I would appreciate too if you could specify what the running processes in the log do.(e.g. InCd.exe is a software I have installed with my cd-dvd writer)
Running processes:
KERNEL32.DLL - Windows Dynamic Link Library file
MSGSRV32.EXE - Windows file; handles 32-bit system messaging services
MPREXE.EXE - Windows file; handles certain network-related tasks
mmtask.tsk - Windows file; handles multitasking for multimedia applications
MSTASK.EXE - Windows' Task Scheduler
MDM.EXE - Windows file; provides debugging support
EXPLORER.EXE - Windows Explorer; the Windows Graphical User Interface
TASKMON.EXE - Windows' Task Manager
SYSTRAY.EXE - Windows System Tray; displays date/time, etc. on the Task Bar
STIMON.EXE - Windows' Still Image Monitor; camera, scanner, etc. support component
PDVDSERV.EXE - Power DVD remote control support
INCD.EXE - Nero CD writing support fileJGRMLFS.EXE - WTF?? I don't like the looks of that one! See Below...
WFXCTL32.EXE - Displays WinFax icon in the System Tray
SPOOL32.EXE - Windows file; handles print spooling services
TAPISRV.EXE - Windows file; provides telephony support
WFXMOD32.EXE - Provides Symantec WinFax modem support
C:\HIJACKTHIS\HIJACKTHIS.EXE - Our friend.
C:\WINDOWS\JGRMLFS.EXE <-- Find this file in Explorer, right-click on it, and choose "Properties" from the pop-up menu. Look through the Properties tabs for any identifying information such as the name of the company which made the file; let us know what you find (or don't find).
Start hijackthis. Click on Config and then click on Miscellaneous Tools. Go to delete a file on reboot and enter c:\windows\tcplddh.exe; when prompted to reboot choose yes.
Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dr-search4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://dr-search4u.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dr-search4u.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dr-search4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://dr-search4u.com/index.htm
O4 - HKCU\..\Run: [jiqoktc] c:\windows\tcplddh.exe
Reboot, run HJT again, and post a fresh log.