You also need to dump your TIF files, cookies, %TEMP% files, recycle bin.
and download SwatIt, it's free, (was when I used it...), and it works.
Now, if it gave you a file name, like, "Downloader.Swizzer.whatever"
shut down and come back in Safe Mode, and run 'search files and Folders, and if it's there, delete it. Run your AV in Safe Mode, and run SpyBot and Adaware in Safe Mode. If you don't have them, do this:
Download and Read the SpyBot tutorial here:
Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.
Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes.
To add an item to your Ignore List click on the little + sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.
When you are done reboot again same way. Two full minutes shut down is best.
Tea Time discussed by designer here:
Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on search for updates, the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.
Download AdAware from click here
check for updates at "webupdate".
I use these settings (green check)
From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.
Put a black dot nest to "Use custom scanning options and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"
At the top of the STATUS page notice the Tweak (gear) icon. Click on it.
The first setting is Scanning Engine. Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and include basic Ad-Aware settings in log file. Next click on the + next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring
Click "proceed", that will save those settings.
When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press next and then yes to the prompt: remove all these entries.
However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do its job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on ignore list.
Shut down, two minute shut down is best, and let Adaware run on reboot if it indicates.
Here's a downloading tip, I do this:
That should keep you busy for an hour or so.
After SWATIT and running AV, Adaware and Spybot in Safe Mode, you come up clean, then that should be it. Re-enable yours system restore, set a check point if it didn't automatically do it for you.
If you feel a HiJackLog would be a help, download it here:
and post it on this site or post it here: