An analysis of your HJT log shows the following problems :
We didn’t detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall.
Platform: Windows XP SP2 (WinNT 5.01.2600)
A newer version of service pack is available. Service packs increase the safety of your system. Visit Microsoft’s windowsupdate site to download the newest version of the service pack. SP3 has been available for more than a year. I suggest that when the computer is clean again that it be upgraded to SP3.
F2 - REG:system.ini: Shell=
This is a common place for trojans, hijackers, and spyware to launch from. It should be noted that the Userinit and the Shell F2 entries will not show in HijackThis unless there is a non-whitelisted value listed.
m1eqos3.exe, also uses the name HERSS.EXE, http://www.prevx.com/filenames/1582978840253270691-X1/M1EQOS3.EXE.html
So fix the 04 entry suggested by Charlie, reboot
Also run autorun eater, it runs in real time,it will find and delete bad autorun.inf files. Also plug in any removable flash drives. This is probably where you got infected
Just for info, I’ve just installed Autorun Eater. Nice clean install. Full list of files added and registry changes made indicated in the help file. Quite impressed by this attention to detail.
The sounds can be turned off.
I have used flash-disinfector, too, it’s great. But this tool, if it works (and the user reviews plus micky77’s recommendation indicates that it will) is a wee beauty.