The Java is out of date. Please update to v7u10 here:
http://java.com/en/download/manual.jsp
Please re-open HiJackThis and scan.*Check* the boxes next to all the entries listed below.
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [A00F590A9C49.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F590A9C49.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) -
http://www.wildtangent.com/webdrivers/webinstall/shockwave/Install.cab
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Question: I\Did you set her up on a VPN:
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) -
https://s.vpn.uprr.com/dana-cached/setup/JuniperSetupSP1.cab
IF not, please have this entry removed.
Now close all windows other than HiJackThis, then click
Fix Checked. Close HiJackThis and reboot into Safe Mode:
Start> Run> type in ''msconfig' without the quotes> Selective Start-up> Startup tab> UNCHECK everything except the antivirus and firewall> Apply> OK.
Start> Run> services.msc> right click on Java Quick Starter> Properties> Change Startup type to Disabled.
Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):
all Java programs except v7u10
WeatherBug
WildTangent
Reboot> Close the nag message that comes up after checking 'don't show this message again'.
I'd like you to run ComboFix because of the additional entries in SuperAntispyware, after Malwarebytes was run and in HijackThis. We may have to use a special uninstaller for the Weather program We'll see.
Please download ComboFix.: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
*With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it.
*Please disable all security programs, such as antiviruses, antispywares, and firewalls.
*Also disable your internet connection.
•
Run Combo-Fix.exe and follow the prompts.
**Understand that things like your system clock changing and your desktop disappearing might happen. Do not worry, because all will be restored later.
• Wait for the scan to be completed.
• If it requires a reboot, please do it.
• After the scan has completed entirely, please post the log here. The log will be located at C:\ComboFix(.txt)
**Do not click on the ComoboFix window, as it may cause it to stall.
Please rerun HijackThis after Combofix and attach both logs.