HiJack This Attached - Pls. Help!

Code: Logfile of Trend Micro jackTs v2.0.0 (BETA)Scan saved at 3:11:33 PM, on 6/4/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winLogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program... ... The 017's are unregistered domain names. O4 - Startup: Saflok_CRS.lnk = C:\Program Files\Saflok\Saflok_CRS.exe O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = reh.ed-ms.com O17 - HKLM\Software\..\Telephony: DomainName = reh.ed-ms.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Last night some needed files in our inetpub directory were removed.I need to know where these files went.Are there any kind of Log files that could tell me if a certain oso.exe, autorun.inf keep appearing undeletable Help with virus a.exe and c.exe Help with Hijack This Log go.google.com Two programs titled: Best Zoo Porn and Quality porn are being downloaded. http://pcialliance.org/hijack-this/hijack-this-log-attached-please-help.html

Grateful for your help.Logfile of HijackThis v1.97.7Scan saved at 18:39:21, on 14/05/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16441)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Spyware Doctor\sdhelp.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Ulead

Click on the View tab and make sure that "Show hidden files and folders" is checked.

Please ensure that you allow it permission to do so.-- If you get a warning from your anti-virus while DSS is scanning, please allow DSS to continue as the scan is safe. Now click "Apply to all folders" Click "Apply" then "OK" Now find and delete: The C:\WINDOWS\System32\dp-k13w13.exe file The C:\WINDOWS\System32\wtsit.exe file Also in safe mode navigate to the C:\documents and settings\bob synowiec\local

Someone told me that this is just normal HP crap - but at one point i was seeing compressed zip folders which contained all my personal pictures and word documents.

Remove everything it finds. Then go here and download Spybot Search & Destroy.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next) Restart your computer.

ESET doesn't launch at startup and the bug seems to be adding exclusions to all the virus software I have that prevent them from detecting it. ( I was surprised that

The problems I am having are - that when I surf I often get redirected to false sites.(I only use Mozilla firefox to surf the web) I could not log onto How to get started Open Forum Hints and Tips Feedback & Announcements Web User magazine feature suggestions Security Security & Privacy Close all windows except HijackThis and click "Fix checked" R3 - Default URLSearchHook is missing O1 - Hosts: search.netscape.com12.129.205.209 sitefinder.verisign.com O4 - HKLM\..\Run: [s0eV] C:\documents and settings\bob synowiec\local settings\temp\s0eV.exe O4 I have ESET smart security - that never finds the problems - but today I ran Adaware pro and it picked up the win32.agent trojan.

