Hi there Bizuca , welcome to PCHF.
Before fixing things with HijackThis Please Do the Following:
Show hidden files and folders:
For XP:- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders.
- If you see a warning message, click Yes.
- Click Apply.
- Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).
How to disable system restore:
WinXP.- Click the Start button.
- Right-click My Computer, and then click Properties.
- On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please download
CCleaner
Then first lets get rid of the mssearchnet.exe and nvctrl.exe:
Reboot youre pc - press F8 during boot, select "SAFE MODE WITH PROMPT"
Change directory to c:\windows\system32 (type cd windows <enter> then type cd system32 <enter>) [cd = Change Directory]
Type del mssearchnet.exe [del = delete]
Type del nvctrl.exe [del = delete]
Type cd\ [The "\" will back you up one directory or "folder"]
Type cd prefetch
Type del mssearchnet*
Type del nvctrl*
Type cd\ (twice, back to the c:\ prompt)
At the C:\ prompt Type REGEDIT
The registry editor will pop up
Use EDIT, then FIND >>> search for mssearchnet - delete all entries
Do it again, until the search function says nothing else found, it is in there several times (3 different places I think) Then do the same for nvctrl.exe.
Then reboot to normal mode.
Download Smitrem to your desktop
http://noahdfear.geekstogo.com/click...click.php?id=1
Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.
Then boot in "normal" safemode
Run SmitRem:
Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on
screen. Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply
And fix this with
hjt if still present:
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpE389.tmp
Delete the file in bold , and run ccleaner.
Reboot again and post the smitrem log plus a new
hjt log by attaching them to a post.