Perform a scan using HJT, and check the following items (if found).
R3 - Default URLSearchHook is missing
O4 - Global Startup: ass.cmd
Close all windows except for the HJT window, and click the Fix Checked button.
Exit out of HijackThis.
Make sure that you can see hidden files.
1. Click Start.
2. Click My Computer.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Click Yes to confirm.
7. Uncheck the Hide file extensions for known file types.
8. Click OK.
Search for Hidden Files
By default, the Search companion does not search for hidden files. Because of this, you may be unable to find files, even though they exist on the drive.
To search for hidden or system files in Windows XP:
Click Start, click Search, click All files and folders, and then click More advanced options.
1. Click to select the Search hidden files and folders check boxes.
Shutdown your computer, and Boot Up into Safe Mode, by hitting the F8 key repeatedly as you power up.
This will bring up a menu, select Safe Mode and press enter. Log on as a user with administrator priviledges, and find and delete the following if found.
This File
ass.cmd
Next we need to delete your Temporary Files.
Use Start > Run and type in %temp% . Delete the entire contents of that temp folder (use Edit > Select All, press Delete, click Yes).
Then, Empty your Temporary Internet Cache completely. Close all instances of Outlook and and Internet Explorer, then use Control Panel > Internet Options > General tab and click the Delete File button. When prompted place a check in: Delete all offline content, then click OK.
Then, use Windows Explorer to clean out ALL the other temp folders on your system (navigate to these folders, use Edit > Select All, press Delete, click Yes): Note: Do not Delete the Folder itself
* C:\Documents and Settings\Your Profile\Local Settings\Temp\
* C:\Documents and Settings\Any other users Profile\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\Any other users Profile\Local Settings\Temp\
* Empty your "Recycle Bin".
Please let me know about any problems with the temp file deletes.
Note: If you cannot delete them all at once because you have too many, then click and hold ctrl and highlight a batch of them at a time. Once highlighted, R-click over the highlight and select delete. Rinse, lather, repeat until folder is empty
Reboot into Normal mode, and send me a new HJT log please.
_________________