Hya Madnz , lets see what we can do.
Before fixing things with HijackThis Please Do the Following:
Show hidden files and folders:
For XP:- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders.
- If you see a warning message, click Yes.
- Click Apply.
- Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).
How to disable system restore:
WinXP.- Click the Start button.
- Right-click My Computer, and then click Properties.
- On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please download
CCleaner
You might have a
LOP infection that
often comes together with Messenger Plus. To remove it we will try the simple way first.
1.
Go to Add/Remove programs.
Double click on "Messenger Plus!" (or click on Remove)
(see quote below!)
2. The "Messenger Plus! - Setup" is now displayed.
Click on the Uninstall button.
Note: options displayed on the first screen are not related to the sponsor program.
3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen,
you have to type the code that is displayed. Once you enter the code, press Uninstall.
4. If you entered the code properly,
the program will ask you to confirm that you want to uninstall.
You must answer "Yes" to this question, else, you won't have another chance of uninstalling.
5.
To complete the uninstallation,
follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete,
restart your computer and,
hopefully one nasty infection is gone.
When removing Lop.com from the Add/Remove screen it may not show up as Messenger Plus instead also look for these and remove them:
Window Search
Window Searching
Lop.com
LOP SEARCH
Browser Enhancer
Ultimate Browser Enhancer
L.O P. Un insta11
L O.P. Un instal1
Live 0n line Portal
Live.0nli ne Porta1
Window Active
Finally there is a step in the removal process of Messneger Plus where the sponsor asks if you want to uninstall that aswell, You have to click YES to this part of the removal process
If you dont do this corretly then you will have no other choice but to reinstall Messenger Plus and then go through the whole removal process again from the start.
Then boot in safemode (hit f8 when boting up) and fix these with
hjt:
O4 - HKLM\..\Run: [dmuzb.exe] C:\WINDOWS\system32\dmuzb.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC0F5417-9811-4661-8D15-E94F251F2C96}: NameServer = 85.255.113.123,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC245462-9A3F-4CE8-9967-DB85A75C2BB6}: NameServer = 85.255.113.123,85.255.112.76
Then run ccleaner , and delete the file in bold.
Then post a new
hjt log please.