Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Open your task manager and end process for(if there).
ptsnoop.exe
winupdates.exe
SYSC00.exe
zkrgcc.exe
KEYBOARD1.exe
MOUSEPAD.exe
ibm00003.exe
ONCEJUGS.exe
Close task manager.
Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [winupdates] \winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [zkrgcc] C:\WINDOWS\SYSTEM\zkrgcc.exe
O4 - HKLM\..\Run: [keyboard] C:\\KEYBOARD1.exe
O4 - HKLM\..\Run: [mousepad] C:\\MOUSEPAD.exe
O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00003.exe"
O4 - HKCU\..\Run: [book blah] C:\WINDOWS\APPLIC~1\DRAWSI~1\ONCEJUGS.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
Click the fix checked button.
Close HJT.
Locate and delete the following bold files(if there).
C:\WINDOWS\
ptsnoop.exe
winupdates.exe
C:\WINDOWS\
SYSC00.exe
C:\WINDOWS\SYSTEM\
zkrgcc.exe
C:\\
KEYBOARD1.exe
C:\\
MOUSEPAD.exe
C:\WINDOWS\SYSTEM\
ibm00003.exe
C:\WINDOWS\APPLIC~1\DRAWSI~1\
ONCEJUGS.exe
Reboot into normal mode.
Regards Howard
