You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.
Turn off system restore.(XP/ME only) See how here.>
http://www.bleepingcomputer.com/forums/tutorial56.html
Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.>
http://www.bleepingcomputer.com/forums/tutorial61.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.>
http://www.bleepingcomputer.com/forums/tutorial62.html
Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).
F2 - REG:system.ini: Shell=Explorer.exe
F3 - REG:win.ini: load=,
F3 - REG:win.ini: run=,
O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\EDUARDO\Mis documentos\mario y natalia\mario y natalia\bit tor\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\DOCUME~1\Prodigy\CONFIG~1\Temp\~AceTemp\h-reb11a-2006-05-272\RegistryBooster. exe /S
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - Winlogon Notify: SharedDlls - C:\WINDOWS\system32\phgfilt.dll (file missing)
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\r2p8lc7u1f.dll (file missing)
Click on the fix checked button.
Close HJT.
Reboot into normal mode, turn system restore back on and rehide your protected OS files.
Post a fresh HJT log and let me know how your system is running.
Regards Howard
This thread is for the use of dontknowjack only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.