I done exactly what you told me. it tooks me 3 hours and i rebooted... but it seems to be persistent viruses.... My task manger is still blocked.
I need info on theses : VXH8JKDQ7.exe and KERNELS32.exe
Also, windows always pop this up when i restart my os -> cannot find c:\SLINSTALLER.exe
Here is a fresh log with the habitual websites i never heard of :
Logfile of HijackThis v1.99.1
Scan saved at 03:51:25, on 2005-05-01
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\kernels32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\rasautou.exe
C:\Documents and Settings\mizu\Desktop\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3
www.iframeprofit.comO1 - Hosts: 127.0.0.3
www.loadcash.bizO1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3
www.traffic2cash.bizO1 - Hosts: 127.0.0.3
www.awmcash.bizO1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3
www.iframedollars.bizO1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3
www.virgin-tgp.netO1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3
www.aaasexypics.comO1 - Hosts: 127.0.0.3
www.pizdato.bizO1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3
www.vesbiz.bizO1 - Hosts: 127.0.0.3
www.newiframe.bizO1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3
www.iframe.bizO1 - Hosts: 127.0.0.3
www.allforadult.comO1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3
www.sexfiles.nuO1 - Hosts: 127.0.0.3
www.awmdabest.comO1 - Hosts: 127.0.0.3
www.autoescrowpay.comO1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3
www.iframeprofit.comO1 - Hosts: 127.0.0.3
www.loadcash.bizO1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3
www.traffic2cash.bizO1 - Hosts: 127.0.0.3
www.awmcash.bizO1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3
www.iframedollars.bizO1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3
www.virgin-tgp.netO1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3
www.aaasexypics.comO1 - Hosts: 127.0.0.3
www.pizdato.bizO1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3
www.vesbiz.bizO1 - Hosts: 127.0.0.3
www.newiframe.bizO1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3
www.iframe.bizO1 - Hosts: 127.0.0.3
www.allforadult.comO1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3
www.sexfiles.nuO1 - Hosts: 127.0.0.3
www.awmdabest.comO1 - Hosts: 127.0.0.3
www.autoescrowpay.comO1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 64.91.255.87
www.dcsresearch.comO1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3
www.iframeprofit.comO1 - Hosts: 127.0.0.3
www.loadcash.bizO1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3
www.traffic2cash.bizO1 - Hosts: 127.0.0.3
www.awmcash.bizO1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3
www.iframedollars.bizO1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3
www.virgin-tgp.netO1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3
www.aaasexypics.comO1 - Hosts: 127.0.0.3
www.pizdato.bizO1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3
www.vesbiz.bizO1 - Hosts: 127.0.0.3
www.newiframe.bizO1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3
www.iframe.bizO1 - Hosts: 127.0.0.3
www.allforadult.comO1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3
www.sexfiles.nuO1 - Hosts: 127.0.0.3
www.awmdabest.comO1 - Hosts: 127.0.0.3
www.autoescrowpay.comO1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3
www.iframeprofit.comO1 - Hosts: 127.0.0.3
www.loadcash.bizO1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3
www.traffic2cash.bizO1 - Hosts: 127.0.0.3
www.awmcash.bizO1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3
www.iframedollars.bizO1 - Hosts: 127.0.0.3 iframedollars.biz
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\kernels32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe