1. Print this post out, since you won't have an access to it, at some point.
2. Close all windows, except for HJT.
2a. Go to Control Panel>Add\Remove, and uninstall WebSavingsfromEbates, and WeatherBug
3. Put a checkmark next to the following HJT entries:
- R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
- O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - (no file)
- O4 - Startup: PowerReg Scheduler.exe
- O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
- O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
- O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
- O18 - Protocol hijack: mhtml -
4. Click on "Fix It" button.
5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)
6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".
7. Delete following folders (if they still exist):
- WebSavingsfromEbates, AWS folders from C:\Program Files
8. Turn off System Restore:
- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK
9. Restart in Normal Mode.
10. Turn System Restore on.
11. Run HJT again, and post back its log back here.