Before we begin, please move HijackThis into a permanent folder. It is important that you run HijackThis.exe in its own folder so the backup files that HijackThis file will create will not be accidentally deleted on reboot.
Open 'My Computer', then double-click to open C:\ (or the drive letter that your Windows is installed)
In the menu bar, click File–>New–>Folder.
That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ or C:\HijackThis\ folder. Put your HijackThis.exe there.
Please go to add/remove programs and uninstall Wintools
Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.
You must disconnect from the internet totally, as staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer closed throughout as opening it will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.
Please continue with the next step and if you run into any problems with the current one, just keep going through the list step by step. Just be sure to let us know what the problem was when you finally reply.
Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
http://www.davehigham.zen.co.uk/downloads/xphidden.zip
Now download About:Buster from
here
Once it is downloaded extract it to c:\aboutbuster. Do NOT use it yet
Download CWShredder from
here, install it but again, don't use it yet.
Please disconnect from the Internet and unplug your modem for the duration of this fix
Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE
Press control-alt-delete to get into the task manager and end the following processes if they exist
javabk.exe
Now you need to search for and delete the following files
C:\WINDOWS\
yeqki.dll <— please search for this file without the dll extension and delete all instances of it
C:\WINDOWS\system32\
iprz32.dll <— please search for this file without the dll extension and delete all instances of it
C:\WINDOWS\system32\
apidy.exe
C:\PROGRA~1\COMMON~1\
WinTools <— folder
C:\WINDOWS\system32\
sysfm.exe
C:\WINDOWS\system32\
tibs3.exe
C:\WINDOWS\system32\
javabk.exe
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yeqki.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {D9E4FCE9-DD60-AD26-B07D-BFB00720C50B} - C:\WINDOWS\system32\iprz32.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [apidy.exe] C:\WINDOWS\system32\apidy.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [sysfm.exe] C:\WINDOWS\system32\sysfm.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\system32\tibs3.exe
O4 - HKLM\..\RunOnce: [javabk.exe] C:\WINDOWS\system32\javabk.exe
Now navigate to the c:\aboutbuster directory and double-click on aboutbuster.exe When the tool is open press the OK button, then the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files. If it asks if you would like to do a second pass, allow it to do so. Post the log file in your next reply
Run CWShredder and let it fix what it finds
Finally, run Adaware and again, let it fix what it finds.
Reboot and post a fresh log for review please