Review all instructions below before proceeding.
Run the following tool in SAFE MODE after downloading (save to desktop or print out these instructions):
Please download ATF Cleaner http://www.atribune.org/ccount/click.php?id=1 by Atribune.
This program is for XP and Windows 2000 only
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
- Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
Click the Empty Selected button.
If you use Firefox browser
- Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
- Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
Click the Empty Selected button.
NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
Many low risk cookies have been found - in Ewido they were deleted for you; in Panda you must manually delete them yourself or pay for their low cost subscription service.
You appear to have acquired song lyric links with inbedded downloader scripting code.
1) Please download the Killbox.
Unzip it to the desktop and run it.
2) Select "Delete on Reboot".
3) Then Click the "All Files" button.
4) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
5) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
C:\Recycled\Q330995.exe
H:\RISHI2\Vallabh hard dsk\LyriCS\whigfield\Lyrics WHIGFIELD - SEXY EYES Song Lyrics_files\CA01TMN6.htm
H:\RISHI2\Vallabh hard dsk\LyriCS\whigfield\Lyrics WHIGFIELD - SATURDAY NIGHT Song Lyrics_files\CALD7SMN.htm
H:\RISHI2\Vallabh hard dsk\LyriCS\goo goo dolls\Lyrics GOO GOO DOLLS - IRIS Song Lyrics_files\CAEB8P2J.htm
C:\WINDOWS\HELP\CHMRedir.chm
C:\WINDOWS\switchagreement.txt
C:\PROGRAM FILES\COMMON FILES\Totem Shared
6) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "Yes" to reboot next
BOOT INTO SAFE MODE:
Run ATF cleaner
Find and delete all FOLDER occurances of:
CONTENT.IE5
(for infected content located at:
H:\Documents and Settings\Internet\Local Settings\Temporary Internet Files\Content.IE5)
POST A REVISED HIJACKTHIS LOG for review:
Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.



