Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\SYSTEM\MSREG32.EXE
F1 - win.ini: run=C:\WINDOWS\SYSTEM\MSREG32.EXE
O4 - Startup: PowerReg Scheduler V3.exe
Reboot into safe mode by following instructions here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
then as some of the files or folders you need to delete may be hidden do this:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
Delete these files
C:\WINDOWS\SYSTEM\MSREG32.EXE
then
Reboot normally &
I would strongly recommend downloading and running a specialised anti trojan
the best antitrojan that I use for dealing with them is
TDS3 from http://tds.diamondcs.com.au/
download & install the 30 day free trial, update it manually as described here http://tds.diamondcs.com.au/index.php?page=update as the trial version doesn't have auto update enabled
then press scan control & tick all the little boxes in the bottom part of that window, press save configuration and then close that window by pressing the red X in top right corner, then select system testing and select full system scan
sit back with a cup of coffee and watch what it finds
NOTE:
Unlike set and forget av's TDS works with you, it doesn't auto delete anything but puts a list of found suspect files in the bottom window
right click any file it finds and it gives you options on dealing with it, the normal selection would be delete , but first select "save as text", that will create a logfile of all the found suspect files and put it in the TDS directory called scandump.txt.
post back with the tds log after running please, just copy & paste the entries from the scandump.txt
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\SYSTEM\MSREG32.EXE
F1 - win.ini: run=C:\WINDOWS\SYSTEM\MSREG32.EXE
O4 - Startup: PowerReg Scheduler V3.exe
Reboot into safe mode by following instructions here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
then as some of the files or folders you need to delete may be hidden do this:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
Delete these files
C:\WINDOWS\SYSTEM\MSREG32.EXE
then
Reboot normally &
I would strongly recommend downloading and running a specialised anti trojan
the best antitrojan that I use for dealing with them is
TDS3 from http://tds.diamondcs.com.au/
download & install the 30 day free trial, update it manually as described here http://tds.diamondcs.com.au/index.php?page=update as the trial version doesn't have auto update enabled
then press scan control & tick all the little boxes in the bottom part of that window, press save configuration and then close that window by pressing the red X in top right corner, then select system testing and select full system scan
sit back with a cup of coffee and watch what it finds
NOTE:
Unlike set and forget av's TDS works with you, it doesn't auto delete anything but puts a list of found suspect files in the bottom window
right click any file it finds and it gives you options on dealing with it, the normal selection would be delete , but first select "save as text", that will create a logfile of all the found suspect files and put it in the TDS directory called scandump.txt.
post back with the tds log after running please, just copy & paste the entries from the scandump.txt