Hi
Now the fact clicking on C:/ drive (left click) doesn't work, but Right click open and explore does work, could mean you for one have Malware that works in the same way like the "Autorun" family of Malware. Or something that does thae same symptom.
1. Your Hijackthis log, You have installed for one what can be called Adware, some Some people and Antispyware do, some don't. What you have is "MyWay.com" also known as MyWaySearch, that family.
Some PC makes like Dell install it on their systems. http://www.pchell.com/support/mywebsearch.shtml
The other Major thing is You have or had a variant of Vundo / Virtumode, some call a Trojan downloader.
Start Hijackthis again and tick (check) these entries
MyWaySearch (optional)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
As For Vundo/ Vurtumonde and others
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {1BD7BC0C-78D8-4764-976A-986E3C4EF540} - C:\WINDOWS\system32\ephuftss.dll (file missing) (BAD)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\arwcosjw.dll (file missing) (BAD)O2 - BHO: (no name) - {ECDBC6D3-3749-448D-860A-D07EB7E30A78} - C:\WINDOWS\system32\sstqr.dll (file missing) (BAD)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O20 - Winlogon Notify: sstqr - C:\WINDOWS\system32\sstqr.dll (file missing) (BAD)
O20 - Winlogon Notify: xxyawvu - xxyawvu.dll (file missing) (BAD)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Now click "Fix Checked" You may need to restart the PC
Now can SuperAntispyware Free be installed http://www.superantispyware.com/download.html , then updated and Run a Full Scan in Safe Mode. See if it finds the likes of an "Autorun.inf" file on the C:\ drive.
If the Problem still persists with the C:\ drive
Try SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix_ReadMe.htm Install in Normal Mode then switch to Safe Mode to run. Here is the instuctions
How to use SDFix:
1. Download SDFix and save to your Desktop.
2. Install SDFix: double-click on the SDFix. If a “Security Warning window opens”, click on the Run button.
3. Follow the prompts.
4. Reboot your PC in to Safe mode.
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
5. Click Start -> Run,type the following text in type box: C:\SDFix\RunThis.bat
6. Press Enter or OK button.
7. When the tool is finished, it will produce a report for you.
Notes:
If this error message is displayed when running SDFix:
The command prompt has been disabled by your administrator. Press any key to continue . . .
Please goto Start Menu > Run > then copy and paste the following line: %systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press OK then run SDFix again
If the Command Prompt window flashes on then off again on XP or Windows2000
Please goto Start Menu > Run > then copy and paste the following line: %systemdrive%\SDFix\apps\FixPath.exe /Q Reboot and then run SDFix again
Quads