Boot into safe mode. See how HERE.
http://www.bleepingcomputer.com/forums/tutorial61.html
Turn off system restore.(XP/ME only) See how HERE.
http://www.bleepingcomputer.com/forums/tutorial56.html
In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.
http://www.bleepingcomputer.com/forums/tutorial62.html
Click start/run and type regsvr32 /u C:\WINDOWS\System32\nsj85.dll into the run box and press the enter key. Do this for the following entry as well.
C:\WINDOWS\System32\irsmenzy.dll
Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://cwshredder.net/cwshredder/cwschronicles.html#smartsearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
http://localhost;
O2 - BHO: Katze - {2A611133-1C57-4DFB-A05C-07EE3BFE6D34} - C:\WINDOWS\System32\nsj85.dll
O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\System32\irsmenzy.dll (file missing)
O4 - HKLM\..\Run: [inst_] C:\WINDOWS\System32\inst_
O4 - HKLM\..\Run: [loader.exeSetup.exeR] C:\WINDOWS\System32\loader.exeSetup.exeR
O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\System32\loadadv64
O4 - HKLM\..\Run: [mcspy.exeion.exeg] C:\WINDOWS\System32\mcspy.exeion.exeg
O4 - HKLM\..\Run: [win.exeouter.exeg] C:\WINDOWS\System32\win.exeouter.exeg
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O17 - HKLM\System\CCS\Services\Tcpip\..\{A40AB765-2B6B-4979-B306-AEAA9B4B5E1D}: NameServer = 151.164.1.8,206.13.28.12
Only fix this entry, if it doesn`t belong to your ISP.
O20 - AppInit_DLLs: repairs302972988.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
Click on the fix checked button.
Close HJT.
Locate and delete the following bold files(if there).
C:\WINDOWS\System32\
nsj85.dll
C:\WINDOWS\System32\
irsmenzy.dll
C:\WINDOWS\System32\
inst_
C:\WINDOWS\System32\
loader.exeSetup.exeR
C:\WINDOWS\System32\
loadadv64
C:\WINDOWS\System32\
mcspy.exeion.exeg
C:\WINDOWS\System32\
win.exeouter.exeg
Reboot into normal mode and turn system restore back on.
Please post a fresh HJT log.
Regards Howard
