Ok lets get to work
We need to get rid of one of the services running on your machine. To do this, copy (Ctrl +C) and paste (Ctrl +V) the text in the code box below to Notepad.
Code:
@echo off
sc stop System Spooler Host
sc delete System Spooler Host
sc stop System TskHlp
sc delete System TskHlp
del service.cmd and exit
Save it to your desktop as File name: service.cmd
Save as type: All Files
Once done, double click service.cmd to run it. A command window will open briefly, then close. This is quite normal.
-------------------------------------------
Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.
Please re-open HiJackThis and scan.**Check the boxes next to all the entries listed below.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Dit] Dit.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{B84E9584-09E9-4C89-AB21-557D7F13872C}: NameServer = 194.74.65.68,194.72.0.114
O23 - Service: System Spooler Host - Unknown owner - C:\WINDOWS\cursors\mstask\services.exe (file missing)
O23 - Service: Task Manager Help (TskHlp) - Unknown owner - C:\windows\cursors\mstask\taskmgr.exe (file missing)
Now
close all windows other than HiJackThis, then click Fix Checked.**Close HiJackThis.
---------------------------------------------
Please
download the
OTMoveIt2 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code:
C:\Windows\System32\Dit.exe
- Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
- Click the red Moveit! button.
- A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
- Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.
------------------------------------------------
Please run an on-line virus scan at
http://www.kaspersky.com/virusscannerKaspersky OnLine Scan or if that doesnt work, you can use
TrendMicro or
BitDefender.
(Please post the results of the scan(s) in your next reply)