Save this to notepad so you will have it while in safe mode and removing entries with hijackthis. It's important to have all of your browser windows closed!
Fix these with hijackthis while logged into the correct profile.
Log 2 (ali)
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKCU\..\Run: [darthold] C:\DOCUME~1\Ali\APPLIC~1\HEARTO~1\Mapiboldsect.exe
Log 3 hannah
O4 - HKCU\..\Run: [darthold] C:\DOCUME~1\Hannah\APPLIC~1\HEARTO~1\Mapiboldsect.exe
Log 4 Owner
O4 - HKCU\..\Run: [darthold] C:\DOCUME~1\HP_Owner\APPLIC~1\HEARTO~1\Mapiboldsect.exe
Log 4 rebecca
O4 - HKCU\..\Run: [darthold] C:\DOCUME~1\HP_Owner\APPLIC~1\HEARTO~1\Mapiboldsect.exe
Please
download the
OTMoveIt2 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code:
C:\WINDOWS\Tasks\AA876005918513C9.job
C:\DOCUME~1\Ali\APPLIC~1\HEARTO~1
C:\DOCUME~1\Hannah\APPLIC~1\HEARTO~1
C:\DOCUME~1\HP_Owner\APPLIC~1\HEARTO~1
C:\Documents and Settings\Becky\Application Data\ZangoToolbar
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDownloadervdt2.zip
- Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
- Click the red Moveit! button.
- A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
- Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.
Restart in Safe Mode.
- To boot up in Safe mode, continuously tap the F8 key while starting your computer.
- You should see a black screen displaying the Windows Advanced Menu Options.
- Using your keyboard's arrow keys, select Safe mode, then hit Enter.
Open Windows Explorer. Go to Tools, Folder Options and click on the View tab. Make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files". Now click "Apply to all folders" Click "Apply" then "OK".
Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Next navigate to the C:\Documents and Settings\Administrator
(Repeat for all user names)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
Empty your recycle bin.
Reboot to normal mode and let me know how the machine is working.