Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(
if there).
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) -
http://www.flashbeer.com.au/player/vivid_ocx.jpeg
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Itim-Huntingdon
O17 - HKLM\Software\..\Telephony: DomainName = Itim-Huntingdon
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Itim-Huntingdon
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = itim-huntingdon
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = itim-huntingdon
Fix the above 017 entries if you don`t recognise the domain.
Click on the fix checked button.
Close HJT.
Download the
DelinvFile utility and see if you can delete the file on your desktop.
Reboot your system and let us know the results.
Edit: Forgot to include link for DelinvFile utility. Fixed now.
Regards Howard
This thread is for the use of will824 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.