Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1551.

Solve : I need help in locating viruses protection.?

Answer»

I need help locating a viruses protection for an old Dell lap top that I have not NEEDED to USE for some time. I now need to get it up and RUNNING. It has Windows ME on it. No one seems to sell any THING for ME any more.Avast! Home Free Edition <- Free and works with 98/ME

Avira AntiVir Personal <- Has paid version that works with 98/METhank you for your reply. I have loaded it. All seems fine. It has to beat a blank.

1552.

Solve : Windows Vista - Issues with Norton?

Answer»

That is all RELATIVELY HARMLESS. Shouldn't have ANYTHING ELSE to WORRY about.

1553.

Solve : How do I permanently delete Incredi-mail Icon from my desktop ??

Answer»

First of all I want to warn you that I am BARELY computer literate. I can turn the computer on and do what I need to do. That being said, this Incredi-mail Icon turned up a few weeks ago. Everytime I boot up I get a message, Incredi-mail Icon is installed on my DESK top, this will MAKE it easier to install the program.
It seems ever since this icon appeared the booting up process takes longer. I have no intention of installing the program, how do I permanently get rid of this icon.
Thanks.This topic has been moved to Computer viruses and spyware.

Download ComboFix by sUBs. Be sure top save it to the Desktop.

Link #1

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a LOG for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is RUNNING. That may cause it to stall.

1554.

Solve : How would one detect "keystroke" spyware on one's computer??

Answer»

Yep . . . . that's the question.  WINDOWS XP / no network / home computer.are you saying you have a viral infecton or just a queston?I think AGP is WORRIED he/she might have a keylogger INSTALLED on the computer.

What ANTIVIRUS and/or Antispyware do you have?

1555.

Solve : deefress site..?

Answer»

hello to all,  I'm new to this world. Anybody there knows deefress, its a security software but I'm not familiar with it I just hear from somebody else. ANYONE can send me the link where to download the installer of this..?thanxI did a couple of searches and nothing came up.

Are you looking for some sort of Antivirus software (security)?I THINK you mean AntiFreeze. http://fileforum.betanews.com/detail/AntiFreeze/1194643486/1

This is on no way to be confused with an antivirus so don't rely on it to protect your PC.thanx for the post, I finally find it. I only got a WRONG info from a friend, the exact NAME of security software is deep freeze. thank you guys!!! Quote

Deep Freeze ensures computers are absolutely bulletproof

Remember that nothing is "bullet proof" when it comes to security. There are flaws in everything. It STILL takes safe internet practice to stay out of harms way no matter how tight your security measures.
1556.

Solve : Pls help to check Log files?

Answer»

My laptop just got infected with malwares and spywares. I followed the instructions on how to remove it. So far, It had been okay. I just want to make sure that I had removed all of it and there is no more infected files. Please help to check...Thanks =)

[recovering disk space -- attachment deleted by admin]Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O4 - HKLM\..\Policies\EXPLORER\Run: [0BmYOzu2C8] C:\Documents and Settings\All Users\Application Data\ipmbeben\ivojezgh.exe

Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"0BmYOzu2C8"=-
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Run CCleaner and then restart the computer.

----------

Set a New Restore Point to prevent POSSIBLE reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > PROGRAMS > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and SCROLL down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates SITES on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1557.

Solve : tcp/ip filtering,i only want the bare minimum.?

Answer»

under the section of TCP/ip filtering it list the FOLLOWING,TCP ports, UDP ports, IP PROTOCOLS and the settings are set to allow all in all three CATAGORIES. my question is, are there a bare minimum i can set to allowed? and also is it possible to prevent my machine from responding to a ping request? i am using comodo firewall and do not see ANYTHING that would prevent this.  i have checked with google on all that is litsted above and have been unsuccessfull in finding the answers. thanks for your time on this !

1558.

Solve : icons and task bar are gone, can't right click on desktop...windows infected?

Answer»

I've tried removing it with add/remove programs when rebooted, F-secure was no longer on the add/remove list but the F-secure folder was still in my program files.
I tried USING the uninstalltool.exe and when rebooted the folder is still thereDownload Unlocker

  • Open the installation file, select the installation language and click OK.
  • An installation wizard will pop up, click Next.
  • Choose the default destination folder C:\Programs Files\Unlocker and click Next.
  • Click INSTALL directly. (Don't change anything)

  • After the installation completes, go back to the file/folder you WANT to delete.
  • Right-click on the file/folder and select Unlocker.
  • There should be a window opening, select Delete.
  • This should permanantly delete your file.
.
If it comes back let me know.ok that worked. Does this also clean the registryNo it doesn't.

Now run CCleaner.
  • From the main window click Run cleaner to clean all files found
  • Next select the Registry tab to the left and then click the Scan for Issues button.
  • When it finishes look through the list to ensure everything found should indeed be removed. Uncheck any you may be unsure of.[/B]
  • Click Fix SELECTED issues...
  • Make SURE you say Yes to the Do you want to backup changes to the registry? prompt and let it save the backup cc_2008xxxxxxx.reg file.  (xxxxxxx is based on the date and time when saved).
  • It may prompt you again with messages about the things being fixed.  Just click Fix All Selected Issues.
ok, done

thank you for all your help!Glad it worked.

Safe surfing....
1559.

Solve : Heavily Infected Laptop w/o Internet Access?

Answer»

My son's Dell Inspiron 8600 laptop is heavily infected. I followed steps 1, 2 & 3. With Step 3, SAS could not UPDATE because the laptop cannot connect to the internet DESPITE a wireless modem that appears to be working fine with an excellent signal. So, I did a complete scan with definitions the program said were 45 days old. It still found 200+ viruses that it quarantined. After rebooting, I was hoping to regain internet access, update SAS, rerun it and continue with the remaining steps but that did not happen.
SAS log is attached.
What do I do now?

[ATTACHMENT deleted by admin]How long have you had the viruses. have you tried a system restore to an earlyer time before the virus were on the machine. after doing this scan your computer and update that virus software.The laptop has been problematic for a couple months. The earliest restore point was Dec 11. I tried to restore to that point but it would not happen. When I hit Next at the Confirm Restore Point Selection, NOTHING happens.

The laptop is running Windows XP PRO ver 2002 with SP3.

1560.

Solve : Spanish warning/IE temp files virus?

Answer»

I am in need of help. I have a virus I cannot get rid of at this time. First off I can detect with Norton Corp Edition, the following is the message:

CA7HDW2U.htm]
C:\Documents and Settings\user name\Local Settings\Temporary Internet Files\Content.IE5\G32YXKAX\
Type: Downloader.

I cannot get rid of it. It is causing a Spanish warning to pop-up everytime it is detected and I cannot access temp IE files through explorer only run. Does anyone have any ideas I am stumped. I have tried Malwarebytes, Norton, and Spybot and only Norton detects it but it only replicates to another folder. 
 
Attached are the appropriate logs and a snapshop of the warning Thanks beforehand

 


[recovering disk space -- attachment deleted by admin]I (as well as Microsoft, McAfee and Symantec)  recommend that you DO NOT have more than one antivirus product installed and running on your computer at a time.

The real-time protection of two antivirus programs may conflict with each other and cause the following:

1) False Alarms: When the ANTI virus software tells you that your PC has a virus when it actually doesn't.
2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

I strongly suggest you either configure only one antivirus program to enable automatic real-time scanning, and leave the REST disabled, using them for on-demand scanners or go to Start > Control PANEL > Add or Remove Programs and uninstall all but one antivirus program.

----------

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- F3 - REG:win.ini: run=""
- O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
- O4 - HKLM\..\Run: [IUpd655] C:\WINDOWS\system32\mscdexntp.exe_.exe
- O18 - Filter hijack: text/html - {865c4b06-774c-4991-947c-7fd31a5e2c57} - (no file)


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis

----------

Download OTMoveIt2 by OldTimer

  • Save it to your desktop.
.
Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
Code: [Select][kill explorer]
C:\WINDOWS\system32\mscdexntp.exe_.exe
EmptyTemp
[start explorer]
  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) and paste it in your next reply.
  • Close OTMoveIt2
.
Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

----------

How is everything now?
Explorer killed successfully
C:\WINDOWS\system32\mscdexntp.exe_.exe moved successfully.
< EmptyTemp >
File delete failed. C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\~DF8572.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\~DF9361.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\~DFC6B6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\~DFC6C3.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully
 
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09102008_094552

Thanks for the help I need to reboot to see.
I still cannot acees temp files. Then do not know about the other problem until detected. Will however take the advice on the virus protection.Download SDFix by AndyManchesta and save it to your desktop.

When using this tool, you must use the Administrator's ACCOUNT or an account with Administrative rights

  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.
Here is the next log files. Still no temp files

[recovering disk space -- attachment deleted by admin] Quote
Still no temp files

What exactly do you mean by this?

There is still two antivirus installed!

Which one do you want to keep? McAfee SecurityCenter or Symantec AntiVirus.
I will go with Symantec. I cannot get to the temp ie files without pathing it out through the run commandGo to add or remove programs and uninstall everything related to McAfee.

Next install and run the McAfee Consumer Products Removal Tool.
http://service.mcafee.com/FAQDocument.aspx?id=107083&lc=1033
Be sure the computer has been restarted after it is finished.

Now run a new HijackThis scan and post the log.

Here you go. Here is the requested file. The Spanish warning has not come up all day Thanks

[recovering disk space -- attachment deleted by admin]Do you use Verizon Broadband? If not then uninstall the Verizon Broadband Toolbar.

Final steps.

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1561.

Solve : I have a Trojan virus and need help?

Answer»

I have a virus and need some help with it. I have a Compaq Presario 2.8 GHz with 760 mb RAM and I'm running Windows XP service pack 2. I have followed all the guidelines on the forum and here are my logs.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/10/2008 at 11:28 AM

Application Version : 4.21.1004

Core Rules Database Version : 3555
Trace Rules Database Version: 1543

Scan type       : Complete Scan
Total Scan Time : 02:02:09

Memory items scanned      : 453
Memory threats detected   : 2
Registry items scanned    : 6832
Registry threats detected : 13
File items scanned        : 81075
File threats detected     : 7

Adware.Vundo Variant/OE
   C:\WINDOWS\SYSTEM32\HGGWTKKA.DLL
   C:\WINDOWS\SYSTEM32\HGGWTKKA.DLL
   C:\WINDOWS\SYSTEM32\HGGYXVUT.DLL
   C:\WINDOWS\SYSTEM32\HGGYXVUT.DLL
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47836122-9D2E-476C-9763-B1D366F704E1}
   HKCR\CLSID\{47836122-9D2E-476C-9763-B1D366F704E1}
   HKCR\CLSID\{47836122-9D2E-476C-9763-B1D366F704E1}\InprocServer32
   HKCR\CLSID\{47836122-9D2E-476C-9763-B1D366F704E1}\InprocServer32#ThreadingModel
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8FD82504-ED1F-4D2C-8081-18B60D377193}
   HKCR\CLSID\{8FD82504-ED1F-4D2C-8081-18B60D377193}
   HKCR\CLSID\{8FD82504-ED1F-4D2C-8081-18B60D377193}\InprocServer32
   HKCR\CLSID\{8FD82504-ED1F-4D2C-8081-18B60D377193}\InprocServer32#ThreadingModel
   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{47836122-9D2E-476C-9763-B1D366F704E1}
   Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\hgGwTkKA
   C:\WINDOWS\SYSTEM32\PONAKEFQ.DLL
   C:\WINDOWS\SYSTEM32\TUVSMMNM.DLL

Trojan.Downloader-Gen/RetAd
   HKLM\Software\Microsoft\Windows\CurrentVersion\Run#runner1 [ C:\WINDOWS\faceback.exe 61A847B5BBF72813329B385772FF01F0B3E35B6 638993F4661AA4EBD86D67C56389B284534F310 ]

Adware.Vundo Variant/Rel
   HKLM\SOFTWARE\Microsoft\FCOVM
   HKLM\SOFTWARE\Microsoft\RemoveRP

Trojan.Unknown Origin
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP142\A0044354.VBS
   C:\WINDOWS\IA\KE.VBS

Adware.AdRotate/System
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP146\A0044434.DLL
Malwarebytes' Anti-Malware 1.28
Database version: 1136
Windows 5.1.2600 Service Pack 2

9/10/2008 12:03:49 PM
mbam-log-2008-09-10 (12-03-49).txt

Scan type: Quick Scan
Objects scanned: 47019
Time elapsed: 13 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{af919fb0-427d-48bd-9bad-ab6916c57692} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{af919fb0-427d-48bd-9bad-ab6916c57692} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmd3ab3550 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\d09806cc (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("%1" %*) Good: ("%1" /S) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\hcp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Xtmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wTR02 (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\iqpfgl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\wTR02\wTR022328.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vvlqgvmq.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMd3ab3550.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMd3ab3550.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

Logfile of HijackThis v1.99.1
Scan saved at 12:11:47 PM, on 9/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {b7f87b37-9e16-0564-7445-1b76ddeb1a5e} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {DA7183A7-47CC-4D34-87E2-3BC8AE37F160} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax6822.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll iqpfgl.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
I (as well as Microsoft, McAfee and Symantec)  recommend that you DO NOT have more than one antivirus product installed and running on your computer at a time.

The real-time protection of two antivirus programs may conflict with each other and cause the following:

1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
2) Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
3) Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.

I strongly suggest you either configure only one antivirus program to enable automatic real-time scanning, and leave the rest disabled, using them for on-demand scanners or go to Start > Control Panel > Add or Remove Programs and uninstall all but one antivirus program.


Post a new HijackThis log when complete.Sorry I totally forgot about Norton being on my computer. Here you go:

Logfile of HijackThis v1.99.1
Scan saved at 1:22:34 PM, on 9/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {b7f87b37-9e16-0564-7445-1b76ddeb1a5e} - (no file)
O2 - BHO: (no name) - {DA7183A7-47CC-4D34-87E2-3BC8AE37F160} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax6822.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll iqpfgl.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

I made a mistake also, forgot to ask you to install the new version of hijackThis and do a scan with it.

First:

Download the Norton Removal Tool (SymNRT) to your Desktop.

Once downloaded please close ALL open browsers, also save any work because this may require a restart.

  • Go to your desktop and double click on the removal tool and then click Setup.
  • Once open Click Next
  • Accept the license agreement and click Next
  • Type in the letters/numbers that you see into the text box then click Next.
  • Then click Next and the tool will start running.
  • Once finished restart the PC and run the tool again to ensure everything has been removed.
.
----------

Download and install TrendMicro HijackThis.exe (HJT)

Don't scan with it yet.

----------

Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

Okay Now it's going even further downhill. When I try to turn off my AVG it's not responding and I'm getting a message about a problem with rundll32. When I try to run Combo fix it POPS open but won't finish running.

What do I do now?

Thanks!Close all other browser windows.
 
Go to Start > Run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /killall

Press Enter and Combofix will begin to run.
 
When finished, it will produce a log file located at C:\ComboFix.txt
 
Post the contents of that log in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall.Sorry for causing so much trouble. When I do that I get a big blue box with a flashing curser that opens up and after 5 minutes of waiting it's still just a flashing cursor there. Is there supposed to be text or something? Lets try this instead.

Download SDFix by AndyManchesta and save it to your desktop.

When using this tool, you must use the Administrator's account or an account with Administrative rights

  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.
OK that worked. Here's my logs:


SDFix: Version 1.223
Run by Administrator on Wed 09/10/2008 at 03:16 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\Documents and Settings\Administrator\Desktop\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :


C:\WINDOWS\Fonts\*.zip - 1 File(s)        115,979 bytes - Deleted



Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed


Removing Temp Files

ADS Check :
 


                                 Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-10 15:24:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"LoadAppInit_DLLs"=dword:00000001
"AppInit_DLLs"="avgrsstx.dll iqpfgl.dll"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Program Files\\Hasbro Interactive\\Scrabble v2.0\\Scrabble v2.0.exe"="C:\\Program Files\\Hasbro Interactive\\Scrabble v2.0\\Scrabble v2.0.exe:*:Enabled:Scrabble v2.0"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Sun 17 Aug 2008           196 A.SHR --- "C:\BOOT.BAK"
Tue 23 Mar 2004             0 A.SH. --- "C:\WINDOWS\SMINST\HPCD.SYS"
Mon  8 Sep 2008         4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 11 Oct 2003           181 A.SH. --- "C:\Documents and Settings\Owner\My Documents\My Music\Desktop.ini.bak"
Sat 11 Oct 2003           183 A.SH. --- "C:\Documents and Settings\Owner\My Documents\My Pictures\Desktop.ini.bak"
Sun 24 Aug 2008             0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\66b1d8e81a20b4b541ab3e558f2fd638\BIT2.tmp"
Wed 10 Sep 2008           444 ...HR --- "C:\Documents and Settings\Owner\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon  8 Sep 2008         4,348 ...H. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv1key.bak"
Mon  8 Sep 2008            20 A..H. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv1lic.bak"
Mon  8 Sep 2008           400 A.SH. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv2key.bak"

Finished!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:29:48 PM, on 9/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {b7f87b37-9e16-0564-7445-1b76ddeb1a5e} - (no file)
O2 - BHO: (no name) - {DA7183A7-47CC-4D34-87E2-3BC8AE37F160} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax6822.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

--
End of file - 8080 bytes
Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
- O2 - BHO: (no name) - {b7f87b37-9e16-0564-7445-1b76ddeb1a5e} - (no file)
- O2 - BHO: (no name) - {DA7183A7-47CC-4D34-87E2-3BC8AE37F160} - (no file)
- O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
- O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Go to Start > Run and type notepad.exe then click OK

Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

Code: [Select]REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"AlcxMonitor"=-
Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

Restart the computer.

----------

How is everything now?Seems to be working great now!! Thank you!!Final steps.

Download OTCleanIt.exe and save it to your Desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it yourself.
.
----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all CRITICAL updates.

----------

To prevent unknown applications from being installed on your computer install WinPatrol 2008
* Using Winpatrol to protect your computer from malicious software

I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and SPAM. Safety ratings from McAfee SiteAdvisor are based on automated safety TESTS of Web sites.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1562.

Solve : VIRUS ALERT in Timebar?

Answer»

Out of nowhere, my WINDOWS XP Comp won't let me ENTER my properties because it has "been disabled by administrator", wont let me enter the C Drive, or get into my programs or registry once again cuz "been disabled by administrator". i have hijack this and have uploaded my log. Please help! 

[recovering disk space -- attachment deleted by ADMIN]Welcome to CH.

Download SDFix by AndyManchesta and save it to your desktop.

When using this tool, you must use the Administrator's account or an account with Administrative rights

  • Double click SDFix.exe and it will extract the files to %systemdrive%
  • (this is the drive that contains the Windows Directory, typically C:\SDFix).
  • DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.
my properties and programs are back!   

But still "virus alert" in time bar abd no "C:\"

Heres my new log and report

Thanks so far



[recovering disk space -- attachment deleted by admin]Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if ASKED to restart the computer, please do so immediately.

    ----------

    Now run a new HijackThis scan and post that log.I tried copying and pasting the MBAM Log but it exceeded the 2000 limit so i attached it instead

    [recovering disk space -- attachment deleted by admin]Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - R3 - URLSearchHook: (no name) - {F7301905-45EC-4459-9919-B6002ABD5102} - (no file)
    - R3 - URLSearchHook: ToolbarURLSearchHook Class - {E26029B4-C5E8-4645-9C02-E798715F8C0D} - (no file)
    - O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
    - O2 - BHO: (no name) - {8CEF3531-5751-4AF4-8735-C87F2B767EFF} - (no file)
    - O2 - BHO: QXK Olive - {A17B7E0A-5C24-4164-AD85-7CA896C66F0F} - (no file)
    - O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    - O2 - BHO: {578ed15d-3cdb-50ca-6a94-2a8ed02cbc6b} - {b6cbc20d-e8a2-49a6-ac05-bdc3d51de875} - (no file)
    - O3 - Toolbar: Protection Bar - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - (no file)
    - O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
    - O3 - Toolbar: (no name) - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
    - O3 - Toolbar: fqbewlna - {75745753-36ED-47BC-B54B-CFCA6403B379} - (no file)
    - O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    - O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    - O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    - O4 - HKLM\..\Run: [ErrorSmart] C:\Program Files\ErrorSmart\ErrorSmart.exe
    - O4 - Startup: BoontyBox Play Toad.lnk = C:\Program Files\Boonty\BoontyBox\BoontyBox.exe
    - O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\system32\shdocvw.dll
    - O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\system32\shdocvw.dll
    - O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    - O22 - SharedTaskScheduler: considerateness - {4d993022-0899-4599-b4b6-0f887d0802e6} - (no file)
    - O22 - SharedTaskScheduler: discommodiousness - {33b8d257-07f6-4c06-8605-94bc21728635} - (no file)


    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis and restart the computer to register the changes made by HijackThis.

    ----------

    Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

    • Double click on RSIT.exe to run.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open.
    • log.txt <will be maximized and info.txt <will be minimized
    • Please post the contents of both logs in the next reply.
    here you go bud

    [recovering disk space -- attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
    1563.

    Solve : Hjt log check plzz?

    Answer»

    Yes, I am back. 

    I haven't really checked much in the way of SPYWARE and viruses for the past month or so so my pc is running slow.  Here is my hjt log.  Can you plz tell me what I need to do.






    thx

     


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:51, on 9/11/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRAM Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SEARCH Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O9 - EXTRA button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {E1E73B44-2D20-47A9-9CA2-B534CEBBF856} (F-Secure Health Check 1.0) - http://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 5121 bytes
    There is nothing wrong in the log.

    Slow Computer? It May Not Be Malwarethanks and thank you for finally responding.  ha

    1564.

    Solve : VIRUS ATTACK!!!! can anyone help pls???

    Answer»

    Hi

    I have read the above post "read this before requesting malware removal"

    I have had to download all the anti virus' to my desktop, then copy to a disk to add to my laptop because I am unable to GET on the internet.
    I successfully ran ccleaner, but when I am unable to run SUPERantispyware, a windows installer error message pops up saying the installer service cannot be accessed. This is because I am in safe mode.

    Is there any other way I can run it? If I am not in safe mode, my laptop is constantely under attack and I am not able to access control panel, task manager or my start menu due to it being blocked by administrators

    I currently run Windows xp prof. I also have spyware doctor, and AWC but I am unable to run EITHER of these in the safe mode. They seem to have disapeared!

    Can the laptop be fixed? I have only had it a couple of days, until some bright spark decided to bring their portable hard drive and upload a movie without checking if there was any virus'

    please help
    thanks Natalie

     

     

      Can you not get into Normal Mode?

    What happens?

    Can you post a HijackThis Log?Hi

    I was brave and went in through normal mode

    here are the logs

    thanks Natalie

    [recovering disk space -- attachment deleted by admin]Good Job.

    Now, we need to wait for a Malware Specialist to analyze the logs.  Thanks v much for your help

    Do I have to send the logs onto somewhere else??

      Nope, they're fine here.Thanks again

      Everything in the MBAM log says No action taken.

    You need to run it again and let it fix what it finds. Then run a new HJT scan and post that log also.Hi

    Sorry about that! Not sure whether I saved the file before taking the action because I have ran it again and nothing was found! I have attached logs as requested though!

    Sorry again

    Natalie
     

    [recovering disk space -- attachment deleted by admin]Looks fine now.

    If you have any questions just let me know.

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More OPTIONS Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable THOROUGH system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    To prevent unknown applications from being installed on your computer INSTALL WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.brilliant!!! you are my hero

    thanks

      Glad it worked.

    Safe surfing.....
    1565.

    Solve : Folder/Window spam at Startup?

    Answer»

    Did you try any of the file recovery programs in the link?Yes I'm trying Recuva and Undelete PLUS.

    Recuva is Deep Scanning right now (30% complete) and Undelete PLUS found a ton of stuff, but NONE of it is my documents/pictures/musicMaybe they will be found before the scan is complete. Hopefully.OH SNAP!

    I was just browsing in windows explorer and found that EVERYTHING that was moved was backed up by the OTMoveIt program itself. It's all here in a folder called "MovedFiles"
    But does it restore your pictures?Yeah man I got everything back, pictures, music, documents, the works. Let me tell you that was THE sigh of relief. I just had to manually place each file/folder back where it was originally, which was a pain, but at least it worked.

    The startup problems remain, but for now I'll just LIVE with it (I rarely reset/turn off my comp anyways). But I will be looking through Google, seeing what I can find.

    And THANKS again for all your help. I'll be around.Glad it worked. I didn't think that would restore your files (music, pics, etc) or I would have suggested it. I learned something new lol.

    I'm off to bed now. I'll look more into it tomorrow. Let me KNOW if you figure anything out.

    1566.

    Solve : Re: task manager & programs button missing?

    Answer»

    Thank you evilfantasy for the info in this. I had been trying to REMOVE some malware w/trend_micro's stuff w/o any success. The other PLACE worked just fine and now I have my "windows task manager" back and the desktop is normal again. Keep up the GOOD WORK Welcome to CH.

    You should post the HijackThis log.

    There is USUALLY more to do, lack of symptoms isn't always an indication the malware is actually gone.

    1567.

    Solve : I have not been able to connect. Now I can. Hijack This log.?

    Answer»

    I have not been able to connect and through some stroke of luck I was able to. I wanted to have the log looked at while I had the chance.

    Logfile of HijackThis v1.99.1
    Scan saved at 8:57:03 AM, on 9/13/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Norton AntiVirus\navapsvc.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\PackethSvc.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Energizer FileSaver\UPSMON_Service.Exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\RioMSC.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Energizer FileSaver\UPSMON.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\FrostWire\FrostWire.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: WEB assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: WhenUSearch Helper - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Program Files\WhenUSearch\search.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
    O4 - HKLM\..\Run: [NEW.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [UPSMON] C:\Program Files\Energizer FileSaver\UPSMON.exe
    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - Global Startup: Netscape Connect Tray Icon.lnk = C:\Program Files\wmconnect\wmtray.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O10 - Hijacked Internet access by New.Net
    O11 - Options GROUP: [INTERNATIONAL] International*
    O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bellsouth.net/sdccommon/download/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
    O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
    O16 - DPF: {670821E0-76D1-11D4-9F60-009027A966BF} (YouBet Secure Data Transfer Control) - http://racing.youbet.com/wr_6_0/controls/ybrequest.cab
    O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{119D75A6-7247-4D18-A3DF-6F66EB226633}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3A5195A9-996D-4009-AE8C-3E6CCC314FF5}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CS1\Services\Tcpip\..\{119D75A6-7247-4D18-A3DF-6F66EB226633}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CS2\Services\Tcpip\..\{119D75A6-7247-4D18-A3DF-6F66EB226633}: NameServer = 208.67.222.222,208.67.220.220
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: FileSaver_Service - Unknown owner - C:\Program Files\Energizer FileSaver\UPSMON_Service.Exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
    O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exeGo to Add or Remove Programs and uninstall:

    Ask Search Bar or Ask Tooolbar, could be something different by Ask needs to be uninstalled.

    Also uninstall WhenUSearch Helper or WhenUSave or WhenU

    Also uninstall New.net or New Dot Net

    Be sure to restart the computer when done.

    ----------

    Download Malwarebytes' Anti-Malware (MBAM)

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
      • Then click Finish.
      • If an update is FOUND, it will download and install the latest version.
      • Once the program has loaded, select Perform quick scan, then click Scan.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Be sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and Paste the entire report in your next reply.
      .
      Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
      1568.

      Solve : Does anyone know of a malware that does this??

      Answer»

      As of now, I removed it... But there was a DLL file in my system32 folder trying to write the same file in the same place continually, and failing every time. I found it with process monitor because I was wondering why my computer was running slowly. When I forcefully deleted the DLL (It was in use, naturally...) it BSoD'd the computer. On reboot everything was fine.

      I can't remember the name of the DLL, but I google'd it before I deleted it and it came up with 0 results, so I don't think that the name of it would matter much. I do remember that the name was 8 letters, all CAPS, began with DF, and was in use by firefox, explorer, msn messenger, and winlogon. Unfortunately when Firefox crashes, RECENT searches aren't saved.

      Apparently Trend Micro didn't catch it, so either its a new one or Trend Micro missed it. Although I would like to note that Trend Micro was writing something to its log every few seconds, but when I checked, that particular log was not in the Trend Micro logs folder, which is all the more annoying. Trend micro is also not writing a huge number of logs now, like it was before.

      Oddly, even an undelete utility didn't find it! Despite the fact it found my data-shredded passwords from 3 months ago, anyway. 

      It's like just gone 

      In any case, the reason I am posting this topic is because I want to know if there is any other malware out there that does this sort of action, in case I happen to get it again, I'll know what to look for. Even if it's not known, I'd like to know what it was trying to accomplish by writing the same file over and over, if anybody out there might have an explanation. Thanks.

      ~ BaRRWelcome to CH.

      Sounds like the Vundo trojan or a variant of it. With these when you find one, there are usually multiple more that you don't see/find.

      Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note:  It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
       
      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.You were right, there were these:

      C:\WINDOWS\system32\fccaBSJY.dll
      C:\WINDOWS\system32\pskill.exe
      C:\WINDOWS\system32\winio.vxd
      C:\WINDOWS\system32\x64

      Ironically, I had disabled these a few weeks ago because I suspected them, but left them in place because I didn't know if they were harmful or not. I guess I missed one file, and I found the name finally: EFCDSLEX.DLL

      I've never had a problem with viruses/malware before yesterday, so I didn't know the procedures to deal with it.

      Guess I need to do a bit more programming on my Suspicious File Detector. It missed one. Well no program is perfect, hence the name "bug."

      ~ BARR Quote

      I've never had a problem with viruses/malware before yesterday, so I didn't know the procedures to deal with it.

      And I do.....

      If you don't post the combofix log I can't help.

      C:\combofix.txtlol evilfantasy I know this is random, but I just noticed that it says ur experience is "beginner" lol i thik ur a little bit better than that The more you learn, the less you know... Quote from: evilfantasy on September 13, 2008, 07:22:36 PM
      The more you learn, the less you know...

      LOL WHAT?! You just had me sitting here for like a minute trying to make sense of that haha lol ok ILL leave now...... 

      Don't leave without meeee
      I write software and there's private stuff on that log, but don't worry, everything's running fine now.

      Quote
      The more you learn, the less you know...

      The more you learn about a subject, the more you realize you don't know about it. I write software, but don't know how to remove viruses, for instance, haha. I completely thought that one DLL was the only file, since it was the only one running, to be honest.

      ~ BaRR Quote
      I write software and there's private stuff on that log

      Nobody can see your code that you have written. Nothing in the log is harmful to you. That would defeat the purpose of what the malware forum is all about.

      Unless you remove it from the registry you are still infected. Removing DLLS isn't enough.

      Your choice though. Quote
      Removing dlls isn't enough

      Aye, I read on the internet how to remove everything. You were a big help, thanks. I wouldn't have known there was more left if you hadn't pointed it out.
      1569.

      Solve : Disabled AV?

      Answer»

      While doing research for my on-line COURSE I've noticed that most of the experts when they're cleaning a computer will advise the poster to disable their AV while running scans. My question is what's protecting the computer while the AV is disabled? I did this once last week while running a Kaspersky on-line scan but I was assuming that Kaspersky was protecting me at the time. Well, my guess is this:  If you arent browsing the web while scanning the computer, you shouldnt RUN into any viruses.  Just a guess thoNot sure I should answer. You pretty much already did maybe WITHOUT knowing it.

      Different helpers might have different reasons also. Quote from: iamtonsoffun247 on September 13, 2008, 07:41:32 PM

      Well, my guess is this:  If you arent browsing the web while scanning the computer, you shouldnt run into any viruses.  Just a guess tho
      While scanning with Kaspersky I'm quite sure I'm not browsing but I'm definitely on the web and my COMPUTERS are ALWAYS connected.
      1570.

      Solve : a bunch or errors in the command prompt...virus??

      Answer»

      Hi

      I just joined this forum. It looks cool. I hope somebody can help me here.

      A couple of weeks ago i committed an amateur mistake and my comp was flooded with trojans, malware and all kind of harmful stuff. I managed to kill most of them by following your malware removal guide here, however i'm still suspicious that something's not OK.

      When my computer starts up the command prompt window pops up, it's full of ERROR - Access Denied messages. I don't know why. Otherwise my computer works fine, but i'm a bit worried. I have all the logs you guys need posted here. The Anti-Malware log is in Hungarian, but it hasn't found anything harmful anyways.

      Could you please help me find out the problem.

      Thank you very much in advance.

      pg

      Here are the logs:




      [RECOVERING disk space -- attachment deleted by admin]welcome to CH.

      Run the Kaspersky Online Scanner

      In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

      • Click on SCAN NOW
      • Click Accept.
      • The program will then begin downloading the latest definition files.
      • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
      • The scan will take a while, so be patient and let it finish.
      When the scan is done, in the Scan is complete window, any infection is displayed.
      There is no option to clean/disinfect, however, we need to analyze the information on the report.

      To obtain the report:
      Click on: Save Report As
      • Next, in the Save as prompt, Save in area, select: Desktop.
      • In the File name area use KScan, or something similar.
      • In Save as type: click the DROP arrow and select: Text file [*.txt]
      • Then, click: Save


      Copy and paste the Kaspersky Online Scanner Report in your next reply.

      Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.Hey evilfantasy!

      Thanks for the support.

      "Unfortunately" Kasper didn't find anything... here's the log: (What's next???)

      --------------------------------------------------------------------------------
      KASPERSKY ONLINE SCANNER 7 REPORT
       Sunday, September 14, 2008
       Operating System: Microsoft Windows Vista Ultimate Edition, 64-bit SERVICE Pack 1 (build 6001)
       Kaspersky Online Scanner 7 version: 7.0.25.0
       Program database last update: Sunday, September 14, 2008 19:42:53
       Records in database: 1229478
      --------------------------------------------------------------------------------

      Scan settings:
         Scan using the following database: extended
         Scan archives: yes
         Scan mail databases: yes

      Scan area - My Computer:
         A:\
         C:\
         D:\
         E:\
         F:\

      Scan statistics:
         Files scanned: 98652
         Threat name: 0
         Infected objects: 0
         Suspicious objects: 0
         Duration of the scan: 01:08:09

      No malware has been detected. The scan area is clean.

      The selected area was scanned.
      Download ComboFix by SUBS from one of the below links. Be sure top save it to the Desktop.

      Link #1
      Link #2

      **Note:  It is important that it is saved directly to your Desktop

      Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
       
      Double click combofix.exe & follow the prompts.
      When finished ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.I downloaded ComboFix bit it didn't work. It says it's not compatible with my OS. I'm using 64bit Vista.

      How long has this been happening?

      How about restoring?

      Restoring Windows Vista to a previous StateThanks. I'm gonna try.

      pg
      1571.

      Solve : virus, trojans, malware oh my....?

      Answer»

      after the combofix restarted i got a mcafee waring about something called RemAdm-ProcLaunch!171 in folder c:\327882r2fwjfw\psexec.cfexe

      does that mean anything to ya?

      continuing with next step atf cleaner

      [recovering disk space -- attachment deleted by admin]k here are the logs for combofix and awf

      also i did the HJT for that one item

      [recovering disk space -- attachment deleted by admin] Quote from: SirOlwyn on September 11, 2008, 09:59:28 PM

      after the combofix restarted i got a mcafee waring about something called RemAdm-ProcLaunch!171 in folder c:\327882r2fwjfw\psexec.cfexe

      does that mean anything to ya?

      Yes that's part of ComboFix, which is why we suggest turning off the AV before running it. ComboFix uses scripts that are seen as malicious by antivirus. Kind of like the old saying "you have to fight fire with fire."

      Double click FindAWF.exe to start the tool.
      • Select option #2 - Restore files from bak folders by typing 2 and press Enter
      • A text file will open up.  Please copy/paste the text in the Code box below into the text file:
      Code: [Select]"C:\Program Files\Dell Support\bak\DSAgnt.exe"
      "C:\Program Files\iTunes\bak\iTunesHelper.exe"
      "C:\Program Files\QuickTime\bak\qttask.exe"
      "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"
      "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
      "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe"
      "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
      "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe"
      "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"
      "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"
      "C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe"
      "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
      "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
      "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe"
      "C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"
      • Close the .txt file and click Yes to save the changes.
      • When the tool has completed, a report will open up in notepad.
      • Please post the results of the awf.txt in the next reply.
      afw log

      [recovering disk space -- attachment deleted by admin]Getting closer.

      Double-click FindAWF.exe to start the tool.
      • Select option #3 - Remove bak folders by typing e and press Enter
      • A text file will open up.  Please copy/paste the text in the box below into the text file:
      Code: [Select]C:\PROGRA~1\DELLSU~1\BAK
      C:\PROGRA~1\ITUNES\BAK
      C:\PROGRA~1\MESSEN~1\BAK
      C:\PROGRA~1\QUICKT~1\BAK
      C:\WINDOWS\SYSTEM32\BAK
      C:\PROGRA~1\COMMON~1\WRUM\BAK
      C:\PROGRA~1\HP\HPCORE~1\BAK
      C:\PROGRA~1\INTEL\MODEME~1\BAK
      C:\WINDOWS\SYSTEM32\DLA\BAK
      C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK
      C:\PROGRA~1\COMMON~1\AOL\ACS\BAK
      C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK
      C:\PROGRA~1\GOOGLE\GOOGLE~2\121128~1.546\BAK
      C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK
      • Close the .txt file and click Yes to save the changes.
      • When the tool has completed, a report will open up in notepad.
      • Please post the results of the awf.txt in the next reply.
      afw

      [recovering disk space -- attachment deleted by admin]Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

      Now download The Avenger by Swandog46 and save it to your Desktop.
      • Extract avenger.exe from the Zip file and save it to your Desktop
      • Run avenger.exe by double-clicking on it.
      • Do not change any check box options!!
      • Copy everything in the Code box below, and paste it into the Input script here window:
      Code: [Select]Comment:

      Folders to delete:
      C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

      • Now click the Execute button.
      • Click Yes to the prompt to confirm you want to execute.
      • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
      • Your PC should reboot, if not, reboot it yourself.
      • A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
      • Add the Avenger log in your next post.
      .
      ----------

      Last step with FindAWF

      Double-click FindAWF.exe to start the tool.
      • Select option #4 - Reset Domain Zones by typing 4 and press Enter
      • You will be prompted to answer  "Reset the domain zones?"   Type 1 and press Enter.
      • After completion, then type E and press Enter
      Note: if you use SPYWAREBLASTER, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

      Download ResetProtocolDefaults to your desktop.

      Double click ResetProtocolDefaults.reg and answer Yes to any prompts and allow it to merge into the Registry.

      ----------

      Download OTCleanIt.exe and save it to your Desktop.
      • Double-click OTCleanIt.exe.
      • Click the CleanUp! button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes, if not delete it yourself.
      .
      -----

      Go to:
      • Start
      • Run
      • type: CLEANMGR.EXE
      • Press Enter.
      .
      When prompted select the C: drive and click OK.
      Check the boxes for:
      • Temporary Internet Files
      • Downloaded Program Files
      • Recycle Bin
      • Temporary Files
      .
      Click OK or Enter

      ----------

      Use the Kaspersky Online Scanner

      In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

      Click on SCAN NOW
      Click on the Accept button and install any components it NEEDS.
      • The program will install and then begin downloading the latest definition files.
      • After the files have been downloaded on the left side of the PAGE in the Scan section select My Computer.
      • This will start the program and scan your system.
      • The scan will take a while, so be patient and let it run.
      • Once the scan is complete, click on View scan report
      • Now, click on the Save Report as button.
      • In Save as type: click the drop ARROW and select: Text file [*.txt]
      • Then, click: Save
      • Save the file to your desktop.
      Post the Kaspersky log in your next reply.

      Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.OTMoveIt has encountered a problem and needs to close.

      does it everytime i try to open it, about 1 sec into itIs this when you are trying to enter the text into it?no trying to launch itI know. There is two sets of instructions for OTMoveIt2. Did you do the first step in entering the text and clicking MoveIt or is it the second when trying to run the CleanUp option?I downloaded it, dbl click to open and it crashes, i never get to imput the textOk thats what I needed to know.

      I just edited the post with NEW directions to use another program.otcleanit will not launch when i dbl click it, same error mesg.Lets try one more.

      Download http://download.bleepingcomputer.com/oldtimer/OTScanIt.exe

      Unzip it to the Desktop, open the folder and then open OTScanIt.exe

      Click the CleanUp button and start the cleanup process. Choose NOT to restart now.

      Close OTCleanIt and then re-open it and click the CleanUp button again and start the cleanup process. This time re-start the computer when prompted.
      1572.

      Solve : Im Not Sure Whats Going On...?

      Answer»

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 09/14/2008 at 09:17 PM

      Application Version : 4.21.1004

      Core Rules Database Version : 3566
      Trace Rules Database Version: 1554

      Scan type       : Quick Scan
      Total Scan Time : 01:04:53

      Memory items scanned      : 409
      Memory threats detected   : 0
      REGISTRY items scanned    : 307
      Registry threats detected : 0
      File items scanned        : 19412
      File threats detected     : 19

      Adware.Tracking Cookie
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\QooBox\Quarantine\C\Documents and Settings\Owner\Cookies\[email protected][2].txt.vir
         C:\QooBox\Quarantine\C\Documents and Settings\Owner\Cookies\[email protected][1].txt.vir
         C:\QooBox\Quarantine\C\Documents and Settings\Owner\Cookies\[email protected][1].txt.vir


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 23:38:15, on 9/14/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18241)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\PROGRA~1\AVG\AVG8\avgfws8.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\PROGRA~1\AVG\AVG8\avgam.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O4 - HKLM\..\RUN: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      --
      End of file - 6119 bytes


      Malwarebytes' Anti-Malware 1.28
      Database version: 1152
      Windows 5.1.2600 Service Pack 2

      9/14/2008 11:42:22 PM
      mbam-log-2008-09-14 (23-42-22).txt

      Scan type: Quick Scan
      Objects scanned: 44693
      Time elapsed: 9 minute(s), 52 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)


      "Scan ""New scheduled task"" was finished."
      "Infections found:";"0"
      "Infected objects removed or healed:";"0"
      "Not removed or healed:";"0"
      "Spyware found:";"0"
      "Spyware removed:";"0"
      "Not removed:";"0"
      "Warnings count:";"0"
      "Information count:";"0"
      "Scan started:";"Sunday, September 14, 2008, 12:01:02 PM"
      "Scan finished:";"Sunday, September 14, 2008, 1:09:26 PM (1 hour(s) 8 minute(s) 24 second(s))"
      "Total object scanned:";"587436"
      "User who launched the scan:";"SYSTEM"

      "Warnings"
      "File";"Infection";"Result"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.2o7";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\2o7.net.e7e7d917";"Found Tracking cookie.2o7";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\ad.yieldmanager.com.539b0606";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\ad.yieldmanager.com.557bf2b0";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adbrite.com.44f92a69";"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adbrite.com.71beeff9";"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adbrite.com.d5e309c2";"Found Tracking cookie.Adbrite";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.17044b51";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.6d7740f7";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.891542da";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.8b1bd7bc";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.fb764ef7";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\adopt.euroclick.com.ffe11db7";"Found Tracking cookie.Euroclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\advertising.com.1820df7a";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\advertising.com.203aa218";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\advertising.com.525a5fb9";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\advertising.com.b624fa46";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\advertising.com.f62113d5";"Found Tracking cookie.Advertising";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\atdmt.com.b3e33b5f";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Bluestreak";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\bluestreak.com.bf396750";"Found Tracking cookie.Bluestreak";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\burstnet.com.27341d57";"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\burstnet.com.a3218a37";"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\burstnet.com.c4fe2ebb";"Found Tracking cookie.Burstnet";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Clickbank";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\clickbank.net.82079eb1";"Found Tracking cookie.Clickbank";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\doubleclick.net.bf396750";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\fastclick.net.19d0b716";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\fastclick.net.57e8da10";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\fastclick.net.6fd479aa";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\fastclick.net.8a6435e9";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\fastclick.net.fac3d6f0";"Found Tracking cookie.Fastclick";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Mediaplex";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\mediaplex.com.f652b123";"Found Tracking cookie.Mediaplex";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.2o7";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\msnportal.112.2o7.net.7225be6f";"Found Tracking cookie.2o7";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Realmedia";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\realmedia.com.4a2ec787";"Found Tracking cookie.Realmedia";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\realmedia.com.68087763";"Found Tracking cookie.Realmedia";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\realmedia.com.6b2e2a72";"Found Tracking cookie.Realmedia";"Deleted"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt";"Found Tracking cookie.Sextracker";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][1].txt:\sextracker.com.26f20167";"Found Tracking cookie.Sextracker";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\trafficmp.com.37644bdb";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\trafficmp.com.a00e30b4";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\trafficmp.com.ae53b8b";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\trafficmp.com.e2e71e33";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\trafficmp.com.f3e5803e";"Found Tracking cookie.Trafficmp";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt";"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
      "C:\Documents and Settings\Owner\Cookies\[email protected][2].txt:\tribalfusion.com.dcc03271";"Found Tracking cookie.Tribalfusion";"Moved to Virus Vault"
      was malwarebytes run before or after you got the hijack this log?After SUPERAntiSpyYou have to run hijack this after both superantispyware and malwarebytes.  Seems that you ran both scans, so post a new hijack this log.  Then one of the malware removal specialists will be able to help youLogfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:26:48, on 9/15/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18241)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\PROGRA~1\AVG\AVG8\avgfws8.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\PROGRA~1\AVG\AVG8\avgam.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe
      C:\Program Files\AIM6\aim6.exe
      C:\Program Files\AIM6\aolsoftware.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Sony\ACID Music Studio 5.0\acid50.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      --
      End of file - 6185 bytes
      Quote

      Im Not Sure Whats Going On...

      Neither do I if you don't tell me...AVG POPS UP IT SAYS HEAL FILE OR SOMETHING ELSE AND THEN IT SAYS HEAL I CLICK HEAL AND IT SAYS FILE NOT FOUNDDownload Malwarebytes' Anti-Malware (MBAM)

      • Double-click mbam-setup.exe and follow the prompts to install the program.
      • At the end, be sure a checkmark is placed next to the following:
        • Update Malwarebytes' Anti-Malware
        • Launch Malwarebytes' Anti-Malware
        • Then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select Perform quick scan, then click Scan.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Be sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra NOTE)
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy and Paste the entire report in your next reply.
        Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection PROCESS, if asked to restart the computer, please do so immediately.
        1573.

        Solve : Help! Spyware/Malware on my computer?

        Answer»

        Here's the scan results list

        Scan results list

        Also wanna say thank you for all your help, you're a lifesaver man.This is a tough one because those files were not fixes by the scanner and there are both legitimate and non-legitimate files with the same names running from the same location.

        Scan Suspicious File(s)

        Use the VirusTotal.com - Multi engine on-line virus scanner
        (If more than one file needs scanned they must be done separately and logs posted for each one)

        • Copy the file path in the below Code box:
        Code: [SELECT]C:\Windows\system32\termsrv.dll
        • At the UPLOAD site, click once inside the window next to Browse.
        • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
        • Next click Send File
          • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
        • This will perform a scan across multiple different virus scanning engines.
        • Important: Wait for all of the scanning engines to complete.
        • Copy and then Paste the link to the results in the next reply.
        .
        -----

        Now do the same with Code: [Select]C:\Windows\system32\winlogon.exetermsrv.dll http://www.virustotal.com/analisis/8b221340fba35115dd354137262600e4

        winlogon.exe
        http://www.virustotal.com/analisis/dfb0e869b9b69bacdec1c27511ca6a0dWith only 2 scanners (and the same ones) hitting on those files I am thinking false positive. They are running from the correct location so I would have to think they are legit.

        Download ATF Cleaner by Atribune to your Desktop.

        Alternate download link

        Note: Vista users must use Run As Administrator
        • Under Main: Select Files to Delete choose: Select All.
        • Click the Empty Selected button.
        • If you use Firefox browser click Firefox at the top and choose: Select All
        • Click the Empty Selected button.
          If you would like to keep your saved passwords click No at the prompt.
        • If you use Opera browser click Opera at the top and choose: Select All
        • Click the Empty Selected button.
          If you would like to keep your saved passwords click No at the prompt.
        • Click Exit on the Main menu to close the program.
        Note that your system will run slower for a reboot or two after having used this tool so don't panic.

        ----------

        1. Double click OTMoveIt2.exe to launch it.
        If using Vista Right-Click OTMoveIt and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        • When finished exit out of OTMoveIt2
        Important: Restart the computer before continuing.

        ----------

        Next: Set a New Restore Point to prevent possible reinfection from an old one.

        Please go to: Start -> All Programs -> Accessories -> System Tools -> System Restore -> System Restore Settings
        Click to add a check mark beside Turn off System Restore and click Apply
        When you are warned that all existing Restore Points will be deleted, click Yes to continue and wait a few moments to let System Restore clear.
        Uncheck "Turn off System Restore"
        Click "Apply," and then click "OK".

        You can find more detailed instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide

        ----------

        Use the Secunia Software Inspector to check for out of date software.
        Click Start Now
        Check the box next to Enable thorough system inspection.
        Click Start
        Allow the scan to finish and scroll down to see if any updates are needed.
        Update anything listed.

        ----------


        How is everything now?I was messing around on here doing my daily stuff and all and it seems ok. I may have to reinstall wmp11 so that online videos work in wmp11 instead of mplayer2

        The scan caught some out of date stuff but out of personal preferences, I'll keep what I have on here.

        Again, thanks a TON man you've been really awesome  Try installing K-Lite to see if it clears up Media Player - http://filehippo.com/download_klite_codec_pack/

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

        To prevent unknown applications from being INSTALLED on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to MAKE it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks, I'll keep this thread and site around for any future problems if they come up.just let us know if anything else comes up.

        Safe surfing.....
        1574.

        Solve : free downloads for antivirus won't intstall, please help?

        Answer»

        I'm trying to go through the steps of removing the biohazard screen saver virus from my computer, and in the steps I was following under STEP A it said to download one of the free anitvirus programs.  Only when I try to download them off of my desk top, it says that the FILES are corrupt and won't let me download them.  Not sure what to do, PLEASE HELP!You can leave the Anti-Virus for now, but you will need it later.

        Continue with the other steps for now.Thank you, I'm sure I'll have more questions later so I really appreciate all the help!

        1575.

        Solve : So I'm gonna give a go at this...?

        Answer»

        I downloaded a few new programs, and I am going to post a HJT log.......  Now what can be removed on this list?  Evilfantasy, I used the program online that you suggested, which removed a few startup items, but I feel like there are a few more I can do:

        Logfile of Trend MICRO HijackThis v2.0.2
        Scan saved at 10:49:33 AM, on 8/27/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\wltrysvc.exe
        C:\WINDOWS\System32\bcmwltry.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Intel\Intel Matrix STORAGE Manager\iaantmon.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
        C:\Program Files\Trend Micro\BM\TMBMSRV.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        C:\WINDOWS\system32\dla\tfswctrl.exe
        C:\WINDOWS\system32\wltray.exe
        C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Logitech\SetPoint\KEM.exe
        C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
        C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet SETTINGS,ProxyOverride = *.local
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
        O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
        O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
        O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
        O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - GLOBAL Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
        O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.yorkphoto.com/YorkActivia.cab
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
        O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
        O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
        O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
        O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

        --
        End of file - 7156 bytes

        Im thinking:
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        and,
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe

        I just need a confirmation that it is safe to remove these before I go ahead and do it..... THANKS Disable SpySweeper

        You can re-enable it after we are done, it may BLOCK the fixes if it's running.

        To disable SpySweeper:

        Open Spysweeper and click > Options over to the left then > Program Options > Uncheck "load at windows startup"

        Over to the left click "shields" and Uncheck all there.

        Uncheck "home page shield"

        Uncheck "automatically restore default without notification"

        ----------

        O4 - HKLM..Run: [PinnacleDriverCheck] C:WINDOWSsystem32\PSDrvCheck.exe < Once loaded it doesn't use any resources so you can leave it enabled

        Open HijackThis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
        - O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
        - O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        - O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        -


        Important: Close all windows except for HijackThis and then click Fix checked.

        Exit HijackThis.

        ----------

        Go to Start > Run and type notepad.exe then click OK

        Copy the text in the Code box below and paste it into Notepad.

        Code: [Select]REGEDIT4

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
        "AppleSyncNotifier"=-
        "iTunesHelper"=-
        "Adobe Reader Speed Launcher"=-
        In Notepad go to File > Save as...

        Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop.

        There should now be a file on the Desktop that looks like this

        Double-click fixme.reg it and allow it to merge with the Registry.

        You may not see anything happen but give it a few seconds or so to finish.

        Now delete the fixme.reg file from the Desktop.

        ----------

        Go to Start > Run and type in Services.msc then click OK
        Scroll down until you find the service.
        Quote

        Apple Mobile Device - Apple Inc.
        Click once on the service to highlight it.
        Click Stop

        Right-Click on the service.
        Click on 'Properties'
        Select the 'General' tab
        Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
        From the drop-down menu, click on 'Disabled'
        Click the 'Apply' tab, then click 'OK'
        The service is now stopped and disabled.

        Also do the same for iPod Service - Apple Inc.

        Restart the computer.Ok I did it.... thank you!

        A few questions....

        1.) How come I had to disable webroot?
        2.) If I plug in an ipod, will my comp recognize it?

        THANKS!1.) How come I had to disable webroot?

        Quote from: evilfantasy
        it may block the fixes if it's running.

        Quote from: evilfantasy
        You can re-enable it after we are done


        2.) If I plug in an ipod, will my comp recognize it?

        Yes. And if you update iTunes it will also set itself to run as a service again.
        1576.

        Solve : Haunt.exe?

        Answer»

        An interesting LITTLE trojon, i have found and tested on my Virtual computer. If you see this file or have it on you computer, just DONT open it. It does some crazy *censored* to your computer.How informative.Indeed. I'm sure your Antivirus would pick it up first though.probably
        It's a fairly tame and well-known infection, so yes, most anti-virus programs should detect it. Quote from: kizza1645 on August 27, 2008, 03:31:57 AM

        An interesting little trojon, i have found and tested on my Virtual computer. If you see this file or have it on you computer, just dont open it. It does some crazy sh*t to your computer.

        like im wondering wat it does?

        I used to have The OLD "OSDmm.exe" Which made my PC Look like it had a different OS on it.

        But that was 3 YEARS ago. Quote from: !~*:.Pink Floyd.:*~! on August 27, 2008, 06:45:24 AM
        Quote from: kizza1645 on August 27, 2008, 03:31:57 AM
        An interesting little trojon, i have found and tested on my Virtual computer. If you see this file or have it on you computer, just dont open it. It does some crazy sh*t to your computer.

        like im wondering wat it does?

        I used to have The old "OSDmm.exe" Which made my PC Look like it had a different OS on it.

        But that was 3 years ago.

        messes around with stuff on your computer expanding itsself by downloading more rubbish onto your computer.
        1577.

        Solve : RTVSCAN.exe and Teatimer.exe?

        Answer»

        both use much memory causing my PC to run very slowly. I've read that teatimer.exe is essential to SPYBOT. Can I make it use LESS memory somehow?

        what is rtvscan.exe? same question: can I make it run faster?Welcome to the FORUM!

        rtvscan = http://www.processlibrary.com/directory/files/rtvscan/24769/
        teatimer = http://www.processlibrary.com/directory/files/teatimer/25451/

        Hope that helped. rtvscan should stay active unless you decide not to use NORTON.

        TeaTimer in all honesty is a bigger pain then anything. I suggest turning it off and using WinPatrol in its place.

        How to Disable Spybot's TeaTimer

        WinPatrol
        thanks for the link and the welcome. it explained clearly what those programs are. i bought and downloaded registry booster 2...not sure yet if it made any difference.
        any input on the variety of posts in this and other sites I've seen saying teatimer is not worth using?

        thanksIt uses too much memory for what it does is the main complaint. Some PC's it will actually cause blue screens and RANDOM crashes. Then some it works fine on.I've also found TeaTimer to be quite intrusive when it comes to working with other programs.  Their heart is in the right place, but I really think you're better off with disabling this feature.thanks...if I disable TeaTimer, will Spybot still be effective or should I just delete Spybot completely?

        it would be interesting to hear what spybot has to say about Teatimer's relative worth vs. its hassle. Quote

        it would be interesting to hear what spybot has to say about Teatimer's relative worth vs. its hassle.

        That's a question they have addressed time and again. They seem to have little patience (understandably) for discussing pros and cons these days. They have said they improved it with the newer builds but I'm not going to try it and see.

        Turning it off will not effect the program at all. Just be sure to update and then run the Immunize feature about once a week.
        1578.

        Solve : Please help with spyware/virus?

        Answer»

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        * Using Winpatrol to protect your computer from malicious software

        I suggest using SiteAdvisor. SiteAdvisor rates SITES on BUSINESS PRACTICES and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.So is my computer now clean?
        And thanks for the tips.  I can't find any malware so you are as clean as I can get you. I'm sure everything is fine now.

        1579.

        Solve : been infected with antivirus xp 2008 can't get pass log in screen?

        Answer»

        All of a sudden I got this thing about antivirus xp 2008 found 1700 and some MALWARE things on my computer and I need to download this spy ware tried to delete this out through add/remove programs noway could I. next thing I know fire computer up come to loggin screen for xp and after putting in my pass word it goes to a blue screen with a banner in the middle saying I have been INFECTED with maleware and I can't get it to go no further just sets there with this screen upCan you get into Windows in Safe Mode?unless I was doing something wrong it took me to a black screen and that was it. I hope there is a way I can save some of my WIFES pics from here mission trip.Is this a LAPTOP or a Desktop Computer?this is a desk top with windows xpPress ctrl+alt+delete (all at the same time) Does open Task Manager open?

        yes it come upyes it come upIn Task Manager go to File > New Task (Run...) and select that.

        Now TYPE in explorer.exe and click OK.

        Do you have any functions/icons now and can you get on the Internet?it will not let me open task manageCan you get in to Safe Mode like Carbon suggested and run a virus scan?I have a window no that says window advanced mode where do I go now to run a scan?Was there not an option to enter Safe Mode?yes I hit enter and it went to login and I logged in but all I have is a black screen now with safe mode on the corners. Now try opening Task Manager to open explorer.exe

        1580.

        Solve : My computer got very slow.?

        Answer»

        Hi, I've had many viruses and I never knew how to get rid of them. I've been having virus or awhile now, and someone recommended me to go to this site. Is someone willing to help me and my problems? Thank you.


        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:05:40 AM, on 8/21/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        C:\WINDOWS\system32\DVDRAMSV.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
        C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
        C:\WINDOWS\system32\TODDSrv.exe
        C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
        C:\Program Files\Toshiba\Tvs\TvsTray.exe
        C:\WINDOWS\system32\TPSMain.exe
        C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\toshiba\ivp\ism\pinger.exe
        C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\RAMASST.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Synaptics\SynTP\Toshiba.exe
        C:\WINDOWS\system32\TPSBattM.exe
        C:\WINDOWS\Integrator.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\Phuoc\Desktop\jxpiinstall.exe
        C:\WINDOWS\system32\msiexec.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\MICROSOFT\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://desktop.google.com/uninstall-feedback.html?hl=en
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
        O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
        O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
        O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
        O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
        O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
        O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
        O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

        --
        End of file - 7921 bytes


        [recovering disk space -- attachment deleted by admin]Well, your MBAM doesn't show anything significant and neither does HJT.  Can we get a SUPERAntiSpyware log as well?

        And what exactly is wrong with your computer?  Is it just acting slow?Hey, yes my only problem is that it runs really slow, and so do the programs. When i open my firefox, I have to wait atleast a minute for it to popup. When i use firefox and use minimize, the browser seems to go out of control. When i do somthing, it freezes for quite a minute, then works properly. I am going to post my log in my next reply.It could be a number of things.

        What are your computer specifications? (RAM and Processor)
        Also, what is your Hard Drive Capacity and Free Space?Multiple AV's
        O23 - Service: LiveUpdate Notice Service
        O23 - Service: BitDefender


        Multiple versions of Java
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        Download the Norton Removal Tool (SymNRT) to your Desktop.

        Once downloaded please close ALL open browsers, also save any work because this may require a restart.

        • Go to your desktop and double click on the removal tool and then click Setup.
        • Once open Click Next
        • ACCEPT the license agreement and click Next
        • Type in the letters/numbers that you see into the text box then click Next.
        • Then click Next and the tool will start running.
        • Once finished restart the PC and run the tool again to ensure everything has been removed.
        .
        ----------

        Download JavaRa

        • Unzip the file and open the JavaRa.exe
        • Click Remove Older Versions
        • JavaRa will search for and remove any outdated version of Java and remove any that are found.
        • Exit JavaRa.
        • Delete the JavaRa .zip .exe and .html files from the Desktop.
        .
        ----------

        Restart the computer and let us know how things are now.Nice catch; I can't believe I overlooked BitDefender and the old Java.  Shame on me.  azncruboi, follow evilfantasy's above instructions.  I can't say that it'll solve your problem, but you should definitely notice a difference.Hi, thanks for the help guys. EVIL Fantasy, I did as you said, and it has helped my laptop. Thanks for that. It is running a bit faster then before. Firefox seems to load faster, and the minimize does not go out of hand. Firefox still does freeze up at times.

        Carbon Dudeoxide,

        Windows XP
        Toshiba
        1.60 GHz
        504MB of RAM
        74.2GB of space
        10.1 GB of free space


        Also, what is your Hard Drive Capacity and Free Space?


        CBMatt,

        I posted the Superantispyware as follows.

        SUPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 08/22/2008 at 01:20 PM

        Application Version : 4.15.1000

        Core Rules Database Version : 3542
        Trace Rules Database Version: 1460

        Scan type       : Complete Scan
        Total Scan Time : 11:20:46

        Memory items scanned      : 423
        Memory threats detected   : 0
        Registry items scanned    : 4854
        Registry threats detected : 0
        File items scanned        : 116986
        File threats detected     : 0


        EDIT: Just incase if needed.

        I don't know what most of the programs are and do.

        Uninstall list
        Adobe Flash Player 9 ActiveX
        Adobe Flash Player Plugin
        Adobe Reader 7.0
        avast! Antivirus
        Bluetooth Stack for Windows by Toshiba
        CCleaner (remove only)
        DivX Codec
        DivX Converter
        DivX Player
        DivX Web Player
        DVD-RAM Driver
        High Definition Audio Driver Package - KB888111
        HijackThis 2.0.2
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix for Windows Media Player 10 (KB903157)
        Hotfix for Windows Media Player 11 (KB939683)
        Hotfix for Windows XP (KB952287)
        Intel(R) Graphics Media Accelerator Driver
        Intel(R) PROSet/Wireless Software
        InterVideo WinDVD Creator 2
        InterVideo WinDVD for TOSHIBA
        Java(TM) 6 Update 7
        Malwarebytes' Anti-Malware
        mCore
        mDrWiFi
        mHelp
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft .NET Framework 2.0 Service Pack 1
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft User-Mode Driver Framework Feature Pack 1.0
        mIWA
        mLogView
        mMHouse
        Mozilla Firefox (2.0.0.16)
        mPfMgr
        mPfWiz
        mProSafe
        MSXML 4.0 SP2 (KB936181)
        mWlsSafe
        mXML
        mZConfig
        Office 2003 Trial Assistant
        QuickTime
        RealPlayer
        REALTEK GbE & FE Ethernet PCI-E NIC Driver
        Realtek High Definition Audio Driver
        Rhapsody Player Engine
        SD Secure Module
        Security Update for Step By Step Interactive Training (KB898458)
        Security Update for Windows Media Player 10 (KB917734)
        Security Update for Windows Media Player 10 (KB936782)
        Security Update for Windows Media Player 11 (KB936782)
        Security Update for Windows XP (KB941569)
        Security Update for Windows XP (KB946648)
        Security Update for Windows XP (KB950759)
        Security Update for Windows XP (KB950760)
        Security Update for Windows XP (KB950762)
        Security Update for Windows XP (KB950974)
        Security Update for Windows XP (KB951066)
        Security Update for Windows XP (KB951376)
        Security Update for Windows XP (KB951376-v2)
        Security Update for Windows XP (KB951698)
        Security Update for Windows XP (KB951748)
        Security Update for Windows XP (KB952954)
        Security Update for Windows XP (KB953838)
        Security Update for Windows XP (KB953839)
        Sonic Encoders
        Synaptics Pointing Device Driver
        TOSHIBA Assist
        TOSHIBA ConfigFree
        TOSHIBA Controls
        TOSHIBA Direct Disc Writer
        TOSHIBA Disc Creator
        TOSHIBA Hotkey Utility
        TOSHIBA PC Diagnostic Tool
        TOSHIBA Power Saver
        TOSHIBA Recovery Disc Creator
        Toshiba Registration
        TOSHIBA SD Memory Card Format
        TOSHIBA Software Upgrades
        TOSHIBA Speech System Applications
        TOSHIBA Speech System SR Engine(U.S.) Version1.0
        TOSHIBA Speech System TTS Engine(U.S.) Version1.0
        TOSHIBA TouchPad ON/Off Utility
        TOSHIBA Utilities
        TOSHIBA Virtual Sound
        TOSHIBA Zooming Utility
        Touch and Launch
        Update for Windows Media Player 10 (KB910393)
        Update for Windows Media Player 10 (KB913800)
        Update for Windows Media Player 10 (KB926251)
        Update for Windows XP (KB951072-v2)
        Update Rollup 2 for Windows XP Media Center Edition 2005
        VeohTV BETA
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows Media Player Firefox Plugin
        Windows XP Media Center Edition 2005 KB888316
        Windows XP Media Center Edition 2005 KB894553
        Windows XP Media Center Edition 2005 KB895678
        Windows XP Media Center Edition 2005 KB925766
        Windows XP Service Pack 3
        WinRAR archiver
        Your Uninstaller! 2006 Version 5


        Process list saved on 3:26:11 AM, on 8/23/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)

        [pid]   [full path to filename]      [file version]   [company name]
        608   C:\WINDOWS\System32\smss.exe      5.1.2600.5512   Microsoft Corporation
        688   C:\WINDOWS\system32\winlogon.exe      5.1.2600.5512   Microsoft Corporation
        732   C:\WINDOWS\system32\services.exe      5.1.2600.5512   Microsoft Corporation
        744   C:\WINDOWS\system32\lsass.exe      5.1.2600.5512   Microsoft Corporation
        916   C:\WINDOWS\system32\svchost.exe      5.1.2600.5512   Microsoft Corporation
        1024   C:\WINDOWS\System32\svchost.exe      5.1.2600.5512   Microsoft Corporation
        1088   C:\Program Files\Intel\Wireless\Bin\EvtEng.exe      10.5.0.20   Intel Corporation
        1136   C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe      10.5.0.34   Intel Corporation
        1516   C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe      4.8.1227.0   ALWIL Software
        1596   C:\Program Files\Alwil Software\Avast4\ashServ.exe      4.8.1227.0   ALWIL Software
        536   C:\WINDOWS\Explorer.EXE      6.0.2900.5512   Microsoft Corporation
        1464   C:\WINDOWS\system32\spoolsv.exe      5.1.2600.5512   Microsoft Corporation
        1608   C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe      6.0.0.1   TOSHIBA CORPORATION
        264   C:\WINDOWS\system32\DVDRAMSV.exe      3.0.0.0   Matsushita Electric Industrial Co., Ltd.
        488   C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe      10.5.0.4   Intel Corporation
        1368   C:\WINDOWS\system32\svchost.exe      5.1.2600.5512   Microsoft Corporation
        1320   c:\TOSHIBA\IVP\swupdate\swupdtmr.exe         
        808   C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe      1.0.0.14   TOSHIBA Corp.
        1904   C:\WINDOWS\system32\TODDSrv.exe      1.0.0.3   TOSHIBA Corporation
        2616   C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe      4.8.1227.0   ALWIL Software
        2692   C:\Program Files\Alwil Software\Avast4\ashWebSv.exe      4.8.1229.0   ALWIL Software
        3404   C:\Program Files\Toshiba\Tvs\TvsTray.exe      1.0.0.7   TOSHIBA Corporation
        3508   C:\WINDOWS\system32\TPSMain.exe      1.0.15.0   TOSHIBA Corporation
        3556   C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe      3.22.0.0   TOSHIBA Corporation
        3620   C:\WINDOWS\system32\TPSBattM.exe      1.0.2.0   TOSHIBA Corporation
        3628   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe      8.2.13.2   Synaptics, Inc.
        3644   C:\WINDOWS\RTHDCPL.EXE      2.0.9.1   Realtek Semiconductor Corp.
        3656   C:\toshiba\ivp\ism\pinger.exe      3.7.0.0   TOSHIBA Corporation
        3660   C:\Program Files\Synaptics\SynTP\Toshiba.exe      8.2.13.2   Synaptics, Inc.
        3700   C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe      6.0.1.2   TOSHIBA CORPORATION
        3728   C:\WINDOWS\ehome\ehtray.exe      5.1.2710.2732   Microsoft Corporation
        3836   C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe      6.0.0.117   TOSHIBA CORPORATION
        3884   C:\Program Files\Common Files\Real\Update_OB\realsched.exe      0.1.1.45   RealNetworks, Inc.
        3932   C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe      6.0.70.6   Sun Microsystems, Inc.
        3956   C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe      4.8.1227.0   ALWIL Software
        3996   C:\WINDOWS\system32\ctfmon.exe      5.1.2600.5512   Microsoft Corporation
        800   C:\WINDOWS\system32\RAMASST.exe      1.1.0.0   Matsushita Electric Industrial Co., Ltd.
        1844   C:\WINDOWS\eHome\ehSched.exe      5.1.2710.2732   Microsoft Corporation
        1848   C:\WINDOWS\eHome\ehRecvr.exe      5.1.2715.3011   Microsoft Corporation
        3044   C:\WINDOWS\system32\dllhost.exe      5.1.2600.5512   Microsoft Corporation
        1884   C:\WINDOWS\eHome\ehmsas.exe      5.1.2710.2732   Microsoft Corporation
        3236   C:\Program Files\Mozilla Firefox\firefox.exe      1.8.20080.4669   Mozilla Corporation
        3276   C:\WINDOWS\system32\msiexec.exe      3.1.4001.5512   Microsoft Corporation
        2080   C:\Program Files\Trend Micro\HijackThis\HijackThis.exe      2.0.0.2   Trend Micro Inc.

        C:\WINDOWS\system32\ntdll.dllHey, out of curiosity, why am I not getting any response?Sorry, sometimes replies slip by us and get forgotten. Not on purpose.....

        I don't think this is a malware issue. Post a new HijackThis log and we will see if there is anything we can do with it to try and speed up the PC.I agree with evilfantasy.  So far, it seems that your computer is just struggling to handle all of the programs.  And like he said, the lack of response was not on purpose.  The problems in the SECTION are fairly involved, so we get busy easily.  It also doesn't help that school is starting up, which eats away at a lot of my time.  My apologies.

        Anyway, go ahead and post the new HJT log and we'll see what else we can do.  Also, you should post as many computer specs as you can, such as CPU, RAM, hard drive (free space and total space), video card, etc.Computer specs:
        Windows xp
        media center edition
        version 2002
        service pack 3
        toshiba
        satellite
        Genuine Intel CPU
        t2050 1.60 GHz
        504MB of RAM.














        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 4:29:59 PM, on 8/28/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        C:\WINDOWS\system32\DVDRAMSV.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
        C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
        C:\WINDOWS\system32\TODDSrv.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\Program Files\Toshiba\Tvs\TvsTray.exe
        C:\WINDOWS\system32\TPSMain.exe
        C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\Synaptics\SynTP\Toshiba.exe
        C:\toshiba\ivp\ism\pinger.exe
        C:\WINDOWS\system32\TPSBattM.exe
        C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\system32\RAMASST.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://desktop.google.com/uninstall-feedback.html?hl=en
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
        O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
        O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
        O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
        O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/v1018/flashax.cab
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
        O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe

        --
        End of file - 6476 bytes
        None of these need to be running at startup.

        Open HijackThis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        - O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
        - O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
        - O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
        - O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        - O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        - O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        - O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


        Important: Close all windows except for HijackThis and then click Fix checked.

        Exit HijackThis.

        ----------

        Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

        Go to Start > Run and type notepad.exe then click OK

        Copy the text in the Code box below and paste it into Notepad.

        Code: [Select]REGEDIT4

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
        "Tvs"=-
        "Pinger"=-
        "igfxtray"=-
        "ehTray"=-
        "Alcmtr"=-
        "TkBellExe"=-
        "SunJavaUpdateSched"=-
        "ctfmon.exe"=-
        In Notepad go to File > Save as...

        Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop.

        There should now be a file on the Desktop that looks like this

        Double-click fixme.reg it and allow it to merge with the Registry.

        You may not see anything happen but give it a few seconds or so to finish.

        Now delete the fixme.reg file from the Desktop and restart the computer.

        ----------

        Use the Secunia Software Inspector

        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        ----------

        That's all I can see. If there are still problems you may need to UPGRADE some hardware.
        1581.

        Solve : Virus help!?

        Answer»

        here you go

        ComboFix 08-08-28.04 - Family 2008-08-28 16:42:33.3 - NTFSx86
        Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.657 [GMT -4:00]
        Running from: C:\Documents and Settings\Family\Desktop\ComboFix.exe
        Command switches used :: C:\Documents and Settings\Family\Desktop\CFScript.txt
         * Created a new restore point

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

        FILE ::
        C:\dtpv.exe
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\-2145839103\
        C:\Documents and Settings\All Users\Application Data\services
        C:\dtpv.exe
        C:\WINDOWS\system32\349168

        .
        (((((((((((((((((((((((((   Files Created from 2008-07-28 to 2008-08-28  )))))))))))))))))))))))))))))))
        .

        2008-08-28 15:36 . 2008-08-28 15:36      d--------   C:\sdfix
        2008-08-27 21:36 . 2008-08-27 21:36      d--------   C:\Program Files\Malwarebytes' Anti-Malware
        2008-08-27 21:36 . 2008-08-17 15:01   38,472   --a------   C:\WINDOWS\system32\drivers\mbamswissarmy.sys
        2008-08-27 21:36 . 2008-08-17 15:01   17,144   --a------   C:\WINDOWS\system32\drivers\mbam.sys
        2008-08-27 20:11 . 2008-08-27 20:11   2   --a------   C:\-2145839103
        2008-08-27 01:23 . 2008-08-27 01:38      d--------   C:\WINDOWS\system32\CatRoot_bak

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-08-28 20:42   ---------   d-----w   C:\Documents and Settings\Family\Application Data\DNA
        2008-08-25 23:03   ---------   d-----w   C:\Documents and Settings\Family\Application Data\LimeWire
        2008-08-08 22:33   ---------   d-----w   C:\Documents and Settings\Family\Application Data\BitTorrent
        2008-07-30 20:31   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\avg8
        2008-07-23 17:27   ---------   d-----w   C:\Program Files\BroadJump
        2008-07-21 18:39   ---------   d-----w   C:\Program Files\V CAST Music with Rhapsody
        2008-07-21 18:39   ---------   d-----w   C:\Program Files\Common Files\Real
        2008-07-21 18:38   ---------   d-----w   C:\Program Files\Real
        2008-07-19 16:55   ---------   d-----w   C:\Documents and Settings\Family\Application Data\InstallShield Installation Information
        2008-07-19 16:55   ---------   d-----w   C:\Documents and Settings\Family\Application Data\2K Games
        2008-07-19 16:53   ---------   d-----w   C:\Documents and Settings\Family\Application Data\InstallShield
        2008-07-19 16:31   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
        2008-07-17 01:26   ---------   d-----w   C:\Program Files\Full Tilt Poker
        2008-07-12 18:08   ---------   d-----w   C:\Program Files\VideoLAN
        2008-07-11 20:03   ---------   d-----w   C:\Program Files\Infogrames Interactive
        2008-07-05 21:50   ---------   d-----w   C:\Program Files\PartyGaming
        2008-07-04 00:14   ---------   d-----w   C:\Program Files\Firaxis Games
        2008-05-17 22:10   36,868   ----a-w   C:\Program Files\uninst-Particular.exe
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17 50736]
        "EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 19:16 454784]
        "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 00:06 2321600]
        "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-06-04 13:14 289088]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 15:52 339968]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 06:06 40048]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 05:41 49152]
        "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 11:38 241664]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 09:24 286720]
        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 23:15 271672]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 08:00 132496]
        "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 20:05 200704]
        "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 17:40 1884160]

        C:\Documents and Settings\Family\Start Menu\Programs\Startup\
        MEMonitor.lnk - C:\Program Files\V CAST Music Manager\MEMonitor.exe [2007-12-24 23:17:32 951640]

        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 07:21:22 288472]
        HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 10:56:20 73728]
        Photo Loader supervisory.lnk - C:\Program Files\CASIO\Photo Loader\Plauto.exe [2007-10-22 22:01:29 229376]

        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
        2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
        SecurityProviders   msapsspc.dllschannel.dlldigest.dllmsnss pc.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
        "C:\\Program Files\\iTunes\\iTunes.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
        "C:\\Program Files\\AIM6\\aim6.exe"=
        "C:\\Program Files\\LimeWire\\LimeWire.exe"=
        "C:\\Program Files\\Azureus\\Azureus.exe"=
        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
        "C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
        "C:\\Program Files\\mIRC\\mirc.exe"=
        "C:\\Program Files\\Cain\\Cain.exe"=
        "C:\\Program Files\\DNA\\btdna.exe"=
        "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
        "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
        "C:\\Documents and Settings\\Family\\Application Data\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Civilization4.exe"=
        "C:\\Documents and Settings\\Family\\Application Data\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Gold\\Warlords\\Civ4Warlords.exe"=
        "C:\\WINDOWS\\system32\\winver.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
        "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
        "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
        "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
        "AllowInboundTimestampRequest"= 1 (0x1)
        "AllowInboundMaskRequest"= 1 (0x1)
        "AllowInboundRouterRequest"= 1 (0x1)
        "AllowOutboundDestinationUnreachable"= 1 (0x1)
        "AllowOutboundSourceQuench"= 1 (0x1)
        "AllowOutboundParameterProblem"= 1 (0x1)
        "AllowOutboundTimeExceeded"= 1 (0x1)
        "AllowRedirect"= 1 (0x1)
        "AllowOutboundPacketTooBig"= 1 (0x1)

        R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
        R1 ts_lb;ts_lb;C:\WINDOWS\system32\drivers\ts_lb.sys [2007-06-19 23:35]
        R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
        S3 CV2K1;CommView Network Monitor;C:\WINDOWS\system32\DRIVERS\cv2k1.sys [2006-12-07 22:04]
        S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 16:22]
        .
        Contents of the 'Scheduled Tasks' folder

        2008-08-21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:15]
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-08-28 16:45:12
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        ------------------------ Other Running Processes ------------------------
        .
        C:\WINDOWS\system32\ati2evxx.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\AIM6\aolsoftware.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
        C:\WINDOWS\system32\HPZipm12.exe
        .
        **************************************************************************
        .
        Completion time: 2008-08-28 16:49:21 - machine was rebooted
        ComboFix-quarantined-files.txt  2008-08-28 20:49:17
        ComboFix2.txt  2008-08-28 20:17:20

        Pre-Run: 79,689,158,656 bytes free
        Post-Run: 79,688,552,448 bytes free

        169   --- E O F ---   2008-08-14 07:01:12
        Download OTCleanIt.exe and save it to your Desktop.

        • Double-click OTCleanIt.exe.
        • Click the CleanUp! button.
        • Select Yes when the "Begin cleanup Process?" prompt appears.
        • If you are prompted to Reboot during the cleanup, select Yes.
        • The tool will DELETE itself once it finishes, if not delete it yourself.
        .
        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the CURRENT date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        -----

        How is everything now?hey ran otclean it but i dont think my problem is fixed beacuse my desktop backround is blue with box in the top left corner that has a red square green circle and blue triangle, when i go to reboot my normal backround pops up though what should i do?Try this. You might loose your current background but I think it needs to be reset as the virus changed the settings.

        Go to start > Control panel > Display > Desktop > Customize Desktop... >  Web tab
        Make sure Lock desktop items is unchecked.
        Select everything you find in there (except for "My current home page") and press the delete button on the right.
        Hit OK below > apply in previous window.

        ----------

        Now lets make sure everything is actually gone with a kaspersky scan.

        Run the Kaspersky Online Scanner

        In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

        • Click on SCAN NOW
        • Click Accept.
        • The program will then begin downloading the latest definition files.
        • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
        • The scan will TAKE a while, so be patient and let it finish.
        When the scan is done, in the Scan is complete window, any infection is displayed.
        There is no option to clean/disinfect, however, we need to analyze the information on the report.

        To obtain the report:
        Click on: Save Report As
        • Next, in the Save as prompt, Save in area, select: Desktop.
        • In the File name area use KScan, or something similar.
        • In Save as type: click the drop arrow and select: Text file [*.txt]
        • Then, click: Save


        Copy and paste the Kaspersky Online Scanner Report in your next reply.

        Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.Did the scan everything seems normal what do you think


        --------------------------------------------------------------------------------
        KASPERSKY ONLINE SCANNER 7 REPORT
         Thursday, August 28, 2008
         Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
         Kaspersky Online Scanner 7 version: 7.0.25.0
         Program database last update: Thursday, August 28, 2008 21:44:06
         Records in database: 1158226
        --------------------------------------------------------------------------------

        Scan settings:
           Scan using the following database: extended
           Scan archives: yes
           Scan mail databases: yes

        Scan area - My Computer:
           A:\
           C:\
           D:\
           E:\
           F:\
           G:\

        Scan statistics:
           Files scanned: 149241
           Threat name: 5
           Infected objects: 7
           Suspicious objects: 0
           Duration of the scan: 02:00:36


        File name / Threat name / Threats count
        C:\Documents and Settings\Family\Desktop\Mom\NetTools5.0.70.zip   Infected: not-a-virus:NetTool.MSIL.Sniffer.a   1
        C:\Documents and Settings\Family\My Documents\Chase\ca_setup.exe   Infected: not-a-virus:PSWTool.Win32.Cain.284   1
        C:\Program Files\Cain\Abel.exe   Infected: not-a-virus:PSWTool.Win32.Cain.284   1
        C:\Program Files\mIRC\mirc.exe   Infected: not-a-virus:Client-IRC.Win32.mIRC.631   1
        D:\Installs\WorkFlow\GUI\actwin2.exe   Infected: Trojan.Win32.Shutdowner.cq   1
        D:\Setup\SST\Data\VNC\MotVNC.exe   Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b   2

        The selected area was scanned.

        I now also want to buy some antivirus software can you suggest the best product. Thanks for all your help.Do you use Cain & Abel?

        There are plenty of free reliable solutions for antivirus.

        Remember to only install one antivirus!
         
        1) Avast! Home Free Edition
        2) AVG Free Edition
        3) Avira AntiVir Personal
        4) Comodo Antivirus
        5) PC Tools AntiVirus Free Edition

        Free firewalls

        1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
        2) Online Armor
        3) Sunbelt/Kerio
        4) Agnitum
        5) PC Tools Firewall Plus

        i used cain and able a while back probley should delete it now, thanks for all your help.Also are the free antivirus programs just as good as the ones you buyAs long as you know Cain & Abel is there, and what it's for...

        Yes the free ones are just as effective.

        Another question. Is this PC set up to be accessed Remotely?I do not think so i have router for my famliys laptops but thats it.and yes i no cain and able is used for hacking i used it for some other things not hacking or cracking passwords. Quote from: ChazMcJazz on August 28, 2008, 06:51:53 PM
        and yes i no cain and able is used for hacking i used it for some other things not hacking or cracking passwords.

        Just wanted to know it was being used by you and not against you.

        Create An Uninstall List
        • Start HijackThis
        • Click on the Open the Misc Tools section
        • Click on the Open Uninstall Manager button.
        • Click on the Save list button and specify where you would like to save this file and click Save.
          • When you press Save button a notepad will open with the contents of that file.
        • Copy and paste that list in your reply.
        1582.

        Solve : What anti-virus would you suggest?

        Answer»

        Quote from: moro on DECEMBER 17, 2010, 02:15:19 PM

        I'm with you
        But if you use the computer is not connected with the Internet. And get updates by another computer. I advise you to use  Avira AntiVir
        Personal - Free because you can get updates PERIODICALLY. And a short time interval. It also has a large database

        i get updates from avast nearly everyday and i think its good

        its a wonder this topic has'nt been locked or moved because of the of topic posts  Quote
        i get updates from avast nearly everyday and i think its good
        Thank you Mr.harry
        I was think that updates of avast need to be online only And I can not get them as updates independent ( like avg- kaspersky-avira )
        Quote
        its a wonder this topic has'nt been locked or moved because of the of topic posts 

        TRUE
        Quote from: moro on December 17, 2010, 03:05:54 PM

        I was think that updates of avast need to be online only And I can not get them as updates independent ( like avg- kaspersky-avira )

        How do you get updates if you are not online, am i missing something?Avast with Malaware bytes I love Kaspersky  it's BEST for me. Quote from: athelnstone on January 05, 2011, 08:49:19 AM
        Quick heal gives online protection.

        Half of the reviews i've read say otherwise -

        http://www.google.co.uk/search?client=firefox-a&rls=org.mozilla%3Aen-GB%3Aofficial&channel=s&hl=en&source=hp&q=Quick+heal&btnG=Google+Search#sclient=psy&hl=en&safe=off&client=firefox-a&hs=8iW&rls=org.mozilla:en-GB%3Aofficial&channel=s&q=Quick+heal+reviews&aq=0&aqi=g1&aql=&oq=Quick+heal+reviews&gs_rfai=&pbx=1&fp=de610b7113b09eab

        Out of 10 reviews on the first page, 4 people say its rubbish, i'm not saying it is, but i would not go for it!Don't be silly, reddevilggg, everybody knows that spam posts never PROMOTE spyware or malware infested products, and they always promote good, honest programs. 
        ...and from what i've seen..........a few times in the last 10 mins.
        1583.

        Solve : ThinkPoint??

        Answer»

        Quote

        Just to be sure, you recommend I keep SUPERAntiSpyware and Malwarebtyes Anti-Malware and run them frequently? Is this correct?
        Do I also keep Avast?

        Yes. Run them about once a week. You will see that SAS will pick up some tracking cookies, some good, some bad and MBAM will usually come up clean.
        You need to keep Avast because that is your Anti-Virus program. The others are to keep malware, spyware etc out.
        Quote
        "Your computer might be at risk
          AVG Firewall is turned off
          Click this balloon to fix this PROBLEM"

        Is this something I want to do? I though we GOT rid of AVG
        If you ran the AVG Removal Tool, it should be gone. You can try running it again. You should turn on your Windows firewall or download and install one of the free ones below.
        If it still gives you that error after you run the tool again, please do this:

        •Start HijackThis
        •Click on the Misc Tools button
        •Click on the OPEN Uninstall Manager button.
        •Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
        Copy and paste this file in your next reply.
        ***********************************************

        Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

        Remember only install ONE firewall

        1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
        2) Online Armor
        3) Agnitum Outpost
        4) PC Tools Firewall Plus

        If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
        1584.

        Solve : Rogue program: "Application cannot be executed."?

        Answer»

        That looks good. Let's do some cleanup.

        * Click START then RUN - Vista users press the Windows Key and the R keys TOGETHER for the Run box.
        * Now type commy /uninstall in the runbox
        * Make sure there's a space between commy and /Uninstall
        * Then hit Enter

        * The above procedure will:
        * Delete the following:
        * ComboFix and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, CLEAN Restore Point.

        If the above doesn't work, please do this: Please let me know which method you use.

        Delete the Combo-Fix.exe file, C:\Combo-Fix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combo-fix.txt and C:\Combo-Fix-quarantined-files.txt
        ***************************************************
        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
        ***********************************************
        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!
        Happy New Year, and I apologize for the long delay.

        I've removed combo-fix manually (i.e. not through the Run box), ALTHOUGH I was unable to delete QooBox folder.  I keep getting the message that "Cannot delete: BackEnv. Access is denied."  I've attempted deleting it in Safe Mode and after closing all applications.  I can't get rid of it.

        Also, is additional work needed since ESET found all those trojans?

        I've installed and configured all the software you suggested.
        Quote

        I've removed combo-fix manually (i.e. not through the Run box), although I was unable to delete QooBox folder.  I keep getting the message that "Cannot delete: BackEnv. Access is denied."  I've attempted deleting it in Safe Mode and after closing all applications.  I can't get rid of it.
        Ok Clean all the files out of that folder that you can and leave it or you can download and install Unlocker and try deleting it with that.

        To turn off Windows XP System Restore:

        NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
        5. Click Apply.
        6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        8. Restart the computer and FOLLOW the instructions in the next section to turn on System Restore.

        To turn on Windows XP System Restore:

        1. Click Start.
        2. Right-click My Computer, and then click Properties.
        3. Click the System Restore tab.
        4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
        5. Click Apply, and then click OK.
        This will give you a new, clean Restore Point.

        Quote
        Also, is additional work needed since ESET found all those trojans?
        No. ESET took CARE of all those infections. Excellent.  Thank you for volunteering your expertise.  I am extremely grateful for your guidance.  My computer is as good as new!I will lock this thread. If you need it opened for any reason, please pm me.
        1585.

        Solve : Freshly reburied Storm zombies burst up out of graves again?

        Answer»

        Security watchers have spotted a malware-seeded SPAM RUN that bears all   the HALLMARKS of a new GENERATION of the infamous STORM worm.

        http://www.theregister.co.uk/2011/01/04/storm_botnet_returns/

        1586.

        Solve : As soon as I boot Windows Explorer it crashes.?

        Answer»

        Thanks in advance.

        Tried the chat, I've done some quick troubleshooting on my own. Basically windows explorer wont work. As soon as I get up and running it crashes. What follows is the usual Win7 options and if I choose to reboot explorer it just crashes on boot. Its a swedish version of Win7 but Ill post the error notes and perhaps youll figure whats what:


        Problemsignatur:
          Problemhändelsens namn:   APPCRASH
          Programnamn:   Explorer.EXE
          Programversion:   6.1.7600.16450
          Programtidsstämpel:   4aeba271
          Namn på felmodul:   DivXMFSource.dll
          Modulens version:   1.0.0.65
          Tidsstämpel för felmodul:   4b7f002f
          Undantagskod:   c0000005
          Undantagsförskjutning:   0004c930
          OS-version:   6.1.7600.2.0.0.768.3
          Språkvariant-ID:   1053
          Ytterligare information 1:   0a9e
          Ytterligare information 2:   0a9e372d3b4ad19135b953a78882e789
          Ytterligare information 3:   0a9e
          Ytterligare information 4:   0a9e372d3b4ad19135b953a78882e789

        Läs vår sekretesspolicy online:
          http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x041d

        Om sekretesspolicyn online inte är tillgänglig kan du läsa vår sekretesspolicy offline:
          C:\Windows\system32\sv-SE\erofflps.txt


        ---
        I can think of two reasons as to why this is happening. I wasn't here at the time it started but my friend did mention the fact that he tried to start video CLIP which was a Matroska file and that DIVX had automatically been set for mkv files. As soon as he tried to play it explorer crashed.

        The first reason I can think of is that it is a bug as stated on wherever I found the information on google.

        The other reason is that there might have been a DivX update that I interrupted as I was in a rush or something like that...

        I cant launch anything cause I cant get to the cmd. The only way I know of is if I BOOTED it through safe-mode but then Id probably just get lost and end up doing something stupid. I honestly just want to get rid of DivX alltogether in hopes that it will solve the problem.

        I was sent here by one of the Chatters who was a user on the site. Who told me to come here in-case it might be virus or such.

        I've already tried booting the Control Panel through "Help" using the txt file link provided by the error note. The link is how I MANAGED to open up my internet browser.

        If anybody could just please point me in the right direction I'd be really grateful. uninstall DivX.or switch to something different. for example: google chrome, mozilla firefox... Quote from: petemosby on January 03, 2011, 12:30:12 PM

        or switch to something different. for example: google chrome, mozilla firefox...

        He wrote "Windows Explorer", not "Internet Explorer".
        my MISTAKE
        1587.

        Solve : McAfee Security Scans blocked by Comodo?

        Answer»

        I downloaded the latest Adobe reader.  I unchecked the (include McAfee) box. 

        Here is the Eset log:

        [email protected] as downloader log:
        all ok
        # version=7
        # OnlineScannerApp.exe=1.0.0.1
        # OnlineScanner.ocx=1.0.0.6419
        # api_version=3.0.2
        # EOSSerial=17e1e7d750000e45a6e1160e9aef7e3e
        # end=finished
        # remove_checked=true
        # archives_checked=true
        # unwanted_checked=true
        # unsafe_checked=false
        # antistealth_checked=true
        # utc_time=2010-12-31 10:54:49
        # local_time=2010-12-31 04:54:49 (-0600, Central Standard Time)
        # country="United States"
        # lang=1033
        # osver=5.1.2600 NT Service Pack 3
        # compatibility_mode=512 16777215 100 0 33274637 33274637 0 0
        # compatibility_mode=768 16777215 100 0 12701577 12701577 0 0
        # compatibility_mode=1024 16777215 100 0 5290176 5290176 0 0
        # compatibility_mode=3073 16777173 80 75 0 0 0 0
        # compatibility_mode=8192 67108863 100 0 0 0 0 0
        # scanned=43626
        # found=0
        # cleaned=0
        # scan_time=2054

        ThanksThat looks good. Were you able to install a new AV? If there are no other issues, it's time for some cleanup.

        Delete the Combo-Fix.exe file, C:\Combo-Fix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combo-fix.txt and C:\Combo-Fix-quarantined-files.txt

        You may have a problem deleting one of the folders (nircma.exe) In that case, delete all the files in the folder that you can and leave it.

        To turn off Windows XP System Restore:

        NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK.

        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore" or "Turn off System Restore on all drives"
        5. Click Apply.
        6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        8. Restart the computer and follow the instructions in the next section to turn on System Restore.

        To turn on Windows XP System Restore:

        1. Click Start.
        2. Right-click My Computer, and then click Properties.
        3. Click the System Restore tab.
        4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
        5. Click Apply, and then click OK.
        ********************************************
        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
        *********************************************
        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to PROTECT your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!
        Quote

        That looks good. Were you able to install a new AV?

        Yes.  I installed Comodo Antivirus.  I lost my firewall, but found out I could reinstall the firewall fairly easy.  I reinstalled the firewall and all seems to be working fine. 

        Quote
        Delete the Combo-Fix.exe file, C:\Combo-Fix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combo-fix.txt and C:\Combo-Fix-quarantined-files.txt

        I couldn't find any C:\Combo "anything" folders.
        I could't find  C:\WINDOWS\nircmd.exe

        I did delete any combo fix files, like logs, that I could find.  Also,  C:\QooBox had a Folder called BackEvn that SAID access denied when I tried to delete it.  It SAYS make sure the disk is not full or write protected or to make sure the file is not in use.

        No problems with the restore step and the TFC steps.

        Quote
        Use the Secunia Software Inspector to check for out of date software.

        It asked me to update internet exporere, which I don't use.  But just in case I might need to use it or another user would like to use it, I wanted to update it.  Secunia gave me a link to Windows update and about 20 or so links showing me which updates I'm missing.  But, when I ran the Windows Update from the Microsoft site, it said I wasn't missing any updates.  What am I missing here, I must be missing something very obvious.



        Thanks
        Quote
        did delete any combo fix files, like logs, that I could find.  Also,  C:\QooBox had a Folder called BackEvn that said access denied when I tried to delete it.  It says make sure the disk is not full or write protected or to make sure the file is not in use.
        Yes. That folder can't be deleted. Just clean out all the files that you can in the folder and leave it there.
        Quote
        What am I missing here, I must be missing something very obvious.
        You're running IE 6. You should download IE 8
        1588.

        Solve : infected and cannot run any programs?

        Answer»

        please help.
         
        I have Trend Micro Titanium antivirus but the program will not run. There is a continuous security warning that says "The application cannot be executed. The file uiSeAgnt.exe is INFECTED. Please activate you antivirus software.." Internet Explorer is the only program I can get to run. Any other attempts to run programs prompts a warning that says "WINDOWS cannot ACCESS the specefied device, path, or file. You may not have the appropriate permissions to access the ITEM."

        Any help is greatly appreciated.Do not double POST. I provided a link for you in your other thread. I'm locking this one.

        1589.

        Solve : Anti Keylogger software?

        Answer»

        Can you recommend a good anti keylogger program?  My WOW account and email were hacked and now im having security problems with other things.Besides virus scans and CHANGING passwords, you need to think about identity THEFT. It is becoming more common and is a nightmare.
        See if there is a local agency in you JURISDICTION that can give you some tips.
        Try a Google search on identity theft but avoid the commercial firms, look for government or non-profit groups.
        In the USA the FEDERAL Trade COMMISSION has a web site.
        http://www.ftc.gov/bcp/edu/microsites/idtheft/

        BTW, this area is used for help with infections. If that does NOT apply to you, this post will be moved to another area.

        1590.

        Solve : Incredimail problem?

        Answer»

        Quote

        Opened up in safe mode and problem with icons and dots on screen not there. Re-appeared when I opened in normal mode. Is this a clue?
        Yes. Something that's causing this is only running in Normal Mode.

        Quote
        Re-ran ComboFix and saved log. (You do not want it so why did I run the scan?)
        I didn't want you to re run ComboFix. I wanted you to run the script to fix some problems in the ComboFix log. Please follow the instructions in Reply # 13.
        Also, can you do a screen print of your desktop and include it in your next reply?
        How to post screenshots or images

        Quote
        Is the problem really a virus or is some software corrupted as a consequence of having and removing the virus?
        I sounds more like an infection because it doesn't run in Safe Mode.

        I'd like to scan your machine with ESET OnlineScan

        •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
        ESET OnlineScan
        •Click the button.
        •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
        • Click on to download the ESET Smart Installer. Save it to your desktop.
        • Double click on the icon on your desktop.
        •Check
        •Click the button.
        •Accept any security warnings from your browser.
        •Check
        •Push the Start button.
        •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
        •When the scan completes, push
        •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
        •Push the button.
        •Push
        A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Had run ComboFix with script fix just confused why you did not want log.

        Ran ESET and no threats found, Here is log

        [email protected] as CAB hook log:
        OnlineScanner.ocx - registred OK
        # version=7
        # iexplore.exe=7.00.6000.17093 (vista_gdr.101017-1200)
        # OnlineScanner.ocx=1.0.0.6419
        # api_version=3.0.2
        # EOSSerial=8cf6e57be4777547bce09df9449d7ee5
        # end=finished
        # remove_checked=false
        # archives_checked=true
        # unwanted_checked=true
        # unsafe_checked=false
        # antistealth_checked=true
        # utc_time=2010-12-23 07:00:11
        # local_time=2010-12-23 01:00:11 (-0600, Central Standard Time)
        # country="United States"
        # lang=1033
        # osver=5.1.2600 NT Service Pack 3
        # compatibility_mode=512 16777215 100 0 43919 43919 0 0
        # compatibility_mode=2304 16777215 100 0 0 0 0 0
        # compatibility_mode=5121 16777189 100 75 0 22232430 0 0
        # compatibility_mode=8192 67108863 100 0 0 0 0 0
        # scanned=99715
        # found=0
        # cleaned=0
        # scan_time=5704

        Also noted that when I ran video on Microsoft Media it had rectangular block blocks (0.25 inches tall 0.05 inches wide) on a regular pattern over screen. Different interference than the desk top. Also on Skype






        Hope I have done screen print correctly.

        Thank you.
        Quote
        Had run ComboFix with script fix just confused why you did not want log.
        It was just some minor housecleaning. Could you please run the ComboFix scan again the post the log. I think I may have MISSED something.

        From the looks of the screenshots, I think there's something wrong with your monitor or the Video card drivers. Is there any chance of hooking up a different monitor to that computer?Unfortunately Dave I can't get another monitor.

        Which dirvers should I uninstall and install - and how do I know what the drivers are?Last minute Christmas shopping to do, will run ComboFix when I come back.

        Annie
        OK here it is Dave, latest scan...



        ComboFix 10-12-23.02 - 12/23/2010  17:10:26.6.2 - x86
        Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.646 [GMT -6:00]
        Running from: c:\documents and settings\Desktop\Commy.exe
        AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
        FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
        .

        (((((((((((((((((((((((((   Files Created from 2010-11-23 to 2010-12-23  )))))))))))))))))))))))))))))))
        .

        2010-12-23 22:36 . 2010-12-23 22:52   --------   dc----w-   C:\commy
        2010-12-22 04:38 . 2010-12-22 04:38   --------   dc----w-   c:\documents and settings\All Users\Application Data\Driver Whiz
        2010-12-22 04:31 . 2010-12-22 04:31   0   -c--a-w-   c:\windows\system32\ConduitEngine.tmp
        2010-12-22 04:28 . 2010-12-22 04:30   --------   dc----w-   c:\documents and settings\Local Settings\Application Data\Conduit
        2010-12-22 04:28 . 2010-12-22 04:28   --------   dc----w-   c:\program files\Conduit
        2010-12-22 04:28 . 2010-12-22 04:31   --------   dc----w-   c:\documents and settings\Local Settings\Application Data\IncrediMail_MediaBar_2
        2010-12-22 04:28 . 2010-12-22 04:28   --------   dc----w-   c:\documents and settings\All Users\Application Data\Photo Notifier and Animation Creator
        2010-12-22 04:28 . 2010-12-22 04:28   --------   dc----w-   c:\program files\Photo Notifier and Animation Creator
        2010-12-22 04:25 . 2010-12-22 04:25   --------   dc----w-   c:\program files\IncrediMail
        2010-12-21 03:12 . 2010-12-21 03:12   --------   dc----w-   c:\program files\CCleaner
        2010-12-21 02:54 . 2010-12-21 02:54   73728   -c--a-w-   c:\windows\system32\javacpl.cpl
        2010-12-21 02:54 . 2010-12-21 02:54   --------   dc----w-   c:\program files\Java
        2010-12-12 02:13 . 2010-12-12 02:13   --------   dc----w-   c:\program files\Trend Micro
        2010-12-10 04:17 . 2010-12-10 20:04   --------   dc----w-   c:\program files\Common Files\PC Tools
        2010-12-10 02:39 . 2010-12-10 02:39   --------   dc----w-   c:\documents and settings\Application Data\SUPERAntiSpyware.com
        2010-12-10 02:39 . 2010-12-10 02:39   --------   dc----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
        2010-12-08 03:41 . 2010-12-08 03:41   --------   dc----w-   c:\documents and settings\Application Data\Malwarebytes
        2010-12-08 03:41 . 2010-12-08 03:41   --------   dc----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
        2010-12-08 02:46 . 2010-12-21 02:54   472808   -c--a-w-   c:\windows\system32\deployJava1.dll

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2010-11-18 18:12 . 2003-08-14 03:06   81920   -c--a-w-   c:\windows\system32\isign32.dll
        2010-11-06 00:34 . 2004-02-06 23:05   832512   -c--a-w-   c:\windows\system32\wininet.dll
        2010-11-06 00:34 . 2004-08-04 07:56   78336   -c--a-w-   c:\windows\system32\ieencode.dll
        2010-11-06 00:34 . 2003-08-14 02:58   1830912   -c--a-w-   c:\windows\system32\inetcpl.cpl
        2010-11-06 00:34 . 2003-08-14 02:57   17408   -c--a-w-   c:\windows\system32\corpol.dll
        2010-11-03 12:25 . 2004-08-04 05:59   389120   -c--a-w-   c:\windows\system32\html.iec
        2010-11-02 15:17 . 2003-08-14 02:58   40960   -c--a-w-   c:\windows\system32\drivers\ndproxy.sys
        2010-10-28 13:13 . 2003-08-14 02:57   290048   -c--a-w-   c:\windows\system32\atmfd.dll
        2010-10-26 13:25 . 2003-08-14 02:58   1853312   -c--a-w-   c:\windows\system32\win32k.sys
        2010-10-19 20:51 . 2009-10-03 18:59   222080   -c----w-   c:\windows\system32\MpSigStub.exe
        2010-10-14 03:28 . 2010-03-13 21:24   9344   -c--a-w-   c:\windows\system32\drivers\mfeclnk.sys
        2010-10-14 03:28 . 2010-03-13 21:24   88544   -c--a-w-   c:\windows\system32\drivers\mfendisk.sys
        2010-10-14 03:28 . 2010-03-13 21:24   84264   -c--a-w-   c:\windows\system32\drivers\mferkdet.sys
        2010-10-14 03:28 . 2010-03-13 21:24   84072   -c--a-w-   c:\windows\system32\drivers\mfetdi2k.sys
        2010-10-14 03:28 . 2010-03-13 21:24   55840   -c--a-w-   c:\windows\system32\drivers\cfwids.sys
        2010-10-14 03:28 . 2010-03-13 21:24   52104   -c--a-w-   c:\windows\system32\drivers\mfebopk.sys
        2010-10-14 03:28 . 2010-03-13 21:24   313288   -c--a-w-   c:\windows\system32\drivers\mfefirek.sys
        2010-10-14 03:28 . 2010-03-13 21:24   152960   -c--a-w-   c:\windows\system32\drivers\mfeavfk.sys
        2010-10-14 03:28 . 2010-01-06 00:04   95600   -c--a-w-   c:\windows\system32\drivers\mfeapfk.sys
        2010-10-14 03:28 . 2010-01-06 00:04   386840   -c--a-w-   c:\windows\system32\drivers\mfehidk.sys
        2007-08-02 18:41 . 2007-08-02 18:41   774144   -c--a-w-   c:\program files\RngInterstitial.dll
        2001-11-30 16:09 . 2004-05-26 00:45   49152   -c--a-r-   c:\program files\Common Files\HDvAvi.dll
        .

        (((((((((((((((((((((((((((((   SnapShot_2010-12-23_22.49.33   )))))))))))))))))))))))))))))))))))))))))
        .
        + 2010-12-23 23:02 . 2010-12-23 23:02   16384              c:\windows\temp\Perflib_Perfdata_858.dat
        + 2010-12-23 23:02 . 2010-12-23 23:02   16384              c:\windows\temp\Perflib_Perfdata_230.dat
        .
        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
        "{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbInc0.dll" [2010-10-18 3908192]

        [HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
        2010-10-18 10:26   3908192   -c--a-w-   c:\program files\ConduitEngine\ConduitEngin0.dll

        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]
        2010-10-18 10:26   3908192   -c--a-w-   c:\program files\IncrediMail_MediaBar_2\tbInc0.dll

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        "{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"= "c:\program files\IncrediMail_MediaBar_2\tbInc0.dll" [2010-10-18 3908192]
        "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-10-18 3908192]

        [HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

        [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
        "{D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0}"= "c:\program files\IncrediMail_MediaBar_2\tbInc0.dll" [2010-10-18 3908192]
        "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-10-18 3908192]

        [HKEY_CLASSES_ROOT\clsid\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}]

        [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-01 68856]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
        "PrinTray"="c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-08-16 36864]
        "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
        "IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
        "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
        "CTHelper"="CTHELPER.EXE" [2003-07-03 28672]
        "AGRSMMSG"="AGRSMMSG.exe" [2003-05-23 88363]
        "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 69632]
        "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-05-22 282624]
        "VAIO RECOVERY"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
        "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
        "ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672]
        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-06 335872]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
        "SetDefaultMidi"="MIDIDEF.EXE" [2003-07-03 49152]

        c:\documents and settings\Start Menu\Programs\Startup\
        Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-16 111376]
        wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2002-6-20 24651]

        c:\documents and settings\All Users\Start Menu\Programs\Startup\
        Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
        Billminder.lnk - c:\program files\Quicken\billmind.exe [2002-9-20 36864]
        CARD Monitor.lnk - c:\program files\Panasonic\Palmcorder\CARD LINK (for USB)\regcnt09.exe [2004-5-24 49152]
        Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-15 809488]
        Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2002-9-20 53248]
        Quicken Startup.lnk - c:\program files\Quicken\QWDLLS.EXE [2002-9-20 36864]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
        2008-11-07 22:41   72208   -c--a-w-   c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
        =""

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
        =""

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
        =""

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
        "c:\\Program Files\\Abacast\\Abaclient.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
        "c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
        "c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
        "c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
        "c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
        "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "8097:TCP"= 8097:TCP:*:Disabled:EarthLink UHP Modem Support

        R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [3/13/2010 3:24 PM 84072]
        R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [1/15/2009 9:27 PM 10384]
        R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [3/13/2010 3:24 PM 271480]
        R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [3/13/2010 3:24 PM 271480]
        R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [3/13/2010 3:24 PM 271480]
        R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [3/13/2010 3:24 PM 188136]
        R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\Mcafee\SystemCore\mfevtps.exe [3/13/2010 3:24 PM 141792]
        R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [3/13/2010 3:24 PM 55840]
        R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [3/13/2010 3:24 PM 313288]
        R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [3/13/2010 3:24 PM 88544]
        S2 gupdate1ca8311c753ab74;Google Update Service (gupdate1ca8311c753ab74);c:\program files\Google\Update\GoogleUpdate.exe [12/22/2009 8:19 AM 133104]
        S2 mrtRate;mrtRate;

        S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [3/13/2010 3:24 PM 88544]
        S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [3/13/2010 3:24 PM 84264]
        S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [12/20/2009 3:58 PM 91830]

        --- Other Services/Drivers In Memory ---

        *Deregistered* - mfeavfk01

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        getPlusHelper   REG_MULTI_SZ      getPlusHelper
        .
        Contents of the 'Scheduled Tasks' folder

        2010-11-05 c:\windows\Tasks\disketchShakeIcon.job
        - c:\program files\NCH Software\Disketch\disketch.exe [2010-11-01 15:04]

        2010-12-23 c:\windows\Tasks\Google Software Updater.job
        - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-26 20:45]

        2010-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-22 14:18]

        2010-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-22 14:18]

        2010-12-23 c:\windows\Tasks\vtscheduletask.job
        - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2010-11-18 20:25]
        .
        .
        ------- Supplementary Scan -------
        .
        uStart PAGE = hxxp://www.google.com/
        mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
        uInternet Settings,ProxyServer = http=localhost:8080
        uInternet Settings,ProxyOverride =
        uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
        IE: &ieSpell Options - d:\iespell\iespell.dll/SPELLOPTION.HTM
        IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
        IE: Check &Spelling - d:\iespell\iespell.dll/SPELLCHECK.HTM
        IE: Lookup on Merriam Webster - file://d:\iespell\Merriam Webster.HTM
        IE: Lookup on Wikipedia - file://d:\iespell\wikipedia.HTM
        Trusted Zone: internet
        Trusted Zone: mcafee.com
        DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
        DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
        DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://download.ewido.net/ewidoOnlineScan.cab
        DPF: {A305FBA3-4A87-483D-A53B-138F9F635357} - hxxp://ciscdb.sel.sony.com/support/pops/mdldetect/PCInfo.CAB
        .

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2010-12-23 17:18
        Windows 5.1.2600 Service Pack 3 NTFS

        scanning hidden processes ... 

        scanning hidden autostart entries ...

        scanning hidden files ... 

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
        Denied: (A 2) (Everyone)
        ="FlashBroker"
        "LocalizedString"="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
        "Enabled"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
        ="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
        Denied: (A 2) (Everyone)
        ="IFlashBroker4"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
        ="{00020424-0000-0000-C000-000000000046}"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
        ="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
        "Version"="1.0"
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------

        - - - - - - - > 'winlogon.exe'(1112)
        c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
        c:\program files\common files\logishrd\bluetooth\LBTServ.dll

        - - - - - - - > 'explorer.exe'(172)
        c:\windows\system32\WININET.dll
        c:\program files\Logitech\SetPoint\lgscroll.dll
        c:\progra~1\WINDOW~2\wmpband.dll
        c:\windows\system32\ieframe.dll
        c:\windows\system32\WPDShServiceObj.dll
        c:\windows\system32\PortableDeviceTypes.dll
        c:\windows\system32\PortableDeviceApi.dll
        .
        Completion time: 2010-12-23  17:22:16
        ComboFix-quarantined-files.txt  2010-12-23 23:22
        ComboFix2.txt  2010-12-23 22:52
        ComboFix3.txt  2010-12-22 03:39
        ComboFix4.txt  2010-12-21 03:48

        Pre-Run: 1,650,237,440 bytes free
        Post-Run: 1,666,478,080 bytes free

        - - End Of File - - 24148E580DDE69CDADC0B41F011F8396
        You should visit the site of the maker of your computer and look for Video card drivers. Uninstall the old driver and install the new one.

        Re-running ComboFix to remove infections:

        • Close any open browsers.
        • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
        • Open notepad and copy/paste the text in the quotebox below into it:
          Quote
          KillAll::

          DDS::
          uInternet Settings,ProxyServer = http=localhost:8080
          Trusted Zone: internet
          Trusted Zone: mcafee.com

        • Save this as CFScript.txt, in the same location as ComboFix.exe



        • Referring to the picture above, drag CFScript into ComboFix.exe
        • When finished, it shall produce a log for you at C:\ComboFix.txt
        • Please post the contents of the log in your next reply.
        Went to Add or Remove Programs to uninstall the video (graphics) driver.

        Removed ATI Display Driver file containing Radeon 9800. Did not remove ATI Control Panel.

        Restarted  computer as part of uninstall process. Dots still on startup images (e.g. MicroSoft Windows) but  when booted up lines on screen ------ and icons  llllll  no longer there. Whooppee!

        Down loaded video driver from Sony Website, Radeon 9800.

        Restarted computer as required. Dots still on startup images (e.g. MicroSoft Windows) and lines on screen and icons,  had returned.

        Did not run ComboFix in case this latest experience prompts new ideas. Should I have also removed ATI Control Panel? If I do, do I need to re-install it and if so how?When you removed the video card driver I suspect that the video card was running on the generic driver just as it did in Safe Mode. It looks like the problem is with the drivers and I really can't help you much with that. I think you should run the ComboFix script, we'll do some CLEANUP and you can get help for the driver problem in another one of forums dealing with such problems. You should start a new thread right now even while we're cleaning up here. I'm sorry we couldn't get this fixed before Christmas.
        1591.

        Solve : Several Different Problems?

        Answer»

        Quote

        When I start my computer up there's a MESSAGE that says "Please select operating system to start" along with other
        That's probably the Recovery Console that was installed when you installed ComboFix. This could be very useful if Windows has problems starting.
        Quote
        The "ASP.NET Machine" is still listed under user accounts as well
        You may have to go to another forum for help with this after we are finished with cleaning.

        Quote
        Also, Malwarebytes still can't finish running and will crash during its scan whenever I try to run it. Please post the log, if SUCCESSFUL.
        Please try running it in SAFE MODE.

        Quote
        I have been able to open my older Adobe Photoshop 7.0, but my tablet still isn't working. I downloaded the driver for it yet again and it seemed fine. I closed Photoshop and opened it again a few times and at first I have pen pressure, but when I restarted the tablet didn't WORK again.
        Again, you may have to search for help with this on another forum. It doesn't sound like an infection has caused this.
        1592.

        Solve : Trojan:DOS/Alureon.A?

        Answer»

        Quote from: SUPERDAVE on December 13, 2010, 04:50:23 PM

        A master boot record (MBR), or partition sector, is the 512-byte boot sector that is the first sector ("LBA/absolute sector 0") of a partitioned data storage device such as a hard disk. Did you just do a re-install without a reformat?

        okay i have two hard drive one IDE 250g and one SATA250g.

        before i installed my new motherboard i had my windows installation on the SATA drive and the IDE drive used to be the backup drive

        now that i upgraded to the EVGA nForce 780I motherboard i had to REINSTALL the os so i installed it on the IDE hard drive and the old windows installation is still on the SATA drive.


        Do you recommend me use the SATA or IDE hard drive? which one performs faster? and ill format it too. Quote
        Do you recommend me use the SATA or IDE hard drive? which one performs faster? and ill format it too.
         
        SATA would be your best bet for your main drive. If you do a full format, you should get rid of the MBR infection. Quote from: SuperDave on December 14, 2010, 12:29:30 PM
        SATA would be your best bet for your main drive. If you do a full format, you should get rid of the MBR infection.

        I found i solution to this. Eventhough i had formated both drives and reinstalled Windows 7 64bit everything was running just fine.. But after a week it came back and i could not remove it. So i did some searches and found out that Kasperky's TDSSKiller was the tool that remove these types of viruses. It removed it in les that 5 minutes.

        Thanks for the help though.
        1593.

        Solve : Google redirects virus, explorer.exe, winlogon.exe infected??

        Answer»

        A couple of questions, if you please. Is your disk DRIVE the E: drive? If it is not, you will have to put the correct letter in the command. On my computer with two disk drives, they are D and H. Are you SURE that you typed the command exactly as I wrote it? Even a missed space would MESS it up.Hey Dave, interesting little UPDATE but I rebooted today when I GOT home from school and explorer.exe was back and running; taskbar and all but so was the google redirect. -head scratch-

        My disk drive is E so putting in exactly what you told me should've worked yeah?Could you please run ComboFix again and post the log?

        1594.

        Solve : Do you really need anti virus??

        Answer»

        Hey,

        I was using AVG anti virus software stuff but it was lagging my games heaps when it did the computer scans or whatever. I was also getting popups from it when I inserted my friend's USBS and stuff, finding viruses or threats and I'd move them to the vault. I got rid of it so it would stop messing with gameplay and annoying me with USB virus crap but dad had a freak and WANTS me to install it again.
        Do you really need anti virus software?
        If so, can you make it so it doesn't scan for viruses or something? so it doesn't stuff with games and annoy me with windows.

        Thanks for any help in advance

        Mike.a good AV is indeed needed , avg will take up a lot of room and i found it slowed the pc as well , download avast free its good , let it RUN it will cause you no bother

        http://www.avast.com/en-gb/free-antivirus-downloadYES you need a good anti virus utility installed and always active. If it's your dad's computer you should not be messing with installed apps in the first place. If it's yours, feel free to do what you want - and be prepared for the consequences. Quote from: Mike55 on December 14, 2010, 04:35:46 AM

        If so, can you make it so it doesn't scan for viruses or something?

        that would sort of defeat the purpose...

        And if it is finding viruses/showing alerts then it's doing it's job; apparently there is some shifty stuff on your friends USB drive.
        My college computer put an Autorun onto my USB drive, this is always flagged as a virus when i plug it in at home.

        Try TAKING the autorun off the usb.Alright, thanks for your help guys, I'll get avast in a tick.
        It's a family computer too, and I'll get my friend to check for any autorun stuff.

        MikeAnti-Virus software is very IMPORTANT, ESPECIALLY if you are running a Microsoft Windows Operating System. AVG has unfortunately become very bulky, similar to many paid, but not all, anti-virus software. If you are looking for a free anti-virus program that does not tax your system resources Avast! Anti-Virus is good. Another alternative is Microsoft Security Essentials (lightweight but not as good as Avast! in my opinion). I also recommend installing Malwarebytes Anti-Malware for basic computer scans.
        1595.

        Solve : Possible virus continued...my thread was locked???

        Answer»

        I am not SURE why I was UNABLE to respond or continue my thread? Why WOULD it be locked in the middle of me trying to get HELP with something?
        To answer the last question, yes, I can find another XP disc. Is there anything else I can do in the meantime?I'm guessing it was locked by accident - not sure how - it doesn't appear SUPERDAVE did it and I can't imagine anyone else on staff locking it.... Anyway, I just unlocked it. Once I see you've responded in the original thread I'll delete this one.

        1596.

        Solve : Browser HiJacked; Here are my 3 logs...PLEASE HELP?

        Answer»

        Hi SuperDave,
        I think I am going to leave well enough alone.  The computer has been running quite well, Kapersky full scan was successful, I installed Adobe successfully. So I think yo have helped me quite a bit and I should not mess with it any more seeing that it is running well.  If I have any additional problems I will proceed with the Safe Mode option.
        Thank you so much for your help.  You are amazing!
        Ok. Let's do some cleanup.

        * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
        * Now type commy /uninstall in the runbox
        * Make sure there's a space between commy and /Uninstall
        * Then hit Enter

        * The above procedure will:
        * Delete the following:
        * COMBOFIX and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, clean Restore Point.
        ***********************************
        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is FINISHED.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
        *******************************************
        Looking over your log it seems you don't have any evidence of a second-party FIREWALL.

        Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

        Remember only install ONE firewall

        1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
        2) Online Armor
        3) Agnitum Outpost
        4) PC Tools Firewall Plus

        If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
        *********************************************
        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ACTIVEX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!

        Oh. This is great.  I am working on it now. I have a question.  I dowmloaded AVG Antivirus (switched out Kapersky) .  Does that have a firewall too or i sthat separate.  Sorry for the novice question!No. The free version is basic AV and spyware protection only. I like Comodo. It gets in the way at first but then later, you will hardly notice it.

        1597.

        Solve : which antivirus?

        Answer»

        my earlier antivirus always blocked a PROGRAM - svchost.exe
         should i allow it ? which KIND of file it is i mean what does it do? is it a virus?

        right now i don`t have any bought antivirus,  and as per the instructions i`ve installed these 4 -
                   Ms windows security essential
                   super antispyware
                   malwarebytes antimalware &
                    hijack this UTILITY

                               but among thiem when i tried to RUN malwarebytes antimalware , it showed run time error 0 & then run time error 440
          rest are in working condition and updated. Am i safe now while using internet and without using?
        http://www.howtogeek.com/howto/windows-vista/what-is-svchostexe-and-why-is-it-running/

                hey you didn`t answer about my antivirus problem   
         is it enough to USE these four-       
                    Ms windows security essential
                   super antispyware
                   malwarebytes antimalware &
                    hijack this utility

                           to ensure safetysure

        1598.

        Solve : Rundll32.xe problem. Definetly a virus?

        Answer»

        Hello, this is my first post and have read most of the things needed to aquire assistance, but it seems i have a bit of a problem. I did not install an anti-VIRUS program and my norton recently expired.                                                                                                                                                                                     

        The problem iam having RIGHT now is with Rundll32.xe. Everything i try to do anything there is a message about a module not in place, and that everything that i click, to open, says its infected. i cant open any web browsers, and the only time it does let me go ONLINE is for buying their "anti-virus" protection. ive read on some other forums about looking at my registry, but i cant even go in that.

        what are my options and how should i deal with this?? this is extremely frustrating and i use my computer all the time. Virus's love me and i also have a Winhdd problem but ill ask for HELP on that after.

        ive logged onto safemode +networking to solve the issue from other posts, but i know iam not very familiar with any commands or things that need to be done to change.

        i can certainly follow instructions on getting to the point, but would like somewhat of a step-by-step process.

        Thanks ALOT for the helpDouble post. I will lock this one and respond to the other thread by the same name.

        1599.

        Solve : Which security programs to put on laptop??

        Answer»

        My daughter bought a laptop and is running NORTON antivirus. I added CCcleaner and Malwarebytes Antimalware. I was GOING to add Spyware doctor but it came with an antivirus and didn't want to RUN 2. What other program (if any) should I install for her to run to make sure her system stays clean and safe? 1) Spyware Doctor is not an anti virus
        2) Norton AV + MalwareBytes + SpywareBlaster + Smart COMPUTING is more than enough
        3) Ccleaner is not a security program
        4) Of everything mentioned, nothing is more important than SMART COMPUTING

        1600.

        Solve : Ransomware Trojan is back and badder than ever....?

        Answer»

        A RANSOMWARE Trojan threat is back – in an even more noxious form – two years after it last appeared.
        A NEW VARIANT of the GpCode ransomware encrypts user files on   infected Windows PCs using theAES 256 and RSA 1024 encryption   algorithms. The malware only encrypts the start of MEDIA or Office   files, but that's enough to make any data RECOVERY process difficult if   not impossible.
        Full story here: http://www.theregister.co.uk/2010/11/30/ransomware_trojan_returns/ Quote from: Allan on November 30, 2010, 10:05:18 AM

        The malware only encrypts the start of media or Office   files, but that's enough to make any data recovery process difficult if   not impossible.

        I wonder why it restricts itself?superb self control