ratm0751
First please place hijackthis in its own folder (you will need to create one) because the program makes backups and will make a mess of your desktop.
Start hijackthis, run it's scan again and place a checkmark in front of the folowing to fix:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {5E0C7C39-C6BE-59DC-6E6B-9693E7FACEDB} - C:\WINDOWS\system32\lzngromi.dll
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\System32\bridge.dll
O4 - HKLM\..\Run: [zuapbilh] C:\WINDOWS\anufqxsk.exe
O4 - HKLM\..\Run: [WinFavorites] c:\program files\winfavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: winlogon.exe
Close all windows except hijack and click "fix checked"
Reboot the computer to safe mode (tap f8 while booting) and delete the following files:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlogon.exe <- file
***note*** Don't delete the winlogon.exe from system32 folder...that one is a valid system file!
C:\WINDOWS\anufqxsk.exe <- file
c:\program files\winfavorites\WinFavorites.exe1 <- file and folder
C:\WINDOWS\Belt.exe <- file
Reboot the computer to normal windows.
Do you know what this file is?..I can't find any info about it.
c:\WINDOWS\System32\zzb.exe
If you don't...can you check it's properties? (right click> properties) and let me know...Thanks.
Also grab the programs I suggested in #4 to Sonny along with Spybot search and destroy and/or ad-aware. (I use both) all are free programs.
Ad-aware
Spybot
Follow advise for usage of those programs from #4
With spybot and ad-aware be sure to update them before running them.
To prevent conflicts with your antivirus; temporarily disable it while scanning with spybot or ad-aware.
Post a new log when done please.
I never give up!