Yeah, i can see you could well be having problems....
Is there any reason that you are not running SP2? it's a big download, but it is ALL about
security...
More on security, download the latest update for SUN Java - it is to fix security holes
also. From control panel >java, and click the update tab.
You're making it tough for youself being this wide open. Okay, enough scolding.. :) .. on
with the cleanup.
Not a bad collection, but nothing to boast about, really....:)
I put all my cleaners, scanners etc in the same partition as my program
files... if u only have a C: drive then open a new folder for this
stuff.. however, HT deserves a folder unto itself. Please do not run it
from the temp folder as you have done - it may miss a lot of stuff. A
point, if you don't do these all these steps some things may not get
fixed...
You may wish to save this to Notepad for the time being.
-I would like you to download CCleaner from
http://www.majorgeeks.com/download4191.html and put it in a new
folder.
-Go here and get Ewido 4 [free].:-
http://free.grisoft.com/doc/2/lng/us/tpl/v5
Install it alongside your other regular applications in Program Files,
because you should keep it for scanning once a week or so - put an icon
on your desktop.
So, Ewido:- start it; the main "Status" menu will appear. Select "Change
state" to inactivate 'Resident Shield' and 'Automatic Updates'. Click on
update tab and then Update Now. When it finishes click on scanner tab
and then Settings:- How to act- click on recommended action and set
Quarantine. For reports, set to generate after every scan and untick
only if threats found. Finally down on the tray right click the Ewido
icon and untick Start with windows, an then Exit it. Don't scan yet.
Ok, you're done with the net. Shut it down. Disconnect..... whatever...
Rclick your recycle bin and run CCleaner. [or go to its folder and
dclick ccleaner.exe] You will lose a lot of handy stuff like histories
etc... but there is a job to do...
Go into safe mode [Restart, key F8 immed after POST runs and select Safe
Mode and Enter.... You'll get a dark desktop with icons etc...]
Start Ewido, do the full system scan. Click "Apply all actions" to place
any infected files into Quarantine, and only then click on "Save Report"
to view all completed scans; click on the scan you just performed and
select "Save report."
Note: Close all open windows, programs, and DO NOT USE the computer
while Ewido is scanning. If Explorer or other programs are open during
the scan that means certain files will also be in use. Some malware will
insert itself and hide in areas that are "protected" by Windows when the
files are being used. This can hamper Ewido's ability to clean properly
and may result in reinfection.
And now, still in Safe Mode and with NOTHING else open, run Hijack This,
check the items i list below and Fix them. [if they still exist]
By nothing else open, i mean open the explorer folder of HT, start it by
dclicking the .exe, then CLOSE the explorer folder, close ALL apps
including browsers [you should be off the net anyway], and finally start
the scan.
Checkmark the following for fixing [if they still exist] and FIX them.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
\blank.htm
R3 - URLSearchHook: (no name) - {2263A239-4FD9-5458-81DF-64349471B3CE} -
C:\WINDOWS\System32\qifoext.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
- (no file)
O2 - BHO: (no name) - {2263A239-4FD9-5458-81DF-64349471B3CE} -
C:\WINDOWS\System32\qifoext.dll
O2 - BHO: (no name) - {40A2988E-C954-4DDE-BD08-453191805BB9} -
C:\WINDOWS\system32\durvil1.dll
O2 - BHO: (no name) - {6b962594-0e69-4ac4-b6f8-eae962809df4} -
C:\WINDOWS\system32\egaapi.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Szdla] C:\Documents and Settings\Steve\Application
Data\F?nts\m?config.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {400429E4-BED4-472E-93BF-F85AB8565DFF} -
http://www.terp17.com/ax/axo.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: egaapi - C:\WINDOWS\SYSTEM32\egaapi.dll
Finally go into this windows folder and delete these three files if they still exist. You
first will have to check "show hidden files and folders" via Tools > folder options > view...
C:\WINDOWS\System32\qifoext.dll
C:\WINDOWS\system32\durvil1.dll
C:\WINDOWS\system32\egaapi.dll
Done? then back to normal windows mode, run HT again and please post it.