Hi,
I would add to Ben's items and say there are more that should be fixed.
I believe all of this is bad:
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe
O1 - Hosts: auto.search.msn.com 127.0.0.1
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Programme\CxtPls\cxtpls.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\GEMEIN~1\WinTools\WToolsB.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: (no name) - {FA5C6032-A7FD-D922-D095-D10FD6E51DC8} - C:\WINDOWS\System32\dldzvd.dll
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{87136014-7009-4179-8D52-C54704A63DCA}\SVCHOST.EXE
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\GEMEIN~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Programme\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [37oQ35P] odescfg.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{343390D9-6724-44AF-9A5F-90C44A385CF4}\SECURITY.EXE
O13 - DefaultPrefix:
O13 -
O13 - Home Prefix:
O13 - Mosaic Prefix:
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted IP range: 67.19.178.84 (HKLM)
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) -
O21 - SSODL: System - {C095DE02-F306-4546-B677-A005FCEB1EC5} - vr_sys.dll (file missing)
Also I believe all of these files/folders are bad and should be deleted:
C:\WINDOWS\System32\vxh8jkdq6.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\Services\{87136014-7009-4179-8D52-C54704A63DCA} <== folder
C:\WINDOWS\System\svchost.exe
C:\Program Files\Internet Optimizer <==== folder
C:\PROGRA~1\GEMEIN~1\WinTools <== folder
C:\Programme\BullsEye Network <== folder
msxct.exe <= file, will have to locate
odescfg.exe <= file, will have to locate
C:\Program Files\AutoUpdate <== folder
C:\WINDOWS\System32\Services\{343390D9-6724-44AF-9A5F-90C44A385CF4} <== folder
Hijackthis may not fix all the trusted zone entries. If that happens try this:
DelDomains.inf:
Link:
Page sub heading: To remove all the sites listed in the Restricted Zone
Additional wintools notes:
You have enough stuff here that I think you would benefit from going through the steps in faq608-4650.
-------------------------------------
It's 10 O'Clock ( somewhere! ).
Are your registry and data backed up?