Before you start,
disconnect the PC from the internet!
Boot in Safe Mode.
Switch System restore OFF.
Press Ctrl/Alt/Del simultaneously, select Taskmanager/Processes, select the process (if there), click "End Process" for:
winnn10n.exe
vssymvea.exe
casclient.exe
sf.exe
sfita.exe
Next, try to UNinstall (NOT delete yet!) anything to do with:
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\sf\sf.exe
Next, run a HJT scan and place a tick-mark in the little square before (if still there):
...................................................................................................
C:\WINDOWS\System32\
winnn10n.exe
C:\WINDOWS\System32\
vssymvea.exe
C:\Program Files
\Cas\Client\casclient.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Bucket Class - {00000001-C003-4A2F-9142-7CB1D78DE6C1} - C:\WINDOWS\
tct101.dll
O2 - BHO: Cas - {B5F3970B-745E-46AC-B890-E08F69777D80} - C:\WINDOWS\System32\
ca.dll
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe
D0CE0C16B1,
D0CE0C16B1 ==>> if you can find these <<==
O4 - HKLM\..\Run: [x32i3qR] winnn10n.exe
O4 - HKCU\..\Run: [g0tsRkd6Q] vssymvea.exe
O4 - HKCU\..\Run: [sf] C:\Program Files
\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\
sfita.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone:
http://www.neededware.com
O15 - Trusted Zone:
http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: NDWCab -
http://www.neededware.com/ndw3.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) -
http://softdev.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1118875347952
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: Winkir - Unknown owner - C:\WINDOWS\System32\Winkir.exe (file missing)
...................................................................................................
Now click on the
Fix Checked button in HJT.
When done, from between the dotted lines, delete the highlighted
bold files.
When a \
directory-name\ is
bold, delete everything in it, including that directory itself.
Delete all files and directories from: C:\Documents and Settings\[username]\Local Settings\Temp
Repeat this for ALL [usernames].
Boot normal. When all OK, switch System Restore back on.
Unless you install at least XP/SP1 don't come back again!