(sorry about that Alex, but it is a bad idea to remove stuff unless you know what it's doing. There are a few system entries that shouldn't be removed which you had marked)
Quote:
Originally Posted by Michael
oh and also a theory of mine- could there be some file or program or dll or crap that is responcable to delete and free up system memory after tasks are done? could this devise be damaged for me?
|
Not that I know of - you shouldn't need such a program anyway (when a process exits Windows goes and frees up usually all of the memory it was using).
Anyway, looking at your HijackThis log, it appears that you have been hit by a variant of CoolWebSearch. Download and run
CWShredder, which should kill it.
It also looks like Norton Internet Security or Norton AntiVirus is installed and running. It looks like it might be versoin 2002, but you may have an upgrade to that installed. Anyway, run Norton (there should be an icon for it in the start menu, under "Norton" or "Symantec"), and run LiveUpdate to ge the latest virus definitions. Then do a full system scan.
Also, download and run both
Spybot Search & Destroy and
Ad-Aware, and update both of them (the internal updateers should do the trick). Then do full system scans (might be called "in-depth" in Ad-Aware) with both of them. Do NOT be tempted by other spyware removers that you may see - most of those actually contain spyware and do more harm than good.
If you have any problems with updating those programs, or doing the system scans, then post here and let us know (some spyware tries to actively intefere with antivirus and antispyware).
Once that's done, if any of those programs find anything then please post details of it (like what nasty was found). Also post a new HijackThis log.
(BTW, the lines in HijackThis that caught my eye are the ones below. Don't remove them with HijackThis yet - it's better for them to be removed by spybot/adaware if detected by them, as some nasties hook deep into the system and can cause problems if not removed properly)
Code:
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?pgdoc (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://find4u.net/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://69.50.184.51/find4u/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://aifind.inf/?id=54
O4 - HKLM\..\Run: [Control] rundll32.exe C:\WINDOWS\SYSTEM\ctrlpan.dll,Restore ControlPanel
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\IMAGE.DLL,Install
O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\SYSTEM\SYSTEM.EXE
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\IMAGE.DLL,Install
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O21 - SSODL: DDE Control Module - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - (no file)