C:\Documents and Settings\Richard\
Desktop\New Folder\HijackThis.exe
put
HijackThis in e.g
C:\Program Files\HJT and
NOT on the Desktop!.
First
Read: Use these HJT-instructions when asked
The text underneath goes between the dotted lines of that post.
...................................................................................................
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.uqfcewheziji.uk/cEI_y8mleQIQjas1pMzmY8Tf5XAbdYrHMcHDKbxbj6VAqD1hrIjnMP5AuD18vSv0.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.glghdvvesrup.com/cEI_y8mleQKzJ9uYQ2Y606Ln/suGrBhifbqxMe4Tr4E.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
/P/U/ O2 - BHO: (no name) - {C31A7B3E-4F8F-FF5C-7B94-914FEF6402DB} - C:\DOCUME~1\Richard\APPLIC~1\
DEAFBU~1\Play delete.exe
/P/U/ O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\
MessengerPlus! 3\MsgPlus.exe"
/P/U/ O4 - HKLM\..\Run: [bolt iso dvd ping] C:\Documents and Settings\All Users\Application Data\
Tons each bolt iso\FreeRegs.exe
/P/U/ O4 - HKCU\..\Run: [dogwindow] C:\DOCUME~1\Richard\APPLIC~1\
FLAPAM~1\Open that.exe
Fix ALL your O16 - DPF: entries
Unless these IP-numbers are from your ISP, fix this O17
O17 - HKLM\System\CCS\Services\Tcpip\..\{39CB019C-971A-4826-9D63-0E7F111711B6}: NameServer = 205.188.146.145
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
...................................................................................................