First download
Ccleaner
Before using Hijack This Can you please do this for me:
Show hidden files and folders:
For XP:
1.On the Tools menu in Windows Explorer, click Folder Options.
2.Click the View tab.
3.Under Hidden files and folders, click Show hidden files and folders.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.
Then disable system restore to prevent re-infection.
(if you have/use it.)
(you can turn it back on when youre pc is clean).
How to disable system restore:
WinXP.
Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Then click Start>Run and type in: services.msc
Click OK
In the Services window find: (one by one)
ISDSMM
Local Security Authority Server
MSGSERVICE
Sound Sservice Driver
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Then boot in safemode (hit f8 when booting up)
Open
HJT and click config > misc tools > ?delete an NT service?
Copy and past: (one by one)
Sysinternals
LSA Server
MSGSERVICE
Sound Service
Click OK.
and then fix these with Hijackthis:
O4 - HKCU\..\Run: [setupPuzzleBlast.exe] C:\
INTERN~1\PUZZLE~1.EXE /r
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O23 - Service: ISDSMM - Sysinternals -
www.sysinternals.com - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
ISDSMM.exe
O23 - Service: Local Security Authority Server (LSA Server) - Unknown owner - C:\WINDOWS\System32\
lsasrv.exe (file missing)
O23 - Service: MSGSERVICE - Unknown owner - C:\WINDOWS\
msgsrv.exe
O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\
cfmon.exe (file missing)
And delete the files/folders in bold , after that run Ccleaner.
Reboot and post a new
HJT log please.