process may need to be run.
When you open Internet Explorer your browser will be redirected to a page called about:Blank, sp.html, or about:NavigationFailure. If you attempt to change your home page to another site, it will not work and continue opening about:blank."
Please re-open HiJackThis and scan.*Check* the boxes next to all the entries listed below.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
C:\Windows\system32\SearchFilterHost.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O4 - Global Startup: Exif Launcher 2.lnk = ?
IF you are not actively using this Remote Assist, the Service should be Disabled. It can be Enabled at any time it is needed
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\ssrc.exe
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe (see additional info about in separate post)
[/QUOTE]
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot into Safe Mode:
Start> Run> type in 'msconfig' without quotes> eenter> Selective Startup> Startup tab>> the following processes do NOT need to start at boot. They can be started Manually as needed. If this is agreeable to you, UNCHECK EACH of the following:
Picasa Media Detector
QuickTime
Adobe Reader Speed Launcher
Windows Media Player
RoxWatchTray
iTunesHelper
.
Apply> OK. (the only processes that NEED to start on boot are the antivirus, firewall, touchpad for laptop and network process if on network.
Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):
Any version of Java EXCEPT v6u10
Google EULA Launcher
Any program you are not using
IF ou are not using the Support Soft: Start> Run> services,msc> right click on SupportSoft> Properties> Change Startup type to either MAnual or Disabled> Apply> OK.
Reboot into Normal Mode. You will get a nag message that you can close after checking 'don't show this message again'. Stay in Selective Startup.
Leave the game files for now. They were cleaned, but they were a source of infection so if you do future downloads, advise Save download to desktop> right click> scan wit AV before installing.
Run HijackThis again and attach new log.