http://photobucket.com/albums/v735/Dragonfire43560/?action=view&current=7.gif

this messege comes up at random times and it apears to be in spanish. I also get this esxplorer icon on my desktop. I ran all my virus scanners and stuff. here is log

Logfile of HijackThis v1.99.1
Scan saved at 4:12:16 AM, on 10/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CRACK] \WINDOWS\system32\config\crack.lnk
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [Content connector] C:\DOCUME~1\Akram\LOCALS~1\Temp\9742.exe -a
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.linkautomatici.com
O15 - Trusted Zone:
O15 - Trusted Zone:
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Dani AI

Generated

Short diagnosis and immediate actions (based on ’s description and the supplied HijackThis log): the symptoms point to a small trojan or browser helper that persists via startup/IE add‑ons and can show scare/popups or create desktop shortcuts. Priority is containment: cut the infected machine off the network and avoid calling numbers or running any installers shown by popups. Then boot to Safe Mode before attempting deeper removal. (ftc.gov)

Recommended removal workflow (ordered, repeat as needed):

  1. Isolate the machine (unplug Ethernet / disable Wi‑Fi).
  2. Boot Safe Mode (F8 on XP-era systems) and run up‑to‑date on‑demand scanners — start with a Threat Scan from Malwarebytes and an on‑demand run of Microsoft Safety Scanner (save the scanner on a clean PC and run from USB if the infected machine blocks downloads).
  3. After quarantining what the scanners find, use Autoruns (Sysinternals) to inspect and disable unknown startup entries, browser helper objects and scheduled tasks; don’t delete files until their location is confirmed.
  4. Reboot normally, re‑scan and repeat until no detections remain.

References for tools and scan types: Malwarebytes Threat Scan, Microsoft Safety Scanner, Autoruns (Sysinternals). (support.malwarebytes.com)

If automated removal fails or persistence remains: back up only personal documents (do not copy executables or unknown installers) to external media scanned from a known‑clean machine, then perform a clean OS reinstall or upgrade to a supported Windows version — Windows XP is no longer supported and remains risky to keep online. After recovery, change all important passwords and check home router DNS/admin settings for tampering. (learn.microsoft.com)

When to get expert help: sanitize and post the HijackThis/FRST logs (no binaries) to a reputable malware‑removal forum for human analysis (for example, BleepingComputer’s removal forum) or engage a trusted local technician; don’t run random “fix” scripts from unknown sites. (bleepingcomputer.com)

Quick cautions

  • Do not run any “crack” or unknown executables seen on the PC; those are common infection vectors.
  • Do not rely on a single scan report to declare a system clean; persistence mechanisms can survive initial removals.

This summary gives a concise, modern removal path grounded in the thread’s evidence and current tool guidance.

oh and i discovered this virus is associated with internet explorer. I use mozilla so i dont know how it got there. I went to this site, http://housecall.trendmicro.com/, and did the scan. It detected 1 infected file and i deleted it. I also ran Avast anti viral and that deleted some stuff. Im not convinced that its gone though, can you just look through my HJT and tell me what you thinkk, thanks.

bump please help!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.