Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1401.

Solve : WinPC rogue Antivirus Infection issues - Help Wanted?

Answer»

Hi -

My laptop has picked up the WinPC rogue antivirus malware and it appears to be preventing various anti-malware progs from running. Unfortunately details of how the malware was picked up are uncertain as I am not the only person who uses this machine -

I have tried to follow your instructions as best I can -

Here is a summary of observations and actions:

1) Initial problem: WinPC Antivirus - bogus antivirus program requesting updates and presenting bogus system security screen
2) Error message indicating PowerISO virtual drive not installed properly
3) Visual studio debugger indicates: (a)Unhandled exception occurred in GoogleUpdate.exe and (b) Unhandled Exception in SuperAntiSpyware.exe
4) Malwarebytes would not execute.
5) Looked at 'Add / Remove Software' for any unwanted progs. Nothing obvious
6) Checked device manager for unwanted devices - nothing from list
- UACd.sys <- Or anything beginning with UAC
- gaopdxserv.sys <- Or anything beginning with gaopd
- gxvxcserv.sys <- Or anything beginning with gxvx
- Seneka.sys <- Or anything beginning with Seneka
- clbdriver.sys <- Or anything beginning with clbdriver
- TDSSserv.sys <- Or anything beginning with TDSS
- ovfst.sys <- Or anything beginning with ovfst


7) Run AVG 8.5 full system scan and nothing found
Installed CCleanerSlim and run successfully on second go. Inspected files (cookies and cache) and cleaned.
9) Tried to run SuperAntispyware and get an unhandled exception
10) Tried to run malwarebytes and it will not run
11) Tried to update JRE but receive an error message that says iexplore.exe is running and must be closed to complete the installation - although Internet Explorer isn't running.
12) Opened task manager and found iexplore.exe and stopped process. This allowed the JRE update to install.
13) Run Hijack this and created log file.
14) Tried starting into safe mode - SuperAntispyware will not execute / Malwarebytes will not run / SDFix will not run / Combofix will not run.

Here is the Hijackthis Log file -
I Hope you guys can help -

Logfile of HijackThis v1.99.1
Scan saved at 12:40:03, on 17/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\WINLOGON.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Sony\VAIO CAMERA Utility\VCUServe.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Crimson Editor\cedt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\HijackThis\sniper.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.automaticbacklinks.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WinInet Class - {39fc2065-c9c7-49cd-8942-44cc2dedc844} - C:\WINDOWS\ieocx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SeoQuake - {9C590067-8A6A-4db6-B052-069283790B04} - C:\Program Files\SeoQuake\seoquake.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\tony\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - GLOBAL Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: APPEND to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, INC. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StumbleUponUpdateService - stumbleupon.com - C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe



Many Thanks

1402.

Solve : PE Patch problem?

Answer»

Go to Add or Remove Programs and uninstall Adobe Reader 8.

Then install the new version. http://get.adobe.com/reader/

----------

Real Player http://majorgeeks.com/RealPlayer_d4093.html

----------

Go to Add or Remove Programs and uninstall all Java except Java 6 UPDATE 13

----------

Download the Flash Player Uninstaller and save it to your desktop.

Run the uninstaller program and then reboot your COMPUTER to complete the uninstall.

Download and install the latest version of Flash PlayerJava 6 Update 13 is the newest version http://www.java.com/en/I'm still in the middle of updating everything, and Trend MICRO pops up with a new problem called "Possible Patch 1" and in the action taken SECTION, it's blank. Any ideas? I was glad that I thought it was finally cleaned and then THAT popped up.Is there any way to get a log from Trend Micro?I'm copying and pasting the log below. As for updating, I've updated RealPlayer, Flash Player, and Adobe Reader. I'll need to restart to completely get rid of the Java stuff, and then I need to update Outlook Express (which I never even use...) and Windows Media Player.
____________________________________
"Virus Log","2009/05/16","D9QBNLB1"
"Time","Event","Source Type","Virus Name","File Name","First Action","Second Action"
"19:37","Real-time Scan","File","Possible_Patch-1","C:\WINDOWS\system32\jsgzu","",""
"19:39","Real-time Scan","File","Possible_Patch-1","C:\WINDOWS\system32\jsgzu","",""
The complete file path is cut off. You can look in your System32 folder and find the file that begins with jsgzu and delete it. C:\WINDOWS\system32\jsgzu???

More information. POSSIBLE_PATCH-1

If you can't find it then we can use another scanner that should find it for us.Deleted the file. I'm going to go ahead and restart the computer, then proceed with updating the Windows Media Player and then Outlook Express, along with any other Windows components I need to, then follow the rest of your post at the bottom of page 1.OK. Be sure to empty your Recycle Bin or it will be found there again by your antivirus.Thanks. You've been a huge help. BTW: Would you suggest getting Sandboxie and running Firefox from it? Would that be safer? What else could I do to help prevent this from happening again?Just be CAREFUL what you download. Using Sandboxie is a safe way to test websites or downloads before allowing them onto your computer.

You can also scan files that you are not sure are safe before installing them.
Online file scanners.
http://www.virscan.org/
http://virusscan.jotti.org/en
http://www.virustotal.com/Thank you very much. I appreciate all of the help you have given me.

1403.

Solve : anti-virus on Virtual Machines?

Answer»

Do virtual machines like MICROSOFT Virtual PC require an anti-virus PROGRAM...I mean, can they get infected?Yes.OK      THX

1404.

Solve : file msnmgnr.exe is missing error message at startup?

Answer»

Hi

Need help in removing file msnmgnr.exe is error message. Please help.
Thank you.

Borikuaseems like u ALSO GOT hit by this virus as it did mine. no worries, i got rid of mine. its a LONG PROCESS, but just religiously follow EVILFANTASY's instructions. Good luck!Thanks. It's annoying at startup. Hope to learn more on removing virus, worms, etc.

Borikua

1405.

Solve : .exe Not a Valid Win32 Application!??

Answer»

This is driving me crazy! I have a new dell notebook with Vista installed, everything was going good up until 2 weeks ago. Almost all of my programs I try to run give me the message "... is not a valid Win32 application." These programs used to run fine but I have no idea what I could have did to make programs stop running.

Heres the part that gets me, all programs are able work correctly in safe mode I've tried starting Windows with a diagnostic start up but I still get the same error.

I will post the HiJackThis log next because I have exeeded the limit.Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 7:57:56 PM, on 4/6/2007
Platform: Windows Vista  (WinNT 6.00.1904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\sttray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Users\Champ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5

\E6M3W3PS\HiJackThis_v2[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by

Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\TOOLBAR,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program

Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program

files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program

Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -

osboot
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop

Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire

Plus\PhotoDownloader.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0

\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11

\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program

Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program

Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program

Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3

\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program

Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} -

c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {700EF03F-A472-4D26-8ACB-300F4D04FD96} (Recovery ActiveX Control Module) -

https://www.lojackforlaptops.com/ctmweb/testoc.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-

3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1

\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop

Search\GoogleDesktopManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common

Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1

\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1

\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1

\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1

\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1

\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1

\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1

\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (mctskshd.exe) - McAfee, Inc. - C:\PROGRA~1

\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1

\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program

Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program

Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0

\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common

Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote PROCEDURE CALL (RPC) Net (Rpcnet) - Absolute Software Corp. -

C:\Windows\SYSTEM32\Rpcnet.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-

Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing

Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9245 bytes


nobody can help me huh? If you think it is a virus or malware problem, maybe it should go in that section.

The issue would be what happened prior to all of this, what applications, what protection you have, etc. which you did not post.if you are a moderator, could you please move it to that section for me. I dont know what I did prior to this, my only protection is the McAfee Suite that came with the computer.Somebody help me Quote from: GX1_Man on April 09, 2007, 05:35:03 PM


The issue would be what happened prior to all of this, what applications, what protection you have, etc. which you did not post.

See below. I had Vista Home and Internet Explorer 8. I started getting csc.exe. It said the Publisher was Microsoft.
It popped up on my page every few minutes asking me if I want to Install it. I clicked "No" and clicked the box that said "Don't bother me anymore, or something to that effect. It still kept popping up.
I ran "Malwarebytes", a Free Program. It found 2 Trojans.
I uninstalled IE 8 and went back to IE 7, SP1. I've read forums that SP 2 is still full of problems.
ptfitzy

Quote
Topic started: April 06, 2007, 07:11:54 PM »

Old topic closed.

EF
1406.

Solve : CTHELPER.EXE?

Answer»

Not 100% sure this is a virus but it seems like one so I'll ask the experts.

Following error MESSAGE OCCURS when you start up.

Its a Dell XPS400 pc and it's running windows XP.

Warning
Application cannot be executed. The file
CTHELPER.EXE is infected.
Please ACTIVATE your antivirus software.See here. http://www.systemlookup.com/Startup/2457-CTHELPER_EXE.html

Depending on where the file is it could be a FALSE positive.

1407.

Solve : Computer Slow?

Answer»

I don't see anything indicating a MALWARE issue. How is the computer running now?Still feels slow ;/ When I start up steam or a program it doesnt respond sometimes.


Doing another scan now.I don't think it's malware. You have a bunch of stuff installed so you could just need to do some cleanup.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
Yeah , still getting a lil BIT do you have anything that uninstalls useless crap I don't need on my pc?Just go through Add or Remove Programs and uninstall anything you don't use any more.

I would also recommend that you Defrag the computer.

You can use the built in Windows Defrag by clicking Start > Run and then type in dfrg.msc then click OK. Or use a faster FREE program. Defraggler is very effective and easy to use.

Note: Be sure to clean out temp files and restart the computer just before beginning a defrag.I just tried to OPEN the taskmgr.exe and I get this error "The wrong volume is in the DRIVE. Please insert volume CSS_1 into drive D:."How long has that been happening?

It sounds like something didn't install right. Printer, sound card or some other hardware.I just now tried it. cause my steam wasn't responding was gonna end the process and now I have the icon in my lower LEFT corner but I can't open it.Restart the computer?
1408.

Solve : sysvxd.exe trojan?

Answer»

Attn: EvilFantasy --

Thanks to you and the team for offering to look at my log files. 

I use ESET as my AV program, run a pretty clean build of XP professional media center, build 2600 xpsp_sp3, with IE 8.0, Acrobat 7, and MS Office XP.   Recently rebuilt from a clean format and partition.   

I kept on getting this error message:

           Error Code 16 bit MS-DOS Subsystem
           c:\windows\s\Sysvxd.exe
           The NTVDM CPU has encountered an illegal instruction.
           CS:0dbf IP:06d0 OP:63 6f 6c 6f 72 Choose 'Close' to terminate the application.

           with Close or Ignore options. 

No noticable change to operations when I closed the 'process'. I looked up sysvxd.exe, and a Kaspersky forum and then this one said it was the result of a Trojan. 

Anyway, here are my log files. 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/08/2009 at 05:45 PM

Application Version : 4.26.1004

Core Rules Database Version : 3929
Trace Rules Database Version: 1872

Scan type       : Complete Scan
Total Scan Time : 00:46:09

Memory items scanned      : 847
Memory threats detected   : 1
Registry items scanned    : 5233
Registry threats detected : 16
File items scanned        : 79084
File threats detected     : 7

Trojan.Unknown ORIGIN
   C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE
   C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE
   [SVCHOST.EXE] C:\WINDOWS\SYSTEM32\DRIVERS\SVCHOST.EXE
   C:\WINDOWS\Prefetch\SVCHOST.EXE-0EB47E31.pf

Unclassified.Unknown Origin
   HKLM\Software\Classes\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{376892AE-1825-4E5F-9F85-23F9640051CC}
   HKU\S-1-5-21-4211940775-4122393118-504975954-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{376892AE-1825-4E5F-9F85-23F9640051CC}
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}#AppID
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\Control
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\InprocServer32
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\InprocServer32#ThreadingModel
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\MiscStatus
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\MiscStatus\1
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\ProgID
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\ToolboxBitmap32
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\TypeLib
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\Version
   HKCR\CLSID\{376892AE-1825-4E5F-9F85-23F9640051CC}\VersionIndependentProgID

Adware.Tracking Cookie
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
   C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt

Malwarebytes' Anti-MALWARE 1.37
Database version: 2249
Windows 5.1.2600 Service Pack 3

6/8/2009 6:14:03 PM
mbam-log-2009-06-08 (18-14-03).txt

Scan type: Quick Scan
Objects scanned: 82217
Time elapsed: 3 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\dnscache.dnscacheobj (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dnscache.dnscacheobj.1 (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Sysvxd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:49 PM, on 6/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\CyberLink Codec\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\MICROS~3\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\Computerfixer1\Computerfixer1.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink Codec\PDVDServ.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [FJUPDNV_Chitose] C:\Program Files\Fujitsu\fjdvrupd\fjdvrupd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcStd7_1_0 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1239386189328
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 9881 bytes

I appreciate any review.  Strange that ESET didn't catch the problem. 

-TomWelcome to H2G.

It looks like the removal guide got most or all of it but we will do another scan as a double check.

Open HijackThis and select Do a system scan only

Vista users right click on HijackThis and select Run as Administrator. (you will receive a UAC prompt, please allow it)

Place a check MARK next to the following entries: (if there)

- O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - (no file)

This is an optional HijackThis fix

- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


*Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers. Removing this with HijackThis will not effect the performance of your Realtek AC97 Audio whatsoever.

Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixHere's the log from Combofix:

ComboFix 09-06-08.03 - Administrator 06/08/2009 23:54.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1022.541 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

(((((((((((((((((((((((((   Files Created from 2009-05-09 to 2009-06-09  )))))))))))))))))))))))))))))))
.

2009-06-09 01:00 . 2009-06-09 01:00   410984   ----a-w-   c:\windows\system32\deploytk.dll
2009-06-09 01:00 . 2009-06-09 01:00   --------   d-----w-   c:\program files\Java
2009-06-08 23:08 . 2009-06-08 23:08   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-08 23:08 . 2009-05-26 18:20   40160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 23:08 . 2009-06-08 23:08   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-06-08 23:08 . 2009-06-08 23:08   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-08 23:08 . 2009-05-26 18:19   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-06-08 21:55 . 2009-06-08 23:02   117760   ----a-w-   c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-08 21:54 . 2009-06-08 21:54   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-08 21:54 . 2009-06-08 21:54   --------   d-----w-   c:\program files\SUPERAntiSpyware
2009-06-08 21:54 . 2009-06-08 21:54   --------   d-----w-   c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-06-08 21:53 . 2009-06-08 21:53   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-06-08 21:38 . 2009-06-08 21:38   --------   d-----w-   c:\program files\CCleaner
2009-06-08 20:37 . 2009-06-08 21:17   --------   d-----w-   c:\program files\Trend Micro
2009-05-27 01:40 . 2009-05-27 01:40   --------   d-----w-   c:\documents and settings\Administrator\Application Data\ieSpell
2009-05-24 17:09 . 2009-05-24 17:09   --------   d-sh--w-   c:\documents and settings\Administrator\IECompatCache
2009-05-24 17:06 . 2009-05-24 17:06   --------   d-sh--w-   c:\documents and settings\Administrator\PrivacIE
2009-05-24 17:05 . 2009-05-24 17:05   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache
2009-05-24 17:05 . 2009-05-24 17:05   --------   d-sh--w-   c:\documents and settings\Administrator\IETldCache
2009-05-24 16:28 . 2009-05-30 02:08   --------   d-----w-   c:\windows\ie8updates
2009-05-24 16:28 . 2009-05-12 05:11   102912   -c----w-   c:\windows\system32\dllcache\iecompat.dll
2009-05-24 16:27 . 2009-05-24 16:27   --------   dc-h--w-   c:\windows\ie8
2009-05-24 15:25 . 2009-05-24 15:25   --------   d-----w-   c:\documents and settings\All Users\Application Data\Chat Republic Games
2009-05-24 14:50 . 2009-05-24 14:50   --------   d-----w-   c:\documents and settings\Administrator\Local Settings\Application Data\Chat Republic Games

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-30 02:06 . 2009-04-14 13:10   --------   d-----w-   c:\documents and settings\Administrator\Application Data\OfficeUpdate12
2009-05-06 04:55 . 2009-05-06 04:55   --------   d-----w-   c:\program files\MSECache
2009-04-19 21:49 . 2005-12-16 22:42   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-04-19 21:48 . 2009-04-13 21:40   0   ----a-w-   c:\windows\system32\drivers\FUJITSU_AA80N1E996000000_WXPMCE.MKR
2009-04-14 04:45 . 2009-04-13 19:28   --------   d-----w-   c:\program files\ieSpell
2009-04-14 03:28 . 2009-04-14 03:28   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Windows Search
2009-04-14 03:10 . 2009-04-14 13:10   264704   ------w-   c:\documents and settings\Administrator\Application Data\OfficeUpdate12\oudetect.dll
2009-04-13 21:17 . 2009-04-13 21:16   --------   d-----w-   c:\program files\ffdshow
2009-04-13 21:13 . 2009-04-13 20:59   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-04-13 20:59 . 2009-04-13 20:59   --------   d-----w-   c:\program files\Media Player Classic
2009-04-13 01:45 . 2009-04-12 23:40   --------   d-----w-   c:\program files\Maxtor
2009-04-13 01:44 . 2009-04-12 23:40   --------   d-----w-   c:\documents and settings\All Users\Application Data\Maxtor
2009-04-12 21:22 . 2009-04-12 03:22   --------   d-----w-   c:\documents and settings\Administrator\Application Data\AdobeUM
2009-04-12 21:18 . 2005-12-16 23:13   --------   d-----w-   c:\program files\Common Files\Adobe
2009-04-12 21:05 . 2009-04-12 21:05   --------   d-----w-   c:\documents and settings\All Users\Application Data\Adobe Systems
2009-04-12 21:05 . 2009-04-12 21:05   --------   d-----w-   c:\program files\Common Files\Adobe Systems Shared
2009-04-12 03:21 . 2009-04-12 03:21   --------   d-----w-   c:\documents and settings\All Users\Application Data\Pure Networks
2009-04-10 22:45 . 2009-04-10 22:45   --------   d-----w-   c:\program files\Microsoft ActiveSync
2009-04-10 22:43 . 2009-04-10 22:43   --------   d-----w-   c:\program files\Common Files\L&H
2009-04-10 22:41 . 2009-04-10 22:40   --------   d-----w-   c:\program files\Hewlett-Packard
2009-04-10 22:40 . 2009-04-10 22:40   --------   d--h--w-   c:\program files\Zenographics
2009-04-10 21:57 . 2009-04-10 21:57   --------   d-----w-   c:\documents and settings\Administrator\Application Data\ESET
2009-04-10 21:57 . 2009-04-10 21:57   --------   d-----w-   c:\program files\ESET
2009-04-10 21:57 . 2009-04-10 21:57   --------   d-----w-   c:\documents and settings\All Users\Application Data\ESET
2009-04-10 21:37 . 2005-12-16 23:19   --------   d-----w-   c:\documents and settings\All Users\Application Data\Symantec
2009-04-10 21:37 . 2005-12-16 23:19   --------   d-----w-   c:\program files\Common Files\Symantec Shared
2009-04-10 21:26 . 2005-12-16 19:21   --------   d-----w-   c:\program files\GemMaster
2009-04-10 21:12 . 2009-04-10 21:12   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Windows Desktop Search
2009-04-10 21:11 . 2009-04-10 21:11   --------   d-----w-   c:\program files\Windows Desktop Search
2009-04-10 20:20 . 2009-04-10 20:20   --------   d-----w-   c:\program files\MSBuild
2009-04-10 20:20 . 2009-04-10 20:20   --------   d-----w-   c:\program files\Reference Assemblies
2009-04-10 18:49 . 2009-04-10 18:49   --------   d-----w-   c:\program files\MSXML 4.0
2009-04-10 18:44 . 2009-04-10 18:44   --------   d-----w-   c:\documents and settings\Administrator\Application Data\Intel
2009-04-10 18:43 . 2009-04-10 18:43   21275   ----a-w-   c:\windows\system32\drivers\AegisP.sys
2009-04-10 18:43 . 2009-04-10 18:43   --------   d-----w-   c:\windows\system32\config\systemprofile\Application Data\Intel
2009-04-10 18:43 . 2009-04-10 18:43   --------   d-----w-   c:\documents and settings\All Users\Application Data\Intel
2009-04-10 18:43 . 2005-12-16 19:14   --------   d-----w-   c:\program files\Intel
2009-04-10 18:42 . 2009-04-10 18:42   --------   d-----w-   c:\program files\Broadcom
2009-04-10 18:04 . 2009-04-10 18:04   --------   d-----w-   c:\program files\Windows Media Connect 2
2009-04-10 17:58 . 2009-04-10 17:58   --------   d-----w-   c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-10 17:54 . 2009-04-10 17:54   --------   d-----w-   c:\program files\Microsoft Silverlight
2009-04-10 17:27 . 2005-12-16 23:11   --------   d-----w-   c:\program files\Quicken
2009-04-10 17:20 . 2005-12-16 18:29   86811   ----a-w-   c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-31 01:01 . 2009-04-13 21:16   84480   ----a-w-   c:\windows\system32\ff_vfw.dll
2009-03-31 01:01 . 2009-04-13 21:16   60273   ----a-w-   c:\windows\system32\pthreadGC2.dll
2009-03-16 23:42 . 2009-03-16 23:42   524288   ----a-w-   c:\windows\opuc.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2005-08-09 81920]
"LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2005-06-08 69632]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2005-11-01 242688]
"LoadBtnHnd"="c:\program files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-11-01 61440]
"RemoteControl"="c:\program files\CyberLink Codec\PDVDServ.exe" [2004-07-15 32768]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-11-10 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-10 602182]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"FJUPDNV_Chitose"="c:\program files\Fujitsu\fjdvrupd\fjdvrupd.exe" [2006-02-17 303104]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-09 148888]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-11-17 88203]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000002}\SC_Acrobat.exe [2009-4-12 25214]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05   356352   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12/21/2007 8:21 AM 468224]
R2 FlashDrv;FlashDrv;c:\progra~1\Fujitsu\FlashAid\FlashDrv.sys [12/16/2005 6:17 PM 7196]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [12/16/2005 1:50 PM 4864]
S3 ADVNTDRV;ADVNTDRV;c:\windows\system32\drivers\ADVNTDRV.SYS [11/18/1999 5:20 PM 3872]
S3 AVUSBPVR;AVerMedia USB MPEG-2 Capture Device;c:\windows\system32\drivers\avusbpvr.sys [12/16/2005 5:56 PM 1947264]
S3 bioschk;FPC BIOS Check Driver;c:\windows\system32\drivers\bioschk.sys [4/10/2009 1:41 PM 3909]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - JAVAQUICKSTARTERSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-08 23:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4211940775-4122393118-504975954-500\Software\Microsoft\Internet Explorer\User Preferences]
Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5 977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f3,12,12,0f,a5,2b,2a,45,9d,66,e5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839 E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f3,12,12,0f,a5,2b,2a,45,9d,66,e5,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1348)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2120)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-09 23:56
ComboFix-quarantined-files.txt  2009-06-09 04:56

Pre-Run: 56,131,862,528 bytes free
Post-Run: 56,132,554,752 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

204   --- E O F ---   2009-05-14 12:28
Looks good. Is the computer running OK now?

Just a few things to do now.

Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the Desktop.

----------

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete: ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file EXTENSIONS, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Wow.  I'll be sure to click the Thank You button in a moment, but for the benefit of the other readers I'll let you know what I discovered. 

First, the Windows Messenger you had me delete.  Had no idea, and thought it was a necessary component.  Now gone, thank you very much.  Not to be confused with MSN Messenger...  Thanks for that.

Thanks for the Combofix /u cleanup suggestion.  Did that, no issues. 

The Secunia website is terrific.  I regularly go to check Windows updates, but even so, it's a new month and there were a bunch more.  Secunia reminded me of these and several more, including Flash and several Adobe updates.  All those Microsoft updates?  Malware designers must have been busy recently.

Gotta tell you that I ran into trouble with an old version (pre-Adobe) of Flash, actually Macromedia Flash 6.0.79.0.  When I tried to upgrade to Adobe's version 10 of the program it didn't work.  Nor could I delete it in the control panel. Instead, I found a technical note about this specific version via Google, which advised where to find the Adobe Uninstaller.   A useful tool for uninstalling Adobe programs that are stubborn.  Found here: http://download.macromedia.com/pub/flashplayer/current/uninstall_flash_player.exe .

This tech tip (on Secunia) also provided a tip about another application you might want to review, called Revo Uninstaller.  --Useful for uninstalling some of the fragments that programs leave behind in the Windows Registry. Please comment on whether this is 'foolproof' enough for the general user. 

Adobe had several updates to make, progressively, on Acrobat and the Adobe Reader.  Had to run Secunia several times.  But that's typical with many update routines.  The trick is to be patient, reboot between each update, and follow the directions. 

I added Web of Trust, and will look at AntiSpywareBlaster in a moment.  Also will read the paper you wrote on improving computer speed - "It may not be malware".  Really, this has been enormously helpful.  Thanks evilfantasy...

Anything else left to do?Glad you found the Adobe Uninstaller. For some reason Flash refuses to remove it's leftovers when it's updated. Anyway , now ya know...


I've used and recommend Revo for a while now. I won't uninstall anything without it and it has never given me any problems whatsoever.

Quote
Anything else left to do?

As long as the computer is running OK then I think you are good to go.
1409.

Solve : HJT Recommendations and Overall Cover?

Answer»

Hi again to the best forum out there!
I've just run SAS and MBAM, and all is clear.
Two questions for you, as and when.
(1) Like to mess/delve around so have been trying out your HJT analyser. The solutions given can be really interesting, but in no way would l start deleting items it suggests, that l leave to you guys! However, it did throw up two items which l'm not sure of, namely No Firewall and Detected potential domain/dns hijack.
Under my Windows Firewall settings it says it's running, and HJT was downloaded from one of your threads (and renamed to sniper). So it's a little bit confusing as to whether there's a problem or not.
My HJT log is attached after (2).

(2) I've just had a massive clearup (well massive for me anyway) and my protection has now been reduced/changed  to -
Avast Free (realtime)
Superantispyware (realtime)
Malwarebytes (realtime)
I know they're great programs, but would you consider this sufficient ENOUGH cover?

Logfile of Trend Micro HIJACKTHIS v2.0.2
Scan saved at 23:33:01, on 08/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wanadoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.wanadoo.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wanadoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223302897125
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CADDFDF-8C2B-436C-8E42-F0AB5C2FD79E}: NameServer = 81.253.149.1 80.10.246.3
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! ANTIVIRUS - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, INC. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5273 bytes

Many ThanksEverything looks fine and that should be enough protection. HijackThis can't "see" the windows firewall so no worries.Many thanks for that evil.
You've put my mind to rest, so will let you get on with SORTING out other peoples more pressing problems.
Nice of you to reply so promptly though.
Kind Regards
WTCYour welcome

1410.

Solve : Tracking cookies?

Answer»

Hi, everytime I run an anti-virus search (daily) either quick scan or auto idle time scan, I have multiple tracking cookies that are then removed. Is there any way to trace where these come from or are they just added by random websites. I'm only wondering if a programme I have installed could be adding the cookies. Although not a major problem would just LIKE to understand it a little bit more.
Thanks in advance.

[attachment deleted by admin]You can TRY Tools>internet options>browsing history settings>view FILES,...this will show cookiesYeah already looked through that before but that just lists all cookies on your system. As you can see from the picture Norton lists all the tracking cookies removed but some of them are not websites I have ever visited or ever will. So I'm wondering if there coming from a third party.Lot's of cookie tools and information....

Are cookies REALLY spyware and are they dangerous?

  • Cookie Viewer - This Power Tool automatically scans your computer, looking for "cookies". It can then display the data stored in each one and can delete them.
  • Cookie Cruncher - Protects your hard drive from unwanted cookies.
  • Cookie Culler - Extended Cookie Manager. Protect/unprotect selected cookies. (Firefox only)
  • Add N Edit Cookies - Gives you the ability to easily alter, edit or delete cookies. (Firefox only)
.
Thanks evil very helpful.   Hi evil sorry since I went into
Internet explorer; tools; privacy; advanced and changed third party cookies to block I get this message every time I start up explorer. It refreshes once and then it's fine, I just want to make sure there is nothing more sinister behind it. Again thanks for your time guy's.

[attachment deleted by admin]I'm not sure how IE8 handles Cookies and not sure why Compatibility View would complain about the change. I found this which has information about using InPrivate Browsing as an alternative.Thanks again Evil very helpful.
1411.

Solve : infected Packed.Generic.200?

Answer»

My computer has been infected with a Packed.Generic.200 virus and I have no idea how I got it.  I have tried running both Ad-Aware and Malewarebytes’ Anti-Maleware in safe mode with the SYSTEM restore turned off.  They both find it and say it was unable to delete and will delete on the reboot but every time I restart the computer the virus is still there.
When I use Ad-Aware it states that; A malicious object of high severity was detected and cleaned. It is recommended that you restart your computer to ensure that all traces of object are removed completely.  In the background you can SEE the family type which is: Win32TrojanTDSS and in orange letters it says reboot required.  I do this and the virus is still there when I reboot.

I have Symantec Anti Virus, and The current location given by Symantec anti virus is:
globalroot\systemroot\system32\
   
The filename is:
uaclyssymivgipnkb.dll

Below is a copy of the Malewarebytes’ report.

Malwarebytes' Anti-Malware 1.37
Database version: 2249
Windows 5.1.2600 Service PACK 3

6/8/2009 1:25:07 PM
mbam-log-2009-06-08 (13-25-07).txt

Scan type: Quick Scan
Objects scanned: 112053
Time elapsed: 11 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\UACgqqgfeajxxyjryj.dll (Trojan.TDSS) -> Delete on reboot.
\\?\globalroot\systemroot\system32\UAClyssymivgipnpkb.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\system32\UACgqqgfeajxxyjryj.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
\\?\globalroot\systemroot\system32\UAClyssymivgipnpkb.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot



Now HijackThis report:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:17 PM, on 6/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
S:\pslips\PSWIN32.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbyam.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\MSNGAM~1\Windows\zclientm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: PHONEslips.lnk = pslips\PSWIN32.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/DinerDash2.1.0.0.68.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - INSTALLER) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://zone.msn.com/bingame/fotg/default/ddfotg.1.0.0.37.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/DinerDash.1.0.0.98.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{DAACC1D4-26FF-4571-9D28-A961879A0FFB}: NameServer = 166.102.165.13
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://www.stamps.com/img/support/stampsicon.gif

--
End of file - 8639 bytes
Download ComboFix© by sUBs from one of the below links. Be SURE top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix

1412.

Solve : craptop goes offline by itself?

Answer»

by the way....cute picture!  Quote from: ponies on September 24, 2008, 01:30:56 PM

ok, i did the superspyware, and ran it. It found a couple of things and quarentined them. I never saw a "log." 
Sure you're following the guide to the letter?

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes
  • To retrieve the removal information please do the following:
  • After reboot, double-click the SUPERAntiSpyware icon on your desktop.
  • Click Preferences. Click the Statistics/Logs tab.
  • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
  • It will open in your default text editor (preferably Notepad).
  • Save the notepad file to your desktop by clicking (in notepad) File > Save As...
* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post

Quote from: ponies on September 24, 2008, 01:30:56 PM
What does it mean "alternate download link (.exe) in step 4?
It's just another link to the program in case he first one doesn't work.Here is the log.... What do I do with it? It MAKES no sense to me..............

Malwarebytes' Anti-Malware 1.28
Database version: 1203
Windows 6.0.6001 Service Pack 1

9/25/2008 12:26:54 AM
mbam-log-2008-09-25 (00-26-54).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 106984
Time elapsed: 1 hour(s), 6 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 17
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{f0d4b230-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23a-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23c-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b15fd82e-85bc-430d-90cb-65db1b030510} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Quarantined and deleted successfully.
C:\Windows\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Should I attempt step 6 now? Quote from: ponies on September 25, 2008, 11:17:09 PM
Should I attempt step 6 now?

Yes, sir!

(also moving this to the Computer Virus Section)GREAT news! My nephew CAME over today and did something, don't know what, and fixed my craptop! It doesn't go offline by itself anymore!  He also showed me how I can get it back online from my craptop w/o having to unplug stuff and go through all of that. Should I continue with step 6 anyway?  What does it do?Never mind.  Craptop is still going offline by itself.  Bless Abe's little heart, he tried but the *censored* thing is still
f-ed up.http://www.snapfiles.com/reviews/HijackThis/hijackthis.html
Quote
TrendMicro HijackThis is a tool, that lists all installed browser add-on, buttons, startup items and allows you to inspect, and optionally remove selected items. The program can create a backup of your original settings and also ignore selected items. Additional features include a startup list report, hosts file manager, uninstall manager and some other tools. Intended for advanced users.

Hope that gives you some insight. I have my solution. Abe fixed my craptop so that when I walk away from it or leave it alone overnight, it doesn't SHUT down and it doesn't go into sleep mode. It hibernates only. It does not go offline that way. As long as I don't shut it down it seems to stay online. I can live with that.  Thank you so much for taking all the time you did to help a techno dunce like me! All right.

Hibernation can be disabled through My Computer --> Properties, if you're interested.what would the craptop do if I disabled hibernate? Quote from: ponies on September 29, 2008, 12:51:19 AM
what would the craptop do if I disabled hibernate?

It simply wouldn't hibernate unless you turn it on again

(I have mine disabled)I think it's ok with me if it hibernates. At least it's not going offline anymore, the stupid piece of s==t! My girlfriends laugh at me and sing SONG "operator error, operator error." Nasty, mean women.Heh, ok.

At least problem solved.
1413.

Solve : Help with Viruses, logs attached?

Answer»

I know that my computer has viruses, but I don't know how to remove them.

When running CCleaner.com the first time the following message popped up:

Debug Assertion Failed!
Program: C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
File: c:\program files\microsoft visual studio.net 2003\vc7\atlmfc\include\atlfile.h
Line: 188
Expression: m_h!=0

Not sure if that is of any help. That appeared the first time I ran CCleaner.com

My Symantec Antivirus has quarantined a number of items, but they all seem to keep coming back with each scan.

I have attached three log files. Let more know what else you might need.

[Saving space - attachment deleted by admin]Download FixWareout by LonnyRJonesfrom from one of the two below links and save it to your Desktop.

  • Run Fixwareout.
  • Click Next
  • then Install
  • Make sure Run fixit is checked
  • Click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
When you run Fixwareout, just follow the prompts, you will need to restart when prompted.

After rebooting (restart) back into normal boot mode. Make sure you have all web browsers closed.
  • Go into Control Panel > Network Connections.
  • Right click on your connection
  • and click Properties.
  • On the Properties page, highlight Internet Protocol(TCP/IP)
  • Click Properties. This will bring up another page.
  • Select Obtain DNS Server Automatically.
  • Click the OK button. The page will close.
  • Press OK on the page in front of you.
  • Restart the computer.
  • Reconnect to the Internet using Internet Explorer.
  • Add the log from Fixwareout in your next reply.
  • It will be located at c:\fixwareout\report.txt
Go to Start > Run and type in cmd
Click OK.
This will open a command prompt.
Type or copy and paste the following line in the command window:

ipconfig /flushdns

Hit Enter.
Exit the command window.

Restart your computer.

Please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.

----------

Is totalinternet.snap.com set as a homepage?

Here they are.

Username "     " - n 09/28/08  9:17:36 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4E2A1DC8-EE09-402A-A2BA-BFF93C6FD1A7}
"nameserver"="194.54.90.226" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{774C0923-518F-45BA-A934-E7BED649E474}
"nameserver"="194.54.90.226"
Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.
 
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe\""
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"AGRSMMSG"="AGRSMMSG.exe"
"Apoint"="\"C:\\Program Files\\Apoint2K\\Apoint.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""
"hpWirelessAssistant"="\"C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe\""
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"eabconfg.cpl"="\"C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe\" /Start"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"QUICKTIME Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\"  -osboot"
"WD Button Manager"="WDBtnMgr.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Uniblue RegistryBooster 2"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:54 AM, on 9/28/08
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://totalinternet.snap.com:8005/channel/search/0,11,totalinternet-0,00.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.centurytel.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: WD Anywhere Backup Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {40F8967E-34A6-474A-837A-CEC1E7DAC54C} (QuickBooks Online Edition UTILITIES Class v9) - https://accounting.quickbooks.com/c9/v15.585/qboax9.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161231099046
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} (QuickBooks Online Edition Utilities Class v8) - https://accounting.quickbooks.com/c1/v14.186/qboax8.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - http://www.arkansashighways.com/road/acgm.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 12304 bytes
Looks much better.

Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Sorry it took so long. Here is the EsetOnlineScanner log.

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3478 (20080928)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=de7fe6ec394aca46986729169f7aaee8
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-09-29 02:31:07
# local_time=2008-09-28 09:31:07 (-0600, Central Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=294652
# found=0
# scan_time=3480Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
----------

Set a New Restore POINT to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about BROWSER Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates SITES on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1414.

Solve : My PC got infected by another virus! Please help!?

Answer»

This is terrible my PC got this another virus that invaded my computer and messed it up in a second!  The virus masks itself calling itself a "Window XP Antivirus Software" program and keeps on running scans on my computer.  It also changed the Desktop background to this bright blue color and took away my ability to remove it.  I first rebooted the computer to safe mode and physically disconnected from the INTERNET I then ran SuperAntiSpyware 2 times in Safe Mode and got rid of everything I could find.
I'm posting the log below.

SUPERAntiSpyware Scan Log
HTTP://www.superantispyware.com

Generated 06/05/2008 at 10:03 PM

Application Version : 4.15.1000

Core Rules Database Version : 3469
Trace Rules Database Version: 1460

Scan type       : Complete Scan
Total Scan Time : 02:08:19

Memory items scanned      : 165
Memory threats detected   : 1
Registry items scanned    : 6318
Registry threats detected : 24
File items scanned        : 116145
File threats detected     : 5

Trojan.Unclassified-Packed/Suspicious
   C:\PROGRA~1\AZR\AZRSHLEX.DLL
   C:\PROGRA~1\AZR\AZRSHLEX.DLL
   C:\PROGRAM FILES\AZR\AZRSHLEX.DLL

Rootkit.SysRest-A
   HKLM\System\ControlSet001\Services\sysrest.sys
   C:\WINDOWS\SYSTEM32\SYSREST.SYS
   HKLM\System\ControlSet001\Enum\Root\LEGACY_sysrest.sys
   HKLM\System\ControlSet003\Services\sysrest.sys
   HKLM\System\ControlSet003\Enum\Root\LEGACY_sysrest.sys
   HKLM\System\CurrentControlSet\Services\sysrest.sys
   HKLM\System\CurrentControlSet\Enum\Root\LEGACY_sysrest.sys

Trojan.NetMon/DNSChange
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc

Trojan.cmdService
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE#NextInstance
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Service
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Legacy
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ConfigFlags
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#Class
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#ClassGUID
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE\0000#DeviceDesc

Adware.Tracking Cookie
   .advertising.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .advertising.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .advertising.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .advertising.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .advertising.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .questionmarket.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .questionmarket.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .doubleclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .doubleclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .atdmt.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .collective-media.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .collective-media.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .collective-media.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .collective-media.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .hit.stat.pl [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad1.clickhype.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   *Blocked Russian URL* [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .kontera.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .kontera.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .kontera.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .kontera.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tracking.vindicosuite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adecn.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tracking.vindicosuite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ad.yieldmanager.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adecn.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .112.2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .insightexpressai.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   www.burstbeacon.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .burstnet.com [ C:\Documents and Settings\CompUSA\Application
Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .burstnet.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .burstnet.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   www.burstnet.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tribalfusion.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.specificclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.addynamix.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   m.rmbclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.addynamix.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   tremor.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tremor.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tremor.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.pointroll.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .bs.serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .serving-sys.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adbrite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adbrite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adbrite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adbrite.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ehg-friendster.hitbox.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .hitbox.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .hitbox.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .mediaplex.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .mediaplex.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   sales.liveperson.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   sales.liveperson.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   sales.liveperson.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   ads.revsci.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .fastclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .fastclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adopt.euroclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .edge.ru4.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .edge.ru4.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .fastclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .fastclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .fastclick.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zedo.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .qksrv.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .apmebf.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .qksrv.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .apmebf.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .cgm.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .network.realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   anad.tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   data.coremetrics.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ehg-tigerdirect2.hitbox.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .videoegg.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .imrworldwide.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .imrworldwide.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .azjmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .reduxads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .stats.virtualreview.org [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .stats.virtualreview.org [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .stats.virtualreview.org [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .ads.clicksor.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .clicksor.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .clicksor.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .media6degrees.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .trafficmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .trafficmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .trafficmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .trafficmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .trafficmp.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .statcounter.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   display.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   display.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   display.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   linkto.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   linkto.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   linkto.mediafire.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .casalemedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .247realmedia.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .precisionclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .precisionclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   anat.tacoda.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .electronicarts.112.2o7.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   partners.webmasterplan.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   partners.webmasterplan.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .usenext.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .usenext.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .usenext.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .usenext.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .usenext.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .interclick.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   stat.onestat.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   stat.onestat.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   stat.onestat.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .axxessads.valuead.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .crucial.adbureau.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .adnetserver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   gomyhit.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   www.tqlkg.net [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .findwhat.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .dynamic.media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .dynamic.media.adrevolver.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   clicktorrent.info [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   adserver.adreactor.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tracker.anirena.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .tracker.anirena.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .zanox-affiliate.de [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .crackle.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .crackle.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   crackle.com [ C:\Documents and Settings\CompUSA\Application
Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .crackle.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   .crackle.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   rotator.adjuggler.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   rotator.adjuggler.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   rotator.adjuggler.com [ C:\Documents and Settings\CompUSA\Application Data\Mozilla\Profiles\default\htzgjdau.slt\cookies.txt ]
   C:\Documents and Settings\CompUSA\Cookies\[email protected][1].txt

Trojan.Downloader-DoneDU
   C:\WINDOWS\SYSTEM32\CIAOTIE.DLL
Ok and I ran SuperAntispyware a second time but I won't post the log because it found nothing in the second try.  Now I ran the Malwarebytes' Anti-Malware software 2 times.  The first time was in normal Windows mode and the second was in Safe Mode.  In Windows mode it foudn some threats about 5 I believe but my computer had some kind of blue screen DOS like page that told me of a terminal error or some kind of mess but after I ctrl + alt + del that went away and I rebooted to safe mode to try to RUN the Anti-Malware again to see if I missed anything.  But the Anti-Malware software stopped after find 3 new threats and I got this little message box saying there is a runtime script error or something.  I think I'll have to reinstall AntiMalware again.  I'll post the Hijack log after this.

Was I supposed to run Anti-Malware in safe mode or Windows?Here is the Anti-Malware file I also put the hijack this log attached
Malwarebytes' Anti-Malware 1.15
Database version: 833

8:40:11 午前 2008/07/13
mbam-log-7-13-2008 (08-40-11).txt

Scan type: Full Scan (C:\|)
Objects scanned: 143333
Time elapsed: 1 hour(s), 0 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\CompUSA\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\CompUSA\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

[recovering disk space -- attachment deleted by admin]Ok this is the latest Malware scan and containment.  I'll post Hijack files with this too.
Please let me know what I NEED to delete with HijackThis in safe mode.  I still have the bright blue background on my desktop.

[recovering disk space -- attachment deleted by admin] Quote

I still have the bright blue background on my desktop.
Don't worry about it, for now.
I'll check HJT, now.*** Open HJT, and checkmark:
- O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (unnecessary startup)
Click "Fix checked" button.

*** Download, and run  CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is also an option to restore the original one.
Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or DISABLE the CTFMON.EXE!

Other than that....


Your computer is clean

1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
Run CCleaner.

2. Turn off System Restore:

- Windows XP:
   1. Click Start.
   2. Right-click the My Computer icon, and then click Properties.
   3. Click the System Restore tab.
   4. Check "Turn off System Restore".
   5. Click Apply.   
   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
   7. Click OK.
- Windows Vista:
   1. Click Start.
   2. Right-click the Computer icon, and then click Properties.
   3. Click on System Protection under the Tasks column on the left side
   4. Click on Continue on the "User Account Control" window that pops up
   5. Under the System Protection tab, find Available Disks
   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
   8. Click OK

3. Restart computer.

4. Turn System Restore on.

5. Download, and install McAfee SiteAdvisor: http://www.siteadvisor.com/download/ff.html. It'll warn you (in most cases) about dangerous web sites.

6. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

7. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

8. Let me know, how your computer is doing.

Thank you so much Mr. Broni!  You are a lifesaver!  Mr. Clean! Mr. Clean!  My computer is so clean now! 

Heres the last Hijack this file I did after I delted that entry you told me and I ran CCleaner and restarted the computer.  I'm definitely going to be more careful when the surfing the web this was a painful lesson!

[recovering disk space -- attachment deleted by admin]Happy surfing
1415.

Solve : My laptop is infected please help!?

Answer»

I have a dell windows 98 laptop that freezes up when trying to turn it on. Two days before this happened I installed a flash player update while using safari because a notice kept popping up.  Please post exact model and manufacturer of laptop.

Why do you think that the computer is infected? What does "freezes up" MEAN? Have you received any error messages? Does the computer run Win98 or Win98SE? Did the problem occur IMMEDIATELY after you updated Flash Player? How long have you had Safari installed? Please list any and all other information that you think MIGHT be helpful and post back.ok ok,
Kieran Quote from: kizza1645 on July 13, 2008, 06:36:21 PM

I can intently see from you what you have told us, that infact the most likely reason for this to be happening, was that you downloaded a flash player. Many website which contain porn etc, will ask you to download a flash player from there website to watch there videos, most of the time these will be infected 
Also its not just porn its heaps of other stuff too.
Kieran

OP said that they downloaded an update to Flash Player - a normal process for security minded computer users.

Let's not ENGAGE in idle speculation about a poster's web habits.
1416.

Solve : pages freeze/lock up, task mgr shows double the pages open.?

Answer»

Final steps.

Set a New Restore Point to prevent POSSIBLE reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to USE System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer REGULARLY to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop CERTAIN cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1417.

Solve : To many programs at start up. What to ckeck in HJT??

Answer»

HJT log attached.
Thanks,
Mike

[recovering DISK space -- attachment deleted by ADMIN]Entries listed below can be safely disabled:
- O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
- O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
- O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (needed, if you overclock video card)
- O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
- O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
- O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
- O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
- O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB
- O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
- O4 - Startup: firefox.lnk = C:\Program Files\Mozilla Firefox\firefox.exe
- O4 - Startup: Secunia PSI (RC3).lnk = C:\Program Files\Secunia\PSI (RC3)\psi.exe (run MANUALLY on occasion)Excellent! She starts much faster now.
Thanks Broni!
BTW, I'm back on my own computer shown in my signature now. My sisters PC you helped me with till YESTERDAY is doing fine. Thanks again for all your help on that.You should note that there are more ways to increase speed as well.
For example, Disk Cleanup and Defragmenting your Hard Disk will speed up the computer.You're welcome, lectrocrew Quote from: Carbon Dudeoxide on July 12, 2008, 01:48:37 PM

You should note that there are more ways to increase speed as well.
For example, Disk Cleanup and Defragmenting your Hard Disk will speed up the computer.
Thanks Carbon Dudeoxide. Speed is good after startup, it's just STARTING all those programs that I was concerned about.
 I ran both programs a few days ago and again just now ='Disk Defragmenter Anylize' says "defrag not needed" on both harddrives. I did find some files in 'Disk Cleanup' > 'more options' > 'Windows Components' and 'Installed Programs' that it fixed.
Thank you also for the help! 
1418.

Solve : Removing Ask from the choices in Internet Explorer?

Answer»

I am using XP HOME with IE7 and for some reason, IE seems to keep defaulting to Ask  (search powered by Ask (default) when I want to use a browser. Could someone please look at the HT log and tell me how I can get rid of Ask?
Thanks,

Harpo


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:52:06, on 30/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Kaluach3\Kaluach3.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
C:\Program Files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig?hl=en
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Israel Radio Toolbar - {5dc2c36d-747c-4fee-8bc3-e86c21981440} - C:\Program Files\Israel_Radio\tbIsra.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar NOTIFIER BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Israel Radio Toolbar - {5dc2c36d-747c-4fee-8bc3-e86c21981440} - C:\Program Files\Israel_Radio\tbIsra.dll
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Kaluach3.lnk = ?
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Sefira Counter.lnk = C:\Program Files\BC CONSULTING Services\Sefira Counter\Sefira.exe
O4 - Global Startup: Webshots Desktop.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (Egg Money Manager Digital Safe) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1211176405553
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jdk/6u10/jinstall-6u10-windows-i586-jc.cab?e=1224789162667&h=6f35ab8cfbaa7b68ba3d01a0ba50401f/&filename=jinstall-6u10-windows-i586-jc.cab
O16 - DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} (Pure Networks Security Scan) - http://scan.networkmagic.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll,avgrsstx.dll
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 15211 bytes
XP may be slightly different however in Vista...
Add/Remove programs will remove the toolbar but to remove the "Ash Search" default you have to use the registry editor.
Search for "Ask Search" and delete the keys...

<edit>

IE7 will now revert to Live Search.
Download random's system information TOOL (RSIT) by random/random from and save it to your Desktop.

  • Double click on RSIT.exe to run.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open.
  • log.txt <will be maximized and info.txt <will be minimized
  • Please post the CONTENTS of both logs in the next reply.
Thank you very much but the problem has sorted itself out.Have HijackThis fix these entries.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Be sure to close all browser windows before clicking Fix checked

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Safe surfing...Thanks, will do.

Best wishes,

Harpo.
1419.

Solve : Following the instructions from evilfantasy...problem encountered?

Answer»

Under step 3 I am unable to install SAS..error message..WINDOWS installer SERVICE not accessible in Safe MODE....PLEASE try again when not in safe mode etc.
Have to be in safe mode to do anything on the machine??

1420.

Solve : Internet Explorer websites keeps popping up?

Answer»

I've ran many anti-VIRUS programs to try and remove it. For example, I've used SpyBlaster, Ad-Aware, Vundo, AVG Anti-Virus, Super Antivirus, HiJackThis, and etc. When I'm on Firefox, the pop ups in IE tends to pop up more than usual. I've ran the programs and supposedly it was removed but for some strange reason, the pop up still seems to be happening. Thank you very much.OK, what site pops up? Or does IE just open? And can you post us a HijackThis log (just scanning with it does nothing) to take a look at? It might take up a few posts, so post in sections (include all headers and such).


Quote

When I'm on Firefox, the pop ups in IE tends to pop up more than usual
Explain.
I think two of them was getmusicfree and revenueloop. Another one seemed to be http://url.cpvfeed.com/cpv.jsp?p=111131&ron=on

IE opens with sites. When I'm off Firefox, it doesn't seem to load as much as when I'm on.

Logfile of HijackThis v1.99.1
Scan saved at 6:44:54 PM, on 6/15/2007
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Default\LOCALS~1\Temp\Rar$EX00.078\HijackThis.exe

O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeIs that the whole log? There should be more.Nope, that's basically it. You win the new record for the SHORTEST log I've ever seen.


Your HijackThis is in a temporary location.  If you leave it there, it (along with its important backups) can and will eventually be deleted.  Please navigate to its current location (C:\DOCUME~1\Default\LOCALS~1\Temp\Rar$EX00.078) and it move to a new permanent folder at C:\Program Files\HJT.  I would also like for you to rename HijackThis.exe to HughJackman.exe.

Before moving on, I'm going to have to ask you to apply Service Pack 1a (do not install Service Pack 2) for Windows XP.  Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here: http://www.microsoft.com/windowsxp/downloads/updates/sp1/default.mspx
Apply the update, reboot, and post a fresh HijackThis log.Okay, done.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Default\Desktop\HughJackman.exe

O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\System32\ewffqhlf.dll
O2 - BHO: (no name) - {93505CBB-CA59-48C2-88E3-4BDF6730B2A0} - C:\WINDOWS\System32\rqoon.dll (file missing)
O2 - BHO: (no name) - {AAE11676-AB2A-4F81-BCBD-7110AC1AA822} - C:\WINDOWS\System32\xxywt.dll
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\System32\dnsersnd.dll (file missing)
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: rqrssqq - rqrssqq.dll (file missing)
O20 - Winlogon Notify: winlnu32 - winlnu32.dll (file missing)
O20 - Winlogon Notify: xxywt - C:\WINDOWS\System32\xxywt.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

xxywt.dll - Trojan
dnsersnd.dll - Trojan


Other than that, everything's fine. No unusual programs running.
I'm not very good at this, so that's all I can gather. Wait for CBMatt, he'll fix your problem.


And I Googled the sites that you said popped up before.

revenueloop and the long sitename one (ww.smashits - the site it links to) both look legit from what I gathered, but getmusicfree isn't so good. Email spamming and links to virus infested sites are what I found out about it.Dark Blade is right about those being infected files (there are more).  You have a Vundo infection, which is most likely causing these popups...

1. Download VundoFix and save it to your desktop.
2. Run VundoFix and click on Scan For Vundo.
3. Once it's done scanning, click on Remove Vundo.
4. When it prompts you to remove the files, click on Yes.
5. Your desktop will go blank as it's removing files.  Don't worry, this is normal.
6. It will prompt you to restart your COMPUTER, so click OK.
7. When your computer is turned back on, your problem should be gone.
8. The program normally produces a Vundofix.txt file.  Please locate this file and paste the contents in your next post.

And then, just to be thorough...
1. Download VirtumundoBeGone and save it to your desktop.
2. Reboot into Safe Mode.
3. Once you are in Safe Mode, run VirtumundoBeGone and follow the instructions.
4. Exit when it has finished and reboot back into normal mode.  Vundo should now be removed from your computer.



After doing so, open up HijackThis and scan.  In a minute, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file.  Open HijackThis and scan again.  Check the following entries, but don't do anything to them yet...

O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\System32\ewffqhlf.dll
O2 - BHO: (no name) - {93505CBB-CA59-48C2-88E3-4BDF6730B2A0} - C:\WINDOWS\System32\rqoon.dll (file missing)
O2 - BHO: (no name) - {AAE11676-AB2A-4F81-BCBD-7110AC1AA822} - C:\WINDOWS\System32\xxywt.dll
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\System32\dnsersnd.dll (file missing)

O20 - Winlogon Notify: rqrssqq - rqrssqq.dll (file missing)
O20 - Winlogon Notify: winlnu32 - winlnu32.dll (file missing)
O20 - Winlogon Notify: xxywt - C:\WINDOWS\System32\xxywt.dll


Now, close all windows (including this one) besides HijackThis, then click Fix Checked.  Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

Navigate to and delete the following file(s) if present (they should be gone after VundoFix, but look for them anyway)...

C:\WINDOWS\System32\ewffqhlf.dll
C:\WINDOWS\System32\rqoon.dll
C:\WINDOWS\System32\xxywt.dll
C:\WINDOWS\System32\dnsersnd.dll
C:\WINDOWS\System32\rqrssqq.dll
C:\WINDOWS\System32\winlnu32.dll


Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up.  Let me know how everything's running now and if you had any problems following my steps.


When you post your next log, please post the whole thing, including the header that lists information about Windows and Internet Explorer.The pop ups are still there.

Logfile of HijackThis v1.99.1
Scan saved at 10:14:10 AM, on 6/16/2007
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Default\Desktop\HughJackman.exe

O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\System32\jjevutlj.dll",realset
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

Here's the one on VBG:

[06/16/2007, 9:40:22] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Default\Desktop\VirtumundoBeGone.exe" )
[06/16/2007, 9:40:28] - Detected System Information:
[06/16/2007, 9:40:29] -  Windows Version: 5.1.2600,
[06/16/2007, 9:40:29] -  Current Username: Default (Admin)
[06/16/2007, 9:40:29] -  Windows is in NORMAL mode.
[06/16/2007, 9:40:29] - Searching for Browser Helper Objects:
[06/16/2007, 9:40:29] -  BHO 1: {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} ()
[06/16/2007, 9:40:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:40:29] -  Checking for HKLM\...\Winlogon\Notify\bmxuclwm
[06/16/2007, 9:40:29] -  Key not found: HKLM\...\Winlogon\Notify\bmxuclwm, continuing.
[06/16/2007, 9:40:29] -  BHO 2: {AAE11676-AB2A-4F81-BCBD-7110AC1AA822} ()
[06/16/2007, 9:40:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:40:29] -  Checking for HKLM\...\Winlogon\Notify\xxywt
[06/16/2007, 9:40:29] -  Key not found: HKLM\...\Winlogon\Notify\xxywt, continuing.
[06/16/2007, 9:40:29] - Finished Searching Browser Helper Objects
[06/16/2007, 9:40:29] - Finishing up...
[06/16/2007, 9:40:29] - Nothing found! Exiting...

[06/16/2007, 9:48:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Default\Desktop\VirtumundoBeGone.exe" )
[06/16/2007, 9:48:02] - Detected System Information:
[06/16/2007, 9:48:02] -  Windows Version: 5.1.2600,
[06/16/2007, 9:48:02] -  Current Username: Administrator (Admin)
[06/16/2007, 9:48:02] -  Windows is in SAFE mode with Networking.
[06/16/2007, 9:48:02] - Searching for Browser Helper Objects:
[06/16/2007, 9:48:02] -  BHO 1: {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} ()
[06/16/2007, 9:48:02] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:48:02] -  Checking for HKLM\...\Winlogon\Notify\bmxuclwm
[06/16/2007, 9:48:02] -  Key not found: HKLM\...\Winlogon\Notify\bmxuclwm, continuing.
[06/16/2007, 9:48:02] -  BHO 2: {AAE11676-AB2A-4F81-BCBD-7110AC1AA822} ()
[06/16/2007, 9:48:02] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:48:02] -  Checking for HKLM\...\Winlogon\Notify\xxywt
[06/16/2007, 9:48:02] -  Key not found: HKLM\...\Winlogon\Notify\xxywt, continuing.
[06/16/2007, 9:48:02] - Finished Searching Browser Helper Objects
[06/16/2007, 9:48:02] - Finishing up...
[06/16/2007, 9:48:02] - Nothing found! Exiting...

[06/16/2007, 9:48:43] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Default\Desktop\VirtumundoBeGone.exe" )
[06/16/2007, 9:48:43] - User choose NOT to continue. Exiting...

[06/16/2007, 9:48:51] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Default\Desktop\VirtumundoBeGone.exe" )
[06/16/2007, 9:48:52] - Detected System Information:
[06/16/2007, 9:48:52] -  Windows Version: 5.1.2600,
[06/16/2007, 9:48:52] -  Current Username: Administrator (Admin)
[06/16/2007, 9:48:52] -  Windows is in SAFE mode with Networking.
[06/16/2007, 9:48:52] - Searching for Browser Helper Objects:
[06/16/2007, 9:48:52] -  BHO 1: {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} ()
[06/16/2007, 9:48:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:48:52] -  Checking for HKLM\...\Winlogon\Notify\bmxuclwm
[06/16/2007, 9:48:52] -  Key not found: HKLM\...\Winlogon\Notify\bmxuclwm, continuing.
[06/16/2007, 9:48:52] -  BHO 2: {AAE11676-AB2A-4F81-BCBD-7110AC1AA822} ()
[06/16/2007, 9:48:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/16/2007, 9:48:52] -  Checking for HKLM\...\Winlogon\Notify\xxywt
[06/16/2007, 9:48:52] -  Key not found: HKLM\...\Winlogon\Notify\xxywt, continuing.
[06/16/2007, 9:48:52] - Finished Searching Browser Helper Objects
[06/16/2007, 9:48:52] - Finishing up...
[06/16/2007, 9:48:52] - Nothing found! Exiting...

Try running VundoFix again, as you still have traces of it left on your computer.  Also, it's very important to update to Service Pack 1 like I stated in my first post.  Once you have done these things, go ahead and post a new HijackThis log.When I scanned for Vundo, there wasn't anything. Also, I did another scan on AVG.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

 + Created at:   3:15:01 PM 6/16/2007

 + Scan result:   



:mozilla.348:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -&GT; TrackingCookie.Adbrite : Cleaned.
:mozilla.349:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.350:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.351:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.352:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.353:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.354:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.355:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.356:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.357:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.358:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.359:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.360:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.361:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.362:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.363:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.364:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.365:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.366:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.367:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.370:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.373:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.374:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.375:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.376:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.519:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.536:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.529:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.530:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.484:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.485:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.486:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.487:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.488:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.483:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.310:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.

:mozilla.311:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.312:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.313:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.314:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.315:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.316:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.397:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Default\Cookies\[email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.413:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.398:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.399:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.400:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.549:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.550:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.551:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.552:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.553:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.521:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.525:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.526:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.527:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.528:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Default\Cookies\[email protected][2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.212:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.213:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.470:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.341:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.342:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.343:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.344:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.345:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.403:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.404:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.405:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.406:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.407:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.408:C:\Documents and Settings\Default\Application Data\Mozilla\Firefox\Profiles\4bhxlc6n.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

It still seems to pop up websites on Internet Explorer.Okay...install Service Pack 1a if you haven't already and then post a new HijackThis log.  Without SP1, it makes it very easy for you to become reinfected.
1421.

Solve : Need Viruses?

Answer»

Quote from: Carbon Dudeoxide on May 09, 2007, 07:17:25 AM

Quote from: CBMatt on May 09, 2007, 07:15:54 AM
Quote from: Carbon Dudeoxide on May 09, 2007, 06:13:46 AM
Quote from: contrex on May 09, 2007, 06:10:16 AM
Is everybody on here AGED about 10? This place is more like a kindergarten than a proper forum. 
Lol, this HAPPENS with the 1000+ posts guys too. 
Quantity doesn't exactly MEAN quality.
Exactly!..........wait, is that a bad thing?
It means that just because a person has a lot of posts, it doesn't mean that they are inelligent or mature.
1422.

Solve : Is this a virus!!?

Answer»

Tony, don't worry if you can't find the files.  They're not always there.  Even thought HJT says the files are missing, I ask people to look because it may not always be true.  I have a question, though: you're absolutely sure you don't have a Network Monitoring folder in Program Folders?

You say you can't get into Safe Mode...  Were you able to before?  Did you try another function key such as F2 or F5 (and so on)?

Quote

if i end the suspected virus it warns me to save and shut down programs and gives me a min before i shuts down.
Exactly what process are you ending?  svchost?  That file is LEGITIMATE; there's no need to shut it down.

Please post a full HijackThis log and let me know if you are experiencing any other problems.network montoring is in add/remove programs but it wnt let me unistall it , i tried unstalling it out of safe mode still wouldnt allow me came up with a error message , i will try and put my computer in safe mode again i have solved the problem with my shockwave player so embrassing i dnt want to say  what the problem was  lol

As far as any virus program i go on her goes its all saying im am fine i have tryed eveything ccleaner , norton , avg , spybot u name it . I WENT onto major geeks installed a few beta programs not very good to be honest , but theres a lot of files on here they shouldnt be here .


As for my pc's cpu its throught the roof its on a flat line then drops ____________
                                                                                                                              /
                                                                                                                             /

Remind me how do i post a screenshot on here of my pc's cpu and proccess  Well, whatever you did, I'm glad you got your Shockwave issue sorted out.

Network Monitor may have already been removed.  Go to C:\Program Files and if you're absolutely sure the Network Monitor folder doesn't exist, then use the Tools feature on CCleaner to remove it from your list.  You should also run the Cleaner and Issues while you're at it, just for good measure.

HJT provides a list of all of your running processes, but if you WOULD like to take a screenshot, press the Print Screen key on your keyboard.  Then open up Paint, press Ctrl+V, and save the file as screenshot.jpg.  You can then attach it to your next post (if the file is too big, you may need to upload it to PhotoBucket).This gunna make me sound like a noob but i will list what ccleaner has listed on my start up ....

1.CFTMON.EXE
2.USERFAULTCHECK AKA (%SYSTEMROOT%\SYUSTEM32\DUMPREP 0-U


Now i have no clue what this 2 are the others i want to run

shall i close them in ccleaner
Quote from: richenstony on May 15, 2007, 08:31:07 PM
1.CFTMON.EXE

It says CFTMON?  Or does it say CTFMON?  If it's CTFMON, leave it alone.  If it's CFTMON, tell me.

Network Monitor wouldn't be listed in the Startup.  When in Tools, click on the UNINSTALL tab and it will give you a long list of programs.  Go all the way down to Network Monitor and click on Run Uninstaller.  If it still doesn't work, then click on DELETE Entry.  But only do this if C:\Program Files\Network Monitor DOES NOT exist.The next HJT log should be run in full mode with Hijack this in it's own directory...

Carry on.
1423.

Solve : TO vundo or not to vundo?

Answer»

c:\\WINDOWS\SYSTEM32\GGJLM.BAK1 vundo picked this up and 10 others like it do i fix them or to i just EXIT vundo need to know due to msn virus last week cheersYou're close to winning the Monthly award for lack of details for your dilemna...

VUndo is an infection. I assume you're running VundoFix (see, when you provide pretty much no information, we have to make assumptions).  In that case, I don't see why you wouldn't delete what it finds.  It is, after all, designed to detect and remove Vundo infections.hMM well sorrys alll round for my lack of understanding in what my pc is doing to me if i DNT write something then i dnt know wether it will be useful for you im only typeing what im SEEING . I have read over 200 diffrent threads on here already and still dnt understand certain PROBLEMS on my computer i dnt reach put for help untill im fully uncaple of doing it myself . Next TIME i will try to add more information about my pc and my problem.

Basically vundofix picked up loads of files i was getting confussed with other program that i got of here .

Im still having serious conneciton problems on shockwave i cnt connect to a game without it taking like 5 min.

List all the protection programs you currently have installed and we'll start there...

1424.

Solve : Javascript/ Flashplayer don't work- virus????

Answer»

Hi, I have a Dell laptop that runs on Windows XP. Recently I had a virus and a computer technician deleted the virus and put McAfee Antivirus on my computer. However, since the virus was deleted, many of my websites don't work, such as BANKING websites and tv websites (like abc.com, mlb.com, etc.). The websites say that I dont have my javascript enabled (which I do) or that I dont have flash player (which I do). I even tried to redownload macromedia flashplayer and the place where I  was supposed to click "install now" didn't show up. Do you have any idea whats wrong with my computer? Thank you!more info plz like what was the infections name?

what protectiond do you have other than MCafee?To enable Javascript:
In the menu bar, click TOOLS>Internet Options
Select the "Advanced" tab
and at the bottom of the options WINDOW, click
"Restore Defaults"

Install Flash player from here:
http://www.adobe.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash
(You may want to Uninstall it, via "Add/Remove Programs" under Start>Control Panel I dont have McAfee, sorry, I have Symantec.  I also have ePest Patrol. I dont know what the name of the virus was. When I try to click on that link to download flashplayer I cant install it- There is no Install Now button (I think wtvr problem i have is BLOCKING the link from showing up). I looked up java in my control panel and it says I have the most current version! I have refreshed the defaults in the internet options panel numerous times and it just does not work. HELP!I am thinking that a reinstall of Microsoft Internet Explorer would be a great idea.

What version are you CURRENTLY using? (Click Help...About Microsoft Internet Explorer)

And when was the last time you ran Windows Updates?

1425.

Solve : W32.IRCBot.Gen PLEASE HELP!?

Answer»

recently my norton system works 2006 has been giving me the message of the W32.IRCBot.Gen virus has been FOUND and ALSO deleted and it comes up the page, found 1 infection and its been deleted etc. Though this message constantly comes up all the time saying its found the W32 and deleted it. What does this mean? I'v done the symantec walkthrough to get rid of this virus/trojan but when i go into safe mode to scan for it, it doesnt show up o nthe scan. Can someone please help?System Restore turned off and Safe Mode are the best way to thoroughly CLEAN so you are not just reinffecting yourself. You may also want to try the online scanner at Panda or Trend Micro

www.trendmicro.comif your having problems with trojans then try AVG anti-spyware, spybot, adaware


unlovedwarriorDLoad and run Stinger.

Do this in safe mode with System Restore turned off as GX1_Man suggested.

This is a low level threat BTW more of a pain in the *CENSORED* than anything.

1426.

Solve : Critical System Errors?

Answer»

Im getting an icon in sys TRAY that says critical system error when i click on it it TAKES me to this SITE http://www.virusbursters.com/?aff=334  Can anyone help me get rid of this. cant find it in startup but its loading every time i restart? Im running win xpClick on the link below.
http://www.bleepingcomputer.com/forums/topic70074.htmlWhat were you using for protection from virus/spyware? It didn't work.  Thanks FED that did the trick. It was my parents computer. I RAN agv and ADAWARE but couldnt get rid of it. The link FED gave me did it though. Thanks again for the quick response.Thanks for the feedback.

1427.

Solve : Spybot S?

Answer»

Here's the answer to the second part of your question.
Quote

SPYBOT
Servers upgraded & update size improved [link]    13. October 2006
We apologize for any downtimes over the past days. The servers for this website and the main update information has been replaced; some update mirror servers will be upgraded as well.

Also, beginning next week, the size of the weekly update files will be reduced as we're optimizing the process of downloading only changes. As a RESULT of this, users using the ADVANCED mode in Spybot-S&D will probably notice ADDITIONAL filesets; those ending in the LETTER C are new ones containing the most up-to-date detection rules.
 
1428.

Solve : ice 2.5 setup.exe?

Answer»

For the past week or so, I've had a lot of problems with my HP 1300 All-In-One printer. Ever since I had to  cancel the printer process to clear the spooler I've had these four programs that continually install themselves.  There named 1300Tour, 1300Trb, 1300_help, and 1300.  The run every time I turn on the printer, insert a CD, or plug-in a USB device like my flash DRIVE.  What's strange is that they do not show up in the Add, Remove programs list.  They do however, show up in the uninstall list for CCleaner, though I am unable to remove them. I did a little searching in my programs folder and discovered in "C:\program files\HP\temp\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" a program named "ICE 2.5 setup.exe." Stupid me I ran the setup file and sure enough it was the HP All-In-One file that runs every single time, though this one was a bit different as it was claiming to be running a "clean up process."  As I looked at the status of what it was cleaning up, I realized it was cleaning up my INSTALLED programs by deleting them. I immediately canceled the process in Task Manager, though I was to late to save my RCT 3 game from being partially deleted. I am total lost on what to do. I've tried preventing the programs from running by having them labeled "kill" by Zone Alarm. That didn't work. I provided the log file from HijackThis below.

Logfile of HijackThis v1.99.1
Scan saved at 2:44:28 PM, on 11/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\SurfControl\CyberPatrol\cpserver.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SurfControl\CyberPatrol\cpACtrl.exe
C:\Program Files\SurfControl\CyberPatrol\cpCCtrl.exe
C:\Program Files\SurfControl\CyberPatrol\cpkbinst.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: AcroIEHlprObj CLASS - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe" /m
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RunDLL32.exe" NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\.Post the complete HijackThis log...Logfile of HijackThis v1.99.1
Scan saved at 2:44:28 PM, on 11/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\SurfControl\CyberPatrol\cpserver.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SurfControl\CyberPatrol\cpACtrl.exe
C:\Program Files\SurfControl\CyberPatrol\cpCCtrl.exe
C:\Program Files\SurfControl\CyberPatrol\cpkbinst.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\SurfControl\CyberPatrol\CPHQ.exe" /m
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RunDLL32.exe" NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exThere is a glitch with some HP software that causes this. If you try to uninstall it, you will hose your system. You MIGHT get lucky and reinstall the software, then update it, but if not, the only solution I have found is torestore the system. If that turns out to be the case, I hope you have an image file to do this with quickly. If not, perhaps system restore is worth a try.

I have never figured out what triggers this, but sometimes it starts after a power surge if the printer is turned on.

I will be interested in how this turns out.   Quote

Post the complete HijackThis log...

You will need to post the log over 2 or 3 posts, there is a 5500 character limitation on forum posts.Here is the rest of the log.

O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: + &Mass Downloader: download this file - C:\Program Files\Mass Downloader\Add_Url.htm
O8 - Extra context menu item: + Mass Downloader: download &All files - C:\Program Files\Mass Downloader\Add_All.htm
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://activex.microsoft.com/objects/ocget.dll
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by16fd.bay16.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\DRIVERS\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
1429.

Solve : virus detectors not working?

Answer»

Quote

If you don't wish to reformat (BTW, it will fix EVERYTHING) then you should really try to get into safe mode and run all the scans.
Are you giving safe mode a long time to LOAD?
I know it MAKES no sense but safe mode TAKES a long time when compared to a normal boot, it should be faster with very little to load but for some reason (Bill Gates) it seems to take forever.

If safemode doesn't load quickly, something is wrong with your system.Well EITHER that's a LOT of Word documents (which I doubt) or a lot of P2P downloads that each may be laced with nasties. Be careful with what you save.

Maybe an external HD would be in order?Agreed. 123G of Word docs sounds like the entire Library of Congress to me...if there where 6150 documents at around 20000 that seems like alot lol
1430.

Solve : virus help,just wanna get rid of them?

Answer»

hey,i been GETTING a yellow triangle in my icon,and things saying my performance is slowing down


i just want it 2 stop,thanks, Quote

hey,i been getting a [highlight]yellow triangle[/highlight] in my [highlight]icon[/highlight],and [highlight]things[/highlight] [highlight]saying[/highlight] my performance is slowing down


i just want it 2 stop,thanks,

What yellow triangle?
What icon?
What things?
What exactly are they saying?

What OS?
What protection are you using?Sounds like a personal PROBLEM.  


Fed, be SURE and check his last 50 posts to refresh your MEMORY of what the problem may be.  That sure are a lot of.. PROBLEMS..   Something about Ebay, haircuts, usb ports and dads? Quote
just want it 2 stop,thanks,

Us too...believe me. Quote
Quote
just want it 2 stop,thanks,

Us too...believe me.

1431.

Solve : Boot Sector Virus Removal??

Answer»

Not through a cable, not through hardware, EXCEPT for an infected hard drive. Only from a download or having/running an infected file.BIOS Virus?

Are those still common?After literally disappearing for 8 or so years because protection programs got so SOPHISTICATED they have recently reared their ugly head...i assume this is a result of the next generation of newbie hackers out there who have nothing better to do than keep us professionals employed.

patio.    8-)Where do you work, Patio?Self employed...all over the State.

patio.   8-) Quote

Self employed...all over the State.

patio.   8-)
Sounds fun!I enjoy my work even though i find the CONCEPT of working for a living pretty ridiculous.... Meanwhile the original poster has gone AWOL.  maybe he'll come back... If he only knew how well his THREAD turned out...

patio.   8-)oh well he might come backThen again if he in fact does have a bootsector virus chances are he can't get back...

patio.    8-)very TRUE i hope hes smart enough to reformat or go to another computer..
1432.

Solve : Trojan Vundo.be issues?

Answer»

This trojan is apparently in or running from sstrs.dll. I've tried everything I can think of to DELETE that file:

SAFE mode
Safemode with command prompt
A BartPE boot CD
Data scrubbers (such as eraser and BCwipe which have delete on reboot type features)
Hijack this delete on reboot
Virus scanners (trend micro can detect it)
unlocker and killbox

yet the file is always inuse or otherwise impossible to delete. Any suggestions?

I'm using widnows 2000
What  about this:

http://www.symantec.com/security_response/writeup.jsp?docid=2004-112210-3747-99

or  these:

http://www.bleepingcomputer.com/forums/topic18610.html

http://www.softpedia.com/get/Antivirus/Trojan-Vundo-B-Free-Removal-Tool.shtmlStarforce, if you haven't tried anything else yet I'd really like to know if Ewido cleans it for you.
http://www.ewido.net/en/
It won't hurt you. *trust me*  
Thanks. Quote

Starforce, if you haven't tried anything else yet I'd really like to know if Ewido cleans it for you.
http://www.ewido.net/en/
It won't hurt you. *trust me*  
Thanks.

Ahh...a new toy. Well, lets just say the trendmicro trail sucked arse, it slowed my system toa  crawl worse than any virus I ever had. I realise I got a 1200 mhz on 256 ram but still...so I'll see what this does.
ok, ewido has givin me a popup alert to sstrs.dll a few times, I asked it to cleana nd quarentine and once to simply delete, so FAR the file is still there. It's in the middle of a full scan right now. Found a few other oddballs the rest missed, such as the fact that I had that effin purity scan again. Also, that vundofix.exe I downloaded, never reopens after I select run as a TASK. Or, atleast I see no evidence it has in task manager or anywhere else.I'm not quite sure exactly where you are at right now?
You could also try Ewido in safe mode, let us know the END result. Quote
I'm not quite sure exactly where you are at right now?
You could also try Ewido in safe mode, let us know the end result.


Well, at this point I'm back where I started. I ran the basic scans on ewido to keep the time short and it removed items and detected the sstrs.dll but didn't delete it. I also tried dos and will trys afe mode command prompt but I hve no idea how to start windows 2000 in dos so..if that option doesn't work...

Also now that I know how to do the cd and delete stuff in dos I might try Bart PE again.Do the full Ewido scan in safe mode, let's see if it works.
Thanks. Quote
Quote
I'm not quite sure exactly where you are at right now?
You could also try Ewido in safe mode, let us know the end result.


Well, at this point I'm back where I started. I ran the basic scans on ewido to keep the time short and it removed items and detected the sstrs.dll but didn't delete it. [highlight]I also tried dos and will trys afe mode command prompt but I hve no idea how to start windows 2000 in dos so..if that option doesn't work...[/highlight]
Also now that I know how to do the cd and delete stuff in dos I might try Bart PE again.


Safe Mode is not DOS. Win2000 does not have DOS. Safe Mode is F8 at boot before the Windows logo.   Yikes a vundo plague, come on Starforce, what happened?I might hafta find someone who can use my drive as a slave drive, and boot of theirs and then sweep all the crap out...What kind of hard and optical drives are in that machine? How much data needs to be backed up roughly?I got 2 hd, one 30 and one 200gb and I got a zip 256 and a dvd+r (I think it's a dual layer). I could just dump everything over and format but I don't see a point in doing a system restore when I'll be building a whole new machine soon.Did you try ASquared as well ? ?

And or the trial version of Trojan Hunter.

Again update them both first...turn off System Restore and run them in SafeMode.

Hope this helps.

patio.   8-)Never heard of either of those.
1433.

Solve : Is this caused by a virus??

Answer»

I have been infected by a spyware program that comes in the form of a spyware add.  I have sbc yahoo so I want to download their free program.  Problem I have Norton antivirus and Mc afee firewall .  Do I have ot uninstall any of them. How? :-?

Welcome Aboard...

More info on what you need solved and someone will be along shortly.

patio.   8-)what antispyware do u have?

what are the specs on ur machine Quote

I have been infected by a spyware program that comes in the form of a spyware add.  I have sbc yahoo so I want to download their free program.  Problem I have Norton antivirus and Mc afee firewall .  Do I have ot uninstall any of them. How? :-?




dellydestiny,

[highlight]Create your own post[/highlight] in this section of the forum and give as much info as possible about your problem and what [highlight]you[/highlight] have done so far to CORRECT it.

Such as, what programs you have ran. etc.

And what free program from SBC/Yahoo? Quote
Welcome Aboard...

More info on what you need solved and someone will be along shortly.

patio.   8-)


Still waiting...Original Poster is AWOL. Next?Yup,

APPEARS to be a HIT and run.Thank goodness their problem is solved...see how efficient we are ? ? ?
 

patio.   8-) Quote
Thank goodness their problem is solved...see how efficient we are ? ? ?
 

patio.   8-)

at scaring ppl away
lolDid you try getting into safe mode.

Start up the computer and press F8 and select safe mode with network connection.

SteeveSteeve,

The original poster has been absent for almost a week. This is called Hit and Run Posting.Sorry dude didn't notice thxs for the shout out.

Regardsdo u think he solved his own problem or just forgot about us Quote
do u think he solved his own problem or just forgot about us


Its hard to SAY. Quote
do u think he solved his own problem or just forgot about us

Let's hope it was the FORMER and assume the latter.
1434.

Solve : spywareblaster's block list: won't "protect"?

Answer»

Greetings everyone!

I need help enabling "protection against checked ITEMS" in spywareblaster.  Here's the background:

i updated my SpywareBlaster today and my "Protection window" showed that "89 items have protection disabled" in the Restricted Sites page.  I clicked "enable all protection" and still the same figure CONTINUED.  I went to the "Restricted Sites" page and noticed that quite a few items were unchecked and printed in red.  I checked all of the boxes next to those items and clicked again on the button "protect against checked items".  The progress bar moves but the items remain unchecked and I still have 89 unprotected items.  BlockCheckers, Clickzs, CoolWebSearchers, Mirar and Z-quest are some of the items on the list.  

X-Cleaner, Spybot, Microsoft Malware Detection Tool, Webroot, macaffee VirusScan Enterprise, Microsoft AntiSpyware and Ad-Ware all seem happy to congratulate me on not having any suspicious stuff on my computer.  Spycatcher caught a few things but only one was a confirmed dangerous piece, which I deleted.  

How can I get rid of the rest of that stuff?  And why are all the other programs not reading them as malicious?

Thank you for your time and help.

driveerased...... First of all which operating system are you using .....?
Quote

X-Cleaner, Spybot, Microsoft Malware Detection Tool, Webroot, macaffee VirusScan Enterprise, Microsoft AntiSpyware and Ad-Ware all seem happy to congratulate me on not having any suspicious stuff on my computer.  Spycatcher caught a few things but only one was a confirmed dangerous piece, which I deleted
....... You must REALIZE , that there hasnt been a nasties scanner desgned that will find and remove everything . You must use a number of various apps to do the job.
When you respond , I will be happy to offer some suggestions.

dl65  ... and i thought i was so thorough in my post LOL... windows XP is my OS.

and you are absolutely right on the need to use different apps.  that's precisely why i tried running all of the ones i mentioned, in addition to AVG and the GDATA Softwared worm remover.

Thank you for writing.  I look forward to your suggestions.

I'm wishing you well.

driveerased..... LOL , your post was pretty complete , however the reason I inquired about your O/S is because some apps won't run on all windows o/s .

I would suggest the following :
A good  Anti-Virus
Ewido Security ........ good for finding and removing trojans
Spybot Search and Destroy ...... Be sure to enable the resident
M/S ...... Windows Defender is decent .
Ad-Aware SE Personal .......
Always check for updates before running any of these


Then in your toolbox ......you should have:
hijackthis ....( very powerful tool )
CWShedder
Vundo Fix
Stinger
CCleaner .... excellant for cleaning up your system
Always check for updates before running any of these

There is a multitude of free apps out there ........ The ones I mention are simply the ones I use.

BTW ..... You didnt mention which version of SpywareBlaster you are using .....I just D/L V3.5.1 ..... and it doesnt have any scanner it just appears to block anything comming in .... so if your machine is infected , another tool will be required to find and remove them .


dl65  



DL65,

thank you for your suggestions.  I have downloaded, installed and run Ewido Security (as well as the online scanner beta), CWShedder, Stinger and CCleaner.  This morning I updated every single one and ran them again.  None of them seems to find an infection. However, G DATA anti-worm tells me that it "looks like" my HOST has been hijacked and it does provide me with a report, which, unfortunately, I can't understand.  What I have noticed, though, is that all addresses end with #SpySweeperCASS, and SINCE I have Webroot Spysweeeper as resident, I'm not sure how this can indicate hijacking.

I continue to be unable to protect against the several instances of BlockCheckers, Clickzs, CoolWebSearch, mirar and Z-Quest that my (newly downloaded version of) Spyblaster indicates are "unprotected".

I was hoping that you might provide other ideas.

Thank you.

I'm wishing you well.

 driveerased...how about posting the report from....G DATA anti-worm

and how about a new hijackthis log .


dl65  Thanks for writing.

Much as I hate to admit it, I don't know what hijackthis is, nor do I know how to get a log through/with it.  I will however post the antiworm hosts report here as soon as i find out how to convert a text file to one of the formats accepted by this forum.

Thank you again for your interest and help.

Regards.Have you used a program like Spybot to 'lock your host file'?i use spybot all the time but i don't recall using it to "lock host file".  i imagine one would do it through the TOOLS tab... i'm running on the affected computer right now.  will look at the TOOLS commands once the scan is over.

Thank you.

PS: what would that accomplish, locking my host file? or are you suggesting that this might be the problem?I'm suggesting that if your hosts file is locked by a third party program then your spyware blaster will not be able to alter it.good pont on the locked hosts files, Fed. Thank you.  I have now locked them with SpyBot. Incidentally, this scan by SpyBot was also unsuccessful in eliciting any malware or programs, which, in turn, brings me back to my original question:  how can i either prevent those items SpywareBlaster tells me are "unprotected"  - BlockCheckers, Clickzs, CoolWebSearch, mirar and Z-Quest among others, from stealing my privacy and/or further demaging my system?  How do I get to them and pry them out?  Incidentally, the SpywareBlaster report shows IE only has these problesm Mozilla Firefox items all appear checked and protected.

Thank you in advance for any help anyone can provide.

I am wishing you well.

At the bottom of the Status tab, click "Enable all protection".
1435.

Solve : What is KernelFaultCheck??

Answer»

Hi Everyone,

I am running Windows XP Service Pack 2.

I was just looking at an entry in Piriform CCleaner, and I just found an entry called KernelFaultCheck in it. I have disabled this debugging for my computer, so I think this is a virus.

My computer hasn't been running smoothly for over 2 months now.
And today, I have being receiving the same update from MS over and over again.

Is this a virus or a sort of trojan?

I am already thinking of removing the stupid thing, since it is already making me worry.

Just asking if it is a virus or trojan.

Thank you in advance.what protections are you running? can you post a hijackthis log for usOh, here you go:

Logfile of HijackThis v1.99.1
Scan saved at 4:45:29 PM, on 28/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\Madotate\madotate.exe
C:\PROGRA~1\INTERN~1\iexplore.exe
C:\WINDOWS\explorer.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aapt.net.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aapt.net.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aapt.net.au/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AAPT
O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Desktop Service Centre] "C:\Program Files\OptusNet DSL Internet\DSC.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Madotate.lnk = C:\Madotate\madotate.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra CONTEXT menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows GENUINE Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179968191281
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://sunnydays07.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

Had a bit of problems while HijackThis was scanning.
Looked more like RunTime errors.

Strange.The log looks pretty CLEAN to me.

The entry in question should be safe.  If you want, you can check out YODA's advice here...
http://forums.thatcomputerguy.us/index.php?showtopic=18478

This will help ensure KFC is turned off.  You say you've been having problems for two months now...exactly what kinds of problems?  When was the last time you updated AVG and scanned with it in Safe Mode?  You should do that as soon as possible.

You should also download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.


And while you're at it, you may want to get a firewall.  You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo.  They're all good free FIREWALLS.  Just be sure you only have one installed at a time!  Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.Actually, I disabled memory dumps before I found this problem.

My mouse moves by itself, and for no reason at all, I just received another 'Moving...' dialog box. But I'm not even doing anything!

By the way, what does KFC mean? Kentucky Fried Chicken? Nah, just joking.
Stands for Kernel Fault Check.Hey, does anybody know how to attatch a TXT file?I'd click on Additional Options in the Post Reply box.Thank you, Fed.

Here is the ComboFix log file.

[Saving disk space - attachment deleted by admin]

1436.

Solve : NEEDED!?

Answer»

hey! this could REALLY sound ridiculous but i really need a simple program on  a computer virus.


       Thx?? Quote

hey! this could really sound ridiculous but i really need a simple program on  a computer virus.


You want a virus? Or you want to GIVE a virus? In either case there are BETTER things to do with a computer.  
Quote
hey! this could really sound ridiculous but i really need a simple program on  a computer virus.

You're right, it does sound ridiculous.
1437.

Solve : Updated HighjackThis Log?

Answer»

So I ran all the programs in regular mode and safe mode and turned off system restore and all that. Here is the new log:

Quote

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRAM Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\armando sr\Local Settings\Temp\wz307f\HijackThis.exe
Quote
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: ADOBE PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3AF9102C-EB4E-47B5-8751-60550E872E39} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {614BBBCC-5C08-30A8-2BB6-0495C885DCBC} - (no file)
O2 - BHO: (no name) - {6449E3C9-575F-61AA-2BB6-0495C885DFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FD704130-FFAA-C159-D0E9-A10FA1E64EB7} - (no file)
O2 - BHO: (no name) - {FD704140-FFDF-B258-D0EF-D00FD3954EC2} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Wireless-B PCI Adapter Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
Quote
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NICSer_WMP11 - Unknown owner - C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
 Armando.... You logfile looks ok...

Did you find anything when you ran the scans in Safe Mode ?

dl65  Surprisingly (for me at least), yes. Ewido found some adware and spyware which I got rid of. Spypot didn't find anything though.
1438.

Solve : Heres my hijackthis log backdated?

Answer»

Thanks for any replys

Quote

Logfile of HijackThis v1.99.1
Scan saved at 15:29:41, on 11/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\mspaint.exe

C:\Documents and Settings\HP_Owner\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.co.uk/iesearch/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.co.uk/iesearch/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q404&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo

Quote
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - TOOLBAR: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Home THEATER SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P17 "EPSON PictureMate" /O6 "USB001" /M "PictureMate"
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB002" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\Pavilion\XPHWWBF4\plugin\bin\pchbutton.exe
O4 - Startup: Climate Change Experiment Manager.lnk = C:\Program Files\Climate Change Experiment\cpdnbbcmgr.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Quote
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/providers/electric_paper2000_hybrid/module05/aware_player/awswaxf.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1134672930531
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1D053275-5219-46F0-AC8B-F5749512E2D0}: NameServer = 195.92.195.94 195.92.195.95
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Thread Master (ThreadMaster) - http://threadmaster.tripod.com  -  [email protected] - C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe
The following should be removed:

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)


I you don't know what these are, remove them also:

O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab

O23 - Service: Thread Master (ThreadMaster) - http://threadmaster.tripod.com - [email protected] - C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe

You have loads of unnecessary crud starting up so please review your Add/Remove Programs applet. Be vicious with it.... You know you want to.
$%^& !
My computer has completely messed up
I shouldn't have deleted that thread master thing, I looked at their homepage and remember downloading from there, but i couldn't remember why... so i just deleted it

Luckly i have found the link to a page i read about it ages ago http://bbc.cpdn.org/forum_thread.php?id=600

I used it to turn down the CPU usage of a program, but now i have deleted it has turned down on everything! no programs will use more than 60% CPU, i cannot play games or use any media without the screen jumping.

Got myself in a right pickle...

I'll look into it tomorow and maybe ask them, but i just can't be botherd right now
I did not backup the file either, does Hijackthis save backups by itself?

no BF1942 for me tonight  Hijackthis does create backups. Run it and click on Config>Backups.
1439.

Solve : Cheap Norton Replacement?

Answer»

I've been a loyal Norton user for years and years.... But find myself strapped for cash as my annual $ubscription runs out...

So, after scanning folks' posts in here, I have decided to replace Norton Firewall with Zone Alarm, and Norton AntiVirus with AVG Free.

[highlight]=> So, someone PLEASE confirm those are two good choices![/highlight]

But I also like to use Norton WinDoctor, System Doctor, DiskDoctor, etc. Is there any good, free software to replace those???

ETA: (I also like the IDEA of Norton GoBack, although I don't think I've ever used it!)

Or am I better off skipping groceries for a week and SENDING the cash to Peter?

Thanks!The Norton utilities SEEM to cause a lot of problems and imho, you are better off without them. Beware of the latest version of ZA - It too seems to have it's fair share of problems. You'll find a good selection of mostly free and above all, clean software [highlight]here[/highlight].
Personally, for a free firewall, I would recommend [highlight]Kerio 215[/highlight].

To fully remove the Norton/Symantec products, you will undoubtedly need one of the remoal tools that Symantec supply.Thanks. I will take note of Kerio... But I have to view your post with some skepticism... Your post count is "666"... Troubling... Quote

Your post count is "666"... Troubling...

LOL ....... Thats because his post before that was 665


dl65   Quote
Thats because his post before that was 665
Post PROOF or retract.

I guess I don't lose utilities when I don't resubscribe, do I? Just the Firewall and AntiVirus....

I'll try both firewalls - one on each machine - and see what happens!

Thanks
rjbinney........
Quote
Post proof or retract.

Excuse me , but what are you refering to?

dl65  See... prove that his previous post was indeed 665... otherwise I'll assume his postcount always is 666.... see, it's a joke... I don't think the guy REALLY is evil incarnate.... See? It's like, well, humour...If you're trying out Firewalls then give Sygate a try.
http://207.33.111.31/spf/
Get Version 5.5 Build 2710.coffe+offler=coffee monster Well, I loaded Kerio... And it instantly gave me an Incoming warning about Java... so I hit Deny, OVER 75 TIMES, so I decided, well, maybe I'll allow it.... OVER 30 TIMES before I forced the machine into Safe Mode and uninstalled it.

So I didn't like that one!

With Kerio, as with any good app based firewall, there are two levels of admittance or denial; temporary and permanent. To make a choice permanent, check the Make Rule box. It's really that simple and it's all there in the help files.
If it was correctly set up, the Norton firewall did exactly the same!

Why did it warn about incoming attempts anyway? It doesn't do it without very good reason."Of course I've tried soapy water!"

Yeah, I figured that Norton had allowed it in the past. That's why I only was going to permit it once, so I could research it (a flawed strategy, but a strategy!) I don't remember the specifics - I should have written it down - but it was like "Attack from [IP], in Germany".

But even when I started permitting it permanently, it came back with the same problem. So I powered it out.

It was just too frustrating!

Maybe I'll try again when I have a good movie on in the background. Or a good book nearby.

But I'm gonna try Sygate next.

Thanks!What was running when these "attacks" were taking place? The only permissible multiple Java connections that I can think of would be if you're running something like Azureus.
Perhaps Norton had blocked it in the past.Well, I do run Azureus, but it doesn't load at startup, and it wasn't on the port I have authorized Azureus to use (which is assigned at my router, anyway).

I don't know a whole heck of a lot about how Java works, so I just went into scared-and-confused mode and punted.

The only things I've put in my Startup folder are Palm's HotSync and Adobe Quick Install (which isn't). (And also a small macro program AutoHotKey because my 8 key doesn't work, so I have SHIFT+WIN+9 = 8.)In that case, no connections, inbound or outbound should be apparent. You were perhaps being scanned but that doesn't add up as to where Java is involved.
You need to make a complete security audit. Quote
You need to make a complete security audit.
Alright, I'll bite.

How?

("complete security audit" sounds much more serious than what I usually do!)

Is it just me, or does everyone start singing "Substitute" to themselves when they see your posts??!?!?
Carry out the procedures listed [highlight]here[/highlight] and post a Hijackthis logfile here when done.

WHO sings substitute? Wow. That's a lot of stuff....

I run SpyBot weekly, AdAware weekly, NAV 3x/week, and have the Norton Firewall on.

NEVER had an issue...Hw do you know you've never had an issue if you don't cross check?
The majority of heavily infected machines that I see (And believe me, that's a *censored* of a lot) with any protection at all are "protected" by NAV....which is one of the reasons why I am looking for something other than NAV.

I will obviously need some time to run all this!So I ran AVG free last night, and it found a virus in a ZIP file I downloaded... But didn't DO anything about it. It didn't OFFER to repair, quarantine, whatever.

I've tooled around with different options, and I can't see how to set it to quarantine or repair a file.

Does it NOT do that - it just alerts me where they are, so I can delete them?

Or did I miss something??!?

Thanks.

(and, btw, to "Look Bloody Young But I'm Just Backdated"... Looking at that laundry list, I do dump my temp files once a week, and every time I add software I scan the Add/Control to make sure nothing else got slammed in.... At least once, sometimes twice, a month, I scan my Task Manager Processes and make sure there's nothing running that shouldn't. But I will still get to that list! Thanks!) Quote
I've been a loyal Norton user for years and years.... But find myself strapped for cash as my annual $ubscription runs out...

So, after scanning folks' posts in here, I have decided to replace Norton Firewall with Zone Alarm, and Norton AntiVirus with AVG Free.

[highlight]=> So, someone PLEASE confirm those are two good choices![/highlight]

But I also like to use Norton WinDoctor, System Doctor, DiskDoctor, etc. Is there any good, free software to replace those???

ETA: (I also like the IDEA of Norton GoBack, although I don't think I've ever used it!)

Or am I better off skipping groceries for a week and sending the cash to Peter?

Thanks!
I gather you have Norton System Works and that's where you NAV came from.  Right?  I'm not here to counter the usual Norton bashing, but, since you've been a long-time user of Norton utilities, you could just remove NAV and keep the Norton utilities installed.  You do not need to install all components of SystemWorks.  While regular updating of the anti-virus component of SystemWorks is obviously critical, the utilities do not fall under that same requirement.Thanks, soybean. I DID realize that after my initial post.

I don't have anything against Norton, as I said, it's literally $60 to them right now or to the gas company.
1440.

Solve : Laptop that won't load explorer.exe?

Answer»

My wife's laptop will not display the desktop at all.  No icons, no start button or task bar.  I went into task manager and stopped the current explorer.exe that was runing and maunually went into the c: drive and started it that way.  When I do that, everything appears to be working.  However, the start button now appears in cursive and it KEEPS trying to load all kinds of pop-up windows. 
When I restart the computer, its as though I haven't done anything.  Nothing on the desktop again.

Any ideas?Welcome aboard

Are you sure, whatever you stopped through Task Manager was spelled:
expolrer.exe
or explorer.exe?

In any case, try your trick:
Quote

When I do that, everything appears to be working.
again.
Get HijackThis: http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html
and post its log back here.  

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:27:42 PM, on 11/15/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\MSSQL7\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\carpserv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\MSSQL7\Binn\sqlmangr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kristin\My Documents\My Music\From Internet\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchv.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchv.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll (file missing)
O3 - Toolbar: My &AMP;Way Speedbar - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [IESet] IExplorer.dll                                                              .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll                                                              .dbt
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\MSSQL7\Binn\sqlmangr.exe
O4 - Global Startup: SQL Server.lnk = C:\MSSQL7\Binn\scm.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_2_3_0.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\sulimo.dat
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\System32\HPZipm12.exe (file missing)

--
End of file - 7142 bytes
Let me take a look..First of all, you need to get SP2 as soon as possible.
Secondly, I can't see any firewall running. Is your Windows firewall up?

Now...

1. Print out these instructions as we will need to close every window that is open later in the fix.

2. Download SmitfraudFix.exe from here and save it to your desktop:

http://www.bleepingcomputer.com/files/smitfraudfix.php

3. Next, please reboot your computer into Safe Mode by doing the following:

   a. Restart your computer

   b. Start tapping F8 key

   c. A menu will appear

   d. Select the first option, to run Windows in Safe Mode.

4. Close all open Windows.

5. Now, double-click on the SmitFraudfix icon.

6. When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.

7. You will now see a menu. Press the number 2 on your keyboard and the press the Enter key to choose the option Clean.

8. The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program.
This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This process can take up a long time depending on your computer, so please be PATIENT. When it is complete, it will close automatically and you should continue with next step.

9. When Disk Cleanup is finished, you will be presented with an option asking Do you want to clean the registry ? (y/n). At this screen you should press the Y button on your keyboard and then press the Enter key.

10. When this last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all applications. You should now press the spacebar on your computer. A COUNTER will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot.

11. Once the computer has rebooted, you will be presented with a Notepad screen containing a log of all the files removed from your computer.
Save that log to your desktop, and attach it to your next reply. Kyle...you need to start new topic with brief description of your problems.
1441.

Solve : redirect problem with google?

Answer»

The software said it was cleaned, but I am not sure. My Out look EXp seems to hang up and I have to run my anti spy thing, then it seems to work.  I seem to get a lot of runtime errors also.  Most of my software works though. 

Is RegCure any GOOD?  What kind of registry repair program would you recommend?Personally, I stay away from registry repairs/cleaners.  Many of them seem to be a bit less than helpful.  HOWEVER, CCleaner is a great program.  Just make sure you install it without the optional Yahoo! toolbar, then use CCleaner to clean out your temp files and registry (be sure to make a backup when prompted).

Try running a scan with SUPERAntiSpyware in SAFE Mode.  If you are still experiencing problems, feel free to post a new HijackThis log so we can see if something else MIGHT be lurking about.I ran ccleaner and downloaded and ran Superantispy in safe mode
CCleaner seemed to remove a lot and I downloaded and ran superantispy in safe mode. It came back negative.

Last night I ran defender in the quick scan mode; came back negative.  Then I ran it in a complete system scan and it found Trojan Downloader: win32Zlob. It did referance HJ as a resource. My computer seems to be running OK, but, I am holding my BREATH. Thanks again for your help and patience. 
Joe

att. HJL

[saving disk space - old attachment deleted by admin]Your HJT log is clean....Keep us updated

How is your computer doing, anyway?

BTW...I don't like Windows Defender. Your warning might have been false positive, since no other program detects anythingMy computer seems to be running OK. I think the Ccleaner may have helped more than anything.  I have had a lot of runtime errors up until today. I haven't had any today.

The only reason I have defender is because it is a free download. 

I read an article a while back about anti virus programs.  They tested most of the popular programs at the time against 1000 known virus'.  Most of them missed about 5 to 7 percent of them.  None of the missed ones were all the same.  That led me to believe that we have to have 200 anti virus programs to get them all. I can't recall which one was the best, but it wasn't Norton or McAfee.
Thanks again, JoeWindows Defender is not antivirus program. It's more antimalware program, but it doesn't have too good press.
I'd recommend to disable it.
You have your firewall, and antivirus program running now. That's the basic protection.
On a top of it, I'd recommend, you download two free programs, which will give you an extra protection in real time:
- a-squared: http://www.emsisoft.com/en/software/free/
- Spyware Terminator: http://www.spywareterminator.com/

1442.

Solve : Trojan????

Answer»

I'm using Mcafee Anti-VIrus...And it had  detected and almost every WEEK that there's this Trojan from the source Download BCF... I tried using others Anti virus software like AVG and it did NOT detect such trojans...What I wanna know is why this trojan keep appearing?...It is because it had not been removed completely?...Also,
which anti virus software is most recommended?...

AVG is an excellent antivirus program, McAfee is not.
You may have some trojan's leftovers.
Download HijackThis: http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html
and post its log back here.Thanks for the quick reply...
Here's my hijack this log file...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:23:30 AM, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O1 - Hosts: 164.78.237.3 ssdlc630
O1 - Hosts: 164.78.237.4 ssdlc640
O1 - Hosts: 164.78.237.5 ssdlc650
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
O2 - BHO: (no name) - {48679499-1F29-B2D8-2C52-07410ECA71A1} - C:\Program Files\mpeeknyp\nnmsyeke.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [vwtmrudy] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\vwtmrudy.dll"
O4 - HKLM\..\Run: [etmvwhmz] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\etmvwhmz.dll"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: MapToPDrive.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fc4e275fcf584a389717496c26df50b3
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fc4e275fcf584a389717496c26df50b3
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/pcpitstop.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170669123703
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5161/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg
O17 - HKLM\Software\..\Telephony: DomainName = sd.sp.edu.sg
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14811 bytes
I'll take a look....1. Print this post out, since you won't have an access to it, at some point.

2. Download, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html

3. Close all windows, except for HJT.

4. Put a checkmark next to following HJT entries:

- R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
(a lot of privacy issues in its EULA agreement)

- If Asia Pacific Network Information Centre is NOT your ISP, check these 3 entries:
   * O1 - Hosts: 164.78.237.3 ssdlc630
   * O1 - Hosts: 164.78.237.4 ssdlc640
   * O1 - Hosts: 164.78.237.5 ssdlc650

- O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)

- O2 - BHO: (no name) - {48679499-1F29-B2D8-2C52-07410ECA71A1} - C:\Program Files\mpeeknyp\nnmsyeke.dll

- O4 - HKLM\..\Run: [vwtmrudy] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\vwtmrudy.dll"

- O4 - HKLM\..\Run: [etmvwhmz] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\etmvwhmz.dll"

- O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
( don't confuse this file with legit Creative Labs Soundblaster file: Ctdetect.exe)

- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg

- O17 - HKLM\Software\..\Telephony: DomainName = sd.sp.edu.sg

- O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg

5. Click on "Fix It" button.

6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

8. Open Windows Explorer. Go Tools>Folder Options, put a checkmark next to "Show hidden files, and folders".

9. Delete following files (if they still exist):

- Macrogaming folder from C:\Program Files\

- mpeeknyp folder from C:\Program Files\

- Creative folder from C:\Program Files\

10. Turn off System Restore:

- Windows XP:
   1. Click Start.
   2. Right-click the My Computer icon, and then click Properties.
   3. Click the System Restore tab.
   4. Check "Turn off System Restore".
   5. Click Apply.   
   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
   7. Click OK.
- Windows Vista:
   1. Click Start.
   2. Right-click the Computer icon, and then click Properties.
   3. Click on System Protection under the Tasks column on the left side
   4. Click on Continue on the "User Account Control" window that pops up
   5. Under the System Protection tab, find Available Disks
   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
   8. Click OK

11. Restart in Normal Mode.

12. Turn System Restore on.

13. Run HJT again, and post back its log back here.Alright...

Before I proceed,

Just want u to know that if the following are to be deleted, will it effect my laptop in anyway as I'm connected to the domain sd.sp.edu.sg which is my school domain...
It's important that I keep connceted to it...

- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg

- O17 - HKLM\Software\..\Telephony: DomainName = sd.sp.edu.sg

- O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg

And I'm using Windows XP PRO SP2...My apology...I should kick myself, because at any rare time, when I don't triple check something, and go too fast, mistake like this one will happen.
Obviously, leave those entries alone.
I'm sorry. Great, you ASKED.It's okay...
Sorry that I took awhile to respond...
Anyway I've done everyting that u asked me too...
But am unable to delete the Macrogaming folder from program files...

Anyways,

Here's the new log...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:48:43 PM, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O1 - Hosts: 164.78.237.3 ssdlc630
O1 - Hosts: 164.78.237.4 ssdlc640
O1 - Hosts: 164.78.237.5 ssdlc650
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: MapToPDrive.bat
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fc4e275fcf584a389717496c26df50b3
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fc4e275fcf584a389717496c26df50b3
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/pcpitstop.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170669123703
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5161/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg
O17 - HKLM\Software\..\Telephony: DomainName = sd.sp.edu.sg
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sd.sp.edu.sg
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14642 bytes
Should I also uninstall Mcafee since I'm already using AVG?...Yes. You should never have more than one antivirus program running. Having two installed can cause system instability and even make windows unable to boot. Therefore you should always uninstall your current antivirus software before installing another one.You should turn off Spybots TeaTimer during removal as it can block some fixes.

Disable Spybot's TeaTimer

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your logs are clean.
* Open Spybot Search & Destroy.
* In the Mode menu click Advanced mode if not already selected.
* Choose Yes at the Warning prompt.
* Expand the Tools menu.
* Click Resident.
* Uncheck the Resident "TeaTimer" (Protection of overall system settings) active box.
* In the File menu click Exit to exit Spybot Search & Destroy.
+ You can re-enable TeaTimer when we are done.

Look in add/remove programs and uninstall all ITEMS named:

Macrogaming
SweetIMBarForIE <---Any combination of this
SweetIM
McAfee
Network Associates


Reboot the computer and post a FRESH HijackThis log please.
Well I uninstalled all that you wanted...
Sorry it took quite a while...

Anyways,

Here's the new hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:35:25 AM, on 17/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 164.78.237.3 ssdlc630
O1 - Hosts: 164.78.237.4 ssdlc640
O1 - Hosts: 164.78.237.5 ssdlc650
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

1443.

Solve : random freezes and lockout?

Answer»

sorry if this is a doublepost my puter froze so i don't know if my first one made it with that said my computer randomly freezes i ran avg ad-ware and superantispyware and came up with nothing other than some cookies.  I tried to reinstall the os but i got a message that stated the one i had now was a newer version and the continue button was fadded and unclickable....with that being said my computer also doesn't accept me as the administrator yet i'm on the admin account and this is my home puter even in safe mode i'm not the admin with all that said if you can help it would be greatfull just ask and i will tell ya all that i know........should only take a couple seconds on that part......also it won't allow me to RESTORE if i try the window a) won't show up or b) show up with nothing in it....its like that in normal and safe modes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:46 AM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\GRISOFT\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 3205 bytesOk, Delete these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

After you've done this, rename your Anti-viruses (not just the short cuts) and also rename HijackThis. Then scan again and post.

Also, if you have a graphics card, what kind is it?
Is that the entire logfile ? ?Do NOT delete anything, yet. Answer patio's question, first.
If it is entire log, it's clean. Do NOT delete anything.yeah thats the full log file my graphics card is a ati radeon 1650 i think lol gimme a few and i'll rename and run log again it was a old mcafee file that was makeing me freeze all DAY no freeze so i'm happy however i can't restore my computer for some reason the window won't load up and when it does its just blank its the same when i go to search for something within my computer and i can't go do microsoft update

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:30 PM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\haha.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Spybot-S&AMP;D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 2544 bytes

1444.

Solve : Someone told me to post this here.?

Answer»

Is your problem only happening in IE?  Have you tried ANOTHER browser such as Firefox?
Also, just out of curiosity, go to the following FOLDER...

C:\WINDOWS\system32\drivers\etc

Open up the HOSTS file in Notepad, then copy all of the contents and post them here.No I use Firefox always so it can't be a problem with IE.  Plus I've tried to Ping blocked web sites with CMD but it also says CONNECTION timed out, so I'm thinking it's not a browser problem.  I also tried bypassing my router but it didn't help (the laptop gets to the websites fine wirelessly, so I don't think it's a router problem either...)  Here's the stuff inside my HOST file:

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the CORRESPONDING host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# LINES or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost
10.254.254.253   XdriveSomething unclear here, so...
Do you use XDrive?

Then, when I check xdrive.com IP address, it says: 64.12.156.129, not 10.254.254.253

This is what I'd do.
Write down this line:
10.254.254.253   Xdrive

Open your "hosts" file in Notepad, and delete the above line. Go File>Save.
Restart your computer.Yea I do use Xdrive (although it has started to act weird lately...it never finishes uploading, it always gets errors).  I deleted the line you told me to, but the websites are still blocked. In this case, I'd recommend CLEAN reinstall of Firefox.

Get a fresh copy of Firefox (don't install it, yet).

Get MozBackup: http://mozbackup.jasnapaka.com/ to backup your data.

Read here:
http://kb.mozillazine.org/Uninstalling_Firefox
how to completely uninstall Firefox.

Install fresh copy of Firefox.

Hey! I've been trying to do this but I didn't know how.  So I did it, but the web pages are still blocked (IE can't get to them either, so I'm thinking it's not a problem with the browser).

1445.

Solve : Think i have virus troubles.... :(?

Answer»

these are my log files.

[Saving space - attachment deleted by admin]*cough* bump *cough*... is there anything wrong with my comp?

FBBumping your post to the top of the forum actually puts you at the end of the list...

Open HIJACKTHIS and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://owa.ncl.ac.uk/CookieAuth.dll?GetLogon?curl=Z2F&reason=0&formdir=2

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Run this ONLINE scan.

This scanner requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option REMOVE found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.ran the scan but i don't think it found anything. Also the start page i put there myself should i still remove it?

i think i have another symptom, i have two startup applications, winamp and launchy, both are working and show up in processes but not in applications, and neither work as they used to.

FB

[Saving space - attachment deleted by admin] Quote

Also the start page i put there myself should i still remove it?

If you want it there then it's OK.

Uninstall and then reinstall anything that isn't working correctly.

No malware.i found ism.exe which when i googled it says it's dangerous and i should GET rid of it. Should i? is so how?

FBWhere was it found?i was looking through the processes on task manager.

FBLook in add/remove programs for InternetSpeedMonitor and unisnstall it.i couldn't find internetspeedmonitor in the add/remove programs, i don't see anything unusual except "scansoft omnipage SE4" which seems to be genuine software just don't remember putting it on. probably came with some printer drivers.

It's not a massive problem as i'm going to format the HDD soon.

FB
1446.

Solve : Noticed Zlob folders scanned during Spybot scanSearch & Destroy?

Answer»

Hi - its been a while... I have located a XP Pro CD, but it is a SP2 version.  I have a 5.1 version.  Is this a PROBLEM? Windows XP - How to TELL which Service Pack is INSTALLED

http://www.rm.com/Support/TechnicalArticle.asp?cref=TEC393756 I have no service pack installed.   Go here and install all of the updates http://update.microsoft.com/windowsupdate

1447.

Solve : Virus detected but it can't remove?

Answer»

Ok I have a question. This keep on questioning in my mind. Virus detected by Antivirus but the Antivirus can't remove it.

So my question is:
1. Why Antivirus detected the virus but can't remove it?it might have binded to too many FILES and the infected files might be vital to your comp, so if you do a system restore to maybe a week or 2 ago, it should be gone, but run an antivirus to make sure its gone after.Actually, the virus is most likely active in memory and the AV program cannot remove it whilst it's there.

Most malware is inactive in safe mode so you might like to boot your computer into safe mode THEN run a scan with your AV program to see of it can get rid of it.


If you want us to investigate further please POST a HijackThis log AND full details of the virus your machine has (name of virus and location of malware files).


OJYou might also want to NOTE the location of the virus. If it is in a restore file the AV cannot remove it, even in safe mode.

1448.

Solve : cant download/ or filepicker??

Answer» HI, at most times now when i TRY to DOWNLOAD SOMETHING from a site it either SAYS cant download to this area, choose another and when I do it says the same, and other times it says filepicker was unexpectedly closed by windows, please help i am baffled??? podlod Disable and or un-install filepicker...it causes problems with some browsers including FireFox.
See if this changes things.
1449.

Solve : Could someone take a look @ the logs, still awaiting expert help as of25th feb.?

Answer»

Please help asap as i need my laptop for uni work. I have done scans with different software which seem to detect different things like rootkit, trojan, cookies. Is there a way of getting rid of all this?
I have used avg anti-virus, virgin broadband pc guard, ad-aware and a-squared free (by disabling the others whilst using one)

In case you need to know: HP pavilion laptop dv6000series, windows vista.

I have done the scans you recommend and have now posted the logs.

[attachment deleted by admin]you had better say what security you have for the expertsgeist09: follow the steps outlines here

attach the three logs to a post here, and a malware removal expert should be with you shortly.

Oh... And good luck!I appreciate that the experts are busy but could somebody please take a look at the logs and help me as soon as they can. I really need to use my laptop for my work,etc. Thanks in advance.geist09 , an expert just has , do as he said and he will come back to you , harry harry, i have done what that expert has said and am waiting.ok , i see you added them to your first post , you should always add them on a seperate post in  your topic so the experts can see that its done Quote from: harry 48 on February 15, 2009, 04:22:12 PM

ok , i see you added them to your first post , you should always add them on a seperate post in  your topic so the experts can see that its done

You always attach them to your first post unless otherwise instructed.O ,  thats new on me    I beg the experts to help me please. I need to meet university coursework deadline by next week and also need to MAKE a payment.Hello geist09. Sorry for the delay.

Download random's system information tool (RSIT) by random/random from and save it to your DESKTOP.

  • Double click on RSIT.exe to run.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open.
  • log.txt <will be maximized and info.txt <will be minimized
  • Please post the contents of both logs in the next reply.
Also tell me what antivirus you want to keep. There are 3 installed and you only need one. Multiple only causes problems and actually offers less protection.Thanks for responding. I have added them as downloads again because they are too big to post. If you mean the anti-virus software i originally downloaded, then I would like to keep virgin pc guard.

[attachment deleted by admin]This should improve things greatly.

Disable Windows Defender

We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Windows Defender
  • Click on Tools > OPTION
  • Scroll down and uncheck Use real-time protection (recommended)
  • After you uncheck this, click on the Save button and then exit Windows Defender
  • Now on your keyboard press and hold Ctrl+Alt and then press the Delete key tow times to bring up the Task Manager.
  • Locate MSASCui.exe then right click on it and choose End Process. Click Yes on the Task Manager Security Warning.
.
After all of the fixes are complete it is very important that you enable real-time protection again.

----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

  • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101677&l=dis
  • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
  • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
  • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
  • O4 - HKLM\..\Run: [Symantec PIF AlertEng] \"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe\" /a /m \"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll\"
  • O4 - HKLM\..\Run: [McAfeeUpdaterUI] \"C:\Program Files\McAfee\Common Framework\UdaterUI.exe\" /StartedFromRunKey
  • O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
  • O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
  • O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
  • O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
  • O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
.
Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Go to Add or Remove Programs and uninstall:
  • avast! Antivirus
  • Java(TM) 6 Update 5
  • Java(TM) 6 Update 7
  • Java(TM) SE Runtime Environment 6
  • LiveUpdate 3.2 (Symantec Corporation)
  • LiveUpdate Notice (Symantec Corporation)
.
----------

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.
  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
  • Delete Nortonremoval tool from your Desktop.
.
----------

Download the McAfee CONSUMER Product Removal Tool to your Desktop.
Using McAfee Consumer Product Removal tool:

  • Double click the MCPR.exe
  • A Command Line window will be displayed, and then close automatically.
  • Wait for a second Command Line window to be displayed.
    • Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.
  • After the second window appears, the program will begin the cleanup.
  • Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
  • Press Y on the keyboard.
  • Wait for the computer to restart.
  • All McAfee products are now removed from your computer.
.
----------

Download the OTMoveIt3 by OldTimer

Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

* Save it to your Desktop.
* Double-click OTMoveIt3.exe to run it.
* Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

Code: [Select]:Processes
explorer.exe

:services

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"=-
"McAfeeUpdaterUI"=-
"avast!"=-

:files
C:\ProgramData\McAfee
C:\Program Files\AVG
C:\Program Files\Common Files\Symantec Shared
C:\Program Files\McAfee
C:\Program Files\Alwil Software
C:\Program Files\Symantec
C:\Windows\tasks\Ad-Aware Update (Weekly).job

:Commands
[purity]
[emptytemp]
[start explorer]

* Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt3

Note: If a file or FOLDER cannot be moved immediately you may be asked to reboot your computer in order to finish the move process.

----------

Please post the OTMoveIt3 log in the next reply.

.ok problem using mcpr.exe. When the first command box appears it says: Mcafee Enterprise software detected cannot continue please contact mcafee technical support. What should I do?
1450.

Solve : guess this is the place to ask this...?

Answer»

If a machine is clean of viruses and spyware, malware, etc., and its defragged, and registry is clean/optimized...can cookies themselves slow it down?No. Cookies are simply tiny little text files. Around 100 to 500 bytes is all they are. It would take a whole, whole bunch to slow down a computer.


SUPERAntiSpyware.com - FREQUENTLY Asked Questions

Are cookies really spyware and are they dangerous?

This subject has been the debate of many newsgroups and online forums. Cookies are simply text files stored on your hard drive and cannot themselves harm your computer in any way. Typically cookies are used to remember logins and keep track of user settings on web-sites.

Cookies can be used to track your movement on the Internet ONLY if a site is aware of the cookies and is designed to USE the specific cookies. Because of their use in tracking, many feel that this constitutes spyware.

We do not consider cookies to be THREATS of anywhere near the same level of severity as actual malware threats that can steal real personal information, serve ads, or render a computer unusable.

SUPERAntiSpyware will detect tracking cookies as "Adware.Tracking Cookies" and you can choose to remove them or leave them on your system. You may turn off this feature in the Preferences -> Scanning Control tab of SUPERAntiSpyware should you not wish cookies to be scanned, detected and removed.

The True Story About Cookies!MajorGeeks.Com First let's get right to the point. Cookies are not problems that you need to be concerned with. Too many antispyware programs flag cookies and make them sound like they are high risk items. The truth is that they are not high risk problems and in most cases are actually very useful to you.
This subject has long been debated on the internet and obviously there are many opinions about cookies. Cookies are not executable programs. They are simple text files stored on your PC to help websites (and you) track useful user settings and non-personal information, like which advertisement you last saw (which prevents you from seeing the same ad over and over again).
Yes some cookies are often referred to tracking cookies, but tracking is more complicated then just having a cookie. Every website you visit would have to have knowledge of the particular cookie so that they could use it to add tracking INFO to it and to make use of it. You will see many antispyware programs indicating various cookies as tracking cookies and this can artifically make detection counts look very high. It is also a sore point when doing comparisons between antispyware programs. If one program detects cookies and another does not, it can make the one that does not detect them look like it is doing a bad job.
Similarly it makes the one detecting them look like a great product since it picks up things the other missed. Thus most (not all) programs will detect cookies to avoid this hazard. Don't be fooled by cookie counting. If cookies are the only thing showing up, you are in good shape. They are not harmful and you can just ignore them or if so desired, you can easily clean them using your browser or other tools like CCleaner.

Microsoft Cookies FAQ
Wikipedia HTTP Cookie

Cookie Viewer allows you to discover the information that web sites store on your computer.
Cookie Cruncher PROTECTS your hard drive from unwanted cookies.
Nice. Thanks for the info! I appreciate it!   Your welcome.