kjames74,
Hi and welcome to the Daniweb forums :).
-
The header for HiJackThis is very important: It helps to determine what steps might need to be taken to better secure your system, and provide more efficient cleanup procedures. For example, some files, which on standard on one platform, may indicate a virus or trojan on another. So, be sure to include this information with any future posts.
===============
Go to www.trendmicro.com , and then:
1. Click "Free Online Scan".
2. Click "Scan now, it's free".
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) "Auto Clean".
3. Click "Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
===============
Download, unzip to your desktop About:Buster and run it, then:
1. Click "Update".
2. Click "Check For Update"
(If no new version is available, skip to step #4.)
3. Click "Download Update", and wait for it to be installed.
4. Click "Start".
(Wait for the initial ADS scan to complete.)
5. Click "Yes", to shutdown any IE session currently open.
(Wait for the about:blank scan to complete.)
6. Click "Ok", to scan once more.
7. Click "Yes", to shutdown any IE sessions currently open.
8. Click "Yes", to begin the second pass.
9. Click "Save log", and post this log back along with your new log.
10. Click "Exit".
11. Click "Exit".
12. "Reboot"..
===============
Run HiJackThis, click "Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\rflwk.dll/sp.html#52409
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {C17618EA-80F0-B763-1419-F55243440287} - C:\WINDOWS\system32\sysit32.dll
O2 - BHO: Class - {E85F1A0E-4BF7-9FC7-5FC6-F9CE2788F77D} - C:\WINDOWS\system32\ipxw32.dll
O4 - HKLM\..\Run: [winxk32.exe] C:\WINDOWS\winxk32.exe
O4 - HKLM\..\RunOnce: [winlw32.exe] C:\WINDOWS\winlw32.exe
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipzp.exe" /s (file missing)
Now, with all windows closed except HiJackThis, click "Fix checked".
===============
Locate and delete the following item(s), if present. Make sure your able to " view system and hidden files/ folders: "
files...
C:\WINDOWS\winxk32.exe
C:\WINDOWS\winlw32.exe
C:\WINDOWS\system32\rflwk.dll
C:\WINDOWS\system32\sysit32.dll
C:\WINDOWS\system32\ipxw32.dll
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in " Safe Mode ".
-
Reboot.
===============
After rebooting your PC, rescan with hijackthis and post a new log.
Let me know how things are now.