Once we start, you won't have access to this post anymore, so I recommend that you
print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet...
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {2FA3B736-1AC7-454D-8E94-8BA8158BF064} - (no file)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [SpywareRemover] C:\Program Files\SpywareRemover\SpywareRemover.exe -boot
O4 - HKCU\..\Run: [SpywareRemover] C:\Program Files\SpywareRemover\SpywareRemover.exe -boot
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O4 - HKLM\..\Run: [ErrorSmart] C:\Program Files\ErrorSmart\ErrorSmart.exe(I'm not familiar with this ErrorSmart program. Based on what I've found, I would remove it, but it could be legitimate. Is this a program you normally use? Don't check this yet.)Now, close
all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and
reboot into Safe Mode and
enable hidden files and folders.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...
MyWebSearch
SpywareRemover (This looks legitimate, but it's considered rogue anti-spyware, which means it shouldn't be trusted.)Please note any other programs that you dont recognize in that list in your next response.Navigate to and delete the following folder(s) if present...
C:\Program Files\SpywareRemoverOnce you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.