Combofix has now revealed the hidden files for me
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open
notepad and copy/paste the text in the quotebox below into it:
Firefox::
FF - ProfilePath - c:\dokumente und einstellungen\Desktop\Anwendungsdaten\Mozilla\Firefox\Profiles\orytotb2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.claro-search.com/?affID=114506&tt=5112_4&babsrc=HP_clro&mntrId=4007f783000000000000bc05430e5d1c
FF - user.js: extensions.claro.tlbrSrchUrl -
FF - user.js: extensions.claro.id - 4007f783000000000000bc05430e5d1c
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15697
FF - user.js: extensions.claro.vrsn - 1.8.3.10
FF - user.js: extensions.claro.vrsni - 1.8.3.10
FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.1023:12
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - claro
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
Save this as
CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at
C:\ComboFix.txt which I will require in your next reply.