Great job!
Left Drag mouse and Copy for Pasting all text in the box below. Make sure the slider bar goes to bottom from the @ to the end of the second exit.
Then paste to the black screen of an open command prompt.
All may not apply so ignore errors.
Code:
@echo off
sc config Alerter start= disabled
sc stop Alerter
sc config AeLookupSvc start= disabled
sc stop AeLookupSvc
sc config ClipBook start= disabled
sc stop ClipBook
sc config Dfs start= disabled
sc stop Dfs
sc config FastUserSwitchingCompatability start= disabled
sc stop FastUserSwitchingCompatability
sc config TrkWks start= disabled
sc stop TrkWks
sc config TrkSvr start= disabled
sc stop TrkSvr
sc config DNSCache start= disabled
sc stop DNSCache
sc config ERSvc start= disabled
sc stop ERSvc
sc config HidServ start= disabled
sc stop HidServ
sc config PolicyAgent start= disabled
sc stop PolicyAgent
sc config CiSvc start= disabled
sc stop CiSvc
sc config IsmServe start= disabled
sc stop IsmServ
sc config kdc start= disabled
sc stop kdc
sc config LicenseService start= disabled
sc stop LicenseService
sc config Messenger start= disabled
sc stop Messenger
sc config Netlogon start= disabled
sc stop Netlogon
sc config NetTcpPortSharing start= disabled
sc stop NetTcpPortSharing
sc config mnmsrvc start= disabled
sc stop mnmsrvc
sc config NetDDE start= disabled
sc stop NetDDE
sc config NetDDEdsdm start= disabled
sc stop NetDDEdsdm
sc config NtLmSsp start= disabled
sc stop NtLmSsp
sc config SysmonLog start= disabled
sc stop SysmonLog
sc config RSVP start= disabled
sc stop RSVP
sc config SSDPSRV start= disabled
sc stop SSDPSRV
sc config upnphost start= disabled
sc stop upnphost
sc config WMPNetworkSvc start= disabled
sc stop WMPNetworkSvc
sc config WmiApSrv start= disabled
sc stop WmiApSrv
sc config WmdmPmSN start= disabled
sc stop WmdmPmSN
sc config RemoteRegistry start= disabled
sc stop RemoteRegistry
sc config RemoteAccess start= disabled
sc stop RemoteAccess
sc config SCardSvr start= disabled
sc stop SCardSvr
sc config TlnSvr start= disabled
sc stop TlnSvr
sc config UPS start= disabled
sc stop UPS
sc config WebClient start= disabled
sc stop WebClient
sc config DNSCache start= disabled
sc stop DNSCache
sc config JavaQuickStarterService start= disabled
sc stop JavaQuickStarterService
sc delete JavaQuickStarterService
attrib -h -s -r /s c:\jqs.*
del /f /q /s c:\jqs.*
sc config RpcSs start= Automatic
sc start RpcSs
sc config RpLocator start= Automatic
sc start RpcLocator
sc config MSIServer start= Automatic
sc start MSIServer
exit
exit
Run HJT select and Fix the below!
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
O20 - Winlogon Notify: identified as: - C:\WINDOWS\
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
Minor but run SAS Quickscan and remove the Tracking cookies!
Because of a couple of the above..
Download ComboFix
Get it here:
https://www.techspot.com/downloads/5587-combofix.html
Or here:
http://subs.geekstogo.com/ComboFix.exe
Double click combofix.exe follow the prompts.
Install Recovery Console if connected to the Internet!
When finished, it will open a log.
Attach the log and a new HJT log in your next reply.
Note: Do not click combofix's window while its running. That may cause it to stall.
This should finish us up, but get me the logs!
Mike