First do an online scan:
This Trendmicro scanner runs on all Browsers:
http://be.trendmicro-europe.com/consumer/housecall/housecall_launch.php
When done, do the following:
Boot in Safe Mode.
Switch System restore OFF, see how here.
In Windows Explorer, turn on "show all files and folders, including hidden and system". See how here.
Next, open Windows Task Manager.
On Windows 95/98/ME, press
CTRL+ALT+DELETE.
On Windows NT/2000/XP, press
CTRL+SHIFT+ESC.
Click the Processes tab, select the process (if there), click
End Process for:
smcss.exe
VisualKore.exe
Next, run a HJT scan and (if still there) place a tick-mark in the little square before:
...................................................................................................
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 67.15.126.34
www.japsclan.com
O1 - Hosts: 67.15.126.34
www.japsclan.info
O1 - Hosts: 67.15.126.34 japsclan.info
O1 - Hosts: 67.15.126.34 japsclan.com
O1 - Hosts: 67.15.126.34 irc.japsclan.com
O1 - Hosts: 67.15.126.34
www.japsclan.us
O1 - Hosts: 67.15.126.34 japsclan.us
O1 - Hosts: 67.15.126.34
www.japsclan.org
O1 - Hosts: 67.15.126.34 japsclan.org
O1 - Hosts: 67.15.126.34 rxp-clan.us
O1 - Hosts: 67.15.126.34
www.rxp-clan.us
O4 - HKLM\..\Run: [smcss] C:\WINDOWS\system32\
smcss.exe
O4 - HKLM\..\Run: [VisualKore] C:\WINDOWS\system32\
VisualKore.exe
O4 - Global Startup: officejet 6100.lnk = ?
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1115185919406
O20 - Winlogon Notify: smcss - smcss.dll (file missing)
...................................................................................................
Now click on the
Fix Checked button in HJT.
When done, from between the above dotted lines, delete the highlighted
bold files.
Delete all files and directories from: C:\Documents and Settings\[username]\Local Settings\Temp
Repeat this for ALL [usernames].
Delete all files and directories from: C:\WINDOWS\Temp (except files dated from TODAY).
Boot normal. When all OK, switch System Restore back on.