I’m curious where this file went C:\WINDOWS\system32\hbeyfc.exe
Did you delete it after you tested it?
Got to control panel, add/remove programs and uninstall these or similar, if present
Funweb Products
My Web Search (Smiley Central or FWP product as applicable)
My Way Speedbar (Smiley Central or other FWP as applicable)
My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
Search Assistant - My Way
Open HJT, run a system scan only, check mark these lines if present
[b]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM..\Run: [jf] C:\WINDOWS\system32\jf.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm098YYGB
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1.0.0.15-3.cab[/b]
Close all other browsers/windows, click fix, close HJT.
This file is supposed to be a printer file, it’s location and size seems strange, so we will test it.
Please submit these files for analysis
To submit a file to virustoal, please click om this link
www.virustotal.com
copy and paste the following into the upload a file box (one at a time if more than one file is listed)
C:\CJXP1100EN.exe
scroll down a bit and click “send file”, wait for the results and post then in your next reply.
Please note:
[]Please, never rename Combofix unless instructed.
[]Close any open browsers.
[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
[*]Close any open browsers.
[*]WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
[]Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
[]If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
Open a new Notepad session (Do not use a Word Processor or WordPad). Click “Format” and be certain that Word Wrap is not enabled.
Copy and paste all the text in the quote box below into Notepad.
Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “CFscript.txt” . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.
File::
C:\WINDOWS\system32\hbeyfc.exe
C:\WINDOWS\system32\jf.exe
This will start ComboFix again.Close all browser/windows first. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HJTlog.
Note: Do not mouseclick combofix’s window while it’s running. That may cause it to stall