Hi pongo
Delete the following
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O4 - HKLM..\Run: [dllhostxp.exe] dllhostxp.exe
O4 - HKLM..\Run: [ajcnw.exe] C:\WINDOWS\System32\ajcnw.exe
Select the above items in HJT CLOSE all other windows and hit fix checked
Then delete files
C:\WINDOWS\System32\ajcnw.exe
dllhostxp.exe (possibly in system32)
(you may need to show all files and folders to get them)
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
Unable to find whois for this - if you know and are happy keep it O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.139 85.255.112.186
You should now be clear the 2 04’s were the trojan along with the BHO
If you have problems deleting the 2 files then Please download the Killbox by Option^Explicit.
Note:In the event you already have Killbox, this is a new version that I need you to download.
[*] Save it to your desktop.
[*] Please double-click Killbox.exe to run it.
[*] Select: [*]"Delete on Reboot[*] then Click on the “All Files” button.
[*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C
C:\WINDOWS\System32\ajcnw.exe
dllhostxp.exe
[*] Return to Killbox, go to the File menu, and choose “Paste from Clipboard”.
[*]Click the red-and-white “Delete File” button. Click “Yes” at the Delete on Reboot prompt. Click “OK” at any PendingRenameOperations prompt.
If your computer does not restart automatically, please restart it manually
Rebbot and run another HJT post the link and I’ll have a look. If you are clean you should download and install SP2