hi. i don't know what to say, but i really hope somebody here can help me.
i had a hijacker, my ie start page was something like search for, i ran hijackthis and it kept telling me i had 2 BHO
O2 - BHO: (no name) - {D6D60BCD-DC0B-CE73-CEF1-F32318178686} - C:\WINDOWS\System32\nvwrsulx.dll, and another one. a dll that was saved on my system32 folder, named ohjikl.dll or something like that (i didn't save any logs) i was never able to delete it, because windows would say it was being used by a program, so today, i turned on my computer and was able to delete it, really fast. i opened IE, and the search for adaware was gone, but so was my ability to do almost anything, now i can't drag & drop files on any folder, start an msn conversation, when i minimize programs they don't show up on the taskbar, and more. i tried restore system, but it freezes everytime i open it. i don't know what to do, i've searched online for the .dll i deleted, but i'vent had much luck.
That's my computer's log:
Logfile of HijackThis v1.97.7
Scan saved at 03:33:47 p.m., on 04/02/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\ARCHIV~1\ARCHIV~1\AOL\ACS\AOLacsd.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Archivos de programa\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\slserv.exe
C:\ARCHIV~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Archivos comunes\AOL\ACS\AOLDial.exe
C:\Didier\Instalers\MSN PLUS\MsgPlus.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\America Online 9.0\waol.exe
C:\Archivos de programa\America Online 9.0\shellmon.exe
C:\Archivos de programa\Archivos comunes\Aol\aoltpspd.exe
C:\WINDOWS\slrundll.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis.exe
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O2 - BHO: (no name) - {D6D60BCD-DC0B-CE73-CEF1-F32318178686} - C:\WINDOWS\System32\nvwrsulx.dll
O4 - HKLM\..\Run: [AOLDialer] C:\Archivos de programa\Archivos comunes\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Didier\Instalers\MSN PLUS\MsgPlus.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Didier\Instalers\MSN PLUS\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [SpySweeper] "C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: cono de Bandeja America Online México 9.0 .lnk = C:\Archivos de programa\America Online 9.0\aoltray.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MS&N Messenger Service (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab27571.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66FF2507-5305-42A8-9F86-B4953CA513D8}: NameServer = 205.188.146.145
O17 - HKLM\System\CS2\Services\Tcpip\..\{66FF2507-5305-42A8-9F86-B4953CA513D8}: NameServer = 205.188.146.145
i really hope somebody can help me please, but if there's not other way, do i've to uninstall windows? or format my disk drive? thanks..