Click START > My Computer > Local Disc C: > Program Files
Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and Click ENTER.
HiJackThis then should be moved to this file C:\HiJackThis. It should not be run from another file. This is where backups will be saved in case they are needed and it won't save files to any other file name.
Secondly, you have programs that you have disabled by using msconfig. Please go back to msconfig and renable ALL start up programs. This is the only was we can be certain that all nasty programs have been removed. Once all this is finished then you can disable unnecessary programs, but for now we need to see everything in that auto start. So please re-enable those programs via msconfig.
Third, turn off background scanning of Windows Defender,
Ewido. These can be re-enabled later, but for now they should be turned off.
Fourth, turn off the program running from your "I" drive which is the mIRC Internet Relay Chat utility which allows you to connect to Internet based servers. This is a non-essential process and was NOT running during your first HJT scan.
Next go to C:\Windows\taskmgr.exe and remove the file noted in red. Don't delete the entire folder just that file.
Now go to C:\Programme\Prevx1\ and delete the file noted in Red.
Now run HJT again and place checkmarks next to the following entries if still present;
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {DA39029C-D291-A968-3FF4-D0990D5CB5FC} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Programme\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Task Manager Help (TskHlp) - Unknown owner - C:\WINDOWS\taskmgr.exe (file missing)
Now once you have placed those checkmarks click the FIX button. Exit HJT.
Reboot and run HJT again. Save that new log and post it here.


Reply With Quote