Let's have a look at this for you.
Before fixing things with HijackThis Please Do the Following:
Show hidden files and folders:
For XP:- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders.
- If you see a warning message, click Yes.
- Click Apply.
- Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).
How to disable system restore:
WinXP.- Click the Start button.
- Right-click My Computer, and then click Properties.
- On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Clean up unneccesary files and folders
Please download
CCleaner
And download this tool but don't run it yet:
http://sarc.com/avcenter/venc/data/adware.istbar.html
And please download AproposFix.exe - but again do NOT run it yet.
http://swandog46.geekstogo.com/aproposfix.exe
Now uninstall "SurfAccuracy" in add/remove programs.
Then boot in safemode (hit f8 when booting up)
Once in Safe Mode, double-click aproposfix.exe and unzip it to the desktop.
Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.
Also now run the Symantec istbarfix tool.
Click Start>Run and type in: services.msc
Click OK
In the Services window find:
A78ddcktnowa
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open
HJT and click config > misc tools > ?delete an NT service?
Copy and past:
A78ddcktnowa
Click OK.
and then fix these with
hjt:
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - (no file)
O4 - HKLM\..\Run: [436T32Q] h32ert2.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O23 - Service: A78ddcktnowa - - (no file)
Then delete the folder in bold , and do a manuall search for:
h32ert2.exe and delete what you find.
Then run Ccleaner.
Reboot and post a new
hjt log and along with the entire contents of the log.txt file in the aproposfix folder by attaching them to a post please.