Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

51.

Solve : Virus Was "Removed" but Still seems to be around?

Answer»

Quote

was also having a problem where the 1/3rd top of my screen would go really light and the mouse pointer would slow if you went up in that area but it keeps coming and going. any ideas?
That sounds like a monitor or video card problem. Can you borrow a monitor from someone to try to isolate the problem. If another monitor works then it could be your video card.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you

**********************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
*****************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup UTILITY along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free SPACE in C drive)
******************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX PROGRAMS to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before IMMUNIZING. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!i got a new monitor so that problem is gone. however I am still getting redirected to other websites....thought this was gone but it still seems to be thereRe-run MBAM:

Code:
Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and PRESS Scan. Remove selected, and post the log in your next reply..

**********************************************
Also, please run adwCleaner again and post the log.been away....I'll run those programs and post the logs tonight. I called best buy and bitched to them about it and they acted cluelessMalwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 912121411

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

12/14/2012 6:38:17 PM
mbam-log-2012-12-14 (18-38-17).txt

Scan type: Full scan (C:\|)
Objects scanned: 553631
Time elapsed: 1 hour(s), 40 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
52.

Solve : DLL file causes lockup - potential malware??

Answer»

That's bad. First, you should defrag your harddrive. Next, run the chkdsk I've posted below. If that doesn't help, please take a look at this.

1. Click Start, click Run, type chkdsk /f /r, and then click OK.
2. At the command prompt, type Y to let the disk scanner run when you restart the computer.
3. Restart the computer.
4. Chkdsk will run.Yikes.

OK, I ran Disk Defragmenter and Chkdsk. The former ran overnight and after around 7 hours locked up.

So I RESEARCHED non-Windows defragging SOFTWARE - I found Auslogics here: http://download.cnet.com/Auslogics-Disk-Defrag/3000-2094_4-10567503.html?tag=mncol;5#editorsreview - which fixed 116 fragmented files without any problems (phew).

I also viewed the SYSTEM Health tab which tells me I have 3,185 Registry Errors (giving me a "Critical" status), and 3,569 Junk Files ("Serious" status).

I ran CHKDSK which told me it had fixed a file in the Winsxs folder, and also placed a couple of bad clusters in a bad cluster folder (the Windows equivalent of the naughty step?...) - I didn't get TIME to  read the full report before it booted up.

What next - try running Kaspersky or one of the other malware scans again?

Many THANKS
A
Quote

What next - try running Kaspersky or one of the other malware scans again?
No. The problem appears to be with the harddrive. You'll just have to wait and see if you have anymore BSOD's. Meanwhile, backup your important data to an external harddrive or DVD's just in case your harddrive gets worse.Hi SD

I went back to the start and ran Windows Security Essentials Full Scan and it went through without a hitch 

Hopefully that's the end of it...

Many many thanks for your advice and patience, you're a superstar.

Take care, all the best
AJust to be on the safe side, why not run a diagnostic on that harddrive.

Run hard drive diagnostics: tacktech.com
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here:

Note : If you do not know how to set your computer to boot from CD follow the steps here
Hi SD

Thanks for the info. I tried running the diagnostic tool but it didn't work - I emailed Toshiba support who told me the diagnostic tools on their site are only for Fujitsu branded Toshiba hard drives, not genuine Toshiba ones. They recommended I use a third party program like SeaTools...

...which is what I've done, and having run most of the scans without a hitch, when I run what appears to be the most comprehensive one, Long Generic, guess what..... It locks up, after about an hour of scanning.

I checked BlueScreenView and there are no new logs there.

Your thoughts welcome as always.

Many thanks
A



Sorry, I can't think of anything else.
53.

Solve : P. C Power Speed: fake? Malware? did homework; logs below?

Answer»

I went ahead and pulled up add/remove programs and deleted P. C. Power Speed, (which showed itself as version 1.0.0.27).  It seemed to work quickly and the undesired program no longer shows up as a desktop icon or in all programs. 

I wonder if it really did completely remove it???  Could something still be buried in the registry?  (I don't know much about working in the registry)

??

Follow up point:  my wife has an iPad she likes.  Along with her iPhome and iPod, she has put them all on Apple's, "iCloud."  Which she updates regularly from HER desktop computer.  Did you see any problems in her computer that were significant in the first place?  (regardless of P C Power Speed)  Do you see any reason that her other devices are infected with anything because of what you found in her computer?

Anything left to do?

Dennis Quote

Question: do you want me to use the program's listed, "uninstaller," or go into Control Panel and use, "add/remove," programs?
Check if the program has it's own uninstaller. If not, use the second method. Yes, it had it's own un-installer.  However, LAST night I decided that if there was one bad way to uninstall, you'd have said so.  Soooo..., in a quick note above,

"I went ahead and pulled up add/remove programs and deleted P. C. Power Speed, (which showed itself as version 1.0.0.27).  It seemed to work quickly and the undesired program no longer shows up as a desktop icon or in 'all programs.' 

I wonder if it really did completely remove it???  Could something still be buried in the registry?  (I don't know much about working in the registry)

??

Follow up point:  my wife has an iPad she likes.  Along with her iPhone and iPod, she has put them all on Apple's, "iCloud."  Which she updates regularly from the desktop computer you are working on here.  Did you see any problems in her computer that were significant in the first place
(regardless of P C Power Speed)?  Do you see any reason that her other devices could be infected with anything because of what you found in her computer?

Anything left to do?"

Dennis




Quote
I wonder if it really did completely remove it???  Could something still be buried in the registry?  (I don't know much about working in the registry)
Please run another scan with adwCleaner and post the log.
Quote
Do you see any reason that her other devices are infected with anything because of what you found in her computer?
No, there wasn't anything dangerous on the computer.Thank you again, Dave.  My wife and I both are getting pretty excited about this.

If I did it right again, here's the AdwCleaner log:

# AdwCleaner v2.011 - Logfile created 12/02/2012 at 18:48:42
# Updated 02/12/2012 by Xplode
# Operating SYSTEM : Microsoft Windows XP Service Pack 3 (32 bits)
# User : User - RCI-E295BA48E47
# Boot Mode : Normal
# Running from : C:\Documents and Settings\User\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF808758-C780-404C-A4EE-4526323FD9B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{438B047C-C041-4D15-98CF-A97C6B366C28}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{615E8AA1-6BB8-4A3D-A1CC-373194DB612C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB02BC6B-B0F0-4074-99E6-884B70FCB6AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]

***** [Internet Browsers] *****

-\\ Internet Explorer v7.0.6000.17114

[OK] Registry is clean.



OK? 

Dennis
Ok. We should do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
********************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click DISK Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
********************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the IMMUNIZE feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Dave:

I've done everything up to getting the Web of Trust which will be next.  I'll work through your suggestions for maintenance now.

I'm guessing that about winds it up.    ?? 

I really appreciate your help and my wife appreciates it even more !

Thank you,
DennisYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
54.

Solve : Malware infection following a moment of madness?

Answer»

Could you please run the ESET scan again and see what comes up?This time ESET scan found one threat.  Should we be expecting more?

C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP159\A0048884.EXE   a variant of Win32/Kryptik.AFAX trojan   cleaned by deleting - quarantined

Ps. Windows Search is still not displaying properly (crunched up search form) as shown in previous post.
Quote

Ps. Windows Search is still not displaying properly (crunched up search form) as shown in previous post.
Is that your only problem now? Could you send me a screenprint?

How to post screenshots or images
Apart from the Windows Search problem, I’m not currently noticing any remaining malbehavior.  Here are two screen images showing the scrunched up search form.

Start > Search > For Files or Folders...


Windows Explorer > Search





Ok. I can't make out those pictures but I would suggest that you create a new thread in this forum and see if someone can help you with that problem.
Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
***********************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup UTILITY along with other selections if you have chosen any. (if you had a LOT System Restore points, you will see a significant change in the free space in C drive)
************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being ADDED to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!While Combofix.was uninstalling it popped up a message box saying, “There’s a newer version of ComboFix available.  Would you like to update ComboFix”.  I clicked “No”.  Later it sounded an alarm and popped the message shown here.



I clicked “OK” and then it popped up another message as shown here.



Again I clicked “OK” and then it ran to completion.

I’m having trouble with the Windows updates.  I have “Automatic Updates” turned on and at every shut down, there are five Windows updates that take ages attempting to INSTALL but fail.  They are listed here.



Looking back through the updates history I see this has been happening from 16th November.

I realise these remaining problems may have nothing to do with lingering virus/malware so I will try to resolve them outside this thread.  Dave, please accept a big thank you from me for helping me through this.  It is much appreciated.

KeithIt reads " If an update failed to install, click the Failed icon to learn how to solve the problem. Did you do that?Yes, I did that for the update that fails but I’m not too concerned about a security update for the ancient .NET Framework 1.1, SP1.  I’m more worried by the other 4 (of the batch of 5) because they have green ticks next to them and yet keep reinstalling at every machine shutdown.  I don’t feel confident they have installed properly?  Maybe I need to try manually installing them.  Maybe I’ll end up reinstalling .NET 4.
I really don't understand why they keep installing. Have you tried contacting MS?Just for the record, and hopefully to help someone if they have similar problems:

I fixed the persistent Windows updates issue described above as follows.

I downloaded and run the .NET Framework Repair Tool, http://www.microsoft.com/en-us/download/details.aspx?id=30135 (this is actually Version 2, I believe).  The tool runs in stages and I had to do stage two, where it repairs .NET Framework (back to 2.0) before I got an improvement.  This fixed 4 of the five updates.  The remaining update is for .NET 1.1, so it makes sense the tool could not fix this.  For this update I simple blocked it from Windows Updater.

I also fixed the jusched.exe crashing problem.  I elected to send an error report, which sent me to a diagnostics page, which the sent me on to a new Java version page.  Installing this new version seems to have fixed it.

Keith
Good news.
55.

Solve : I guess I don't know how to clean a HDD after all.?

Answer»

Hi Dave,

Before I cleaned this computer, it reported "Kaspersky database corrupted" for any Kaspersky  utility.
When I opened most other programs the dialog box came up "Not support this platform", the keyboard
was disabled and "WINDOWS security can't be started" came up.
I cleaned the HDD with Eraser and used a partition program to delete System reserved partition and
reinstall the boot information. Installed win 7 and A/V three days ago and haven't seen anything that
isn't operating properly. Thanks again for all your help.It's too bad you had to resort to a re-format but now you have a new computer. Good luck. I'm SURPRISED no one mentioned NTFS error 55 from second post .
 
http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Windows+Operating+System&ProdVer=5.2.3790.1830&EvtID=55&EvtSrc=ntfs&LCID=1033

 File system CORRUPT , chkdsk /R , likely would have fixed you right up , as  the reformat seems to have done. Likely no virus or malware to BEGIN with!

56.

Solve : Partially disabled by malware. Can't follow your instructions?

Answer»

Quote

Once I am updated, should I run ComboFix or any of the other scans? ComboFix did not work previously because necessary files were missing or corrupted.

No, just let me know what happens after you get your updates.All updates are loaded. Computer seems fine now. What NEXT?Ok. Try to run Security Check again.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a NEW window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be SAVED here: C:\Program Files\ESET\ESET Online Scanner\log.txt
I ran Security Check without disabling Norton. Got this:
Results of screen317's Security Check version 0.99.57 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 9 
``````````````Antivirus/Firewall Check:``````````````[/u]
 Windows Security Center service is not running! This report may not be accurate!
 Windows Firewall Enabled! 
Norton Security Suite   
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````[/u]
 Java(TM) 6 Update 37 
 Java version out of Date!
 Adobe Reader 10.1.5 Adobe Reader out of Date! 
 Google Chrome 23.0.1271.95 
 Google Chrome 24.0.1312.57 
````````Process Check: objlist.exe by Laurent````````[/u] 
`````````````````System Health check`````````````````[/u]
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````[/u]

I then went back to normal mode and disabled Norton. Then was unable to get back into Safe mode because my touch pad and keyboard were inoperative. Tried Control-Alt-Delete and hard shutdown (removing battery). Cannot get into normal mode either. My computer is stuck on the log-in screen, with my password.
I guess I did not make myself clear. I could not run ESET because I could not get past my log-on screen. While booting up, I could use the arrow keys to get into Safe Mode, Normal Mode, etc, but once the log-on screen appeared, the touch-pad and the keys were disabled. Thus I could not log in to Windows 7.  Problem persisted despite removing and replacing battery, leaving battery out for a few minutes and replacing it, recharging overnight, etc. Checked with Lenovo forum; they suggested OneKey Recovery, which would return my machine to factory default. Then I would have to reinstall software and rebuild DATABASE from scratch. I have backups but the thumbdrives may have malware on them. Do you have any other suggestions? Thanks. Quote
they suggested OneKey Recovery, which would return my machine to factory default. Then I would have to reinstall software and rebuild database from scratch. I have backups but the thumbdrives may have malware on them. Do you have any other suggestions? Thanks.
The Recovery is probably your best bet. Just hold the SHIFT key while inserting your thumbdrives and this will prevent the transfer of infections. If you need to get into your computer to save any important data please let me know and I'll help you with that.OneKey Recovery implemented. Now building my databases. Computer does not appear to have a problem now. Thanks for all your help. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
57.

Solve : Error ox80070424?

Answer»

Quote

I  rebooted but did not help, should I RUN COMBO fix again....maybe in safe mode this TIME?
Yes, please try it in Safe Mode.
Quote
Allso.... I have a motorola (model sbg6580 router) If I am CORRECT it has a built in firewall, could thid be the problem?
No, that shouldn't bother ComboFix.
Quote
also I know how to reformatte my computer the only thing is I have problems connecting to the internet after a clean install.... If we have to do this will you walk me thru the internet PROCESS?,
If that is what you want to do.
58.

Solve : Pc slow after virus removal?

Answer»

Quote from: ashleemac on February 01, 2013, 03:47:08 PM

Do I delete the checked found items in RogueKiller?
Yes, please.
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the BUTTON.
•For alternate browsers only: (Microsoft INTERNET Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
No threats found
Scanned files 141654
Infected files 0
Cleaned files 0
Total scan time 01:19:20
Scan status finishedHow's the computer running now? Any other issues before we clean up?It's still PRETTY slow.Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.Okay, thanks. Ok. We can do some cleanup and you can let me know if the tips I gave you have helped or not.

Download this program and run it Uninstall COMBOFIX .It will remove ComboFix for you.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
I haven't had to do any system restores. I've run disk cleanup & defrag once again this afternoon. It's now running slower than ever  now it's now allowing me to lock, restart or shut down my system...Please do a hard shutdown(hold your power button until the computer stops) and try running in Safe Mode to see if it's still slow.
59.

Solve : FBI virus, black screen for desktop, etc HELP?

Answer»

At this point, your best bet would be save your important data and run The System Recover.I downloaded the AVG anit-virus and ran the scan...FOUND this....








Uploaded with ImageShack.usBut, you still have the black screen?This is from the sfc scan....  it will not let me open the log.
Yes, I still have the black screen, but I have ,my desktop if I run explorer from t/m.






Uploaded with ImageShack.us


Uploaded with ImageShack.usI don't know if this is helpful, but some of my updates cannot load successfully.




Uploaded with ImageShack.us

Also, I updated my version of Java followed the INSTRUCTIONS from ch on how to disable pop-ups thru about:config  (except the privacy popups.firstTime option was not htere yo change to false)  But I am still getting pop-ups. Quote

This is from the sfc scan....  it will not let me open the log.
That's ok. I didn't need to see the log. Did it ever ask for the OS disk while running SFC?
Quote
Yes, I still have the black screen, but I have ,my desktop if I run explorer from t/m.
There are two ways that I know off to fix that problem. One is to run the Recovery Console which will take your computer back to the day it was purchased. The other way is to edit the registry so that it will boot normally. This is DANGEROUS procedure and most experts don't even want to mess around in the Registry. I still think the Recovery would be your best bet. It's a bit more work but you end up with a new computer.There are two ways that I know off to fix that problem. One is to run the Recovery Console which will take your computer back to the day it was purchased. The other way is to edit the registry so that it will boot normally. This is dangerous procedure and most experts don't even want to mess around in the Registry. I still think the Recovery would be your best bet. It's a bit more work but you end up with a new computer.
[/quote]

Will this delete my photos and other programs I have downloaded? And I have found Microsoft office, it just won't let me run it. And no, it did not ask for my OS disk.

Could you please run aswMBR.exe again as described in Reply # 19 and post the log.
Quote
Will this delete my photos and other programs I have downloaded?
You should save your important photos, videos, music and other important data to DVD's. You should also make a note of which programs you have downloaded and install so that you can re-install them.aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-01 18:56:28
-----------------------------
18:56:28.326    OS Version: Windows 6.0.6001 Service Pack 1
18:56:28.326    Number of processors: 1 586 0x7F02
18:56:28.326    ComputerName: HAILEY-PC  UserName: Hailey
18:56:41.066    Initialize success
18:56:57.551    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000055
18:56:57.561    Disk 0 Vendor: ST325031 3.AH Size: 238475MB BusType: 3
18:56:57.601    Disk 0 MBR read successfully
18:56:57.621    Disk 0 MBR scan
18:56:57.631    Disk 0 Windows VISTA default MBR code
18:56:57.651    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       226674 MB offset 63
18:56:57.691    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        11797 MB offset 464230305
18:56:57.741    Disk 0 scanning sectors +488392065
18:56:57.841    Disk 0 scanning C:\Windows\system32\drivers
18:57:09.111    Service scanning
18:57:30.871    Modules scanning
18:57:41.741    Disk 0 trace - called modules:
18:57:41.771    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
18:57:41.781    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x853000c8]
18:57:41.791    3 CLASSPNP.SYS[86335745] -> nt!IofCallDriver -> [0x845ea688]
18:57:42.041    5 acpi.sys[862126a0] -> nt!IofCallDriver -> \Device\00000055[0x845ea9c0]
18:57:42.061    Scan finished successfully
18:58:48.851    Disk 0 MBR has been saved successfully to "C:\Users\Hailey\Documents\MBR.dat"
18:58:48.881    The log file has been saved successfully to "C:\Users\Hailey\Documents\aswMBR3.txt"

I've had my mentor take a look at your problem and he suggests that you should try another monitor on the computer. Your monitor is almost 5 years old and they can go bad. Another thing to try is located here.I fixed the issue with my videos not being able to go full screen (if I clicked on the full screen option, my screen would go black, had to hit escape to return to the screen with a minimized video) In settings, I DISABLED the hardware acceleration selection in adobe flash and now my videos can go full screen.Ok, I didn't know you were having problems with videos. Do you require any more assistance?If I do the Windows security reset, will I loose and pictures, downloads, etc.?  This is different from a system restore isn't it?
Reply #39 about the videos. Quote from: katlyn on February 02, 2013, 05:26:36 PM
If I do the Windows security reset, will I loose and pictures, downloads, etc.?  This is different from a system restore isn't it?
Reply #39 about the videos.
If you run the Recovery Console it will return your computer back to the date you bought it. As I stated before, you can save your photos, videos, music and your downloads to an external hard drive or DVD's . You should make a note of what programs you have installed so you may go back and re-install them afterwards.
System Restore will only return your computer to the state it was in to a specific date and will not harm your data. You could try that if you have a Restore point previous to the date you started having problems.

Run the Vista Recovery Console.

1. Eject and remove any DISCS or memory cards from your computer.

2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart".

3. Hold the "F8" key on your computer's keyboard as Windows Vista reboots.

4. Highlight and select "Repair your computer" choose your keyboard type and click "Next".

5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.
60.

Solve : My machine is still acting up even worse than before.?

Answer» To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides SYSTEM files and folders, and resets System Restore.
If this doesn't remove ComboFix, please let me KNOW.
***********************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility ALONG with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*****************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free TOOLS to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!SUPERDAVE:OKAY, I'm done.   Thanks again,   JIMYou're WELCOME. I will lock this thread. If you need it re-opened, please send me a pm.
61.

Solve : My AV keeps detecting a virus from the same pop-up on different sites?

Answer»

It shows that you have Authentium Antivirus and AVG Anti-Virus Free Edition 2013 plus the AV from Earthlink but it also shows that they are DISABLED. One of them should be enabled.

Quote

Total Fragmentation on Drive C:: 11% Defragment your hard drive soon! (Do NOT defrag if SSD!)
Don't ignore this warning and run your defragger soon. SSD means Solid State Drive.
You should turn on your Windows Firewall.
Please try to run ComboFix again even though you can't disable your AV's Quote from: SuperDave on January 19, 2013, 06:41:39 PM
It shows that you have Authentium Antivirus and AVG Anti-Virus Free Edition 2013 plus the AV from Earthlink but it also shows that they are disabled. One of them should be enabled.

I use AVG. I do not know how to enable/disable/use/uninstall/whatever the others. I had no IDEA they were installed until now. And I don't see where it says they're disabled, besides for "On Access scanning". What is that?

Quote from: SuperDave on January 19, 2013, 06:41:39 PM
Please try to run ComboFix again even though you can't disable your AV's

It SURE sounds to me like ComboFix will mess up the computer, ESPECIALLY if my AV's aren't disabled. I have not encountered the pop-up since the second time (which was a month ago), can we skip that part, or is there a safer alternative or something?

I guess I will just use the Windows Firewall, and if I ever figure out what the other one is I'll use it. Quote
And I don't see where it says they're disabled, besides for "On Access scanning". What is that?
Quote
Authentium Antivirus               
AVG Anti-Virus Free Edition 2013   
ECHO is off.
EarthLink Anti-virus               
 Antivirus up to date! (On Access scanning disabled!)
On Access scanning disabled means that you have no AV to protect your computer while on-line. If you use AVG you should activate it now.
Quote
It sure sounds to me like ComboFix will mess up the computer, especially if my AV's aren't disabled
Not really. It will just mess up the scan a bit.
Quote
I guess I will just use the Windows Firewall, and if I ever figure out what the other one is I'll use it.
[/COLOR]
If you decide to use another firewall make sure you disable the Windows Firewall.

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A REPORT (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
Quote from: SuperDave on January 20, 2013, 06:30:09 PM
On Access scanning disabled means that you have no AV to protect your computer while on-line. If you use AVG you should activate it now.

How do I activate it? AVG is enabled, and it blocks sites if it finds something on them. I don't understand how it's not enabled?

AVG found something (It just said "Unknown") when I ran RogueKiller. Is that what you mean by "RogueKiller has been blocked"? Quote
How do I activate it? AVG is enabled, and it blocks sites if it finds something on them. I don't understand how it's not enabled?
Ok. The securty check showed that it was not enabled. Just want to make sure.
Quote
AVG found something (It just said "Unknown") when I ran RogueKiller. Is that what you mean by "RogueKiller has been blocked"?
Exactly. Please keep trying to run it
62.

Solve : ds-any-world.ngd.ysm.yahoodns.net?

Answer»

You're WELCOME. I will LOCK this THREAD. If you NEED it re-opened, please send me a pm.

63.

Solve : Bad Image - Application or DLL is not a valid windows Image?

Answer» SORRY, it didn't work.
I also get some error reports related to the installation failure the next time i start up and log in. The kind of report which windows wants to send in to Microsoft. Quote
Problem: A problem on your computer is preventing updates from being downloaded or installed
Solution: To fix the problem, try installing the updates again. If that doesn't work, use the Troubleshooter to try solve the problem.
Did you try running the Troubleshooter?No nothing, couldn't find ANYTHING by searching with the error code (Error Code: 0x643). Perhaps I should just reinstall windows? Quote from: EV on December 25, 2012, 12:32:48 PM
No nothing, couldn't find anything by searching with the error code (Error Code: 0x643). Perhaps I should just reinstall windows?
Perhaps that would be the best solution if you don't have too much data to backup and you have the OS DISK(s). I'll give it a shot. Quote from: EV on December 27, 2012, 09:56:43 AM
I'll give it a shot.
Ok. Let me know how it works out.I have, after a lot of hustling and some procrastination, managed to get my computer BACK online. I'm not encountering any of my previous problems. Quote from: EV on January 15, 2013, 01:27:02 PM
I have, after a lot of hustling and some procrastination, managed to get my computer back online. I'm not encountering any of my previous problems.
Did you wipe the drive and do a re-install?No, I just did a reinstall.
64.

Solve : I think my computer in infected with Pup.PlaySushi?

Answer»

It is safe to use. It's just that when a program doesn't have it's latest updates, it's more vulnerable to infections. I'm going to consult someone on this. Did you try going to MicroSoft about this?Yes, I have. They're basically telling me the same thing that's been said over and over in their forum threads.

Is there anything else I need to do about the viruses? Do I need to uninstall any of the PROGRAMS?

You don't know how much I appreciate your help and patience through all of this.  Ok. We can do some CLEANUP.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***************************************************
I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your BROWSER. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ENSURE you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
65.

Solve : CPU/RAM usage spikes, music files going bad, something suspicious??

Answer»

Quote from: Coco423 on March 31, 2018, 07:56:03 PM

I know my system is 64 bit. Do you want me to do the full install/uninstall one or the zip file?
Do the full install/uninstall version.Since I got the new battery, not getting as hot, no more blue screens. Local computer store said overheoverheatining my BSODs, but I ran into another problem. They said to CHARGE the new battery la or EIGHT hours for the first use, did that. Then tey said to use the battery until it was at 0%, to program the battery. Was doing that, after can use it on AC or battery and can switch as much as I want, charge 2-3 hrs. Except for one thing that arose jus a few minutes ago, PC suddenly shut off with new battery, on battery, when battery was still at about 20%. Not booting up on new battery at all now. Just shows a small flash of screen and shuts off again. By small, I mean 1-2 seconds. Any advice? Try AC despite what local computer store said? Would do eset and update and scan with MSE but don't have internet, and this that just arose. Quote
By small, I mean 1-2 seconds. Any advice? Try AC despite what local computer store said? Would do eset and update and scan with MSE but don't have internet, and this that just arose.
I would suspect that the battery is actually dead and not at 20%. Why can't you connect to the internet?I can connect to the internet, it's just thatI don't have the internet. Can't afford internet. I have to post this on a prepaid phone.

 ALSO, I got no critical battery warning or brightness decrease saying battery was almost dead, not sure if volume was turned down. Also, in the screen flash, I got a green battery light.

Saw that new battery voltage was slightly higher than old one (by 0.3) and the Wh was 32 less, 53 instead of 85. I thought to check the voltage. I am trying to cooperate, the best I can right now.Is it possible that your laptop is overheating? Can you hear the fans running?The laptop us not overheating now, not lately. I just check and check constantly. It was when I got the BSODs.Download BLUESCREENVIEW to your desktop.
BlueScreenView
unzip downloaded file and double click on BlueScreenView.exe to run the program.
when scanning is done, go to EDIT - Select All
Go to FILE - SAVE Selected Items, and save the report as BSOD.txt
Open BSOD.txt in Notepad, copy all of the CONTENT, and paste it into your next reply.
Will still download, but said not getting them now. Quote from: Coco423 on April 19, 2018, 05:51:04 PM
Will still download, but said not getting them now.
Sorry, I don't understand what you mean.I am not getting the BSODs now. But, will still install BlueScreenView.

Quote from: SuperDave on April 20, 2018, 12:38:40 PM
Sorry, I don't understand what you mean.
If you're not getting BSOD's don't bother with that scan. How is the computer working now?Hi Coco,

Did you buy an original Lenovo battery the correct one for your laptop?
OEM batteries can work if they are exactly the same specs as the original but it appears the one you received isn't.
Do you remember when you were asking in the hardware section about your laptop getting really hot and me explaining it could make it unreliable and/or damage the ATI graphics chip if you kept using it, Seems you have kept using it.
Did you get the over heating problem fixed by a technician?
With the on going problems over the last 3 months, once the laptop is fixed it would pay to use the Lenovo factory restore disks to reload windows.
*****Backup your important files first!*****  I let someone use it and they forgot how to turn the brightness up and pounded on it a couple months ago. Now I need a new hard drive.
66.

Solve : Hidden supervirus??

Answer»

You're welcome. I will LOCK this THREAD. If you NEED it re-opened, please send me a pm.

67.

Solve : UNWANTED ADS?

Answer»

try this Dave its how it came out.I don't see any photo.can you not see that PICTURE of my desktop google page with ADS down the right HAND side that is what im trying to get rid of.That looks normal for Google. You should be ABLE to right-click on each one and delete it. If not, RESET you Google to default.

68.

Solve : Pop-ups Re-directs?

Answer»

You're welcome. I will LOCK this THREAD. If you need it re-opened, please SEND me a pm.

69.

Solve : Need Help with spyware adds....?

Answer» BYE Bye
70.

Solve : Trojan in system file Removal not easy?

Answer»

Hi guys.  Good morning At least it is still morning here.

You are right FED I reinfected myself but I also picked up a Hacktool.Rootkit
The Hack tool Norton took care of but could you look at my HJT again?

I am looking to get rid of the msctl32.dll now

Logfile of HijackThis v1.99.1
Scan saved at 10:26:16 AM, on 06/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\henrietta\My Documents\Unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TELUS Internet Services
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - Startup: Norton Disk Doctor.LNK = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.telus.net/homepage
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1116734391647
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130015153638
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVO23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase PROTECTION (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec NETWORK Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

I think I need to get rid of :
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

Am I right?Good morning *yawn*  
Your log is fine, how is your computer?
(file missing is of no real concern)no emails GOING out so far. I just logged on but Norton is telling me I have a trojan and it is in my system files

msctl32.dll
But I am releived that I kept at it and found you guys to help me.  

I did a little more googling and realized it was a trojan that caused the emails
Learned a little about trojans turning my computer into a Zombie.Did Norton remove the trojan for you?No norton cant repair, remove or quarantine it.  This is its location

c:\windows\system32\msctl32.dllBTW the dirty little bugger is called  Trojan HorseGoogle for KillBox.exe, it's a small program, easy to use & will delete anything you want.Hi Guys.  I GOT rid of the Trojan Horse.  Used Norton in Safe mode and it removed it.  yeehaw!!   So far since doing that No blasted out going emails  Yippee  Knock on wood though LOL  
Once again thanks for all your help I am glad I found you   See you guys around:D
Thank you for the feedback Twylla.

71.

Solve : spyware promotions?

Answer»

Raze Spyware has gone.  Xsoftspy killed it on the first attempt.  This looks like a good tool.  After SCANNING over 130,000 objects on my HARD drive it found 69 intruders that AVG, Adaware and Spybot had missed.  It is not free, though, the scan is but you PAY for the surgery.

Thanks for the COMMENTS and advice.  I'll know where to TURN in future.  Blackbird.

72.

Solve : Panda Cloud Antivirus - Freeware Download?

Answer»

Check out the following website for info on how this cloud antivirus software works!

1. http://blog.cloudantivirus.com/2009/04/29/new-protection-model-explained/
2. http://blog.cloudantivirus.com/ Quote from: 2x3i5x on June 15, 2009, 12:42:19 PM

Cloud antivirus is a good idea --> also coming from a respected antivirus vendor. But yet, it'll need more TIME to develop, like all software does in its initial phases.

2x3i5x - We just released version 2.0 of Cloud Antivirus today, so you should check out the improvements. We have fixed the initial slow post-install scan some users experienced, CREATED an “undo” option for the recycle bin and more. This version does require a download (after uninstalling the current version). More details and the link to the download are up on our blog: http://blog.cloudantivirus.com/2009/06/30/cloud-antivirus-beta2-released/

Also, version 3.0 will be out in EARLY fall, so keep an eye out for that, as well. We’re working on some exciting stuff (and often requested features) for that version: new platforms (Windows7, 64bits), improved features, a new site, a Collective Intelligence real-time encyclopedia, etc.
I’m happy to tell you that we’ve officially launched Cloud Antivirus out of beta as of today. We’ve all been working hard over the last several months to bring you a number of key updates, including an UPDATED user interface, improved performance, real-time access to the latest malware detected in our user community, new Web site and online support forums. We’ve also made Cloud Antivirus compatible with Windows 7/64 bits, which was one of the top requests we received throughout the beta.

The download if you’re interested (it’s free!) is available on the Cloud Antivirus site: http://www.cloudantivirus.com. Also, if you have any questions or technical issues, please post them here and I’ll be sure to address them openly here in the forum. 
73.

Solve : HELP Virus Shutting down everything even MBAM etc.?

Answer»

Yes, please try ASKING how to boot from a USB in the Windows forum. You might COPY that LAST POST and add it to the new thread.

74.

Solve : internet explorer opens to www.syserrors.com?

Answer»

This might sound like a stupid idea but seen as the file is broken (the PSGuard licence) if i downloaded it again then when the file was ok DELETED it dya RECKON THATD work?
am grabbing at straws now. Quote

If worst comes to worst have you got the original Windows or recovery CD to reinstall?   :-/ :-/ :-/


What about this?   Seems like we're not MAKING much progress.Have you TRIED running Ewido in safe mode?Aidan Colyer.....  You hijackthis log indicates your using an older version of IE .....and you haven't got SP2 installed ........you should consider D/L SP2 as it has some very good features ......and then you could D/L antispyware Beta .........  http://www.microsoft.com/athome/security/spyware/software/default.mspx

dl65
75.

Solve : Boot fails post-restart after scan?

Answer»

On this laptop it was Windows Vista Home premiumI also have an external harddrive as well as a DVD burner on the other notebook...OK...I have the Vista Home premium disk which is spotless...the Toshiba Satellite P100 disk is scratchedYou're getting me confused. Do you have the OS disk for the disfunctional computer?yes1/ Click the Start button.

2/ From the Start Menu, Click All programs followed by Accessories.

3/ In the Accessories menu, Right Click on the Command Prompt option.

4/ From the drop down menu that appears, Click on the Run as administrator option.

5/ If you have the User Account Control (UAC) ENABLED you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

7/ A message will APPEAR stating that the SYSTEM scan will begin.

8/ Be patient because the scan may take some time.

9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

11/ After the scan has completed, Close the command prompt window.
I am running this thru Reatogo-X-PE as that is the only option available to me as I described earlier(it has Windows XP as the OS).  From Command Prompt, when I elect to Run As Administrator, it asks for a password which I have no knowledge of as this is Reatogo and nothing I set up.  I tried some of the obvious passwords such as admin, guest, password and just "ok" sans a password, but none of them work. Any ideas?What happens when you boot with your OS disk in?After booting with the Windows Vista OS disk in, I chose Startup Repair.  After searching for problems and then repairing problems, the computer restarted.  It is now back to the original loop of Toshiba screen> Windows Error Recovery> Microsoft screen> blue screen, followed by Toshiba screen, etc.. Under Windows Error Recovery, when attempting Safe Mode or Safe Mode with Networking or Command Prompt, the Windows system 32 files and drivers are loaded then "Please wait..." is indicated for 30sec, followed by blue screen then loop resumes as indicated above. Last Known Good Configuration and Start Windows Normally result in Microsoft screen then blue screen, etc. as indicated above.



I'm going to check with my colleagues about this problem.Startup Repair in the Windows Vista Home Premium disk fixed the issue. Quote

Startup Repair in the Windows Vista Home Premium disk fixed the issue.
That's good NEWS. So, everything is running well?ran an ad-aware scan which found one high-level threat, removed and restarted w/ no issues; then ran a malwarebytes' scan which found one high level threat, removed and restarted successfully; Windows Defender scan run w/ no threats detected; so far, more than one day of running well with no issues; the Startup Repair on the full Vista OS disk was successful, whereas that of the Restore Only disk was not (initial attempt).
76.

Solve : Everything is messed up!!!?

Answer»

Nothing really, i just rebooted and they CAME BACK, so i rebooted again, and they came back. Weired eh? They have been back now for about 2 days but i didnt want to SAY again in case they went. Also you might remeber that i said the red LED that told you if the computer was thinking was on CONSTANTLY, well that stopped about a week ago. Puzzeling really!Did you remove all spyware and viruses if PRESENT?

77.

Solve : firewall and spyware.?

Answer»

What did you do just prior to this popup?

http://support.microsoft.com/kb/310560Just what you said and then rebooted.Oh and also I had deselected in add/remove the zone alarm toolbar.What do I do? You have to give me time to reply....

After what step. HijackThis or the Java?

Have you used Msconfig?

Select Normal Startup mode.Sorry I was panicking.

Used msconfig earlier in the day to put a tick against teatime but when I GOT the below message I put it back to normal start up mode.

Then when I did all of what you said which was the trend thingy and the hijack I rebooted. I have not done the java thing yet.

After rebooting I got that message again.

Select Normal Startup Mode. Any time you change settings with Msconfig you will get that message. OK have put it back into normal and rebooted ....again.  LOL

I will do the java and c.c. cleaner thing tomorrow don't THINK I can cope with anymore tonight I am exhausted !!!!!

Just one final query. I used msconfig to remove msn MESSENGER from popping up every time the puter starts up as my son downloaded it plus xfire. So how do I stop them  popping up as I want them to just be there if and when needed.For a good Startup MANAGER open CCleaner then click Tools > Startup.

Click anything you don't want to run at startup then click Delete.

Msconfig is meant to be used for diagnosing problems. Using CCleaner will remove the startup from the Registry and cause less problems.Oh I see, thank you very much.

I cannot tell you how much I appreciate your PATIENCE and help.

I only found this forum when I did a google search and didn't know if it was UK or just US.

I will certainly do the rest of what you have advised tomorrow after work.

Once again many many thanks you are a hun. Jill xxx We have members from all over the world so you never know where the person you are talking to is from.

Let me know if you have any more questions.

78.

Solve : Trojan.Packed.NsAnti giving me problems. Please Help me?

Answer»

Your welcome.

Safe SURFING...

79.

Solve : Very slow computer, need help please!?

Answer»

Glad it worked.

Keep CCleaner, SUPERAntiSpyware and MalwareBytes. UPDATE and run a scan with MBAM and SAS EVERY other week or so and use CCleaner as a daily drive CLEANER to keep the junk files off of your computer.

You can REMOVE ANYTHING else.

80.

Solve : document appearing on my computer?

Answer»

Good MORNING -- I need help.  I discovered that someone had installed a program called Spector on my system -- the entire version.  My husband -- who I work for -- was the one who did it.  While that was for work -- and could care less -- now documents have gotten into his hands -- appearing that I wrote and supposedly that came off this computer -- which I did not.  How does that happen and how do I prevent it from happening again?  There were quite a few and are of such a nature that my husband actually believes that I wrote them -- something that if I had -- I would readily admit.  Our IT Director is the gentleman in question -- and while in our employ -- has been sent to very exclusive seminars on "HACKING" -- can someone assist with how this can be done and how to stop it. Quote

my husband actually believes that I wrote them
Wrote what exactly?

I am not exactly sure what the problem is. Do you want SpectorSoft removed or is someone stealing your work?My husband and I jointly own a company.  There were documents and files that were "supposedly" found on my computer -- which I have not seen.  But having read these documents -- I know that I did not write them --may be bi-polar -- but I would remember that stuff as it could result in the loss of jobs for over 50 people.  The IT Director had installed a program called Spector Soft on my system -- which has since been removed and prevention programs put in place to prevent that from happening again.

My question -- could someone (IT Director) at this point -- have written these documents and made it look as though they were typed and came off my system.  If so -- how and is there a way to prevent this from happening again? Quote
made it look as though they were typed and came off my system.

what do you mean by "look as thought it were typed"? are you referring to a scanned document?

what do you mean by "came off my system"?I think Topsail is saying that someone else has put a file onto the computer without permission.

In answer to your question 'How do I prevent this from happening again', you just need a good antivirus if it's over the internet (remote) or add a password to your computer (if the person had access to your computer).



By the way, Nice to see you again JXY  If your company computers are all connected on the same network (highly likely), then you may have some network drives. In which case someone on the same network may be sharing files with you, and not putting them on your pc.
The documents in question were HANDED to my husband and he was told that I had typed them and that they were found on my individual computer.  I work from home -- on a separate network -- not networked into the main OFFICE network -- but totally independent.  I access files using an FTP system -- and my IP address is capture to give me access to the FTP site.  My problem is that I did not type those documents -- but the IT director says that I did -- and that he accessed them using the Spector system.  I run on Vista -- and use Spyware Doctor to remove threats -- and thought that the eblaster program -- as well as  -- the Spector system (including the Pro_Keylogger) were totally removed.  The scans for over a week showed a clean computer -- today -- came back with the Pro_Keylogger system back again.  Does anyone know how that works and how to get it off?  The documents -- how could someone gain access to a computer and make it look as though a document were created by an individual when it was not?  How is that possible?  I don't do technical -- I do databases so this is "over my head" but there are a few jobs which could be in question if I don't find a resolution.I think you need to take this up with the IT guy. He put it on, he needs to take it off, or ensure it is actually gone.

Does the keylogger on your computer possess evidence that you typed the document(s)? Could someone else have gained access to your pc manually, and typed it themselves? Have you checked the date of the creation of the document? You can verify if you've truly typed the document yourself, by looking at the time and date.
81.

Solve : Spybot scan found "ABetterInternet.Aurora"?

Answer»

Please help!
Spybot just found this today although I usually only autoscan daily with AVG8 and MBAM, {both auto-update - paid versions}, and the latest full system autoscan logs from both of them show no infections.
I have not tried to remove this with Spybot yet. I googled it and the first result was http://www.proz.com/forum/safe_computing/40742-how_to_get_rid_of_abetterinternetaurora-.html
After reading that thread I suspected my best move was to post here before I screw with anything.
 Scan log with SUPERAntiSpyware pasted below. I will scan with MBAM and HJT and will post logs in my next reply.
 
Spybot scan results screenshot here:
http://i243.photobucket.com/albums/ff1/letrocrew/screenshotSpybotAbetterInternetAuro.jpg

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/21/2008 at 01:09 PM

Application Version : 4.1.1046

Core Rules Database Version : 3459
Trace Rules Database Version: 1450

Scan type       : Complete Scan
Total Scan Time : 00:55:05

Memory items scanned      : 568
Memory threats detected   : 0
Registry items scanned    : 4738
Registry threats detected : 0
File items scanned        : 74020
File threats detected     : 0
While my MBAM scans I checked the latest scan log of AVG8 and in the results under "warnings" there is an entry "Adware.BetterInternet".
Is this the same file as what Spybot sees as a threat?
AVG screen shot here:
http://i243.photobucket.com/albums/ff1/letrocrew/AVGscreenshotAdwareBetterInternet.jpgMBAM log and HJT next when it gets through.

Malwarebytes' Anti-Malware 1.12
Database version: 774

Scan type: Full Scan (C:\|L:\|)
Objects scanned: 121780
Time elapsed: 48 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:41:41 PM, on 5/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\BONJOUR\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\Linksys EasyLink Advisor\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Secunia\PSI (RC1)\psi.exe
C:\Program Files\YPOPs\YPOPs.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Trend Micro\LowJackThis\LowJackThis.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no NAME) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PSDiagnosticM] "C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5 SE\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Bluetooth Connection ASSISTANT] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [SBAutoUpdate] "C:\Program Files\SpywareBlaster\sbautoupdate.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [NoAdware5] C:\Program Files\NoAdware5.0\NoAdware5.exe :Min:
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: Secunia PSI (RC1).lnk = C:\Program Files\Secunia\PSI (RC1)\psi.exe
O4 - Startup: YPOPs.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1205953650720
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208977382562
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5291/mcfscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15035/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe
O23 - Service: lxdc_device -   - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe

--
End of file - 12490 bytes
Are you having AVG and Spybot fix what they are finding?

The logs look fine but we can run another scan to be sure.

Download COMBOFIX by sUBs from one of the below links.
(Try all three if necessary)

Important! Combofix.exe MUST be saved to and ran from the Desktop.
  • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
  • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
    • Click this link to see a list of security programs that should be disabled and how to disable them.
    • If yours is not listed and you don't know how to disable it, please ask.
  • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
  • Double click combofix.exe & follow the prompts.
    • Choose Yes to accept the Disclaimers.
    • When finished, it will produce a log for you.
    • Post that log in your next reply.
    Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
    • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
    • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly. Quote from: evilfantasy on May 21, 2008, 12:47:52 PM
    Are you having AVG and Spybot fix what they are finding?
    AVG fixed ("infected objects removed or healed') automatically for the only 2 "infections" it has found (5-13-08) since I re-installed it on 4-24-08.
    It has not been automatically removing ALL "warnings" and I don't see where to set it to do so in 'Advanced Settings'. Looking at all the past logs shows it sometimes "deletes", sometimes "moved to virus vault", but several entries are listed as "potentially dangerous object" but no action has been taken. I don't know exactly where the setting is to make it delete 'ALL "warnings".
     The AVG scan log screen shot I linked above shows "trojan"s and "logger"s ect. Shouldn't AVG be fixing these?
     Also, before I run Combofix shouldn't I go ahead and fix all these manually with AVG and Spybot?
    If you are infected I will find it in the CF log.

    Too many characters to copy paste the log. I guess attachment will work. If not I'll paste it in the next 2 replies.
    combofix log attached

    [recovering space - attachment deleted by admin]Looks fine. If you want a 'second opinion' we can run an online scan to be sure.

    This scanner works with Internet Explorer only
    Go to the BitDefender Online Scanner
    Click I Agree to the license and then install the ActiveX control.
    Please DO NOT change the Scanning Options.
    That will make your logs huge and we don't need to see clean files.

    Select Start Scan to begin.
    This scan can take a while so please be patient and let it complete.

     Once Bitdefender completes the scan:
     Click-on the Detected Problems tab.
     Then select Click here to export the scan report


     
     When the window comes up to save the report, change the Save as type: box to:
     Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save


     
     This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)
     
     This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
     If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us
     
    Attach the bdscan.txt in the next post.
    Quote from: evilfantasy on May 21, 2008, 02:42:35 PM
    Looks fine. If you want a 'second opinion' we can run an online scan to be sure
    We can skip the scan. I highly value your opinion.  I'm not having any problems. In fact, my computer is really running well LATELY, although I would like to set AVG to get rid of all thoso cookies ect. automatically. I'll search the AVG 8 support page to get directions on changing that later. Right now I've got to get some sleep so I can work tonight.
     Once again, thanks a ton for your time and expert knowledge!!!  No problem. Hope you find the info, I have stopped using AVG in favor of Avast...
    82.

    Solve : AVG8 scan logs have partially broken letters when scrolling down warnings list?

    Answer»

    I noticed this when I first upgraded from AVG 7.5 paid to AVG 8. So I un-installed / re-installed NEW FILES downloaded from the AVG Grisoft site but it still does it. The letters SHOW up FINE when scrolling up, they only show as having a horizontal space through them about 2/3 of the WAY up the letters, all the way across the entry. Everything else with AVG 8 seems to work fine. I just found this odd and have not seen it with any other software I run.

    Does anyone else see this with AVG 8?Could you perhaps post a screenshot of what is happening?

    83.

    Solve : i have a avg free 8.0 e-mail scanner problem?

    Answer»

    when i installed 8.0 i selected personal e-mail setting, set it to notify me of e-mail scan on incoming and outgoing messages, it did state  that the installer detected my default mailer is EITHER not set or not supported by avg. when i checked the avg setting it STATED there are no e-mail plugins installed. never had this problem with 7.5, it always stated with a notification that avg was scanning the email. now the really funny part, when i check e-mails now norton scans them, i have never used norton and those sending me mail dont use norton.what gives? i use at&t yahoo internet service and my e-mail acct. is with them. when i go to the avg control board and check overveiw it states the email scanner is funcitional  and working properly, however checking stats it states no e-mail has been scanned, sorry for being so long but i am TOTALLY lost. thanks Take a look at this thread

    Quote

    There is no good reason for an email scanning module. It is driven from the marketing folks at AV vendors, not from the technical side of the House.

    Your Antivirus software acts as a kernel level file filter. That means that even if you remove the email filter module, the emails are scanned every time they are OPENED. It has proved the case for years under Win9x, ME, XP and now again in Vista, that the introduction of email MODULES to an antivirus product offers no additional protection, but is a serious cause of database corruption in Outlook Express, Outlook and now Windows Mail under Vista.
    84.

    Solve : virus to remove?

    Answer»

    hi,i got virus by one *CENSORED* SITE,i not know much about how to REMOVE it.i am also getting advertisement by some company to BUY some kit of  29euro to remove.lz,let me know what i do to clean my system.any free site to remove virus.thanks-malikhttp://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.htmlThen FOLLOW These Instructions...

    85.

    Solve : spyware message?

    Answer»

    I get a blue background that SAYS warning spyware detected, What do I have to do to get rid of this. Im running Windows XP.Prior to posting for help we ASK that you please read and follow all instructions in the pinned topic titled Please read this before REQUESTING malware removal help. Following the steps in the Guide will allow for US to QUICKLY help you with specific fixes for what may remain on your system.

    When you have completed those steps post the logs in this thread.

    86.

    Solve : Why do my virus scans take 5 to 6 hours?????

    Answer»

    My PC-Cillin anti virus program was driving me crazy because it would take 5 hours to scan.  So it was about to expire and I decided to download AVG.  Well right now it has been running 4 1/2 hours so evidently it's not the program.  What is up with this??  HELP!!!It pretty much depends on how many files you have in your drive.
    How much space have you used in your drive? For example, 20GB out of 40GBHow do I determine that?go to my computer - right click the drive - select properties.
    a diagram will shown  122 gb free spacehow much free space?122 GB free?how big is the HDD?
    depending on how big the drive, your computer speed and running programs that's possible.
    1.  Defrag the file system before running the anti-virus / anti-malware scans.  These scans check files one by one for malware.  If each file is stored in one contiguous cluster block it takes less disk accesses to retrieve the file.  If the file is stored in clusters scattered all over the disk, it can take many disk accesses to retrieve the file.

    2.  Before you "defrag" the file system, it's a good idea to check the integrity of the file system before you start moving files around on the disk.  You should also periodically check the integrity of the disk surface (identifying and marking bad sectors so you can avoid them).

    3.  You may also cleanup your file system by removing unnecessary programs (uninstalling?), clearing out the contents of temporary directories, and clearing your browser caches.  The less junk on your system, the fewer files your anti-malware software has to thumb through.

    4.  Cleaning, error checking, and defragging your file system (in that order) are standard maintenance functions that you need to perform on a regular basis to KEEP your system working well.  If it's been a long time (or forever) since you've performed these functions, you could probably reduce your anti-virus scan time to half of what it is now.

    5.  The "Help" function of your Windows operating system should provide information and directions towards performing these functions.My scans run while i'm asleep.
    AVG does have a schedule feature. In the main window click on scheduler and then Edit...you can change this to any time.
    Mine updates at 3AM and runs at 4AM...the only 2 hours i'm not awake.4 1/2 hours is a lot. It shouldn't take that long. Start with dahlarbear's advice. Quote from: pepper on November 24, 2007, 11:25:46 PM

    My PC-Cillin anti virus program was driving me crazy because it would take 5 hours to scan.  So it was about to expire and I decided to download AVG.  Well right now it has been running 4 1/2 hours so evidently it's not the program.  What is up with this??  Help!!!

    Your scan time is also dependent on the "power" of your computer:
        o  Processor Type and Speed (CPU)
        o  Amount of L1, L2 Cache
        o  Front Side Bus Speed
        o  Amount of Main Memory
        o  Disk Access Speed
        o  Version of Operating System
        o  Number and Type of Files to scan

    The point I'm trying to make is if you're using an older computer with the minimum amount of memory the factory put in, it's going to be a "dog"; a faithful dog maybe, but still a dog.

    Having said all of that, I'm confident that you can reduce the scan time significantly if you keep your file system "defragged" and in good shape.
    Okay here comes some more dumb questions.  My computer is only two years old.  I have 122 gb of free space. I have cable hookup.  When I had this computer set up I had the "computer guy" take out the hard drive from my old computer and put it into the NEW one to use as a backup file.  That drive is now FULL but I'm thinking when the virus scan is going it's scanning that whole drive too which probably isn't needed.  When I set up the scan should I just set to just scan drive C?  I did that the other day to test it and it only took two hours.  Hopefully someone, who uses PC-cillin will come up here to help with those settings.http://www.hackfix.org/software/configure/pccillin.html

    With Pc-cillin open you are presented with a side BAR of options, some options can be
    configured here and others must be done via the top toolbar.

    Side Bar options: (these options are also found in the top toolbar under File)

    Scan:  This is where you can perform manual scans as required or set up scheduled
    scans.

    Scan wizard is your manual scan wizard.  Regardless of what you are scanning
    (file/folder/system etc) the settings should Always include:

    Under scan options.  All files and include boot sector should be selected
    Under action when found: clean is the best option, be sure "back up files before
    cleaning" Is selected.
    Under action on uncleanable files: select Quarantine so files can be researched if
    need be.
    Select Apply to save your changes.

    Web trap: This is where your web browser and web downloads protection is enabled.

    Scan manager is to schedule scans on a timed basis.  Set as desired.Broni I don't have PC-cillin anymore as previously stated.  I have AVG.
    87.

    Solve : my computers acting really weird?

    Answer»

    I dont know what this is but i think its a virus
    what it does is when i type i type in all caps but when i type with caps lock they are lowercase

    when i hit the numbers above the keyboard, they just end up as the symbols ([email protected]#$%^&*())

    the keypad does not work at all, num lock or not

    when i hit tab to get to the next text box, it highlights the text box above it

    whenever i click on a link on a webpage, it opens a new window

    the mouse wheel SCROLL thing doesnt scroll pages, in my browser (firefox) it just browses through the history of that window

    theres more stuff but i think you get the gist of it

    EDIT:
    and my virus and adware scanners dont pick anything up
    (avast! home edition, ad aware, and SPYBOT s&d)

    please help, thanksphantms ....... You dont mention which program this is happening with ...or is it all?

    You are having issues with both the mouse as well as the keyboard.......
    Are you using a wireless keyboard and mouse?  If you are try changing the batteries .

    dl65  im sure its not my keyboard and mouse, i use a laptop as my desktop and the way its set up is i have a keyboard and mouse hooked up to it, so EVEN when i try unhooking them and using the keyboard and touchpad on my laptop, these errors still occur

    but incase it helps
    mouse:
    logitech mx310

    keyboard:
    logitech media keyboard elite

    both are corded by the wayOk, your problem is your shift key is stuck or malfunctioning. From what you described, it could be nothing ELSE that I can think of.

    Shift + TAB makes the tab go to the previous box, not next.

    Hold shift makes the keypad keys not work.

    Shift + Link click in browsers opens the link in a new window

    Shift plus mouse wheel in browser scrolls history

    Since this happens when the external keyboard is unplugged, I'm gonna guess it's one of your laptop's shift keys. Try giving them a couple of good taps each and SEE if you can't unstick it.What Windows version is it?
    Did you try System Restore?you are a genius quaxo, that did it! thank you so much!We sometimes overlook the simplest causes and solutions. 

    Come again if you ever have any problems, we're always happy to help

    88.

    Solve : Hijack log Sluggish computer first time boot?

    Answer»

    When I boot up my computer the first time it takes a long time to load and it is really sluggish. Any problem with my log.


    Running PROCESSES:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    C:\Program Files\America Online 9.0\waol.exe
    C:\Program Files\America Online 9.0\shellmon.exe
    C:\Program Files\Common Files\AOL\1192374632\ee\aolsoftware.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

    --
    End of file - 8335 bytes
    You chopped off the very top part of the log.

    It looks like this:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:10:17 PM, on 12/2/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Please add just that part in the next post.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:24:30 AM, on 12/2/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    C:\Program Files\America Online 9.0\waol.exe
    C:\Program Files\America Online 9.0\shellmon.exe
    C:\Program Files\Common Files\AOL\1192374632\ee\aolsoftware.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn5\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

    --
    End of file - 8335 bytes
    Open HijackThis and select Do a system scan only and place a check MARK next to:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


    Now click Fix checked

    I don't see any malware in the log.

    A few free suggestions:

    You can try turning off the Ad-Aware 2007 Service, Spyware Terminator should be plenty and I have heard that the aawservice is a resource hog.

    Try running CCleaner.

    StartUp Tool is a simple, yet powerful start-up items manager.

    Auslogics Disk Defrag s designed for fast optimization of modern hard disks.

    If this doesn't help then try running the steps in this post Quote

    I have heard that the aawservice is a resource hog
    This is true, but...
    Quote
    You can try turning off the Ad-Aware 2007 Service
    There is a problem with this solution.
    When you disable "aawservice" , Ad-aware won't start at all. If you set it to Manual, Ad-aware will start, but when it's done, its service will stay ON, so you're back to square one.
    We have to hate Lavasoft for putting some service on our computer, which we really don't need, and we didn't agree to have running.

    The only workaround, I know of is this:

    1. Go Start>Run. Type in:
    services.msc
    2. Find Ad-Aware 2007 Service. Set it to Manual
    3. Create start_adaware.bat batch file with the following lines:

    ECHO OFF
    Ad-Aware2007.exe
    sc stop aawservice
    echo Done


    4. Place start_adaware.bat in Ad-aware folder
    5. Launch start_adaware.bat for launch Ad-aware 2007

    aawservice will be stopped when ad-aware quit

    I have it set like this for myself, and it works.
    89.

    Solve : Cannot open the control panel. adware spyware?

    Answer»

    Hi there,

    I scaned the computer with Hijackthis and the log is as below. The scan results are attached.
    Can you please help?

    [saving space - attachment deleted by admin]I'll take a look, but meanwhile....
    You can't run HijackThis from temporary folder. Before you apply any fixes, I'll GIVE you, you have to create HijackThis folder in C:\Program Files, and move hijackthis.exe file there.
    Don't proceed before you do so.1. Print this post out, since you won't have an access to it, at some point.

    2. Download, and install Spybot (if you don't have it) from here: http://www.download.com/3000-2144-10122137.html

    3. Close all windows, except for HJT.

    3a. Go Start>CONTROL Panel>Add/Remove, and uninstall AVSystemCare

    4. Put a checkmark NEXT to the following HJT entries:

    - R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)

    - O4 - HKLM\..\Run: [rtasks] C:\Program Files\AVSystemCare\rtasks.exe

    - O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    - O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://w4s2.work4sure.com/c/ge/w4sgeen10.exe



    5. Click on "Fix It" button.

    6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

    7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

    8. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

    9. Delete following files (if they still exist):

    - AVSystemCare folder from C:\Program Files

    10. Turn off System Restore:

    - Windows XP:
       1. Click Start.
       2. Right-click the My Computer icon, and then click Properties.
       3. Click the System Restore tab.
       4. Check "Turn off System Restore".
       5. Click Apply.   
       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
       7. Click OK.
    - Windows Vista:
       1. Click Start.
       2. Right-click the Computer icon, and then click Properties.
       3. Click on System Protection under the Tasks column on the left side
       4. Click on Continue on the "User Account Control" window that pops up
       5. Under the System Protection tab, find Available Disks
       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
       8. Click OK

    11. Restart in Normal Mode.

    12. Turn System Restore on.

    13. Run HJT again, and post back its log back here.Thanks for your lightning response. log is attached.
    Thanks for your help!

    [saving space - attachment deleted by admin]Your HJT log is nice, and clean. Can you access your Control Panel, now?Hi there,

    Not yet. I cannot access both Control panel or Calendar. Please help.
    I could do it only in Safe Mode.What EXACTLY happens when you try to access Control Panel? Doesn't respond at all?
    What Calendar are we talking about?

    Try this:
    1.   Press CTRL+ALT+DEL, and then click Task Manager.
    2.   Click the Processes tab, and then click the Conime.exe process.
    3.   Click End Process, and then click Yes to confirm.
    4.   Close Task Manager.

    I'll be out for a few hours.Couple of different things to try.

    1. Go to the Start Menu > Run > control.exe

    2. Right click on Task Bar > Properties > Start Menu tab > make sure Start Menu is selected below and click on Customize > Advanced > under Start Menu Items you'll see Control Panel > select whatever you prefer and click on OK

    3. Go to the Start Menu > Run > appwiz.cpl

    90.

    Solve : Virus Drowor D. Trojan plus other Infestation?

    Answer»

    Infestation !   Identified by XoftspySE
    Drowor D.Trojan  c:/windows/system/internat.exe
    EliteKeylogger     c:/windows/system/mciole.dll
    Virus.Win32.Delf.ak c:/windows/wupdmgr.exe
    wintective           c:/windows?setup1.exe
    Smitfraud            c:/windows/rundll32.exe

    Used XoftspySE removal but Drowor D.Trojan returns again and again (all others gone)
    Attempted to stop restore function in case image is being replaced from restore but difficulty accessing system functions via control panel as error of "MISSING rundll32.exe"prevents system functions running from control panel.
    Managed to use system restore (using safe mode) and rolled back. No improvement. Drowor D Trojan persists.
    AVG 7.5 doesnt identify, neither does Spybot S&D, AdAware or SuperAntiSpyware.  Is Xoftspy exceptionally good in identifying when others do not or is Xoftspy 'questionable'.  Reluctant to delete Xoftspy (at present) because it holds the quarantined images which I may need.

    Removal into quarantine (by Xoftspy) seems to have removed the rundll32.exe
    Should I restore the removed problem items from quarantine -all or just Smitfraud which I suspect affected the rundll32.exe?
    Have downloaded all latest from SpybotS&D, AdAware,AVG7.5 & SuperAntiSpyware so not running old definitions.  What will not update is Xoftspy - stuck on data base 264 31.10.07 where as update 266 is available but will not load.

    Current situation is:- Drowor D Trojan persists and have 'lost' some system functions accessibility because of loss of rundll32.exe    How can I remove Drowor permanently and how do I restore missing rundll32.exe ?
    Have tried my best (as a keen intermediate) but now need some extra help / ideas.

    System
    Win Me v4.90 (with all patches from MS until closedown)
    40Gb drive C (21Gb free)
    40Gb drive D (21 Gb free)
    640Mb memory
    AVG 7.5 ; AdAware ; SpybotS&D ; SuperAntiSpyware all with latest updates
    Xoftspy SE (DB 264 31.10.07 database). 
    Zone Alarm.

    Help please
    Aussie



    I don't fully trust Xoftspy and its findings.

    Download HijackThis.
    Double-click on the installer you just downloaded.
    Click on the "Install" button to install.
    It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
    Please do not change the default install location.
    Upon install, HijackThis should open for you.

    Next click on the "Do a system scan and save a log file" button.
    HijackThis will scan and then a log will open in notepad.
    In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
    Please save the log as a text (.txt) file or .log
    In your post, add the log as an Attachment
    .
    * Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

    How to attach logs in a post

    Save the log to somewhere you can easily find it. (usually the desktop)

    To do this, from within the notepad go to the top of the page and select "File" > "Save As..." enter the file name and click "Save" Be sure the desktop is the location selected to save to.
    Please save all files as Text Documents (.txt)

    Posting the log

    1. Below the text box click "Additional Options..."
    * If replying in a thread, before putting text into the reply box select "Preview"
    2. Scroll down and select "Additional Options..."
    3. Click "Browse"
    4. Locate the file you want to attach and double click it to enter it into the window.
    5. If you have more than one log click "(more attachments)" and a NEW window will open for adding another log.
    * You will need to enter a message in the text box as well.Thanks Evil, you are 'first out of bed' on this one - much appreciated; also the step by step help is great.
    I am on long workshift all this weekend/monday so be patient for reply I will be back to you.
    Cheers  Aussie.No problem, hope work goes well.....Managed to get this done before shift starts. Welcome feedback.

    [saving disk space - old attachment deleted by admin]The log doesn't show any malware.

    Open SpyBot
    Look at the top and select "Mode" > select "Advanced Mode"
    Then on the left select:
    Tools > IE tweaks section
    Let me know if these are checked.
    "Lock IE start page ..."
    "Lock IE control panel ..."


    Neither are checked.  Should I do so? Quote from: Aussie on November 22, 2007, 06:34:58 PM

    Neither are checked.  Should I do so?

    No, we will fix it.

    Open HijackThis and select "Do a system scan only"

    Place a check mark next to:

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    Close all windows and click "Fix checked"

    What system functions have you lost?

    Have done. No identifiable loss of functions (but not run every program - yet!)
    Cant access control panel because of missing rundll32.exe but that existed prior to your instruction.

    For interest, I have just run Norton Win Doctor which identified 50 'errors'. I have not at this stage requested repair fix for these in case confuses your solution.
    One is missing shortcut link on start menu windows update "wupdmgr.exe"  (affected by Virus Win32.Delf.ak  ? )
    One is invalid Subkey entry - "invalid identifier"
    Remainder all refer to missing "rundll32.exe"  (affected by virus Smitfraud  ?)

    Question: if I did ask Win Doctor to 'fix', would it only repair the missing item content or will it drag the entire virus back with it?Since you are on winME then I think letting Win Doctor try to fix this is best for now. Most of the normal tools will not work with 98 and ME.

    Also, it seems every time Xysoft is involved it reports more issues then are actually there. False positives, "things" missing etc. I would uninstall it and go with SUPERAntispyware Free Edition
    instead. Quote from: evilfantasy on November 22, 2007, 09:39:13 PM
    Also, it seems every time Xysoft is involved it reports more issues then are actually there. False positives, "things" missing etc. I would uninstall it and go with SUPERAntispyware Free Edition
    instead.

    Agreed.  SAS is a much more reliable and TRUSTWORTHY program.Hi Evil & CB,
    Used Norton WinDoctor accepting recommended fixes.
    Re-run Xoftspy and yet again identifies Drowor D. Trojan. (all others originally identified are gone).
    Xoftspy says deleted but re-appears very next scan! Being reinstalled from Restore mirror image?
    Re scanned with AdAwareSE nothing found.
    Rescanned with SpybotS&D nothing found.
    Rescanned with AGV antivirus nothing found.
    Rescanned with SuperAnti SpyWare nothing found.
    Rescanned with Norton Win Doctor - no errors
    Definitely had something affect pc because cannot access control panel due to 'missing' rundll32.exe therefore I cant access and stop restore function reboot and wipe clear.
    How do I reinstate the missing rundll32.exe ? I have original Win Me disk, can I extract and reload just this missing dll ?
    I have not yet deleted XoftspySE just incase you recommend pulling lost dll back from quarantine (but bring virus back with it!?
    What is the next step guys?With Xysoft being the only program out of those to report anything I would have to say they are false findings.

    We will wait on CBMatt to (possibly) confirm this as I am not 100% positive if Xysoft does this or not, but some antivirus/antispyware will hide certain features in an attempt to make it harder to uninstall them. They say it is to protect the computer but I believe otherwise. Like hiding the add/remove programs button, control panel and so on.

    Quote
    How do I reinstate the missing rundll32.exe

    You can replace the rundll32.exe from Merjin.org

    I'm not sure you can COPY it from the the WinME disk like you can with XP. Quote from: evilfantasy on November 26, 2007, 12:56:16 AM
    We will wait on CBMatt to (possibly) confirm this as I am not 100% positive if Xysoft does this or not, but some antivirus/antispyware will hide certain features in an attempt to make it harder to uninstall them. They say it is to protect the computer but I believe otherwise. Like hiding the add/remove programs button, control panel and so on.

    To be honest, I'm not 100% sure either.

    Aussie,
    Try running another virus scan, but this time, do it in Safe Mode.  Does the file still come back?  Because Xoftspy found Smitfraud, go ahead and try out the instructions on this page...
    http://www.bleepingcomputer.com/files/smitfraudfix.php

    Also, what is the exact message you are getting about rundll32?  Typically, that file is kept in C:\WINDOWS\system32 (perhaps ME is different in this regard) and the one you're talking about is in C:\WINDOWS, so it sounds to me like your Control Panel is being pointed to the wrong location.  As soon as you can, try my above suggestions and post back with your results.Hi CB,  (& Evil)     Ran new Xoftspy scan twice in safe mode (reboot between) and second time it cleared and not re-appeared       Also ran all others AVG, Spybot S&D, AdAware, Super AntiSpyware & Win Doctor - all clear.
    Tried your suggestion re smitfraudfix but found wouldnt run - went back to download page and says for O/s WinXP / 2000 so appears not to be functional for Win Me.  Leaves me with Icon & folder on desktop (no great problem) but cant go into Ad/remove programs because of loss of access to Control panel functions due to missing rundll32.exe
    Exact wording denying control panel access is :
    "Windows cannot find C:/WINDOWS/rundll32.exe.  You may have TYPED the name incorrectly in the Run dialog. or another open program cannot find a systemfile. To search for a file, click the Start button and then click Search"
    (please note as an aside; the forward slash in above string should be a backslash. - might sound daft but I cant find the backslash key on the laptop I am using (not the affected machine) as it is set up for communication with the UK using £ instead of hash with digit 3, this in turn has changed backslash key to the hash with no trace anywhere now of backslash function. This doesnt matter other than your reading of the string above).
    Do you need a new HJT scan report or not? Looks as if system clear now; simply need to reinstall the rundll which I think goes to windows/options/cabs in Win Me.
    Await your observations re next step.
    Nearly there I think

    Aussie

    ps: public opinion 'virus' got the government here - all wiped out - new Labor team moving in. As a self exiled Brit I have no comment to make.
    91.

    Solve : Computer Question?

    Answer»

    Not sure where to post this question but I download a FILE and then my computer went crazy. All kinds of stuff started popping up like my instant messanger when I wasn't USING it. It was like SOMEONE was clicking around on my computer! I ran my McAfee antivirus nothing came up. Also ran spybot and deleted items that came up.  I used system restore and it seems ok now but I made such a mistake I didn't pay attention where the file was SAVED to my computer so now I don't know how to find it and delete it. Does system restore delete it? I'm not even sure what I should do or where to begin.  Does it sound like a VIRUS? What should I do? Any help would be great. ThanksThis is a good place to start. Follow the instructions, and download ComboFix as well.

    92.

    Solve : Brother Has A Virus Called clspring.HJ?

    Answer»

    Hello Everyone, My brother says it is suppose to be in win32systems, but we cannot find it. The hijackThis log is clean and we searched the registry with no luck.
    The COMPLETE name as told by him is

    >>> "cz8b035d279cb3fe926d9da7ab CLSPRING.HJ " <<<


    His antivirus would not quarantine, or DELETE it, just gave the name!
    I STILL think it is hidden in his SYSTEM 32 but he lives in ANOTHER state and we are having trouble getting Remote assistance started.

    Anyone have any idea's as to where to find this so we cannot remove it? Thanks
    You will need to follow the steps in this post and add the logs as attachments so we can see what is on the PC.

    93.

    Solve : Unbootable PC after downloading - help!?

    Answer»

    Hi there good folks,

    Against my better judgement (on the recommendation of a "friend") I downloaded some software from a torrent site and ran it - since then my desktop PC is now unbootable.  The desktop background appears but no icons, taskbar, clock etc.  With ctrl-alt-del I can get the task manager and it SHOWS a small fraction of the usual processes present.  In particular I notice that explorer.exe keeps terminating and restarting.

    I have a copy of the Ultimate Boot CD for Windows and that boots OK - I've ran several scans using various virus/spyware/malware checkers and they found nothing.  I tried booting into safe mode but that also gives my just the desktop background and then hangs.

    I have run HijackThis and will attached the log...any help or advice would be greatly appreciated.

    Many thanks...James.HijackThis log...



    [saving disk space - old attachment deleted by admin]WOW! That must be one of the worst HJT logs, I've seen for a while.

    Firstly, I don't see any firewall running, unless you have Windows firewall up. Please, update me on this.
    Secondly, you run HJT from temp folder: C:\Temp\HijackThis.exe. Before you run any fixes, create C:\HijackThis folder, put "hijackthis.exe" in that folder, and run it from there.

    Now...

    Download the program HostsXpert (http://www.funkytoad.com/download/HostsXpert.zip) which gives you the ability to restore the default host file back onto your MACHINE. To do so, download the HostsXpert program and run it. When it opens, click on the Restore Original Hosts button and then exit HostsXpert.

    POST new HJT log.OK - I ran the HostsXpert utility and restored the hosts file.  Attached is the new HJT log.

    Many thanks.

    [saving disk space - old attachment deleted by admin]Much better.
    What about that firewall question, while I'm looking at your new HJT log?YES, with regard to the firewall, I only have the Windows firewall running.  Sounds like that's not enough?1. Print this post out, since you won't have an access to it, at some point.

    2. Download, and install Spybot (if you don't have it) from here: http://www.download.com/3000-2144-10122137.html

    3. Close all windows, except for HJT.

    4. Put a checkmark next to the following HJT entries:

    - O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)

    - O4 - HKLM\..\Run: [Application Layer Services] avrsvc.exe

    - O4 - HKLM\..\Run: [Application Layer Scheduler] agtsvc.exe

    - O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)

    - O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)

    - O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    - O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

    - O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)



    5. Click on "Fix It" button.

    6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

    7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

    8. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

    9. Delete following files (if they still exist):

    - EmpirePoker folder from C:\Program Files

    10. Turn off System Restore:

    - Windows XP:
       1. Click Start.
       2. Right-click the My Computer icon, and then click Properties.
       3. Click the System Restore tab.
       4. Check "Turn off System Restore".
       5. Click Apply.   
       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
       7. Click OK.
    - Windows Vista:
       1. Click Start.
       2. Right-click the Computer icon, and then click Properties.
       3. Click on System Protection under the Tasks column on the left side
       4. Click on Continue on the "User Account Control" window that pops up
       5. Under the System Protection tab, find Available Disks
       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
       8. Click OK

    11. Restart in Normal Mode.

    12. Turn System Restore on.

    13. Run HJT again, and post back its log back here. Quote

    Yes, with regard to the firewall, I only have the Windows firewall running.  Sounds like that's not enough?
    Yeah, but better, then nothing. We'll take care of it later, along with tens of your startups, where some of them are not necessary as startups. They just clog your system. Ok - I have spybot and I also have the latest updates for it.  I did as you specified with HJT - ticking the listed entries and clicking on the fixit button - all ok. 

    However, when starting up in safe mode I was unable to get access to start spybot.  The safe mode desktop background appeared with the windows cursor but clicking or using ctrl-alt-del did nothing at all.  Both keyboard and mouse were completely UNRESPONSIVE.  (Itried booting into safe mode several times with the same result)  I used the power button to re-boot back into normal mode and that at least allows me to use ctrl-alt-del to get the task manager working. (I get no start button and right click does nothing).  With task manager I can then do: "File - New task(run)" and execute spybot.  Spybot is now running...

    Hope this makes sense.It's OK...Let's see what Spybot will come up with.
    There may be some other issues involved.Spybot found and fixed 10 problems - proceeding to next step...Opening Windows Explorere is a challaneg as I don't have access to the start button, right click menus or any icons.  Also if I run explorer.exe from inside Task manager it starts for a few seconds and then terminates (see above).  So I ran Xplorer2 from my UBCD4WIN cd and looked for the EmpirePoker folder in Program files but it is not there. 

    How do you suggest I turn off System Restore?

    Many thanks.Latest HJT log...

    [saving disk space - old attachment deleted by admin]Anything serious found there?No not really - spybot found just tracker cookie's
    94.

    Solve : Annoying pop up window?

    Answer»

    I have had this annoying pop up window for quite some time, it just flasher on the screen then gone. Its a large BLACK window and says C:\windowssystem32\QPRAGENT.exe. I have tried everything I can think of to delete it, and in the process I have found that I have no MSCONFIG file or HELP and support.
    I am running WindowsXP HOME SP2
    Can someone please help??WORK through this post and submit the logs so we can see what is going on.

    95.

    Solve : COMODO Firewall Pro??

    Answer»

    Since I put COMODO on my PC I can not get online unless I turn that off all the way and the Win. firewall...If i KEEP COMODO on I can not get online
    Any ideas?
    There's a bit of a learning curve setting up Comodo or any firewall app properly...have you spent any time reading the Help files ? ?I am now.
    Thanks.
    It does not help that my cable company is down 80% of the time.lol
    I keep THINKING that its something I did...
    Quote from: patio on November 24, 2007, 08:31:13 PM

    There's a bit of a learning curve setting up Comodo or any firewall app properly...have you spent any time reading the Help files ? ?
    Who is the competition in your area ? ?
    Many times contacting their DIRECT competitors and mentioning switching you can wind up with a sweet deal... Quote
    It does not help that my cable company is down 80% of the time
    Then, it's HARD to know, if it's you, or them.
    When you install firewall, basically they are all set not to prevent you from Internet connection. If you play with your firewall later on, you may screw your connection, but I don't think it's possible for firewall to interfere from the get go.
    What kind of connection is it, anyway?Sad to say guys I have Suddenlink now for my cable TV and PC.
    The only other choice I would have would be Centurytel.And they want ALOT down.($250)
    Parts of my area can use AT&T but,not where I am right now.
    Ugh.As i write this now it has already went down twice.
    So I'll have to send this out later.
    I used to work for MCI then Sunrocket (a VoIp company)
    So I know some about tech support-and Suddenlink SUCKS when it comes to that also.Its a major pain calling them up.
    Did you try to complain to Suddenlink? Quote from: Broni on November 25, 2007, 02:46:02 PM
    Did you try to complain to Suddenlink?
    Yeah did,I got one buck off my bill 
    Whatever.lol.Working better now.I don't know, if this is gonna help, but try to run TCP Optimizer: http://www.speedguide.net/downloads.php
    Put a checkmark into "Optimize settings", and click "Apply changes".
    96.

    Solve : Zone Alarm Fire wall new questions.?

    Answer»

    I should have asked these questions first before I made my changes.  Learning and flying off the cuff.

    I just deleted my Norton suite and have exchanged all my protections using free ware's.  My firewall of choice is Zone Alarm.

    I just downloaded and installed it but I don't know how to find it.  How do I know it is turned on and protecting?  I should only be operating one firewall to avoid PC confusion.

    During REGISTRATION, it asked me to submit my address so I would get new information and I think updates via email.  Is Zone Alarm a completely stand alone (visually passive) program that I cannot make changes to or view its status.  I don't know when to turn off Window's default firewall that I still have "on".  Any ideas and your experience please.

    Thanks, Tom

    What Windows version? I can't give you instruction for Windows firewall without this info.
    Windows firewall has to be disabled first, before installing ZoneAlarm.
    Zone Alarm, if active, should show up as an icon in your taskbar.
    Check C:\Program Files.....look for Zonelabs folderYou should see ZA in your Task Bar. It should have installed to C:Program Files so you may look there for it.

    Disable windows firewall http://support.microsoft.com/kb/283673Got scooped by Broni, sorry for double info....Thanks Broni for your reply, at least we have a dialogue started.  My O/S is Window's 5.1.  Maybe you can readvise me again after I discuss my issue and assumptions.

    First, I know how to use windows control panel and either the "firewall or security center" icons to disable the Window's firewall.  It is currently set to "on".  I've since removed the download; it completely locked up my internet capability.

    While I had the download installed, I tried turning off the Win f/w and my internet capability was still disrupted.  I know it is a compromise to have two f/w's operating at the same time.

    What I don't understand is, how do I access the internet to download the z/a f/w without the protection of of at least the window's f/w still in operation while I am working?

    Am I missing a step?

    Since I am new, it would help if the instructions come slow at my speed of understanding especially when it comes to learning how to access the program files discussion that was brought up earlier.

    Incidently, the icon on my taskbar (as previously mentioned) never appeared.   I used the install / uninstall function to remove the download.
     

       





    Firstly...
    Quote

    My O/S is Window's 5.1
    I assume, we're talking Windows XP, then.

    Secondly, turn your Windows firewall ON, for now.

    Now, when you uninstalled Norton, it's very possible, it didn't remove everything, especially registry entries.
    Go START>Run, type in:
    regedit
    Hit Enter.
    Registry Editor will open.
    Go File>Export, and save your registry file to known location.
    Go Edit>Find
    In "Find" field type in:
    Norton
    Click OK.
    When entry is found, right click on it, click Delete
    Hit F3 to find next Norton related entry. Right click, Delete.
    Continue, until no more Norton entries are found.

    Repeat same action, looking for:
    Symantec

    Now, you need a firewall. I'm not a big fan of ZoneAlarm, so I'll recommend Comodo: http://www.personalfirewall.comodo.com/
    Download it.
    Turn your Windows firewall OFF.
    Install Comodo.
    Restart computer to see, if everything checks out.Broni,

    I am still trying to clean up the PC with your instructions.  I think everything is working so far as I am editing the registry like you said to do. 

    I've removed my spyware , rootkit and (from some time ago) past A/V trial programs.  I just got done deleting the Norton files the registry identified.  I have a new question now. 

    After Norton; I asked the registry to "find" Symantec.  The left side of the screen seems to look like it located a point somewhere in the middle of the drop down tree.  I'm lookin at a MILE listing of binary type files.  The point is, I don't know where Symantec starts and where it ends so I know I have completely deleted all the Symantec files. 

    Any ideas how I should approach this?

    Since you advised a free firewall, do you use and recommend a free anti virus?

    Thanks for all your help. 

    T    Quote
    The left side of the screen seems to look like it located a point somewhere in the middle of the drop down tree.  I'm lookin at a mile listing of binary type files.  The point is, I don't know where Symantec starts and where it ends
    I'm not quiet sure, if I understand. When "Find" finds something, that entry is usually highlighted.

    As for free antivirus, yes I'm using AVG free, and happy with it: http://free.grisoft.com/
    Have you tried the Norton Removal Tool?
    Not yet.

    First I felt is was more important for me to understand how to learn and use the "run" commands and functions of editing the registry.  I'm new so I am cautious and take my time learning; stop everytime I see something wrong or just don't understand it.  You guy's out there are a great help and I really appreciate your time.  By that; I can one day maybe help someone.

    So I went back to work in the registry and think I have solved many of my problems.  The other reason I didn't run the tool yet was; if I'm going to remove Norton Symantec, installing the tool would be downloading more software and that might just compromise my initial objective which is to remove any identity of old Norton ware. 

    Now that I cleaned it up, AVG A/V free edition is now working properly where it wasn't before when I started this project. 

    Now back to the beginning of what started this whole dialogue; a firewall.  I've decided to stop my attempt working with Zone Alarm and go with the other recommendation "comodo".  What are your opinions, what has WORKED for you?

    TomEvilF,

    I just read your entry at the beginning of this catagory "read first".  Very informative; I will study it.

    Thanks, T Quote from: tpolcha on November 22, 2007, 11:44:28 AM
    EvilF,

    I just read your entry at the beginning of this catagory "read first".  Very informative; I will study it.

    Thanks, T

    Thanks 

    The Norton Removal Tool runs from the desktop, it doesn't actually install. Just delete the exe when done and it is GONE. I would still suggest running it. Symantec/Norton entries are everywhere and finding them all manually might be impossible.

    Comodo and I/my computer don't get along very well. My preferrence is PC Tools Firewall Plus Free But everyone has their preference.

    The registry is really not the place to start learning in. It is a dangerous place to make changes even for a skilled user. It is best to use tools to clean it up. The space gained by deleting dead entries is so minimal you will most likely never notice the difference.

    Auslogics Registry Defrag is what I use "if" I am bored. It isn't something that needs to be done often.

    Then the Registry cleaner in CCleaner is probably the safest to use.

    Let us know how everything goes. EFComodo is the best, you can get (including paid firewalls). Quote
    I would still suggest running it.
    I'd be curious myself, if it's gonna find more stuff.I will give it all a try especially the removal tool; except the Ccleaner right now. 

    I read an article that it could cause some interference with Window's Media Player 10. 

    I had to roll back to WMP10 when my daughters b/d gift; mp3 player specifically required that version in order to download music to her player.   

    I've collected and saved all of yall's notes.  Once again, I appreciate your help.  It has saved me allot of grief.  I'll post my new success's.

    If you folk's live in America, please enjoy a Happy Thanks Giving.

    97.

    Solve : Widows Explorer/Dr. Morten?

    Answer»

    I downloaded what I think was a bad file from a torrent about a month ago and now I can't open the folder I downloaded it in. I use Windows XP. I put it in My Documents>My Videos>My Movies. Sometimes I can open my videos, but most of the time I can't. If I try and delete it or open it I get an error message saying that Windows Explorer has encountered a problem and needs to close. Then it freezes up. A couple time it would came up with a Dr. Morten's Postmortem Debugger error message. Can you help me fix it?

    I tried to put a hijackthis log in but it exceded the maximum amount of characters, so I attached it in a text file.

    Edit: Also I ran a virus scan with McAfee nothing came up

    [getting space - attachment deleted by admin]You have quiet few bad guys there, but it's getting late, so I'll get back to you tomorrow, unless someone ELSE CHIMES in.Did you turn your firewall on, yet?Yeah the firewall is and has been on.Let me check your HJT log...1. PRINT this post out, since you won't have an access to it, at some point.

    2. DOWNLOAD, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html

    3. Close all windows, except for HJT.

    4. Put a checkmark next to following HJT entries:

    - R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SEARCH Bar = http://bfc.myway.com/search/de_srchlft.html

    - O2 - BHO: (no name) - {A6ACAE64-F798-4930-AD86-BD3FB32038DB} - C:\Program Files\Video Access ActiveX Object\isadd.dll (file missing)

    - O2 - BHO: XBTBPos00 - {E552EEFC-DE97-45D4-BA1A-F534A1B4A579} - C:\PROGRA~1\MORPHE~1\MORPHE~1.DLL (file missing)

    - O3 - Toolbar: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll (file missing)

    - O3 - Toolbar: (no name) - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - (no file)

    - O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (remove from "msconfig/startup")

    - O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus

    - O9 - Extra button: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll (file missing)

    - O9 - Extra 'Tools' menuitem: Morpheus Toolbar - {119DBEDA-9c41-4F97-94B4-B6BCD01133CF} - C:\Program Files\Morpheus Toolbar\morpheustoolbar.dll (file missing)

    - O9 - Extra button: Start EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - C:\PROGRA~1\EASYWE~1\easywebcam.exe (file missing)

    - O9 - Extra 'Tools' menuitem: &EasyFreeWebCam - {ECC5777A-6E88-BFCE-13CE-81F134789E8B} - C:\PROGRA~1\EASYWE~1\easywebcam.exe (file missing)

    - O22 - SharedTaskScheduler: homina - {df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4} - C:\WINDOWS\system32\oyopu.dll (file missing)


    ***Is "RIPE Network Coordination Centre" your ISP provider?***


    5. Click on "Fix It" button.

    6. Restart your computer in Safe Mode (F8)

    7. Run Spybot (click on updates, first), and fix whatever it asks you to fix.

    8. Open Windows Explorer. Go Tools>Folder Options, put a checkmark next to "Show hidden files, and folders".

    9. Delete following files (if they still exist):

    nothing to delete, for now

    10. Turn off System Restore.

    11. Restart in Normal Mode.

    12. Turn System Restore on.

    13. Run HJT again, and post back its log back here.I did as you said, but I don't think it did much. I attached the log again.

    [getting space - attachment deleted by admin]I'm not sure what you did, because basically everything is back, nothing was fixed.
    Follow EXACT steps from my previous post with couple of extra steps:

    While in "Safe Mode", go Start>Control Panel>Add/Remove, and look for:
    Acceleration Software, or Stop Sign program
    If exist, uninstall.
    Then...
    Open Windows Explorer, navigate to:
    C:\Program Files\Acceleration Software\ directory, right click on Acceleration Software, and click "Delete".

    Post new HJT log.Alright I did as you said here's the new log. It didn't fix the problem I was having though. Also the StopSign and Accelleration wasn't there.

    [getting space - attachment deleted by admin]OK...your HJT log is clean, now, so the culprit must be somewhere else.
    Do you still have that "bad" downloaded file on your computer, and still can't delete it?Yeah I'm pretty sure it's there still I can't get to the file to check though. Also if I try and delete any folder that contains it, it freezes up.Remove the offending folder and it's contents in safemode...I've tried that it doesn't work, the same thing happens.Does freezing happen in Safe Mode, too?
    Did you try to access that folder from Command Prompt?Move On Boot...

    Make sure to read the tutorial at the bottom of the DLoad page.

    98.

    Solve : Please Help Me! i Cant Get Rid of A Virus!?

    Answer»

    Hi my computer caught a virus called JOKWMP.DLL TROJAN.VIRTUMOND and it continually directs me to web pages trying to sell antivirus software plus it has also slowed down my computer heaps. i tryed NAV and spydoctor but both didnt remove it. iam really desperate to fix it because i need my computer for work. i dont know much about computers so if someone could explain wat to do in simple terms that would be great. thankslet's try a quick help. download avira anti virus and S&D for spy ware, update and run full scan in safe mode.

    http://www.free-av.com/
    http://www.safer-networking.org/en/index.html
    Follow the steps in this post. Once we have the logs we can determine what to do next.ok so i followed your intructions and found that there were two suspicious programs in add remove program called ANIWZCS2 service and ANIO Service im not sure if they are good or bad  but i cannot uninstall them through add remove programs or cc cleaner. i then ran cc cleaner followed by super anti spyware, ESET Nod32 Online Scanner, deleted a old version of java and kept the Java 6 Update 3 version and hijack this. the virus is still on my comp 

    We need the logs.ok here are all the LOG files

    [saving disk space - old attachment deleted by admin]And a HijackThis logsorry mate here it is

    [saving disk space - old attachment deleted by admin]Open HijackThis and select "Do a system scan only"

    Place a check mark next to:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O21 - SSODL: rmvgor - {B0F1A5EF-AE0F-4EAC-857A-63BE540A7B85} - C:\WINDOWS\rmvgor.dll
    O21 - SSODL: sapnet - {EE538701-E473-44CF-BF64-26595693CEBE} - C:\WINDOWS\sapnet.dll
    O21 - SSODL: msmhost - {D5798D9B-6A06-4B02-9DE7-F8395BB6BB52} - C:\WINDOWS\msmhost.dll (file missing)
    O21 - SSODL: msmdev - {B1BE01C9-0B08-4667-9237-50F1FA04254E} - C:\WINDOWS\msmdev.dll (file missing)
    O22 - SharedTaskScheduler: andropogon - {655560a9-3ca8-4509-9632-6abbef21426b} - (no file)
    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm


    Close all windows and click "Fix checked"

    ==========

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large AMOUNTS of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note: process.exe ( which is used by SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
    http://www.beyondlogic.org/consulting/processutil/processutil.htm

    =====

    Next post please attach
    rapport.txt
    Rapport

    [saving disk space - old attachment deleted by admin]PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    You may want print out these instructions or copy and paste them to notepad and save it to the desktop as you will not be ABLE to see this page in safe mode

    Please reboot your computer in Safe Mode by tapping the F8 key just before Windows starts to load and selecting Safe Mode.

    Open the SmitfraudFix Folder on your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    The program will start cleaning your computer and go through a series of cleanup processes. Wait for the tool to complete and disk cleanup to finish. This process can take some time depending on your computer, so please be patient. When it is complete, it will close automatically and you should continue with next step.

    You will be prompted: "Registry cleaning - Do you want to clean the registry?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt

    Optional:
    To restore Trusted and Restricted site zone, select 3 and hit Enter.
    You will be prompted: Restore Trusted Zone? answer Y (yes) and hit Enter to delete trusted zone.

    Now reboot into normal mode and attach this new rapport.txt in the next post.

    WARNING Running this option on a non infected computer will remove the desktop background. So only run it once!

    =====

    Next post attach
    rapport.txt
    New HijackThis log
    ok here they are mate

    [saving disk space - old attachment deleted by admin]We are getting close, just one entry that looks like trouble. 

    Please download Vundofix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Put a check next to Run VundoFix as a task.
    * You will RECEIVE a message saying vundofix will close and re-open in a minute or less. Click OK
    * When VundoFix re-opens, click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will shutdown your computer, click OK.
    * Turn your computer back on.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

    Please let Vundo finish, sometimes it can take multiple passes

    ==========

    Next post attach
    vundofix.txt
    Another NEW HijackThis log.
    ok so i downloaded vundofix and i couldnt see any box to tick about run as task so it just opened  up and i clicked on scan. once it scanned my computer it said there were no files found. here is the hijack log though

    [saving disk space - old attachment deleted by admin]OK, we will try this.

    Please download Combofix by sUBs from EITHER here or here

    Save Combofix.exe to your your Desktop.

    1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
    2. When finished, it will produce a log for you.
    3. Attach that log in your next reply.

    Note:
    Do not mouseclick combofix's window while it's running. That may cause your computer to stall


    Next post
    combofix log
    new hijackthis log

    99.

    Solve : Hijack logfile part 1and part 2?

    Answer»

    log file is too big I had to put it in 2 messages

    I have AVG antivirus and use Windows Firewall
    everytime I log on the computer I find like 10 viruses

    Whats the next step?  Thanks in advance
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:52:47 PM, on 11/20/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\USB FlashDisk\UFD Utility 2003\ufdlmon.exe
    C:\Program Files\USB FlashDisk\UFD Utility 2003\UFDTool.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    c:\program files\common files\installshield\updateservice\isuspm.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {0255f062-2513-4740-b02c-b59480c91538} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {099FDF61-2801-40D2-B678-CF72E7C95529} - (no file)
    O2 - BHO: (no name) - {36D388C0-445E-4F50-B5B6-77C838430EED} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7B58A8E2-BA17-4561-BC9E-76C0055867F0} - (no file)
    O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\mrtisino.dll (file missing)
    O2 - BHO: (no name) - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - (no file)
    O2 - BHO: (no name) - {8D379397-86C9-400B-24BF-9BE4C10F9AF3} - C:\Program Files\Windows Plus\lavu387.dll (file missing)
    O2 - BHO: (no name) - {93884D92-A5FE-4254-B82B-023CF36B0AFF} - (no file)
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: (no name) - {ACF67FCF-E842-4584-8743-182141E396D6} - \
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: (no name) - {B63149A7-0699-497B-B0C8-A77BEAB5F4C6} - (no file)
    O2 - BHO: (no name) - {BFF0C184-49DE-4D2A-A332-A02D028FB142} - (no file)
    O2 - BHO: (no name) - {C2EFFF71-6BA0-46EB-B6B2-F78D039100A6} - (no file)
    O2 - BHO: (no name) - {C3352FCD-CFE5-4F35-831A-19C68DDB7CF4} - C:\WINDOWS\system32\urqrpon.dll (file missing)
    O2 - BHO: (no name) - {C4FC47A6-5997-4B93-B279-C82BD058B991} - (no file)
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
    O2 - BHO: (no name) - {D8684225-C586-4D61-A32C-D03457DBE6B0} - C:\WINDOWS\system32\mllmj.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
    Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Broadcom WIRELESS Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [ShowLOMControl]
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
    O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [UFD Monitor9382] C:\Program Files\USB FlashDisk\UFD Utility 2003\ufdlmon.exe
    O4 - HKLM\..\Run: [UFD Utility9382] C:\Program Files\USB FlashDisk\UFD Utility 2003\UFDTool.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\nmarhiff.dll",sitypnow
    O4 - HKLM\..\Run: [b834324b] rundll32.exe "C:\WINDOWS\system32\onfofdwt.dll",b
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: urqrpon - urqrpon.dll (file missing)
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\abwbrivq.exe (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
    O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Plus\profsy.html

    --
    End of file - 12027 bytesHello...

    Download ViewpointKiller

    * Unzip the program and all of the contents of ViewpointKiller.zip to a location such as your desktop.
    * Double click the ViewpointKiller icon to run ViewpointKiller.exe. Select the "File" menu, and select "Check to see if you have Viewpoint installed".
    * If ViewpointKiller indicates that any of the Viewpoint variants are installed, select the proper "Kill" OPTION in the File menu.

    Follow the prompts and instructions very carefully, answering "Yes" or "No" depending on which option you are most comfortable with. The MsConfig instructions are very important, so be sure to read them carefully.

    * When ViewpointKiller is done a log will be shown. Please add that log as an attachment in the next post.

    NOTE: When done with ViewpointKiller, simply right click and delete all files that were unzipped.

    Then attach a new HijackThis log also please.

    How to attach logs in a post

    Save the log to somewhere you can easily find it. (usually the desktop)

    To do this, from within the notepad go to the top of the page and select "File" > "Save As..." enter the file name and click "Save" Be sure the desktop is the location selected to save to.
    Please save all files as Text Documents (.txt)

    Posting the log

    1. Below the text box click "Additional Options..."
    * If replying in a thread, before putting text into the reply box select "Preview"
    2. Scroll down and select "Additional Options..."
    3. Click "Browse"
    4. Locate the file you want to attach and double click it to enter it into the window.
    5. If you have more than one log click "(more attachments)" and a new window will open for adding another log.
    * You will need to enter a message in the text box as well.
    Attached are the log files for Viewpoint - had difficulty - but I think I got it to work
    and the Hijack post viewpoint killer log file

    [saving disk space - old attachment deleted by admin]Open HijackThis and select "Do a system scan only"

    Place a check mark next to:

    O2 - BHO: (no name) - {0255f062-2513-4740-b02c-b59480c91538} - (no file)
    O2 - BHO: (no name) - {099FDF61-2801-40D2-B678-CF72E7C95529} - (no file)
    O2 - BHO: (no name) - {36D388C0-445E-4F50-B5B6-77C838430EED} - (no file)
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
    O2 - BHO: (no name) - {7B58A8E2-BA17-4561-BC9E-76C0055867F0} - (no file)
    O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\mrtisino.dll (file missing)
    O2 - BHO: (no name) - {8B27CC68-110C-46a9-80D3-F3107DE6EB98} - (no file)
    O2 - BHO: (no name) - {8D379397-86C9-400B-24BF-9BE4C10F9AF3} - C:\Program Files\Windows Plus\lavu387.dll (file missing)
    O2 - BHO: (no name) - {93884D92-A5FE-4254-B82B-023CF36B0AFF} - (no file)
    O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
    O2 - BHO: (no name) - {ACF67FCF-E842-4584-8743-182141E396D6} - \
    O2 - BHO: (no name) - {B63149A7-0699-497B-B0C8-A77BEAB5F4C6} - (no file)
    O2 - BHO: (no name) - {BFF0C184-49DE-4D2A-A332-A02D028FB142} - (no file)
    O2 - BHO: (no name) - {C2EFFF71-6BA0-46EB-B6B2-F78D039100A6} - (no file)
    O2 - BHO: (no name) - {C3352FCD-CFE5-4F35-831A-19C68DDB7CF4} - C:\WINDOWS\system32\urqrpon.dll (file missing)O2 - BHO: (no name) - {C4FC47A6-5997-4B93-B279-C82BD058B991} - (no file)
    O2 - BHO: (no name) - {D8684225-C586-4D61-A32C-D03457DBE6B0} - C:\WINDOWS\system32\mllmj.dll (file missing)
    O3 - Toolbar: (no name) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O20 - Winlogon Notify: urqrpon - urqrpon.dll (file missing)
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\abwbrivq.exe (file missing)
    O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Plus\profsy.html


    Close all windows and click "Fix checked"


    Exit HijackThis

    Go to C:\Program Files\Windows Plus\profsy.html and delete if found: (the part in red)

    ===

    Please download Vundofix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Put a check next to Run VundoFix as a task.
    * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
    * When VundoFix re-opens, click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will shutdown your computer, click OK.
    * Turn your computer back on.
    * Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

    Please let Vundo finish, sometimes it can take multiple passes

    Next Post Attach:
    vundofix.txt
    New HijackThis log



    Also, how is the computer now?So I ran Vundo fix - was not able to acess the txt file
    I attached the Hijack file.

    I am still getting and error at startup:

    ERROR loading C:\WINDOWS\system32\onfofdwt.dll
    The specified module could not be found. 

    Also I ran the Vudo scan 2 x no errors were found the second time.

    After this resolves is there a way to get the computer to run faster besides the obvious maintence(defrag, compress files)

    Thanks

    [saving disk space - old attachment deleted by admin]Can you get to it by GOING to C:\vundofix.txt

    If so please attach it.Got it

    [saving disk space - old attachment deleted by admin]Right click and delete the HijackThis shortcut on the desktop (or wherever it is) We need to rename it.

    Un-hide protected system files.
    To enable the viewing of Hidden files follow these steps:
     
       1. Close all programs so that you are at your desktop.
       2. Double-click on the My Computer icon.
       3. Select the Tools menu and click Folder Options.
       4. After the new window appears select the View tab.
       5. Put a checkmark in the checkbox labeled Display the contents of system folders.
       6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
       7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
       8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
       9. Press the Apply button and then the OK button and close My Computer.

    Next go to C:\Program Files\Trend Micro\HijackThis\HijackThis.exe <--Right click HijackThis.exe and rename it analyze.exe

    Right click the new analyze.exe and create a new shortcut on the desktop.

    Re-hide protected files

    =====

    Go to add/remove programs and uninstall Java version is 1.4.2.3

    Reboot the computer.

    =====

    Please download ATF Cleaner by Atribune. ATF Cleaner.exe This program does not require an installation. The executable actually runs the program.

    NOTE: ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser
    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    =====

    Online Virus Scan

    Requires Internet Explorer

    Use the ESET Nod32 Online Scanner
    Click YES, I accept the Terms of Use. Then click Start
    The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt
    Add the EsetOnlineScanner\log.txt in your post as an Attachment

    =====

    Next post attach
    EsetOnlineScanner log
    New Renamed HijackThis log


    =====

    The onfofdwt.dll is something I am looking into.

    Is there any reason for your USB FlashDisk (ufdlmon.exe and UFDTool.exe) need to be autoloading at startup?



    I deleted Java and also the Java(TM)6 update 3

    I could not run online virus scan you suggested but my browser is not supported

    I should have told you to keep the Java 6 Update 3, sorry.

    Download the latest version of Java Runtime Environment (JRE) 6
    * Click the Free Java Download button.
    * Click the Download Now button.
    * When the Software Installation dialog box opens. Click on the Install Now button.
    * Follow the prompts to complete installation.

    You have to run the Online Scan with Internet Explorer, but, I think we should run SUPERAntiSpyware.

    First though.....

    Download Superantispyware (SAS)

    SUPERAntispyware Free Edition

    Install it and double-click the icon on your desktop to run it.
    *  It will ask if you want to Update the program definitions, click Yes.
    *  Under Configuration and Preferences, click the Preferences button.
    *  Click the Scanning Control tab.
    *  Under Scanner Options make sure the following are checked:
    +  Close browsers before scanning
    +  Scan for tracking cookies
    +  Terminate memory threats before quarantining.
    +  Please leave the others unchecked.
    +  Click the Close button to leave the control center screen.
    *  On the main screen, under Scan for Harmful Software click Scan your computer.
    *  On the left check C:\Fixed Drive.
    *  On the right, under Complete Scan, choose Perform Complete Scan.
    *  Click Next to start the scan. Please be patient while it scans your computer.
    *  After the scan is complete a summary box will appear. Click OK.
    *  Make sure everything in the white box has a check next to it, then click Next.
    *  It will quarantine what it found and if it asks if you want to reboot, click Yes.
    *  To retrieve the removal information please do the following:
    +  After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    +  Click Preferences. Click the Statistics/Logs tab.
    +  Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    +  It will open in your default text editor (such as Notepad/Wordpad).
    +  Save the notepad file to your desktop by clicking (in notepad) "File" "Save As"
    * Save the log somewhere you can easily find it. (normally the desktop)
    *  Click close and close again to exit the program.
    *  Please add the log as an attachment along with a new HijackThis log in the next post.

    ===

    Next post attach
    SUPERAntiSpyware (SAS) log
    New Renamed HijackThis log


    attached are the files
    The error is still occuring

    [saving disk space - old attachment deleted by admin]We "should" be able to take care of the error in the next set of instructions. First however......

    Enable Viewing Of Hidden System Files & Folders

    1. Right Click Start.
    2. Select Control Panel.
    3. Select the Tools menu and click Folder Options.
    4. Select the View Tab.
    5. Under the Hidden files and folders heading select Show hidden files and folders.
    6. Uncheck the Hide extensions for known file types option.
    7. Uncheck the Hide protected operating system files (recommended) option.
    8. Click Apply.
    9. Click OK.

    Now go to www.virustotal.com

    Click Browse and locate C:\Program Files\USB FlashDisk\UFD Utility 2003\ufdlmon.exe <--Double click ufdlmon.exe

    Then click Send File Virus Total will run it through 32 different antivirus scanners and show the results. This takes a few minutes. Let me know the results.

    result was 0/32 (0%)Download Killbox.exe to your desktop. Don't use it yet.

    =====

    You may want to print out or copy and paste the rest of this to notepad and save it to the desktop. You won't be able to see this page in safe mode.


    =====

    Reboot into Safe Mode

    Safe Mode Instructions

    =====

    Open HijackThis (HJT) and select Do a system scan only

    Place a check mark next to:

    O4 - HKLM\..\Run: [b834324b] rundll32.exe "C:\WINDOWS\system32\onfofdwt.dll",b

    Close all windows and click Fix checked

    =====

    Double-click on Killbox.exe to run it. Make sure Standard File Kill is selected.
    In the Full Path of File to Delete box, copy and paste the following
    line into the box.
    Quote

    C:\WINDOWS\system32\onfofdwt.dll
    Then click on the button that has the red circle with the
    X in the middle after you enter the file. It will ask for confirmation to
    delete the file. Click Yes.

    Note: It is possible that Killbox will tell you that the file does not
    exist.

    Reboot to normal mode and re-hide the protected files.

    =====

    Let me know how things are now.

    100.

    Solve : My Hijack logfile & others...?

    Answer»

    Here are my HijackThis  AND SUPERAntiSpyware Scan Log...
    I can get online now But,Not without alot of pop-ups.
    Any more HELP would be great.=]
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:37:33 AM, on 11/23/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:

    End of file - 5913 bytes
    WOW! A lot of stuff....

    Let's start with this:

    Download VundoFix:
    http://www.atribune.org/content/view/24/2/

        * Double-click VundoFix.exe to run it.
        * When VundoFix re-opens, click the Scan for Vundo button.
        * Once it's done scanning, click the Remove Vundo button.
        * You will receive a prompt asking if you want to remove the files, click YES
        * Once you click yes, your desktop will go blank as it starts removing Vundo.
        * When completed, it will prompt that it will reboot your computer, click OK.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.

    Post new HJT log. Quote from: Broni on November 23, 2007, 10:24:24 AM

    WOW! A lot of stuff....

    Let's start with this:

    Download VundoFix:
    http://www.atribune.org/content/view/24/2/

        * Double-click VundoFix.exe to run it.
        * When VundoFix re-opens, click the Scan for Vundo button.
        * Once it's done scanning, click the Remove Vundo button.
        * You will receive a prompt asking if you want to remove the files, click YES
        * Once you click yes, your desktop will go blank as it starts removing Vundo.
        * When completed, it will prompt that it will reboot your computer, click OK.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
    Scan for Vundo button." when VundoFix appears at reboot.

    Post new HJT log.
    Did it.It found nothing....It looks like SUPERAntiSpyware did pretty good job.
    Post new HJT log. Quote from: Broni on November 23, 2007, 04:42:55 PM
    It looks like SUPERAntiSpyware did pretty good job.
    Post new HJT log.
    Okay here is the new one:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:18:41 AM, on 11/24/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ibwhuxr.exe
    O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Eek! Promoter] C:\Program Files\Eek! Records\Eek! Promoter\EekPromoter.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: SUN Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{77765848-D713-4D0B-BFF8-9CF403173596}: NameServer = 208.180.42.68,208.180.42.100
    O18 - Filter hijack: text/html - (no CLSID) - (no file)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O24 - Desktop Component 0: (no name) - C:\Program Files\MSN Gaming Zone\rteqe.html

    --
    End of file - 6193 bytesI can't see any firewall running. Do you have Windows firewall up?

    Download, and run CWShredder: http://www.intermute.com/spysubtract/cwshredder_download.html
    Let it fix whatever it finds.

    1. Print this post out, since you won't have an access to it, at some point.

    2. Download, and install Spybot (if you don't have it) from here: http://www.download.com/3000-2144-10122137.html

    3. Close all windows, except for HJT.

    4. Put a checkmark next to the following HJT ENTRIES:

    - O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto

    - O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

    - O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

    - O18 - Filter hijack: text/html - (no CLSID) - (no file)

    5. Click on "Fix It" button.

    6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

    7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

    8. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

    9. Delete following files (if they still exist):

    - outlook folder from C:\Program Files

    10. Turn off System Restore:

    - Windows XP:
       1. Click Start.
       2. Right-click the My Computer icon, and then click Properties.
       3. Click the System Restore tab.
       4. Check "Turn off System Restore".
       5. Click Apply.   
       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
       7. Click OK.
    - Windows Vista:
       1. Click Start.
       2. Right-click the Computer icon, and then click Properties.
       3. Click on System Protection under the Tasks column on the left side
       4. Click on Continue on the "User Account Control" window that pops up
       5. Under the System Protection tab, find Available Disks
       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
       8. Click OK

    11. Restart in Normal Mode.

    12. Turn System Restore on.

    13. Run HJT again, and post back its log back here. Okay I'll do that now-And No I do not have a Windows Firewall up.
    Quote from: Broni on November 24, 2007, 09:59:01 AM
    I can't see any firewall running. Do you have Windows firewall up?

    Download, and run CWShredder: http://www.intermute.com/spysubtract/cwshredder_download.html
    Let it fix whatever it finds.

    1. Print this post out, since you won't have an access to it, at some point.

    2. Download, and install Spybot (if you don't have it) from here: http://www.download.com/3000-2144-10122137.html

    3. Close all windows, except for HJT.

    4. Put a checkmark next to the following HJT entries:

    - O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto

    - O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

    - O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

    - O18 - Filter hijack: text/html - (no CLSID) - (no file)

    5. Click on "Fix It" button.

    6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

    7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

    8. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

    9. Delete following files (if they still exist):

    - outlook folder from C:\Program Files

    10. Turn off System Restore:

    - Windows XP:
       1. Click Start.
       2. Right-click the My Computer icon, and then click Properties.
       3. Click the System Restore tab.
       4. Check "Turn off System Restore".
       5. Click Apply.   
       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
       7. Click OK.
    - Windows Vista:
       1. Click Start.
       2. Right-click the Computer icon, and then click Properties.
       3. Click on System Protection under the Tasks column on the left side
       4. Click on Continue on the "User Account Control" window that pops up
       5. Under the System Protection tab, find Available Disks
       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
       8. Click OK

    11. Restart in Normal Mode.

    12. Turn System Restore on.

    13. Run HJT again, and post back its log back here.
    You CAN'T be without any firewall. For now, turn your Windows firewall ON. Quote from: Broni on November 24, 2007, 10:50:57 AM
    You CAN'T be without any firewall. For now, turn your Windows firewall ON.
    Okay,How would I do that?
    Also just ran the CWShredder it found nothing.1.   Click Start, click Run, type Firewall.cpl, and then click OK.
    2.   On the General tab, click On (recommended), and then click OK. Quote
    Also just ran the CWShredder it found nothing.
    GoodHere is the new HijackThis file:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:36:54 PM, on 11/24/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\System32\atievxx.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ibwhuxr.exe
    O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Eek! Promoter] C:\Program Files\Eek! Records\Eek! Promoter\EekPromoter.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{77765848-D713-4D0B-BFF8-9CF403173596}: NameServer = 208.180.42.68,208.180.42.100
    O18 - Filter hijack: text/html - (no CLSID) - (no file)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O24 - Desktop Component 0: (no name) - C:\Program Files\MSN Gaming Zone\rteqe.html

    --
    End of file - 6205 bytesDid you turn on Windows firewall?
    How are the pop-ups?
    Do you USE MSN Gaming Zone? Quote from: Broni on November 24, 2007, 02:02:21 PM
    Did you turn on Windows firewall?
    How are the pop-ups?
    Do you use MSN Gaming Zone?
    Yes I did turn on the windows firewall-Before I did everything.
    So far no pop-ups-Since I did everything.
    And I not use MSN Gaming Zone.-I use Hotmail.com but,thats it.lolIf so, run HJT one more time, put a checkmark next to:
    - O24 - Desktop Component 0: (no name) - C:\Program Files\MSN Gaming Zone\rteqe.html
    and click on "Fix it".
    That should take care of last questionable entry.

    Now, Windows firewall isn't that good, so I'd recommend to:
    - download free Comodo firewall: http://www.personalfirewall.comodo.com/
    - turn off Windows firewall (reverse steps as described above
    - install Comodo.