Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2851.

Solve : Fake Antivirus Virus Help Please Thanks =D?

Answer»

Ok so i got hijackthis and superantispyware logs

Thanks

by the way is the Antivirus XP 2008 virus

[recovering disk space -- attachment deleted by admin]You need to run Malwarebytes, post its log, and then, fresh HJT log.ok Malwarebyte log and fresh HJT log



[recovering disk space -- attachment deleted by admin]You're running Sympatico Security Advisor, which I BELIEVE comes from Bell, includes antivirus, and a firewall, and I see some Norton leftovers.
What's the story behind this?what do u mean by that

my mom clicked on a fake antivirus wich is named XP antivirus 2008
i believe i got it REMOVED
but i just wana double checkLet me rephrase....Is Sympatico Security Advisor your current antivirus, and firewall?yesVery well. Let me proceed with your logs.
Download, and run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
Post new HJT log.ok

[recovering disk space -- attachment deleted by admin]*** You need to update Java:
http://java.sun.com/javase/downloads/index.jsp
Java Runtime Environment (JRE) 6 Update 7
Uninstall all previous versions of Java through Add\Remove.

*** Download, and run CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is also an option to restore the original one.
Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

*** Disable TeaTimer, as it'll INTERFERE with the cleaning process:
Right click Spybot's TeaTimer System Tray Icon.
Click Exit Spybot-S&D Resident.
TeaTimer closes.

*** Disable Windows Defender, as it'll interfere with cleaning process:
* Open Windows Defender
* Click Tools
* Click General SETTINGS
* Scroll down to Real Time Protection Options
* Uncheck Turn on Real Time Protection
* After you uncheck this, click on the Save button
* Close Windows Defender

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark NEXT to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

- O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
- *O4 - HKLM\..\Run: [HPHUPD08] "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
- *O4 - HKLM\..\Run: [DISCover] "C:\Program Files\DISC\DISCover.exe"
- *O4 - HKLM\..\Run: [DiscUpdateManager] "C:\Program Files\DISC\DiscUpdateMgr.exe"
- *O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
- *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
- O4 - HKLM\..\Run: [SMrhc5v5j0e14r] C:\Program Files\rhc5v5j0e14r\rhc5v5j0e14r.exe
- *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- *O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
- *O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
- O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


4. Click on Fix checked button.

5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

7. Delete following files/folders (if present):

- rhc5v5j0e14r folder from C:\Program Files

8. Restart in Normal Mode.

9. Post new HijackThis log.



[recovering disk space -- attachment deleted by admin]Your computer is clean

1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
Run CCleaner.

2. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

3. Restart computer.

4. Turn System Restore on.

5. Download, and install McAfee SiteAdvisor: http://www.siteadvisor.com/download/ff.html. It'll warn you (in most cases) about dangerous web sites.

6. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

7. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

8. Let me know, how your computer is doing.

Is this the annoying popup with the red circle and the X saying windows has detected spyware infection? If so this is what i have and will follow the list above if someone can review the logs - JTJtquad it is not advised to use someone elses thread for reference.

Start here and post the logs in your own thread when complete, not this one.

2852.

Solve : Re: Fake Antivirus Virus Help - Jtquad?

Answer»

No problem, except i can get a super anti spyware log it wont let the program run - JTI moved this into a new THREAD so we can work from here.

Can you get MBAM to run? If not then just post the HijackThis log.I can not get Superanti spyware or hi jack this to run - JT
P.S. Can you delete the other thread i just posted thanksDo you get any errors when you try to run them? If so what are the errors.

Try this.

Download Deckard's System Scanner (DSS) to your Desktop.
Note: You must be logged onto an account with administrator privileges.
Vista users RIGHT click DSS and Run as Administrator.

  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open.
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply.
when i click dss.exe nothing opens. I click it then hit run and nothing it just goes back to the desktop - JTCan you restart the PC into Safe Mode to run this next tool?

Download SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Now then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup PROCESS.
  • It will REMOVE any Trojan Services and Registry Entries that it FINDS then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally copy and paste the contents of the results file Report.txt with a NEW HijackThis log in your next reply.
If SDFix won't run or you get errors, follow the link for instructions on running SDFix How to use SDFix
2853.

Solve : what is svchost.exe??

Answer»

Also, running time for AVG, Superantispyware, and Malwarebytes can easily exceed 1 hour. Nothing strange here.Well, I'll be dipped in chocolate and painted green....THAT downloaded!

Thank you.

Could I trouble you to explain about System Restore?

grazie Not at all...
Go Start>Run, copy, and paste this:
%systemroot%\system32\restore\rstrui.exe
I'll bring you right into System Restore window.
Select some date from the past, and run System Restore.Well, as this continues to be a challenge that is getting RATHER tiresome, did copy and paste, pulled up the system restore window...and then it said that there was no dates available to choose from.

This annoys and perplexes me, as I know that I have done the System Restore thing now at LEAST three times, after help from you and others here on CH.

*sigh*...my brain is hurting, it's nearly four in the morning...I'm going to bed. I'll try again tomorrow...

Thanks Broni... buona notteWhen you are up, go Start>Run, type in:
sfc /scannow
Click OK.
Have Windows CD handy.Sorry again...but I don't have a Windows CD. *sigh* You see, I bought this laptop used, and I think it was probably not the WISEST purchase. I've had a mountain of problems, what with WGA thinking that my copy of Windows is pirated, tho the gentlemen at the computer store assured me it isn't. They said that it was used in an office before, and was connected to a network of computers there, apparently all logged into one main computer, that being the one with the registered ID number. Does that sound reasonable to you?

Along those lines, I have a friend that recently bought a new computer and is now using Vista, and he said that he still has a registered copy of Windows XP that he would be willing to give me. He said that we can wipe my computer clean, and start over with his copy of XP. This seems appealing to me on the one hand, but on the other, I will lose everything on my computer as a result, correct? And as far as backing up...I suppose I could do that (actually SHOULD do that, considering the wacky nature of my computer anyway), but as of this moment, I have no idea how to do that. I'm sure my friend can show me, but I'm wondering if it's even reasonable to go to all that hassle?

At any rate, for now, things seem to be fairly ok. Most of the time the CPU is running at a normal usage, but now and again, RUNS up to 100% and stays there for an hour or so, before coming back down. When the CPU usage is high, I often get kicked OFFLINE as well. At that point, I've taken to just giving up, and coming back to the computer the next day.

It will oftentimes SHOOT up to 100% for seemingly no reason. However, the two things I've noticed that consistently wonk-out the CPU usage are if I try to play any kind of online games (flash probs?...I don't have problems when watching YouTube tho...), or if I log into Yahoo messenger. Both those things seem to activate some kind of weirdness.

Anyway, things are definately not right, but are running much better than they have for quite some time, so I do thank you for getting me this far. I'd definitely go fro clean install with your friend's CD.
As for backing up your data, here is a very nice little program, Fab's Autobackup: http://fabs.dyndns.org/index2.php?lang=en&section=freewares, which should backup most of your stuff. When it's done with backing, you can manually double check other folders for any files, you may need.Thank you Broni.

I'll see what we can do about getting things backed up, and then installing the new version of XP. If things go well, I'll let you know. If not...well, I'll be back asking for new advice I'm sure.

Thank you again SO MUCH for all your help!You're welcome
Remember, our help will be here for you, anytime

2854.

Solve : An even newer laptop...?

Answer»

I hate bringin OLD TOPICS back, but id RATHER do this than start a new one...

I SAW that people are still having probems with the new AVG. Its on my gf's computer. Should I use a different one? she hasnt complained about anything wrong with it.Apparently, it works fine for some people, but not for others.
If it works, let her keep it, but if any trouble, you'll know what the first SUSPECT is.

2855.

Solve : hijack this... desktop and toolbar not showing?

Answer»

Can anyone check and help me get my desktop icons and toolbars back?
Ive been using task manager to open pages.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:36 PM, on 7/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.planetprepaid.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.planetprepaid.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planetprepaid.com.au
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: (no name) - {15A862F9-AF7A-45B2-850F-9A7576C4A2AA} - C:\WINDOWS\system32\awtspnKD.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: {049fe1cb-83af-78f8-8fe4-8234223759f8} - {8f957322-4328-4ef8-8f87-fa38bc1ef940} - C:\WINDOWS\system32\xydewz.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [BM4bf8b83b] Rundll32.exe "C:\WINDOWS\system32\qiaxpalt.dll",s
O4 - HKLM\..\Run: [48cb8ba7] rundll32.exe "C:\WINDOWS\system32\dgoxpiyx.dll",b
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [scheduler_monitor] C:\Program Files\ReaConverter 5.5 Pro\init_scheduler.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00C4254.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - SERVICE: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\Program Files\ReaConverter 5.5 Pro\rcp_scheduler.exe

--
End of file - 8025 bytes
Your computer is infected by at least one Keylogger and various Backdoor Trojans. Please read all of this carefully.

Backdoor Trojans, IRCBots and rootkits are very dangerous because they provide a means of accessing a computer system that bypasses security mechanisms and steal sensitive information like passwords, personal and financial data which they send back to the hacker. Remote attackers use Backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

Your PC has likely been compromised and there is no way to be SURE the computer can ever be trusted again. It is dangerous and incorrect to assume that because the Backdoor Trojan has been removed the computer is now secure. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS.

When should I re-format? How should I reinstall?.
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it will be 100% secure afterwards or that the removal will be successful.

Should you have any questions, please feel free to ask.

Let me know what you have decided to do in your next post. that sounds really bad. I use my comp for everything.
Ive decided to re format and re-install, would my comp
be clean from everything and EVERYONE after i do that?Formatting your laptop will remove everything from it, including viruses yes.
Check out Evilfantasy's link.

Quote from: evilfantasy on July 25, 2008, 05:06:03 PM

Banking and credit card institutions should be notified of the possible security breach.
I strongly suggest you take that seriously.Yes reformatting and reinstalling is the best way to eliminate this type of threat.

Note that I see many PC's with trojans on them but rarely do I give that particular speech. The nature of the infections that are on your PC are some of the worst known.

Consider your private information stolen! Read the instructions and follow through with contacting everyone ASAP. Especially follow through with the below instructions and contact your bank so they are AWARE that your account may be compromised.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. P.S. I should add to contact any Credit Card company ASAP as well. Credit Cards are easy targets because there are less "hoops" to jump through when using one online.

Someone can easily be in another country and use one within a matter of seconds after getting the card number.
2856.

Solve : HiJackThis log and virus and spyware help?

Answer»

I'm on my other computer which I never use, but my brother does, and he hardly knows how to turn a computer on, let alone keep it clean. So here I am, on it and it is not going as well as it should.
It is an Hp Pavilion a1400e
~512mb RAM shared
~256mb Nvidia Graphics
~Amd Sempron 1.8Ghz
Avast home
Spyware Terminator
Super antispyware

Here is the hjt log


Logfile of Trend Micro HIJACKTHIS v2.0.2
Scan saved at 5:31:38 PM, on 22/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\ACHJ937A\zlsSetup_70_483_000_en[1].exe
C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\GLB7.tmp
c:\windows\SYSTEM\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6504 bytes


I really need help with this computer..

Thx




Download ATF Cleaner by Atribune and save it to your Desktop.
Alternate Download link

Windows Vista users: ATF-Cleaner must be Run as an Administrator

Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:

  • Windows Temp
  • Current User Temp
  • All Users Temp
  • Temporary Internet Files
  • Prefetch
  • Java Cache
  • Recycle bin
The rest are optional - if you want it to remove everything check Select All
Now click Empty Selected
When you get the Done Cleaning message, click OK

Firefox
users click Firefox on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved PASSWORDS click No on the prompt.

Opera users click Opera on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved Passwords click No on the prompt

Important: Restart the computer before continuing.

Note that your system will run slower for a reboot or two after having used this tool so don't panic

----------

Delete temporary files

Go to:
  • Start
  • Run
  • type: CLEANMGR.EXE
  • Press Enter.
When prompted select the C: drive and click OK.
Check the boxes for:
  • Temporary Internet Files
  • Downloaded Program Files
  • Recycle Bin
  • Temporary Files
Click OK or Enter

----------

Now run a new HijackThis scan and post the new log.ok thx I'll try it

my brother is being as stupid as a 3 year old on a sugar rush. (he needs to grow up)
so this is going to be a lo0ng clean upLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:38:28 PM, on 22/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_CA&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6535 bytes
That took care of the two entries that might have caused problems.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide

----------

Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

  • Go to add/remove programs and uninstall all old versions.
  • Be sure not to remove the new version that was just installed.
  • Download JavaRa.zip and unzip the file to your Desktop.
  • Open JavaRA.exe and choose Remove Older Versions
  • Once complete exit JavaRA and delete the program.
  • Run CCleaner.
.
----------

Use the Kaspersky Online Scanner

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command.

  • Click on SCAN NOW
  • Click Accept.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
  • The scan will take a while, so be patient and let it finish.
When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, HOWEVER, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop.
  • In the File name area use KScan, or something similar.
  • In Save as type: click the drop arrow and select: Text file [*.txt]
  • Then, click: Save


Copy and paste the Kaspersky Online Scanner Report in your next reply.okay, my brother settled dpwn so this might get easier.The Kaspersky scan will take a while, probably around an hour, so he can use the computer while it's running. Just be sure to get the log from it.well, he is playing his xbox 360, so is there anything else that needs done in the mean time?Nope. Kaspersky will let us know what to do next....if anything.alrighty then, thank you very much for your help, evilfantasyok the scan is finally done, but i don't know how ot save it. It says that there are no infections and no threats though.i got it to save!





--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, July 22, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, July 22, 2008 23:34:08
Records in database: 987374
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan ARCHIVES: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 53253
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 01:49:16

No malware has been detected. The scan area is clean.

The selected area was scanned.
Excellent! No malware.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
-----

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Use only trusted security software like the programs listed on this page. Trusted security tools & resources

Let me know if you have any more questions.ok. All is good now. I can't thank you enough!No problem. Safe surfing...
2857.

Solve : Best AntiSpyware And Malware??

Answer»

Quote from: evilfantasy on July 22, 2008, 11:43:17 PM

Hmm, I THOUGHT it added to the Hosts file but the more I read on it I'm realizing it doesn't. Looks like it adds changes to the Registry.

Thanks!

Btw, what's your opinion on Spyware TERMINATOR?I've never had any problems with it. I like that you can ADD clamwin to it and scan for virus and spyware. I don't recommend it to people because some of the settings can be confusing. It gives almost too much information lol. It's a GOOD program from what I know.Quote from: evilfantasy on July 22, 2008, 11:52:31 PM
I've never had any problems with it. I like that you can add clamwin to it and scan for virus and spyware. I don't recommend it to people because some of the settings can be confusing. It gives almost too much information lol. It's a good program from what I know.

Thanks. I've been using it for some time now and never had a problem with it.
2858.

Solve : my computer has a trojan?

Answer»

*JS_REDIR is a Java Script Redirector Trojan. These usually sit in your temporary internet files folder. If you purge this folder or if the software quanartined it, its likely GONE. If you do a rescan and nothing detected, I'd say it may have removed it on its own.

I would however go with a better antivirus as well than that package if your DATA is very important. I havent heard BAD things about the Trend MICRO AV, but their hardware is generally not top of the LINE quality so the AV may also be questionable quality programming wise.You can go ahead and re-post your log file and one of our Malware Specialists will see if you're still infected if you want.

2859.

Solve : complete browser hijack?

Answer»

From ZA website. There is a FIX with an update I think.

Workaround to SUDDEN Loss of INTERNET Access ProblemThank you.

2860.

Solve : Winoldap and random-number programs slow/stop computer?

Answer»

older computer, 386 RAM, ME OPER. SYSTEM. Only when I go online using dialup AOL as ISP, as I retrieve my email, programs start running that slow the system. When i CONT/ALT/DEL to check what is running, there are many "winoldap" programs, plus a program identified only by 9 numbers. When I highlight the 9-number program and click "end task" - very SHORTLY, a different 9-number program comes on. As I keep trying to end the programs by clicking cont/alt/del and end task, the programs start multiplying, more and more 9-digit and even 10-digit number programs show up, and sometimes a program called "lcf", and rarely, a program called .
All of these winoldap programs, and the 9-digit programs, and lcf -- quickly use up so much operating memory, that i get a warning window, saying my system is dangerously low on resources, or doesn't have the resources to continue. my only recourse is to restart the computer and start over.
It's as if a hacker out there, or his/her computer slave, has malware that notifies them that I have just gotten online, and sends these harassing programs to use up my operating memory and shut me down.
by the way, sometimes i access the internet through a high-speed connection using an external antenna and program - and it doesn't happen then. Only when i go through my dialup AOL.
I have run spybot which tells me i am clean.
anyone know of this problem, and how to cure?Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by SELECTING "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.Broni, Thank you for your help. Your reply recommended i download three programs. After many tries for each, I was SUCCESSFUL in downloading two of them: Superantispyware, and Hijack this. Each time I tried to install Malwarebytes, i got an error window saying: "Mbam has caused an error in KERNEL32.DLL" i couldn't get past that.
You asked me to post the scan logs, so below are the scanlogs for Superantispyware and Hijack this. I did fix the problems revealed in the Superantispyware scan. thank you again. i presume you will review this and give your expert opinion on further action, if any?
Lovetodance - a newbie

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:14:54 AM, on 4/26/2008
Platform: Windows ME (Win9x 4.90.3000A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMPACT WIRELESS-G USB ADAPTER WIRELESS NETWORK MONITOR\WUSB54GC.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\ICF.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.netcenter.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
O4 - HKLM\..\Run: [icf] c:\windows\system\icf.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [WUSB54GC] C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com/start.html
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4482/mcfscan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/controls/activex_10/TMSSReport.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL
--
End of file - 5328 bytes

SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/25/2008 at 05:45 PM
Application Version : 4.0.1154
Core Rules Database Version : 3412
Trace Rules Database Version: 1440
Scan type : Complete Scan
Total Scan Time : 02:45:24
Memory items scanned : 78
Memory threats detected : 0
Registry items scanned : 2788
Registry threats detected : 0
File items scanned : 93083
File threats detected : 318
Adware.Tracking Cookie
C:\WINDOWS\Cookies\[emailprotected][3].txt
C:\WINDOWS\Cookies\[emailprotected][3].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][1].txt
C:\WINDOWS\Cookies\[emailprotected][3].txt
C:\WINDOWS\Cookies\[emailprotected][3].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][1].txt
C:\WINDOWS\Cookies\[emailprotected][1].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
C:\WINDOWS\Cookies\[emailprotected][1].txt
C:\WINDOWS\Cookies\[emailprotected][3].txt
C:\WINDOWS\Cookies\[emailprotected][2].txt
c:\WINDOWS\Cookies\[emailprotected][1].txt
c:\WINDOWS\Cookies\[emailprotected][1].txt
c:\WINDOWS\Cookies\[emailprotected][1].txt
c:\WINDOWS\Cookies\[emailprotected][2].txt
c:\WINDOWS\Cookies\[emailprotected][1].txt
c:\WINDOWS\Cookies\[emailprotected][1].txt
c:\WINDOWS\Cookies\[emailprotected][2].txt
c:\WINDOWS\Cookies\[emailprotected][2].txt
Trojan.Downloader-CounterMeasures
C:\WINDOWS\TEMP\1783461810.EXE
C:\WINDOWS\TEMP\116607120.EXE
C:\WINDOWS\TEMP\497114715.EXE
C:\WINDOWS\TEMP\226565080.EXE
C:\WINDOWS\TEMP\2064817459.EXE
C:\WINDOWS\TEMP\25417723.EXE
C:\WINDOWS\TEMP\1747663756.EXE
C:\WINDOWS\TEMP\857084248.EXE
C:\WINDOWS\TEMP\1753131485.EXE
C:\WINDOWS\TEMP\192667731.EXE
C:\WINDOWS\TEMP\1677266996.EXE
C:\WINDOWS\TEMP\1527001250.EXE
C:\WINDOWS\TEMP\1381021729.EXE
C:\WINDOWS\TEMP\128165402.EXE
C:\WINDOWS\TEMP\248703477.EXE
C:\WINDOWS\TEMP\2031814652.EXE
C:\WINDOWS\TEMP\850056738.EXE
C:\WINDOWS\TEMP\111115232.EXE
C:\WINDOWS\TEMP\243217668.EXE
C:\WINDOWS\TEMP\985131022.EXE
C:\WINDOWS\TEMP\1091753169.EXE
C:\WINDOWS\TEMP\1691555916.EXE
C:\WINDOWS\TEMP\427845405.EXE
C:\WINDOWS\TEMP\808891721.EXE
C:\WINDOWS\TEMP\1033571203.EXE
C:\WINDOWS\TEMP\1871884576.EXE
C:\WINDOWS\TEMP\574680213.EXE
C:\WINDOWS\TEMP\245275572.EXE
C:\WINDOWS\TEMP\185296495.EXE
C:\WINDOWS\TEMP\794643484.EXE
C:\WINDOWS\TEMP\940385718.EXE
C:\WINDOWS\TEMP\1903574919.EXE
C:\WINDOWS\TEMP\566402021.EXE
C:\WINDOWS\TEMP\1592199453.EXE
C:\WINDOWS\TEMP\425656949.EXE
C:\WINDOWS\TEMP\681817648.EXE
C:\WINDOWS\TEMP\463580536.EXE
C:\WINDOWS\TEMP\1652406392.EXE
C:\WINDOWS\TEMP\1557278300.EXE
C:\WINDOWS\TEMP\1104594359.EXE
C:\WINDOWS\TEMP\686226940.EXE
C:\WINDOWS\TEMP\1803777637.EXE
C:\WINDOWS\TEMP\1030396019.EXE
C:\WINDOWS\TEMP\881183940.EXE
C:\WINDOWS\TEMP\1401328552.EXE
C:\WINDOWS\TEMP\1468893358.EXE
C:\WINDOWS\TEMP\1724155919.EXE
C:\WINDOWS\TEMP\224800123.EXE
C:\WINDOWS\TEMP\979177663.EXE
C:\WINDOWS\TEMP\1646385628.EXE
C:\WINDOWS\TEMP\1888443144.EXE
C:\WINDOWS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\8LLVKOD6\N2_21_09_07_0[1].EXE
C:\WINDOWS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\8LLVKOD6\MUN1_26_11_070[1].EXE
C:\WINDOWS\TEMP\883388576.EXE
C:\WINDOWS\TEMP\1995744544.EXE
C:\WINDOWS\TEMP\797888104.EXE
C:\WINDOWS\TEMP\823724944.EXE
C:\WINDOWS\TEMP\1195428889.EXE
C:\WINDOWS\TEMP\351049212.EXE
C:\WINDOWS\TEMP\1929578738.EXE
C:\WINDOWS\TEMP\164029912.EXE
C:\WINDOWS\TEMP\1048552821.EXE
C:\WINDOWS\TEMP\718143316.EXE
C:\WINDOWS\TEMP\149601261.EXE
C:\WINDOWS\TEMP\2015354910.EXE
C:\WINDOWS\TEMP\1651329155.EXE
C:\WINDOWS\TEMP\1705759227.EXE
C:\WINDOWS\TEMP\1034695850.EXE
C:\WINDOWS\TEMP\361810599.EXE
C:\WINDOWS\TEMP\983624423.EXE
C:\WINDOWS\TEMP\995011927.EXE
C:\WINDOWS\TEMP\300535267.EXE
C:\WINDOWS\TEMP\1996309425.EXE
C:\WINDOWS\TEMP\1615837304.EXE
C:\WINDOWS\TEMP\1772834805.EXE
C:\WINDOWS\TEMP\738425988.EXE
C:\WINDOWS\TEMP\1341740041.EXE
C:\WINDOWS\TEMP\386053685.EXE
C:\WINDOWS\TEMP\1295878583.EXE
C:\WINDOWS\TEMP\1783561729.EXE
C:\WINDOWS\TEMP\603101180.EXE
C:\WINDOWS\TEMP\2089265122.EXE
C:\WINDOWS\TEMP\656415497.EXE
C:\WINDOWS\TEMP\1294431606.EXE
C:\WINDOWS\TEMP\240400285.EXE
C:\WINDOWS\TEMP\450701862.EXE
C:\WINDOWS\TEMP\956250694.EXE
C:\WINDOWS\TEMP\1658541624.EXE
C:\WINDOWS\TEMP\2087124551.EXE
C:\WINDOWS\TEMP\677410116.EXE
C:\WINDOWS\TEMP\947328951.EXE
C:\WINDOWS\TEMP\2121376641.EXE
C:\WINDOWS\TEMP\1988165569.EXE
C:\WINDOWS\TEMP\442609994.EXE
C:\WINDOWS\TEMP\1557750878.EXE
C:\WINDOWS\TEMP\1992838175.EXE
C:\WINDOWS\TEMP\2073680032.EXE
C:\WINDOWS\TEMP\1189050570.EXE
C:\WINDOWS\TEMP\852507429.EXE
C:\WINDOWS\TEMP\740539713.EXE
C:\WINDOWS\TEMP\126494284.EXE
C:\WINDOWS\TEMP\2080014793.EXE
C:\WINDOWS\TEMP\541476132.EXE
C:\WINDOWS\TEMP\1591287222.EXE
C:\WINDOWS\TEMP\1727404724.EXE
C:\WINDOWS\TEMP\553978405.EXE
C:\WINDOWS\TEMP\1580214671.EXE
C:\WINDOWS\TEMP\1629932814.EXE
C:\WINDOWS\TEMP\1903848543.EXE
C:\WINDOWS\TEMP\1856011470.EXE
C:\WINDOWS\TEMP\1706184932.EXE
C:\WINDOWS\TEMP\885603543.EXE
C:\WINDOWS\TEMP\2141927667.EXE
C:\WINDOWS\TEMP\1104037648.EXE
C:\WINDOWS\TEMP\2047333949.EXE
C:\WINDOWS\TEMP\1200113612.EXE
C:\WINDOWS\TEMP\873651765.EXE
C:\WINDOWS\TEMP\394041053.EXE
C:\WINDOWS\TEMP\2135144844.EXE
C:\WINDOWS\TEMP\2026810824.EXE
C:\WINDOWS\TEMP\199153595.EXE
C:\WINDOWS\TEMP\353138128.EXE
C:\WINDOWS\TEMP\501352008.EXE
C:\WINDOWS\TEMP\1013563911.EXE
C:\WINDOWS\TEMP\498860695.EXE
C:\WINDOWS\TEMP\796833231.EXE
C:\WINDOWS\TEMP\903272850.EXE
C:\WINDOWS\TEMP\1106438600.EXE
C:\WINDOWS\TEMP\338258924.EXE
C:\WINDOWS\TEMP\1743649742.EXE
C:\WINDOWS\TEMP\1604711391.EXE
C:\WINDOWS\TEMP\1773622609.EXE
C:\WINDOWS\TEMP\36175615.EXE
C:\WINDOWS\TEMP\1021212171.EXE
C:\WINDOWS\TEMP\694580450.EXE
C:\WINDOWS\TEMP\305738688.EXE
C:\WINDOWS\TEMP\727107768.EXE
C:\WINDOWS\TEMP\1062500794.EXE
C:\WINDOWS\TEMP\948000871.EXE
C:\WINDOWS\TEMP\1576227941.EXE
C:\WINDOWS\TEMP\312733638.EXE
C:\WINDOWS\TEMP\192137425.EXE
C:\WINDOWS\TEMP\1307780432.EXE
C:\WINDOWS\TEMP\393872833.EXE
C:\WINDOWS\TEMP\1537071879.EXE
C:\WINDOWS\TEMP\577173495.EXE
C:\WINDOWS\TEMP\1409181888.EXE
C:\WINDOWS\TEMP\1297503350.EXE
C:\WINDOWS\TEMP\1294519278.EXE
C:\WINDOWS\TEMP\374536230.EXE
C:\WINDOWS\TEMP\253275134.EXE
C:\WINDOWS\TEMP\1056901638.EXE
C:\WINDOWS\TEMP\1121155218.EXE
C:\WINDOWS\TEMP\2012915916.EXE
C:\WINDOWS\TEMP\2000342918.EXE
C:\WINDOWS\TEMP\1798261627.EXE
C:\WINDOWS\TEMP\629732237.EXE
C:\WINDOWS\TEMP\141220456.EXE
C:\WINDOWS\TEMP\1277225550.EXE
C:\WINDOWS\TEMP\447830807.EXE
C:\WINDOWS\TEMP\196833965.EXE
C:\WINDOWS\TEMP\467587296.EXE
C:\WINDOWS\TEMP\1663038582.EXE
C:\WINDOWS\TEMP\1454731974.EXE
C:\WINDOWS\TEMP\155730963.EXE
C:\WINDOWS\TEMP\1468874206.EXE
C:\WINDOWS\TEMP\519222298.EXE
C:\WINDOWS\TEMP\1155224580.EXE
C:\WINDOWS\TEMP\902495874.EXE
C:\WINDOWS\TEMP\1548618164.EXE
C:\WINDOWS\TEMP\1879167743.EXE
C:\WINDOWS\TEMP\758582975.EXE
C:\WINDOWS\TEMP\1720065934.EXE
C:\WINDOWS\TEMP\1889635645.EXE
C:\WINDOWS\TEMP\724008402.EXE
C:\WINDOWS\TEMP\1749819921.EXE
C:\WINDOWS\TEMP\559654817.EXE
C:\WINDOWS\TEMP\1548074364.EXE
C:\WINDOWS\TEMP\461000619.EXE
C:\WINDOWS\TEMP\1401304279.EXE
C:\WINDOWS\TEMP\685729430.EXE
C:\WINDOWS\TEMP\1190060941.EXE
C:\WINDOWS\TEMP\925127392.EXE
C:\WINDOWS\TEMP\1244167452.EXE
C:\WINDOWS\TEMP\701747115.EXE
C:\WINDOWS\TEMP\1475097384.EXE
C:\WINDOWS\TEMP\1605222081.EXE
C:\WINDOWS\TEMP\548531169.EXE
C:\WINDOWS\TEMP\179641900.EXE
C:\WINDOWS\TEMP\1117017547.EXE
C:\WINDOWS\TEMP\574251572.EXE
C:\WINDOWS\TEMP\379014259.EXE
C:\WINDOWS\TEMP\341346903.EXE
C:\WINDOWS\TEMP\1232915079.EXE
C:\WINDOWS\TEMP\1944798515.EXE
C:\WINDOWS\TEMP\1324496912.EXE
C:\WINDOWS\TEMP\1700032886.EXE
C:\WINDOWS\TEMP\523321960.EXE
C:\WINDOWS\TEMP\933682476.EXE
C:\WINDOWS\TEMP\1519783249.EXE
C:\WINDOWS\TEMP\1466616894.EXE
C:\WINDOWS\TEMP\868649713.EXE
C:\WINDOWS\TEMP\1041515000.EXE
C:\WINDOWS\TEMP\339595423.EXE
C:\WINDOWS\TEMP\1960428149.EXE
C:\WINDOWS\TEMP\788922347.EXE
C:\WINDOWS\TEMP\931004790.EXE
C:\WINDOWS\TEMP\1065339651.EXE
C:\WINDOWS\TEMP\2127863161.EXE
C:\WINDOWS\TEMP\633369841.EXE
C:\WINDOWS\TEMP\1570446159.EXE
C:\WINDOWS\TEMP\1244276680.EXE
C:\WINDOWS\TEMP\378364822.EXE
C:\WINDOWS\TEMP\634815060.EXE
C:\WINDOWS\TEMP\1240410851.EXE
C:\WINDOWS\TEMP\1657556769.EXE
C:\WINDOWS\TEMP\1452253732.EXE
C:\WINDOWS\TEMP\904252060.EXE
C:\WINDOWS\TEMP\1865761204.EXE
C:\WINDOWS\TEMP\875745760.EXE
C:\WINDOWS\TEMP\1659794345.EXE
C:\WINDOWS\TEMP\1294778947.EXE
C:\WINDOWS\TEMP\583819388.EXE
C:\WINDOWS\TEMP\1607971730.EXE
C:\WINDOWS\TEMP\1332993152.EXE
C:\WINDOWS\TEMP\227065640.EXE
C:\WINDOWS\TEMP\467296176.EXE
C:\WINDOWS\TEMP\1138057378.EXE
C:\WINDOWS\TEMP\1463319338.EXE
C:\WINDOWS\TEMP\2134659209.EXE
C:\WINDOWS\TEMP\1295623186.EXE
C:\WINDOWS\TEMP\1691256261.EXE
C:\WINDOWS\TEMP\1202758815.EXE
C:\WINDOWS\TEMP\1462138988.EXE
C:\WINDOWS\TEMP\386688466.EXE
C:\WINDOWS\TEMP\1403761852.EXE
C:\WINDOWS\TEMP\833091513.EXE
C:\WINDOWS\TEMP\604820707.EXE
C:\WINDOWS\TEMP\1144270734.EXE
C:\WINDOWS\TEMP\1872512701.EXE
C:\WINDOWS\TEMP\796178611.EXE
C:\WINDOWS\TEMP\1803863233.EXE
C:\WINDOWS\TEMP\1767460363.EXE
C:\WINDOWS\TEMP\168824278.EXE
C:\WINDOWS\TEMP\577610588.EXE
C:\WINDOWS\TEMP\145772399.EXE
C:\WINDOWS\TEMP\1591078409.EXE
C:\WINDOWS\TEMP\1276210648.EXE
C:\WINDOWS\TEMP\1547463941.EXE
C:\WINDOWS\TEMP\238429684.EXE
C:\WINDOWS\TEMP\1244279795.EXE
C:\WINDOWS\TEMP\948522789.EXE
C:\WINDOWS\TEMP\461783995.EXE
C:\WINDOWS\TEMP\374010561.EXE
C:\WINDOWS\TEMP\1030921599.EXE
C:\WINDOWS\TEMP\1373336898.EXE
C:\WINDOWS\TEMP\1996429664.EXE
C:\WINDOWS\TEMP\1383957323.EXE
C:\WINDOWS\TEMP\1037419389.EXE
C:\WINDOWS\TEMP\88421448.EXE
C:\WINDOWS\TEMP\687979530.EXE
C:\WINDOWS\TEMP\1514822543.EXE
C:\WINDOWS\TEMP\1257596660.EXE
C:\WINDOWS\TEMP\1900247045.EXE
C:\WINDOWS\TEMP\2039777676.EXE
C:\WINDOWS\TEMP\2010166493.EXE
C:\WINDOWS\TEMP\375852463.EXE
C:\WINDOWS\TEMP\2004408143.EXE
C:\WINDOWS\TEMP\1731702606.EXE
C:\WINDOWS\TEMP\1240417269.EXE
C:\WINDOWS\TEMP\366129353.EXE
C:\WINDOWS\TEMP\5636449.EXE
C:\WINDOWS\TEMP\587472105.EXE
C:\WINDOWS\TEMP\1868004981.EXE
C:\WINDOWS\TEMP\2115581590.EXE
C:\WINDOWS\TEMP\286012072.EXE
C:\WINDOWS\TEMP\1335519833.EXE
C:\WINDOWS\TEMP\1944766562.EXE
C:\WINDOWS\TEMP\430142298.EXE
C:\WINDOWS\TEMP\412195269.EXE
C:\WINDOWS\TEMP\1929699942.EXE
C:\WINDOWS\TEMP\1849685769.EXE
C:\WINDOWS\TEMP\895913854.EXE
C:\WINDOWS\TEMP\2118840552.EXE
C:\WINDOWS\TEMP\813868102.EXE
C:\WINDOWS\TEMP\798787136.EXE
C:\WINDOWS\TEMP\426801159.EXE
C:\WINDOWS\TEMP\749075629.EXE
C:\WINDOWS\TEMP\394188147.EXE
C:\WINDOWS\TEMP\1275496277.EXE
C:\WINDOWS\TEMP\2074726245.EXE
C:\WINDOWS\TEMP\790411404.EXE
C:\WINDOWS\TEMP\1237909462.EXE
C:\WINDOWS\TEMP\50961291.EXE



*** You're not using any firewall, which is not good.
Download, and install Jetico Personal Firewall v.1 freeware: http://www.jetico.com/index.htm#/jpfirewall.htm

*** Disable TeaTimer, as it'll interfere with the cleaning process:
Right click Spybot's TeaTimer System Tray Icon.
Click Exit Spybot-S&D Resident.
TeaTimer closes.

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- *O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
- O4 - HKLM\..\Run: [icf] c:\windows\system\icf.exe
- *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
- *O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE (User 'Default user')
- *O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL

4. Click on Fix checked button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

7. Delete following files/folders (if present):

- icf.exe from c:\windows\system

8. Restart in Normal Mode.

9. Post new HijackThis log.I accomplished all of the above, BUT BIG PROBLEM. Now I cannot get online with my AOL dialup. it hangs up at step 5 - "Talking to Network" and almost everything freezes. Cursor moves, but nothing responds to clicks or keys. when i hit "Contol - alt-delete" even once, it immediately starts rebooting. I have tried many times, cannot get past this. (I am sending this from a friend's computer) help!I am happy to report that I solved this problem. I just uninstalled the Jetico Firewall, and everything SEEMS to work fine now. whew! ... needless to say, i am not a fan of Jetico Firewall.That's the only free firewall available for ME. You can't be safe on the internet without firewall.
I also need fresh HJT log.Here's the fresh HJT log, hot out of the oven (by the way, thanks for your time and expertise. the other actions you recomended cured the other problem.)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:41 AM, on 4/29/2008
Platform: Windows ME (Win9x 4.90.3000A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMPACT WIRELESS-G USB ADAPTER WIRELESS NETWORK MONITOR\WUSB54GC.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.netcenter.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [WUSB54GC] C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com/start.html
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4482/mcfscan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/controls/activex_10/TMSSReport.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL

--
End of file - 5171 bytes
The log is clean, now.

Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

Turn System Restore off: http://download.nai.com/products/mcafee-avert/SystemHelpDocs/DisableSysRestore.htm

Restart computer.

Turn System Restore on.

Try to install Jetico again.
Im just wanted to thank Broni VERY much, who solved the problem with the advice in this topic.You're very welcome
Thank you for posting back.

2861.

Solve : SYSTEM32 message;virus,malware or other??

Answer»

Several days ago,I received a windows update notice for SP3;as normal,I complied and thought no more about it.Since then,I am constantly recieving a warning box stating "DLL C:\WINDOWS\system32\MSACM32.dll". It makes a reference to some windows image being unable to load,and states that I need to match it up against some diskette.At the same time,I have lost all audio.I have checked and rechecked wires,plug-ins,sound card,mixer settings,etc;nothing seems amiss.The only info I found out about MSACM32 on the net was that it might be some kind of audio compression file.HELP! Is this a bug,or do I need to get in a different topic.Any reply is greatly appreciated...Thanks...CNReddMSACM32.dll - msacm32.dll is a module containing functions for audio compression for 32-bit applications.

I will move this topic to the Computer software forum. I don't think this is malware related.I appreciate that you put this in the right category...I wasn't sure.Could this have anything to do with the Windows SP3 download? I hate to think that,but thats when it started.I am also leary of removing that without some more educated opinions.Thanks in advance....CNReddNot sure whats causing it. A few things to try.

Try running sfc /scannow, Start > Run type sfc /scannow then click OK. Make sure that the Windows XP installation cd is in the computer.

Try downloading the msacm32.dll file from http://www.webzila.com/?wz=dll then register it with your system by following these instructions: http://forum.webzila.com/index.php?showtopic=543OK....XP was already installed when I purchased the PC,so all I have is the back-up that was suggested I make.I placed it in the pc and followed the "run" commands and got nothing.It verified that all windows files were intact and then did nada.As for step 2, that hasn't resolved anything either.I considered restoring to factory specs,but this issue will not allow me to burn a cd or dvd.Now what?Post a HJT log so we can do a quick check for malware. Although I don't think it is malware it won't hurt to look real fast.

Download and rename TrendMicro HijackThis.exe (HJT)

  • Double-click on HJTInstall.
  • Click on the Install button.
  • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
  • Upon install, HijackThis should open for you.
  • Close HijackThis and rename it.
  • Go to C:\Program Files\TREND Micro\HijackThis.exe
  • Right click on HijackThis.exe and select Rename.
  • Type in sniper.exe and press Enter.
  • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
  • From the desktop open HijackThis.
  • If using Windows Vista, Right-click and Run As Administrator.
  • Click on the Do a system scan and save a log file button
  • Hijackthis will scan and then a log will open in notepad.
  • Copy and then paste the entire contents of the log in your post.
  • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Although we have renamed HijackThis to sniper, we will still refer to it as HijackThis or HJT.Have you tried to uninstall SP3?
Have you tried sytem restore?
Ok,Egghead,give me a bit and I'll have that for you.As for the last post,I'm unsure and uninformed on deleting SP3,so I won't unless I hear otherwise.As far as a restore,I tried several restore points,going back nearly a month,and my system will not allow it.I'v had this problem before,too,and I don't understand why it will not allow a restore.Ok,dude...here my grocery list.....


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:25:42 AM, on 7/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exeC:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\SPEEDB~1\VideoAccelerator.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\system32\sol.exe
c:\program files\aol\aol toolbar 5.0\AolTbServer.exe
C:\Program Files\Common Files\AOL\1165668632\ee\aolsoftware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 24.197.97.135:80
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: TTB000000 - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI ROBOFORM\roboform.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\WINDOWS\CouponBarIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RCSystemTray] "C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe"
O4 - HKLM\..\Run: [MagicSpeed] "C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe" /autorun
O4 - HKLM\..\Run: [dvd43] "C:\Program Files\dvd43\dvd43_tray.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1165668632\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BOC-427] C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Window Washer] "C:\Program Files\Webroot\Washer\wwDisp.exe"
O4 - HKCU\..\Run: [EPSON Stylus CX8400 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEA.EXE" /FU "C:\WINDOWS\TEMP\E_S6BBA.tmp" /EF "HKCU"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Owner"
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Iolo Macro Magic.lnk = C:\Program Files\iolo\Macro Magic\Macros.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: PackageCab - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinner.com/games/v46/solitairerush/solitairerush.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} - http://coupons.smartsource.com/download/cscmv5X.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200135186109
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 11440 bytes




Thanks in advance,manI'm moving this thread to the Computer viruses and spyware forum.

Go here HERE and do the SCANS. Post the logs when complete.
2862.

Solve : Does this have to Malware??

Answer»

ever SINCE that's popped up (which has been like 20 mins) My PC has been running super slow.
Anyway Im running a scan just in case. Can SOMEONE confirm that's something to do with Malware?We won't know until you present logs.all I know for sure is my computer is running severely slow. Its taken me 3 mins to type this phrase. Could this VIRUS completely KILL my computer?We don't know, if it's a virus, yet.
You have to try running prescribed programs. Don't waste your time for replying.
2863.

Solve : Infected?

Answer»

Hi all,

I have a PC with has been seriously infected with all sorts of rubbish. I have done the USUAL scans, and most of it seems to have been deleted. I have attached the log files.

Cheers

Nick

[recovering disk space -- ATTACHMENT deleted by admin]You're right, it looks like just about everything has been removed. You should close all windows (including this one) and fix the following entries with HijackThis...

O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
O20 - Winlogon Notify: pMdcdBtQ - pMdcdBtQ.dll (file missing)


Then if you're up to it, you should run the three scans again just to be sure.

While you're at it, you need a firewall. Without it, you are leaving yourself vulnerable. My suggestion would be Comodo.

Also...
Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new SUN Java Runtime Environment

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

  • Go to add/remove programs and uninstall all old versions.
  • Be sure not to remove the new version that was just installed.
  • Download JavaRa.zip and UNZIP the file to your Desktop.
  • Open JavaRA.exe and choose Remove Older Versions
  • Once complete exit JavaRA and delete the program.
  • Run CCleaner.
(stolen from evilfantasy)



How is everything running?Thanks for the reply.

I removed the Hijack This entries, then ran the scans again. SuperAntiSpyware found some tracking cookies, which i had it remove, then scanned it again, and it was fine. All other scans came up clean. I updated Java too.

I use the Windows Firewall, which has always seemed to do the job OK for me. Everything seems to be running pretty smoothly again. I've attached a final Hijack This log.

[recovering disk space -- attachment deleted by admin]Looks clean to me. Feel free to fix these two entries if you wish...

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)


Nothing malicious; they're just taking up extra space in the registry. If you want to use Windows Firewall, that's fine, but I should inform you that it only offers very basic protection and doesn't monitor most OUTGOING connections (or any incoming). If you decide to upgrade to a better firewall, you may be surprised to see just how many connections are coming and going to your computer.

Your log is still showing an older version of Java. Did you scan before or after updating it?

Also...you might want to make sure your clock has the right date. I know UK is ahead of us by several hours, but judging by the time that your scan was made, it seems to me that it still should've been the 22nd and not the 23rd. But I'm tired, so I could be wrong.
2864.

Solve : NEED SERIOUS HELP PLEASE!!?

Answer»

Press Ctrl+Alt+DELETE (all at once)

Copy this "%userprofile%\desktop\combofix.exe" /killall

In Task Manager go to File > New Task (Run...) then paste in the "%userprofile%\desktop\combofix.exe" /killall and click OK.when i go into safemode, an extra user comes up.
it says administrator and requires a password
usually i am the main account
but when i try to control alt delete, it says that the task has been disabled by your administratorI'm about of ideas,

Download this registry file to the Desktop.

RIGHT click it and and choose Merge.

Now try to run Combofix.

You may have to restart the computer for it to take effect.I'll be signing off shortly but will try to check back in here in a few hours or so. maybe not until tomorrow. You may try running this Antivirus from the flash drive. It might clean enough to get some functions back.

Download ClamWin Portable to a portable device and make sure to update it.

Now put the flash drive in to the infected computer.
To start up ClamWin Portable, just double-click PortableClamWin.exe file where you installed Portable ClamWin on your portable drive.
Select the drive(s) you want to scan and click Scan.
Let ClamWin fix whatever it finds.

Removing Your Drive - When you're done, exit ClamWin.
Then select the Safely Remove Hardware option from the icon in the system tray.
If you remove the drive while it is writing, you may lose data.ok ill try that
thaksIf you can get Combofix to run it will be a huge help. The log is also very important. If you do get it to run and loose the log for some reason it can be found in c:\combofix.txt

GOOD luck, I'll be back later...
i think im just gonna have SOMEBODY come fix it
thanks for all the help thoughIt may be a good idea to reinstall the Operating System.

2865.

Solve : monitor control pops-up & adjusts randomly by itself, is this a virus??

Answer»

i'm using WINDOWS XP, downloaded a malware once that triggered a trojan-outbreak ... had to reformat my PC. while Windows was already installing the monitor's brightness option kept popping-out and adjusts itself. i even deleted, created, & reformatted the partitions...it's still there, during start-ups til i shut down!

then i installed AVG, while pressing the monitor button down- it somehow stops it. however it proceeds whenever i leave it alone. it became worse, toying with all the monitor controls?!? i also had to install SP2, then it stopped from selecting all of the controls and only the "brightness/contrast" options were manipulated. i scanned the whole computer with AVG, but it didn't detect anything unusual!

Now the 'brightness' control's the only one that pops-out, from start-ups til shut-down, and avg still doesn't detect anything... please help ASAP, am an out-of-school-youngster and i have to study a lot even just online and all... i don't know if this sort of malfunction would infect my tablet, this hinders me from my drawing/animating practices... badly... please help.Welcome to CH.

Download and rename TrendMicro HijackThis.exe (HJT)

  • Double-click on HJTInstall.
  • Click on the Install button.
  • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
  • Upon install, HijackThis should open for you.
  • Close HijackThis and rename it.
  • Go to C:\Program Files\Trend Micro\HijackThis.exe
  • Right click on HijackThis.exe and select Rename.
  • Type in sniper.exe and press Enter.
  • Right-click on sniper.exe and select Send To > Desktop (CREATE shortcut)
  • From the desktop open HijackThis.
  • If using Windows Vista, Right-click and Run As Administrator.
  • Click on the Do a system scan and save a log file button
  • HijackThis will scan and then a log will open in notepad.
  • Copy and then paste the entire contents of the log in your post.
  • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Although we have renamed HijackThis to sniper, we will still refer to it as HijackThis or HJT.
ok, done. what next?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:01 PM, on 7/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\SERVICES.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TSE_PLUtil] C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\system32\HotfixQ0306270.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

--
End of file - 4351 bytesI don't see any malware and the symptoms you describe don't sound like it either.

I see you have SUPERAntiSpyware installed, have you done a scan with it?

Quote
Now the 'brightness' control's the only one that pops-out, from start-ups til shut-down

I don't understand what you mean by this. Quote
Now the 'brightness' control's the only one that pops-out, from start-ups til shut-down

i took pics from the PC next to it...

am still scanning SUPERAntiSpyware ... so far it's detected 8 Adware.Tracking Cookies ...

[recovering disk space -- attachment deleted by admin]I'm not sure that this is malware related. Let's see if Superantispyware finds anything.Cookies are nothing to worry about.

I'm with evilfantasy on this one...it doesn't sound like a malware issue. By the looks of it, your monitor is probably on the fritz. Your graphics card could also be the culprit, but I think that's not as likely. Do you have another monitor you can try? And can you hook your monitor up to a different computer? This is always the first thing you want to try when having significant monitor problems.I found some information on this in the links below. Sounds like it may just be a dust problem.

Why does my brightness control on my monitor keep coming up

Monitor Problems

Quote
If the menu keeps coming up the monitor thinks you pressed a button. A button is just a way of completing an electrical circuit. If dust accumulates on a circuit it can cause the circuit to act strangely. Purchasing some canned air from your local office supply store can solve this problem in most cases. Just blow the air in all the vent holes of the monitor to blow the dust out. Be sure to FOLLOW the directions on the can.[/qoute]
Quote from: CBMatt on July 22, 2008, 11:34:41 PM
Cookies are nothing to worry about.

I'm with evilfantasy on this one...it doesn't sound like a malware issue. By the looks of it, your monitor is probably on the fritz. Your graphics card could also be the culprit, but I think that's not as likely. Do you have another monitor you can try? And can you hook your monitor up to a different computer? This is always the first thing you want to try when having significant monitor problems.

yes, i know the cookies are less of a threat...but...uhm, sure, once i get someone to lift the monitors for me ^^; everyone's busy... the video card's new, GeForce... i may try that thoughQuote
If the menu keeps coming up the monitor thinks you pressed a button. A button is just a way of completing an electrical circuit. If dust accumulates on a circuit it can cause the circuit to act strangely. Purchasing some canned air from your local office supply store can solve this problem in most cases. Just blow the air in all the vent holes of the monitor to blow the dust out. Be sure to follow the directions on the can.[/qoute]

I remembered something like that! only they taught me the exact opposite.. anyway, it's proven that dust can be that kind of conductor. somebody dusted the fans on this PC, last month... is it likely? (canned air isn't available here)

and Spyware's done:

[recovering disk space -- attachment deleted by admin]
Yes I think you need to get inside of the monitor and clean it out.

Don't worry about the cookies, they are just .txt files so they can't do anything malicious.Quote from: evilfantasy on July 23, 2008, 12:14:20 AM
Yes I think you need to get inside of the monitor and clean it out.

Don't worry about the cookies, they are just .txt files so they can't do anything malicious.


K, i'll update you when am done... brb... i almost forgot, the same thing happens even if the screen-saver's already on, and even when i'm in safe-mode. I dusted the monitor carefully but i may have to do it again, it's still in the middle of the screen. does that mean i can use my tablet on this computer? it's the only one i could borrow. we're short on cash, can't replace it at the moment.

I also want to ask about PREVENTING hardware-hacking, is AVG & SUPERAntiSpyware enough?
2866.

Solve : Can't open any web browser except Internet Explorer! And can't open SOME exe/ink?

Answer»

Hi! Thankies for clicking!

Okay well i recently have been attacked by a virus (cleaned it up w/ smitfraud) but now i have 2 major problems, if anyone can help i give you 100000 hugs!!!

Okay so like the subject is, i can only open Internet Explorer or Safari. I CANNOT open Opera or Firefox! Those are my main browsers, and i just downloaded Safari to see if that worked and it has, but i want my Firefox back!

SECOND problem, i cannot open .exe files!!! I used a computer at my sister's house to export .exe registry files onto a flash drive and things like that, i deleted the reg. on my laptop, and imported those ones. It hasn't worked Major help please!!

Also, randomly i was unable to open "Notepad" and "Internet Explorer" I have found it was on the list of Data Execution Prevention files (Control Panel>System>Performance Options) however Firefox was not on it, but nevertheless i did remove them from the list, and now they randomly pop up on it again and i'm continuously having to remove them when i start up my laptop and stuff.

Once again, .exe files don't work, so i cant download Hijack this or Malware Bytes, but however i to have Smitfraud and SUPERANTIVIRUS installed, and for some reason both do work, but ive deleted all threats found on Super anti virus, hasn't help.

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program DEFINITIONS, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while DOWNLOADING the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all OTHERS unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.Quote

Once again, .exe files don't work, so i cant download Hijack this or Malware Bytes

Download Deckard's Association File Tool (DAFT) and save it to your desktop.
  • Rename daft.exe to daft.com and double click on it to run.
  • Read the disclaimer and click OK.
  • Click on the Scan button.
  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a checkmark (tick) in the boxes in question.
  • Click the Fix button.
.

Now try to download and run the scans.
2867.

Solve : Is My Computer Functioning??

Answer»

I have attached SAS/MBAM/HiJack logs.

I'd like to know:

1) Is the computter functioning properly based on the results?
2) What steps to take and resolve?
3) Also I have:
CCleaner/avast/SAS/MBAM/HiJack/Wpsetup/Avenger/Scotty on Patrol
-Do I need any more protection...if so what...or do I need all of these?


Thanks.

[recovering disk space -- attachment deleted by admin]I want to check something as one of the entries is questionable.

Download FindAWF.exe by Noadfear to your Desktop.

  • Double-click FindAWF.exe to START the tool.

  • If a Security Alert shows, allow the program to run.
  • As instructed, press any key to continue.
  • Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
  • When the tool has COMPLETED, a report will open up in notepad.
  • Please post the results of the awf.txt in your reply.
.
----------

What is Wpsetup? Is this the WinPatrol setup file? If so DELETE it.here it is

winptr deleted

[recovering disk space -- attachment deleted by admin]You can delete FindAWF.


Use the Kaspersky Online Scanner

You must use Internet Explorer.
  • Click Accept.
  • Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & CONFIGURE to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
      • Click OK & have it scan My Computer
      When the scan is done, in the Scan is complete window (below), any infection is displayed.
      There is no option to clean/disinfect, however, we need to analyze the information on the report.

      To obtain the report:
      Click on: Save Report As...



      • Next, in the Save as prompt, Save in area, select: Desktop.
      • In the File name area, use KScan, or something similar.
      • In Save as type: click the drop arrow and select: Text file [*.txt]
      • Then, click: Save


      Copy and paste the Kaspersky Online Scanner Report in your next reply.Can't do it....I used your link.
      It will not let me hit accept....it keeps saying I need Java 1.5 or later...I verified...and already have version 7.Hmm, I just tried it in IE and Firefox and it works.

      Try this. How do I enable Java in my web browser?Here is the scan....I didn't find the scan settings...only scan options...hopefully this wasn't a problem.

      [recovering disk space -- attachment deleted by admin]
        Quote from: bluecountry on July 11, 2008, 10:51:07 PM
        I didn't find the scan settings...only scan options...hopefully this wasn't a problem.

        Yes they have recently updated the site and a few things are different. I didn't even know until I went there to try it when you couldn't get it to load. Another canned speech I need to do some tweaking on.....

        The good news is that there are only a few files to take care of and you will be malware free!

        Download OTMoveIt2 by OldTimer
        • Save it to your desktop.
        • Double-click OTMoveIt2.exe to run it.
        • Copy the lines in the codebox below.
        [/list]Code: [Select][kill explorer]
        C:\Documents and Settings\Trent Berger\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0dc2-3357f2a4.zip
        C:\Documents and Settings\Trent Berger\DoctorWeb\Quarantine\pkill.exe
        C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe
        EmptyTemp
        [start explorer]
        • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
        • Click the red Moveit! button.
        • Copy everything in the Results window (under the green bar) and paste it in your next reply.
        • Close OTMoveIt2
        .
        ----------

        Next post add
        OTMoveIt log


        Also let me know how things are now.


        Was I supposed to check off Unregister Dll's and Ocx's and Zip Files After Move?

        I didn't...here are the results


        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\HCCMP.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\ichk2.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\iChkSA.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\IWGen.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\kave.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\lha.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\L_llio.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\mdb.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\minizip.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\MKavIO.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\msoe.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\nfio.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\prKernel.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\prLoader.dll scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\PrUtil.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\rar.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\sfdb.PPL scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\TempFile.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\thpimpl.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\UniArc.ppl scheduled to be deleted on reboot.
        File delete failed. C:\DOCUME~1\TRENTB~1\LOCALS~1\Temp\jkos-Trent Berger\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6c4.dat scheduled to be deleted on reboot.
        Temp folders emptied.
        IE temp folders emptied.
        Explorer started successfully

        OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07122008_021423
        It deleted the temp files like it was supposed to but not the other ones.

        Open OTMoveIt again and copy then paste just these 3 lines to be moved.

        C:\Documents and Settings\Trent Berger\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0dc2-3357f2a4.zip
        C:\Documents and Settings\Trent Berger\DoctorWeb\Quarantine\pkill.exe
        C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exeFile/Folder C:\Documents and Settings\Trent Berger\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0dc2-3357f2a4.zip not found.
        File/Folder C:\Documents and Settings\Trent Berger\DoctorWeb\Quarantine\pkill.exe not found.
        File/Folder C:\Program Files\Common Files\aolback\Comps\toolbar\toolbr.exe not found.

        OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07122008_025238OK looks good. How is everything now?

        1. Double click OTMoveIt2.exe to launch it.
        Vista users right click and choose Run As Administrator
        2. Click on the CleanUp! button.
        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
        5. Once complete exit out of OTMoveIt2

        ----------

        Set a New Restore Point to prevent possible reinfection from an old one
        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
        • Go to Start > Programs > Accessories > System Tools and click System Restore
        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
        • Next go to Start > Run and type Cleanmgr
        • Click OK
        • Click the More Options Tab.
        • Click Clean Up in the System Restore section to remove all previous restore POINTS except the newly created clean one.
        You can find instructions on how to enable and re-enable system restore here:

        Windows XP System Restore Guide or Windows Vista System Restore Guide
        .
        ----------

        Use the Secunia Software Inspector to check for out of date software.
        • Click Start Now
        • Check the box next to Enable thorough system inspection.
        • Click Start
        • Allow the scan to finish and scroll down to see if any updates are needed.
        • Update anything listed.
        .
        ----------

        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

        ----------

        Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

        To prevent unknown applications from being installed on your computer install WinPatrol 2008
        Using Winpatrol to protect your computer from malicious software

        Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

        SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        *Using SpywareBlaster to protect your computer from Spyware and Malware
        *If you don't know what ActiveX controls are, see here

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.These are the results from cleaning on moveit2...I wanted you to see them before I go on with the rest of what you said.


        [recovering disk space -- attachment deleted by admin]Looks good. Everything is scheduled to be deleted on reboot.OK...so on my computer I have

        -AVast Anti-virrus
        -CCleaner
        -SAS
        -Malwarebytes Anti-Malware
        -SpywareBlaster

        -Win Pattrol
        -Site Advisor


        Is this all I need?
        Am I all set with proper programs meaning if I update/scan I should be alright?

        I don't need Hi-Jack this on the computer?
        Thanks.
        2868.

        Solve : Re: Can you help me please??

        Answer»

        i'm facing de same problem with Kain's and trying to solve it by following evilfantasy's method:

        ""Open Hijackthis and select Do a system scan only then place a check mark next to:
        - O2 - BHO:.....................Exit Hijackthis and run CCleaner.""

        But..................

        i can't find these items in my Hijackthis Scan Result:

        - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        - O4 - Startup: PowerReg Scheduler.exe
        - O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-be3dfe2fec863c6b.spaces.live.com/PhotoUpload/MsnPUpld.cab
        - O20 - Winlogon Notify: tuvWNFYr - tuvWNFYr.dll (file missing).

        Here's the Log:
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 1:27:57 PM, on 7/11/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        D:\WINDOWS\System32\smss.exe
        D:\WINDOWS\system32\winlogon.exe
        D:\WINDOWS\system32\services.exe
        D:\WINDOWS\system32\lsass.exe
        D:\WINDOWS\system32\svchost.exe
        D:\WINDOWS\System32\svchost.exe
        D:\WINDOWS\Explorer.EXE
        D:\WINDOWS\system32\spoolsv.exe
        D:\WINDOWS\system32\ctfmon.exe
        D:\WINDOWS\SOUNDMAN.EXE
        D:\PROGRA~1\AVG\AVG8\avgtray.exe
        D:\Program Files\Unlocker\UnlockerAssistant.exe
        D:\Program Files\K-Lite Codec Pack\Real\Update_OB\realsched.exe
        D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        D:\Program Files\Messenger\msmsgs.exe
        D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        D:\Program Files\Common Files\LightScribe\LSSrvc.exe
        D:\PROGRA~1\AVG\AVG8\avgrsx.exe
        D:\PROGRA~1\AVG\AVG8\avgemc.exe
        D:\WINDOWS\system32\wscntfy.exe
        D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        E:\Program Files\Opera 9.25\Opera.exe
        D:\WINDOWS\system32\rundll32.exe
        D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        D:\Program Files\AVG\AVG8\avgui.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com.my/
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: 778670 helper - {1B12F639-CBA9-45DD-89FE-9FA7D4340716} - D:\WINDOWS\system32\778670\778670.dll (file missing)
        O2 - BHO: (no name) - {30AA1511-5129-41F3-AE22-F13FC9470116} - D:\WINDOWS\system32\mlJDttsR.dll (file missing)
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Program Files\BitComet 0.98\BitComet\tools\BitCometBHO_1.2.1.2.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: (no name) - {5B4B28C0-9623-4B9A-A001-7AF2B47336FE} - D:\WINDOWS\system32\hgGyvsqp.dll (file missing)
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
        O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
        O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\K-Lite Codec Pack\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [000000af] rundll32.exe "D:\WINDOWS\system32\wjjbrcvj.dll",b
        O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: &D&ownload &with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddAllLink.htm
        O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://E:\Program Files\BitComet 0.98\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O17 - HKLM\System\CCS\Services\Tcpip\..\{37B57CAC-1FF1-4410-B56D-C444A633B5FD}: NameServer = 202.188.0.133 202.188.1.5
        O17 - HKLM\System\CS1\Services\Tcpip\..\{37B57CAC-1FF1-4410-B56D-C444A633B5FD}: NameServer = 202.188.0.133 202.188.1.5
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O20 - AppInit_DLLs: avgrsstx.dll
        O20 - Winlogon Notify: mlJDttsR - mlJDttsR.dll (file missing)
        O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: hpdj - HP - D:\DOCUME~1\aaa\LOCALS~1\Temp\hpdj.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - D:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

        --
        End of file - 7490 bytes

        Hope evilfantasy can advise me on this if there is something more serious problem had occured to my p c OR i have to 'check-mark" on other item.

        P.S.-What is CCleaner? A software? Whr to dl?

        Your help will be highly appreciated.

        Thanks.
        I moved this to a new topic so we aren't interfering with the fixes in the other thread.

        Welcome to CH.

        Open Hijackthis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        - O2 - BHO: 778670 helper - {1B12F639-CBA9-45DD-89FE-9FA7D4340716} - D:\WINDOWS\system32\778670\778670.dll (file missing)
        - O2 - BHO: (no name) - {30AA1511-5129-41F3-AE22-F13FC9470116} - D:\WINDOWS\system32\mlJDttsR.dll (file missing)
        - O2 - BHO: (no name) - {5B4B28C0-9623-4B9A-A001-7AF2B47336FE} - D:\WINDOWS\system32\hgGyvsqp.dll (file missing)
        - O20 - Winlogon Notify: mlJDttsR - mlJDttsR.dll (file missing)


        Important: Close all windows except for Hijackthis and then click Fix checked.

        Exit Hijackthis and run CCleaner.

        Download instructions for CCleaner are found > here <

        Be sure to uncheck Install Yahoo Toolbar during the install of CCleaner to avoid installing the Yahoo Toolbar.

        ----------

        Download Malwarebytes' Anti-Malware from here or here

        Double Click mbam-setup.exe to install the application.

        • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select "Perform Quick Scan", then click Scan.
        • The scan may take some time to finish,so please be patient.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Make sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy&Paste the entire report in your next reply.
        .
        Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

        ----------

        Now run a new Hijackthis scan and post that log along with the MBAM log.

        Also let me know how the computer is now.Thaks for your rapid reply.

        Before i proceed with Hijackthis, there r a situation of my p c & afew few Qs i think i shld consult:-
        1) Started frm yesterday - upon boots-up my pc, ther's an allert msg pop-up:
        [ D:\WINDOWS\System32\wjjbrcvj.dll
        The Specified module
        could not be found
        " Ok" ] .
        ....i just press "Ok" & my pc cotinue booting and nothing strange happens so
        far, but i wonder would thr be any interuption in the future when i intend to
        open or run a software needs that "specified module" ( actually wt is this module
        for?)
        P.S.> I chked the Voult report frm my Avg and found that these in the Voult :

        \WINDOWS\System32\wjjbrcvj.dll (INFECTION:Trojan Horse BHO.EQL)

        \WINDOWS\System32\778670\778670.dll (Infection:Trojan Horse BHO.EPL)

        and

        \WINDOWS\System32\hgGyvsqp.dll (Infection:Trojan Horse BHO.EPM)

        Q1: DO I NEED TO RESTORE THEM BEFORE I RUN Hijackthis ?

        Q2: DO I NEED TO CLOSE AVG BEFORE I RUN Hijackthis ?

        Q3: DO I NEED TO DISCONNECT MY I NTERNET BEFORE I RUN Hijackthis ?

        Thank you and look forward to your valuable advice.
        Just follow all of the instructions I give exactly as the are written and we will get everything back to normal. Just done all you advised and here are the 2 logs report for your advice:
        1) Hijackthis(2nd scan)
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 2:59:14 AM, on 7/12/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        D:\WINDOWS\System32\smss.exe
        D:\WINDOWS\system32\winlogon.exe
        D:\WINDOWS\system32\services.exe
        D:\WINDOWS\system32\lsass.exe
        D:\WINDOWS\system32\svchost.exe
        D:\WINDOWS\System32\svchost.exe
        D:\WINDOWS\Explorer.EXE
        D:\WINDOWS\system32\spoolsv.exe
        D:\WINDOWS\system32\ctfmon.exe
        D:\WINDOWS\SOUNDMAN.EXE
        D:\Program Files\Unlocker\UnlockerAssistant.exe
        D:\Program Files\K-Lite Codec Pack\Real\Update_OB\realsched.exe
        D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        D:\Program Files\Messenger\msmsgs.exe
        D:\PROGRA~1\MICROS~3\wcescomm.exe
        D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        D:\PROGRA~1\MICROS~3\rapimgr.exe
        D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        D:\Program Files\Common Files\LightScribe\LSSrvc.exe
        D:\PROGRA~1\AVG\AVG8\avgrsx.exe
        D:\PROGRA~1\AVG\AVG8\avgemc.exe
        D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
        D:\WINDOWS\system32\wscntfy.exe
        D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com.my/
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Program Files\BitComet 0.98\BitComet\tools\BitCometBHO_1.2.1.2.dll
        O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - D:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
        O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\K-Lite Codec Pack\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [WinPatrol] D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
        O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\PROGRA~1\MICROS~3\wcescomm.exe"
        O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: &D&ownload &with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://E:\Program Files\BitComet 0.98\BitComet\BitComet.exe/AddAllLink.htm
        O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~3\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~3\INetRepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~3\INetRepl.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://E:\Program Files\BitComet 0.98\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O20 - AppInit_DLLs: avgrsstx.dll
        O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: hpdj - Unknown owner - D:\DOCUME~1\aaa\LOCALS~1\Temp\hpdj.exe (file missing)
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - D:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

        --
        End of file - 8371 bytes

        2) mbam-log
        Malwarebytes' Anti-Malware 1.20
        Database version: 938
        Windows 5.1.2600 Service Pack 2

        2:06:37 AM 7/12/2008
        mbam-log-7-12-2008 (02-06-37).txt

        Scan type: Quick Scan
        Objects scanned: 38829
        Time elapsed: 4 minute(s), 13 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 6
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 1
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        D:\WINDOWS\system32\778670 (Trojan.BHO) -> Quarantined and deleted successfully.

        Files Infected:
        (No malicious items detected)

        P.S. > The alert mentioned earlier dose not appear anymore when i restart my p c.
        and everythg seems find at this momment.

        Thank you
        Looks good. We will run another scan to be sure everything is gone.

        Delete TEMPORARY FILES

        Go to:
        • Start
        • Run
        • type: CLEANMGR.EXE
        • Press Enter.
        .
        When prompted select the C: drive and click OK.
        Check the boxes for:
        • Temporary Internet Files
        • Downloaded Program Files
        • Recycle Bin
        • Temporary Files
        .
        Click OK or Enter

        ----------

        Use the Kaspersky Online Scanner

        You must use Internet Explorer.
        • Click Accept.
        • Answer Yes, when prompted to install an ActiveX component.
        • The program will then begin downloading the latest definition files.
        • Once the files have been downloaded click on NEXT
        • Locate the Scan Settings button & configure to:
          • Scan using the following Anti-Virus database:
            • Extended
          • Scan Options:
            • Scan Archives
            • Scan Mail Bases[/COLOR]
            • Click OK & have it scan My Computer
            When the scan is done, in the Scan is complete window (below), any infection is displayed.
            There is no option to clean/disinfect, HOWEVER, we need to analyze the information on the report.

            To obtain the report:
            Click on: Save Report As...



            • Next, in the Save as prompt, Save in AREA, select: Desktop.
            • In the File name area, use KScan, or something similar.
            • In Save as type: click the drop arrow and select: Text file [*.txt]
            • Then, click: Save


            Copy and paste the Kaspersky Online Scanner Report in your next reply.

            after i click "accept" in Kaspersky Online Scanner, my p c start to hang while Kaspersky Online Scanner starts varifying ......
            What shld i do?
            try clearing Internet Explorers cache then try again. You may also want to restart the computer before trying.

            Empty the IE cache

            The first thing to do when Internet Explorer is misbehaving is empty your Internet Explorer cache. Often the cache is not corrupt or damaged – it is simply too large.
            1. Click Tools, then Internet Options, and then click the Delete Files button.
            2. A Delete Files window will appear. Select the option to Delete all offline content, and then click OK.
            3. Click Settings and reduce the size of your cache to, say, 50 to 100 MB (more if you routinely download very large files).
            This will invariably fix the dreaded red x, View, Source, and sometimes "Page cannot be displayed" errors. Same thing happens - han g,hang,hang
            Run this online scan. Requires Internet Explorer

            Use the ESET Nod32 Online Scanner

            1. Check the box next to YES, I accept the Terms of Use.
            2. Click Start
            3. When asked, allow the activex control to install
            4. Click Start
            5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
            6. Click Scan
            7. Wait for the scan to finish
            8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
            9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply EsetOnlineScanner Log Tax:
            # version=4
            # OnlineScanner.ocx=1.0.0.635
            # OnlineScannerDLLA.dll=1, 0, 0, 79
            # OnlineScannerDLLW.dll=1, 0, 0, 78
            # OnlineScannerUninstaller.exe=1, 0, 0, 49
            # vers_standard_module=3263 (20080711)
            # vers_arch_module=1.064 (20080214)
            # vers_adv_heur_module=1.064 (20070717)
            # EOSSerial=5d701be7a6df3b42b28279589a4742c3
            # end=stopped
            # remove_checked=true
            # unwanted_checked=true
            # utc_time=2008-07-12 06:42:17
            # local_time=2008-07-12 02:42:17 (+0800, Malay Peninsula Standard Time)
            # country="United States"
            # osver=5.1.2600 NT Service Pack 2
            # scanned=158820
            # found=1
            # scan_time=1623
            E:\Favorites\ÊÕ²Ø.urlprobably a variant of Win32/Agent trojan (unable to clean - deleted)00000000000000000000000000000000
            Looks good. Final steps.

            Set a New Restore Point to prevent possible reinfection from an old one
            Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
            • Go to Start > Programs > Accessories > System Tools and click System Restore
            • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
            • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
            • Next go to Start > Run and type Cleanmgr
            • Click OK
            • Click the More Options Tab.
            • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
            You can find instructions on how to enable and re-enable system restore here:

            Windows XP System Restore Guide or Windows Vista System Restore Guide
            .
            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

            If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

            ----------

            Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

            Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            * Using Winpatrol to protect your computer from malicious software

            I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

            Before i proceed, u think i need to re-scan my pc as i suspect that the first scanning process has been interrupted as i saw -
            "end=stopped" in the Log Tax as my internet connection had been disconnected when i chked the scan;
            AND...
            "scanned=158820"........ which i think shld be more than that.

            Will post a Log Tax again once the scan is completed successfully.

            Thank you
            All rite, This is the complete one:

            # version=4
            # OnlineScanner.ocx=1.0.0.635
            # OnlineScannerDLLA.dll=1, 0, 0, 79
            # OnlineScannerDLLW.dll=1, 0, 0, 78
            # OnlineScannerUninstaller.exe=1, 0, 0, 49
            # vers_standard_module=3263 (20080711)
            # vers_arch_module=1.064 (20080214)
            # vers_adv_heur_module=1.064 (20070717)
            # EOSSerial=5d701be7a6df3b42b28279589a4742c3
            # end=finished
            # remove_checked=true
            # unwanted_checked=true
            # utc_time=2008-07-12 10:00:44
            # local_time=2008-07-12 06:00:44 (+0800, Malay Peninsula Standard Time)
            # country="United States"
            # osver=5.1.2600 NT Service Pack 2
            # scanned=433998
            # found=0
            # scan_time=4271

            Please advise.

            Thank you
            It looks OK.
            2869.

            Solve : What is better Avast or Avira??

            Answer»

            Hey EVERYONE,

            What is a better Anti Virus AVAST or Avira?

            If someone says Avast? How do I USE it to scan? When you click on it in the right on my task bar. It's scanning but won't tell me anything. I had to switch to Avira. How do I use Avast if it's a better program?You right click on Avast icon, and click "START Avast Antivirus".
            Memory scan starts:



            When done, main scanner window opens:



            You click on "Start scan" (indicated by me with red arrow), and scan starts:

            Thank you. Let me TRY it. Is Home free?Yes.

            2870.

            Solve : unknown process?

            Answer»

            and here's a fresh log of HJT

            [recovering disk space -- ATTACHMENT deleted by admin]Download HostsXpert (http://www.majorgeeks.com/Hoster_d4626.html) and then follow the steps below:

            * Unzip HostsXpert.zip
            * It will create a folder named HostsXpert in whatever folder you extract it to.
            * Run HostsXpert.exe by double clicking on it.
            * click the MAKE Writeable? button.
            * click Restore Microsoft's Hosts File and then click OK.
            * Click the X to exit the program

            Post new HJT log.all the help is really much appreciated guys
            here's the new log for HJT

            [recovering disk space -- attachment deleted by admin]*** Are you familiar with Windows Vista Ultimate Keygen? I'm aware, it's a torrent download, but my question is, if you downloaded it, and why do you need to run it on Windows XP?

            *** Download, and run CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
            The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows OPERATING system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is ALSO an option to restore the original one.
            Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

            1. Print this post out, since you won't have an access to it, at some point.

            2. Close all windows, except for HijackThis.

            3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

            - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            - *O4 - HKLM\..\Run: [win.exe] G:\Windows Vista Ultimate Keygen.exe
            - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            - *O4 - HKCU\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
            - *O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
            - *O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
            - *O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            - *O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            - *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            - O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
            - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


            4. Click on Fix checked button.

            5. Restart computer.

            6. Post new HijackThis log.*** Are you familiar with Windows Vista Ultimate Keygen? I'm aware, it's a torrent download, but my question is, if you downloaded it, and why do you need to run it on Windows XP?


            so is that where it came from........ a neighbour was round using my computer a few days ago whilst i was at work and later that night told me they had been searching / researching stuff on vista ultimate !!!!!!!!
            now i know what she was doing....... god *censored* BEEAAATCCCHHHH
            i'll be givin her a mouthful (literally )this is the new HJT log

            [recovering disk space -- attachment deleted by admin]Quote

            now i know what she was doing....... god *censored* BEEAAATCCCHHHH
            LOOOOOOOOOOOOOOOL

            Delete Windows Vista Ultimate Keygen.exe file from G:\ drive, whatever G is.

            When done...



            Your computer is clean

            1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
            Run CCleaner.

            2. Turn off System Restore:

            - Windows XP:
            1. Click Start.
            2. Right-click the My Computer icon, and then click Properties.
            3. Click the System Restore tab.
            4. Check "Turn off System Restore".
            5. Click Apply.
            6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
            7. Click OK.
            - Windows Vista:
            1. Click Start.
            2. Right-click the Computer icon, and then click Properties.
            3. Click on System Protection under the Tasks column on the left side
            4. Click on Continue on the "User Account Control" window that pops up
            5. Under the System Protection tab, find Available Disks
            6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
            7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
            8. Click OK

            3. Restart computer.

            4. Turn System Restore on.

            5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

            6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

            7. Let me know, how your computer is doing.
            thx a million guys , I couldn't have done it without you guys
            totally sorted !!!! 1 more thing , the programs you have recommended to download and install are they all OK to leave on my system or should i save 'em somewhere where i have easy access to 'em ( on a stick )I'm glad, your computer is back to normal
            Did you talk to your neighbour, yet?...LOL

            Leave those programs on your computer. You may occasionally run a scan with Superantispyware, and Malwarebytes.
            Do NOT touch HJT, though, unless asked to. If you PLAY with it, you may end up with unbootable computer.
            2871.

            Solve : Malware removal help (dkinfl)- all steps followed?

            Answer»

            I have/had a virus/spyware/malware PROBLEM and upon doing an internet search I found your forum. I have followed the steps in "Read this before requesting malware removal help".

            Background - I mistakenly authorized a download (my AVE internet security warned me) and immediately knew it was loading bad software. Being a novice I panicked and tried to shutdown my computer and disconnected my high speed internet. When I restarted I had several anti-spyware icons on my desk top. I ran my AVE virus checker and it was finding viruses, but was running very slow. As it continued additional windows popped up warning that software was trying access the internet. At first I clicked OK to not allow access, but then Internet explorer would open. I decided not to click any more windows and just let my virus scan run. At one point the scan stopped before completing it's check. It had removed and placed Trojans and other viruses in the vault. So I cancelled the scan. I was still receiving software unauthorized internet access windows popping up. I decided to run my Max Registry Cleaner to restore a prior registry. Following this no more unauthorized accesses OCCURRED. I reran my virus scan and it ran fast. The only issue I have now is Windows Automatic Update is off and I can't turn it on. It will also not run manually. I received a error code 0x8DDD0018, but Microsoft does not have info on this code.

            I complete all the steps as described in Malware removal help. The logs are attached:
            SUPERANTISPYWARE log, Malwarebytes Log, Hijackthis log.

            [recovering disk space -- attachment deleted by admin]Open Hijackthis and select Do a system scan only then place a check mark next to:

            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            Now click Fix checked, exit Hijackthis and run CCleaner.

            The logs look fine, any more signs of malware?

            -----

            Look here for your error message. http://support.microsoft.com/kb/910337ALRIGHT. You are the BEST. No more signs of malware. Thanks for the Microsoft link, as that fixed the last issue.Glad to help.

            Set a New Restore Point to prevent possible reinfection from an old one
            Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

            • Go to Start > Programs > Accessories > System Tools and click System Restore
            • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
            • The new restore point will be stamped with the CURRENT date and time. Keep a log of this so you can find it easily should you need to use System Restore.
            • Next go to Start > Run and type Cleanmgr
            • Click OK
            • Click the More Options Tab.
            • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
            You can find instructions on how to enable and re-enable system restore here:

            Windows XP System Restore Guide or Windows Vista System Restore Guide
            .
            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a WEEK minimum.

            Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            Using Winpatrol to protect your computer from malicious software

            Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            *Using SpywareBlaster to protect your computer from Spyware and Malware
            *If you don't know what ActiveX controls are, see here

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.I had a problem when trying to run cleanmgr. I did not get a "more options" tab. I got a select drive window.Turn off system restore, restart the computer and turn it back on.

            Windows XP System Restore Guide http://www.bleepingcomputer.com/forums/tutorial56.html
            2872.

            Solve : vanishing text, stretching windows.. WHAT IS THIS???

            Answer»

            Not sure if this is where i need to be.. Perhaps you could redirect me if i you cannot help me,

            I run Windows Vista on my Laptop

            I have been experiencing some strange behavior on my computer..

            Random bits of text seem to vanish from anywhere and everywhere on my computer.. Whether it be from the start menu or folder names. I also EXPERIENCE this on messenger and on some various websites.
            On occasion some "windows" seem to take on obscure lengths or widths

            This doesn't happen all the time though. Restarting the computer can temporarily fix the problem but it either returns soon after or it could be many days before it happens again.
            I have run 3 different virus DETECTORS including kaspersky, and windows live one care.. These DETECTED absolutely nothing.. A clean system.. I have also TRIED a disk defrag and still the problem prevails..
            I've search what seems like every page on the web but cannot find a single thing resembling my issue..
            I have tried formatting.. The problem returned.
            I wondered if it were something wrong with the hardware because soon after the issue occurred my systems performance has diminished. But i was told that a hardware issue won't produce problems like this.

            The only thing I could link to ANY of my computer issues was my D-link wireless adapter.. Not a single thing was wrong with my com till i installed it..

            Can anybody help??

            Anyone that can help would be a godsend!!Have you gone and gotten all Windows updates?I had all windows updates till recently.. And now I cannot install SP1 for Vista. But i was fully up to date when this FIRST occured..

            2873.

            Solve : Am I infested? No symptoms noted but . . .?

            Answer»

            I was on a fan forum for my favorite online game when I clicked on an outside link that supposedly had humour on it. When the site started to load a popup window came up that said something like: Your internet has been running slower than usual install Microsoft Vista Anti-Virus to scan for problems. There were two BUTTONS "OK" and "Cancel". (more or less the message, wish I written it down) I panicked because my father said he got something similar and had (I think) chosen "Cancel" but still ended up with a huge virus that Microsoft had to help him quarantine (but couldn't remove completely). Instead of hitting any of the buttons I touched nothing and powered down my computer completely using the on/off button waited a bit, powered it back on and immediately ran my CCleaner, AVG Free, and Ad-Aware. It found nothing, but worried, I still found your site and followed your instructions down to and including installing and running HijackThis, SuperAntiSpyware, and Malwarebytes. SuperAntiSpyware and Malwarebytes found no problems either but Hijackthis came up with the following log:

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:29:47 AM, on 7/12/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
            C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\PROGRA~1\AVG\AVG8\avgemc.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\PROGRA~1\AVG\AVG8\avgtray.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
            C:\Program Files\Dell Support Center\bin\sprtcmd.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\AVG\AVG8\avgui.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Opera\opera.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\Trend Micro\HijackThis\sniper.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080423
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: ADOBE PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
            O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
            O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
            O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
            O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
            O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

            --
            End of file - 7239 bytes


            Am I infected with anything? My computer is less than 2 months old and I am worried. I have not been experiencing any symptoms but it has only been about 4 hours since I got the popup window.

            If it helps to know, I run Windows XP. My web browser is Opera, but I was previously using Mozilla Firefox. I have never used Internet Explorer on this computer because I heard it is more likely to get viruses than many other browsers.Welcome to CH.

            I don't see any malware but there are a few things to fix.

            Open Hijackthis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
            O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)


            Important: Close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis and run CCleaner.

            ----------

            Your Java is out of date.

            Older versions have vulnerabilities that malicious sites can use to infect your system.

            First install the new Sun Java Runtime Environment

            Remove the old version(s)

            • Go to add/remove programs and uninstall all old versions.
            • Be sure not to remove the new version that was just installed.
            • Download JavaRa and unzip the file to your Desktop.
            • Open JavaRA.exe and CHOOSE Remove Older Versions
            • Once complete exit JavaRA and delete the program.
            • Run CCleaner.
            .
            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

            If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

            ----------

            Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

            Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            * Using Winpatrol to protect your computer from malicious software

            Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Done, thank you!! Just as a side note, when I run CCleaner, is it necessary to check any of the subheadings under Advanced (where it says Old Prefetch Date and such)? I clicked them all when I first installed it over a year ago on my old computer and, when I got this computer 2 months ago and installed CCleaner on it, I just did the same and left them clicked. I really don't know whether that is overkill or something I should have even touched. (Oh to the ignorant who click things when they do not know what they do, lol)
            I usually leave the Advanced settings alone just to be on the safe side.Thank you. Your site was recommended by another player on the online game fan forum I use. You all HELPED him with some Malware he'd picked up browsing the internet. I'll have to let him know it worked for me too. I'll have to recommend you to my father as well. Maybe it will save him a call to Microsoft if something happens again.

            Now that my worry over my new computer is over, I'm going to bed as it's after 1:30 am here .Glad we could help.

            We're much cheaper then MS help is...

            Safe surfing.....
            2874.

            Solve : How do I stop false positives with AVG??

            Answer»

            Hello,

            I found a topic about how do I stop false positives with AVG but not sure what they are talking about.

            Here is the link: HTTP://answers.yahoo.com/question/index?qid=20080511134332AAEl2fO

            The part I am not understand is this part: You need to go to Tools > Advanced Settings, and then under Resident Shield go to Exceptions and ADD the path that ePSXe is in.

            I tried using the search to scan my entire hard DISK for ePSXe and it found no results so I am not sure what to do. Even if it did find results. I am not sure how to add the path. Thank you for any replies.Do you have AVG 8.0? If you do, id reccommend either downloading avast or avira free antivirus in place of it. But, if you do like AVG, id say wait for a malware specialist to help you out The reason I say replace it is because I have heard that a lot of problems have risen since AVG came out wih 8.0Quote from: iamtonsoffun247 on July 08, 2008, 09:52:39 AM

            Do you have AVG 8.0? If you do, id reccommend either downloading avast or avira free antivirus in place of it. But, if you do like AVG, id say wait for a malware specialist to help you out The reason I say replace it is because I have heard that a lot of problems have risen since AVG came out wih 8.0

            I had Avast but I don't know how to use it to scan my computer. I did have AVG 8.0 installed.Is AVG completely uninstalled? And yea, IM not a computer genius, I had trouble finding how to scan the comp with that antivirus too hahaFirst, do you have a problem with false positives?

            SECOND, you need to look at the link that you provided; 'ePSXe' is the program that the poster in your link knew was ok but AVG falsely identified it as a threat. You won't have this file (program) on your computer.

            If the answer to my first question is "No," then don't tinker with AVG's settings. If you are comfortable with AVG and don't have any problems, keep it.

            2875.

            Solve : weird pattern on my screen when booted up?

            Answer»

            hi I have a Compaq computer and it is running office 2000. Something really strange happened, one day I booted it up and there was this really weird Aztec looking background and as soon as it got to the screen where all my icons are my regular display screen came back to normal. However, my web browsers are not working and i cant install any software. An error message comes up something about kernel. I am really confused. I have AVG free edition for anti virus could i still have gotten a virus? Any help would be appreciated. Post exact error message.okay I should have explained this a BIT better. I am still connected to online through a router and it will let aim come up. However the message when the web BROWSER pops up is webpage you request is not available offline. The other message that popped up was when i tried to install windows live on care and I cant remember what it was because I am using a different computer right now and the computer that has these problems is in someones room which i dont have access to at the moment. (if needed I will try to get this info. for you) Also when i ran avg a new thing came up that said wsock32.dll but it just changed it. I dont know if that is something to be concerned with or not. This is the error message I'm talking about:
            Quote

            An error message comes up something about kernel
            Kernel error message is always important, so it MAY help, if we know what it says, exactly.

            Just in case...
            Download HijackThis:
            http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
            Click on Download HijackThis Installer
            Post HijackTHis log.Here is the error message for when i try and install windows live one care.....The procedure entry point attach console could not be located in the dynamic link library kernel32.dll As for the hijack this log its to hard for me to dl something when i cant get online because the web browser is mest up. I can only get online from this computer. Can you download it from the comp you are using to post with and put it on a jump drive or cd and then install it on the other comp?Are you sure about "attach console" part? I can't find any reference to it.

            Also, proceed with mroilfield's advice.
            You may also, go Start>Run, and TYPE in:
            sfc /scannow
            Click OK.
            Have Windows CD handy.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 1:53:09 AM, on 7/9/2008
            Platform: Windows 2000 SP3 (WinNT 5.00.2195)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
            Boot mode: Normal

            Running processes:
            C:\WINNT\System32\smss.exe
            C:\WINNT\system32\winlogon.exe
            C:\WINNT\system32\services.exe
            C:\WINNT\system32\lsass.exe
            C:\WINNT\system32\svchost.exe
            C:\WINNT\system32\spoolsv.exe
            C:\WINNT\system32\acs.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            C:\WINNT\System32\svchost.exe
            C:\WINNT\system32\hidserv.exe
            C:\Program Files\PC Tools Firewall Plus\FWService.exe
            C:\WINNT\system32\regsvc.exe
            C:\WINNT\system32\MSTask.exe
            C:\WINNT\system32\stisvc.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
            C:\WINNT\System32\WBEM\WinMgmt.exe
            C:\WINNT\system32\svchost.exe
            C:\WINNT\System32\svchost.exe
            C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
            C:\WINNT\Explorer.EXE
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
            C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
            C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\Program Files\AIM\aim.exe
            C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
            C:\Program Files\Belkin\PCI F5D7000\Wireless Utility\Belkinwcui.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
            C:\Documents and Settings\braun2go\Desktop\HJTInstall.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O3 - Toolbar: @msdxmLC.dll,[emailprotected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [dcsm] "C:\Program Files\Common Files\DriveCleaner Free\dcsm.exe"
            O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
            O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
            O4 - Global Startup: Belkin Wireless Utility.lnk = C:\Program Files\Belkin\PCI F5D7000\Wireless Utility\Belkinwcui.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra button: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
            O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
            O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170625035390
            O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINNT\system32\acs.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
            O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
            O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe

            --
            End of file - 6439 bytes
            There are some infections...

            Using same method transfer, and run....

            Print these instructions out.

            1. Download SUPERAntiSpyware Free for Home Users:
            http://www.superantispyware.com/

            * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
            * An icon will be created on your desktop. Double-click that icon to launch the program.
            * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
            * Close SUPERAntiSpyware.

            PHYSICALLY DISCONNECT FROM THE INTERNET

            Restart computer in Safe Mode.
            To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

            * Open SUPERAntiSpyware.
            * Under "Configuration and Preferences", click the Preferences button.
            * Click the Scanning Control tab.
            * Under Scanner Options make sure the following are checked (leave all others unchecked):
            o Close browsers before scanning.
            o Scan for tracking cookies.
            o Terminate memory threats before quarantining.
            * Click the "Close" button to leave the control center screen.
            * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
            * On the left, make sure you check C:\Fixed Drive.
            * On the right, under "Complete Scan", choose Perform Complete Scan.
            * Click "Next" to start the scan. Please be patient while it scans your computer.
            * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
            * Make sure everything has a checkmark next to it and click "Next".
            * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
            * If asked if you want to reboot, click "Yes".
            * To retrieve the removal information after reboot, launch SUPERAntispyware again.
            o Click Preferences, then click the Statistics/Logs tab.
            o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
            o If there are SEVERAL logs, click the current dated log and press View log. A text file will open in your default text editor.
            o Please copy and paste the Scan Log results in your next reply.
            * Click Close to exit the program.
            Post SUPERAntiSpyware log.

            RECONNECT TO THE INTERNET

            RESTART COMPUTER!

            2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

            * Double-click mbam-setup.exe and follow the prompts to install the program.
            * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
            * If an update is found, it will download and install the latest version.
            * Once the program has loaded, select Perform full scan, then click Scan.
            * When the scan is complete, click OK, then Show Results to view the results.
            * Be sure that everything is checked, and click Remove Selected.
            * When completed, a log will open in Notepad.
            * Post the log back here.

            The log can also be found here:
            C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
            Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

            RESTART COMPUTER!

            3. Post new HijackThis log.Here is the information that you requested.



            [recovering disk space -- attachment deleted by admin]*** You need to update Java:
            http://java.sun.com/javase/downloads/index.jsp
            Java Runtime Environment (JRE) 6 Update 7
            Uninstall all previous versions of Java through Add\Remove.

            *** Go to Add\Remove, and uninstall NetRatingsNetSight, and DriveCleaner Free
            Uninstall any of the following programs associated with Viewpoint:
            * Viewpoint Manager
            * Viewpoint Media Player
            * Viewpoint Toolbar

            This program does not do anything bad such as deliver ads or spy on you, but it is considered foistware ("drive-by-install") as it is installed without your consent through programs like AOl, AIM, Compuserve, etc.

            1. Print this post out, since you won't have an access to it, at some point.

            2. Close all windows, except for HijackThis.

            3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

            - O4 - HKLM\..\Run: [dcsm] "C:\Program Files\Common Files\DriveCleaner Free\dcsm.exe"
            - O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
            - *O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
            - *O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            - *O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
            - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            - *O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
            - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            - *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            - O9 - Extra button: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
            - O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            - O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

            4. Click on Fix checked button.

            5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

            6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

            7. Delete following files/folders (if present):

            - DriveCleaner Free folder from C:\Program Files\Common Files
            - NetRatingsNetSight, and Viewpoint folders from C:\Program Files

            8. Restart in Normal Mode.

            9. Post new HijackThis log.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 1:37:06 AM, on 7/12/2008
            Platform: Windows 2000 SP3 (WinNT 5.00.2195)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
            Boot mode: Safe mode

            Running processes:
            C:\WINNT\System32\smss.exe
            C:\WINNT\system32\winlogon.exe
            C:\WINNT\system32\services.exe
            C:\WINNT\system32\lsass.exe
            C:\WINNT\system32\svchost.exe
            C:\WINNT\System32\WBEM\WinMgmt.exe
            C:\WINNT\Explorer.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O3 - Toolbar: @msdxmLC.dll,[emailprotected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
            O4 - Global Startup: Belkin Wireless Utility.lnk = C:\Program Files\Belkin\PCI F5D7000\Wireless Utility\Belkinwcui.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
            O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
            O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170625035390
            O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINNT\system32\acs.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
            O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
            O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe

            --
            End of file - 4301 bytes
            I need HJT log from Normal, not Safe Mode.
            2876.

            Solve : Can someone check this for me please??

            Answer»

            This is a log, not of my own computer but of someone else's.
            It had a lot of issues at first but me and my friend have fixed them all.
            I uninstalled Norton and installed AVG and Spybot.
            Spybot found nothing, AVG found 3 viruses and two threats - if I remember correctly the viruses were named as w32.heur and the threats were adware.generic and something like adware/cc3.generic, I can't recall the exact names.
            The viruses APPEARED to be remnants of Norton which I found odd.
            The computer wasn't showing any signs of virus infection - no popups etc.
            The OS is XP Home - it started off with SP1, I had to update to SP2 to install AVG, and then after it appeared fine it was updated to SP3.
            Anyway, I'd be grateful if someone can take a look at the HJT log for me and see if anything is wrong with it.

            Thanks in advance.

            [Log follows]


            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:40:06, on 09/07/2008
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0013)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
            C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\UPHClean\uphclean.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\Logi_MwX.Exe
            C:\Program Files\iRiver\HSeries\iHPDetect.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wuauclt.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.orange.co.uk
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R3 - URLSearchHook: (no name) - {4FBACD73-F67C-42AE-B46A-03960AFE3DFB} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
            O2 - BHO: Adobe PDF Reader LINK Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: PopupKiller Class - {49E489BF-C4B8-11D6-9547-00C0DFF1DE9E} - C:\PROGRA~1\NoPops\NoPops.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
            O3 - Toolbar: Orange Toolbar - {E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12} - C:\Program Files\Orange Toolbar UK\ToolbarContainer230.dll
            O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
            O4 - HKLM\..\Run: [iHP-100] C:\Program Files\iRiver\HSeries\iHPDetect.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
            O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: MESSENGER - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
            O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
            O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/277b50a32e3d02c1dc18/netzip/RdxIE601.cab
            O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150198831734
            O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
            O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: ptssvc - Unknown owner - C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe

            --
            End of file - 5710 bytesI don't see any antivirus installed?

            C:\PROGRA~1\NoPops\NoPops.dll <- This program has had some questionable tactics in the past and the company (SpyBlocs) is listed on http://www.spywarewarrior.com/rogue_anti-spyware.htm

            Look in add/remove programs for PopupKiller or NoPops and uninstall it. (if there)

            Have HJT fix these entries.

            - O2 - BHO: PopupKiller Class - {49E489BF-C4B8-11D6-9547-00C0DFF1DE9E} - C:\PROGRA~1\NoPops\NoPops.dll
            - O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm

            ----------

            Delete the folder C:\Program Files\NoPops

            ----------

            I think it would be wise to run MBAM

            Download Malwarebytes' Anti-Malware from here or here

            Double Click mbam-setup.exe to install the application.

            • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
            • If an update is found, it will download and install the latest version.
            • Once the program has loaded, select "Perform Quick Scan", then click Scan.
            • The scan may take some time to finish,so please be patient.
            • When the scan is complete, click OK, then Show Results to VIEW the results.
            • Make sure that everything is checked, and click Remove Selected.
            • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
            • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
            • Copy&Paste the entire report in your next reply.
            Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

            There is no AV installed right now as I removed AVG, he's dead set on reinstalling Norton despite my best efforts.
            I'll remove NoPops, I did wonder if that was legit or not but didn't have time to research yesterday.
            I'll run MBAM in a few minutes, and will edit this post with the log when it's done (I have to disconnect this computer to plug in the other one you see so I can't do it right now).

            Edit: Sorry, took longer than I thought because I had some other things to do.
            Here it is, it found Hotbar and successfully removed it, the next scan was clean.

            Malwarebytes' Anti-Malware 1.20
            Database version: 932
            Windows 5.1.2600 Service Pack 3

            11:22:21 10/07/2008
            mbam-log-7-10-2008 (11-22-21).txt

            Scan type: Quick Scan
            Objects scanned: 39593
            Time elapsed: 3 minute(s), 48 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 0
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 1
            Files Infected: 1

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            (No malicious items detected)

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            C:\Program Files\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.

            Files Infected:
            C:\Program Files\Hotbar\Hotbar.log (Adware.Hotbar) -> Quarantined and deleted successfully.
            Looks like you got rid of everything.Cool, thanks for the help.
            Now I just need to get hold of the guy to give his computer back . . .
            2877.

            Solve : HELP: Cannot access certain websites?

            Answer»

            Hello. Let me start out by saying that I am not the most Tech-Savy guy out there, but I do know a bit about computers. My computer is custom built and has not had any major problems until now.

            Last night, i rebooted my computer because it was acting funky, when i tried to reaccess the websites i was on (myspace, dictionary.com, google) there was no action taken at all. I am currently using the latest version of Modzilla firefox. I will go to open firefox, and it will load my homepage with ease, then when i type in a URL, it just sits there, with the 'loading' action in the upper righthand corner. What websites usually load in less than 2 seconds, now will not load within 3 hours.

            What's worse, is that some websites do infact work with ease, like youtube, this one, and several other 'low traffic' websites.

            I have pinged myspace, dictionary.com, and google, all returning packets within a short amount of time. It was then that I did a virus scan and discovered I was infected with the Vundo Trojan. I figured that this would be the problem, so I spent the past 5 hours getting it off my machine with a combination of Spybot Search & Destroy and manual removal. I am 95% sure that it is fully removed as Spybot doesn't list anything, and I haven't gotten any annoying popups lately.

            After I removed Vundo, I attempted to retry accessing myspace again, but the same thing happened. I tried opening firefox in SAFEMODE, and i also tried PUTTING the entire computer in safemode, both of which didn't work.

            This problem occurs with Firefox and with Windows Internet Explorer. Please help.

            Thanks for reading!Let's make sure, your computer is clean, first.

            Print these instructions out.

            1. Download SUPERAntiSpyware Free for Home Users:
            http://www.superantispyware.com/

            * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
            * An icon will be created on your desktop. Double-click that icon to launch the program.
            * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
            * Close SUPERAntiSpyware.

            PHYSICALLY DISCONNECT FROM THE INTERNET

            Restart computer in Safe Mode.
            To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

            * Open SUPERAntiSpyware.
            * Under "Configuration and Preferences", click the Preferences button.
            * Click the Scanning Control tab.
            * Under SCANNER Options make sure the following are checked (leave all others unchecked):
            o Close browsers before scanning.
            o Scan for tracking COOKIES.
            o Terminate memory threats before quarantining.
            * Click the "Close" button to leave the control center screen.
            * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
            * On the left, make sure you check C:\Fixed Drive.
            * On the RIGHT, under "Complete Scan", choose Perform Complete Scan.
            * Click "Next" to start the scan. Please be patient while it scans your computer.
            * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
            * Make sure everything has a checkmark next to it and click "Next".
            * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
            * If asked if you want to reboot, click "Yes".
            * To retrieve the removal information after reboot, launch SUPERAntispyware again.
            o Click Preferences, then click the Statistics/Logs tab.
            o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
            o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
            o Please copy and paste the Scan Log results in your next reply.
            * Click Close to exit the program.
            Post SUPERAntiSpyware log.

            RECONNECT TO THE INTERNET

            RESTART COMPUTER!

            2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

            * Double-click mbam-setup.exe and follow the prompts to install the program.
            * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
            * If an update is found, it will download and install the latest version.
            * Once the program has loaded, select Perform full scan, then click Scan.
            * When the scan is complete, click OK, then Show Results to view the results.
            * Be sure that everything is checked, and click Remove Selected.
            * When completed, a log will open in Notepad.
            * Post the log back here.

            The log can also be found here:
            C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
            Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

            RESTART COMPUTER!

            3. Download HijackThis:
            http://www.snapfiles.com/get/hijackthis.html
            Post HijackThis log.

            2878.

            Solve : Item in Spybot S&D?

            Answer»

            Everytime I run Spybot S&AMP;D, I GET this item. should I FIX it or not?
            Microsoft.WindowsSecurityCenter.AntiVir usOverride: [SBI $3604910C] Settings (Registry change, nothing done)
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride
            Read here: http://forums.spybot.info/archive/index.php/t-205.htmlThanks Broni, but all my protection is updated and functioning. I wonder what is this message trying to tell me?What version of Spybot do you have?

            To find out open Spybot and click Help > About.

            Post what all of the numbers say here. It will either start with 1.4 or 1.5.1.5.2.20Uninstall that version in add/remove programs then install the new 1.6 version. http://filehippo.com/download_spybot_search_destroy/

            Run a new SCAN and see if it still reports the Registry change.I upgrade Spybot on my laptop and my PC. The laptop with Vista didn't show this item but it showed up on my PC.They probably won't show on Vista but will on XP.

            From the Spybot forums see HERE.

            Thanks, Evil. At least Vista is showing me why it is SUPPOSEDLY better than XP.

            2879.

            Solve : Computer shuts off when scanning for virus........?

            Answer»

            I've fixed all my problems. I just downloaded sum malware software removal tool.......fixed my problem. Thanks for all you guyz help.Well...we're glad your problem seems to be RESOLVED on your end.

            However, based on the STOP error you supplied us, there may have been another ISSUE at fault here.

            Please review the following page from Microsoft regarding probable causes and RESOLUTIONS to this particular STOP error code:

            http://support.microsoft.com/default.aspx?scid=kb;en-us;137539

            You might want to save the above link as a favorite...just in case that STOP error code rears its ugly face again...

            Good luck!Quote

            I just downloaded sum malware software removal tool.......fixed my problem.
            Without SEEING all logs, there is no guarantee, the INFECTION is completely gone.
            2880.

            Solve : Re: Computer shuts off when scanning for virus........?

            Answer»

            Uh instead of starting a new topic, I'll just use this one I PRETTY much have the same problem as he had, but I can't finish a scan with MalwareBytes, or SuperantiSpyware. I did do the HijackThis scan though, and thus far it seems to be the only one that finishes without the blue screen appearing. I'm currently in Safe Mode with Networking, so that I can try to figure out how to get it off. I don't know if it helps, but I know the approximate location of where it is located, but every time I try to access/delete the file the blue screen pops-up.

            Here is the HijackThis log.

            Logfile of HijackThis v1.99.1
            Scan saved at 11:14:39 AM, on 7/11/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\SYSTEM32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\HijackThis\Crusty.exe.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.BIN\MWSSRCAS.DLL
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
            O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: Seekmo /fleok=1D8A83A5C5E3147799AB6B2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
            O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
            O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O2 - BHO: (no name) - {184746EC-9E9D-4C7D-B9E7-9039EBD801A9} - (no file)
            O2 - BHO: MSVPS System - {2D42D689-4B94-4734-92C2-606FC5F4C15D} - C:\WINDOWS\oprevtdp.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
            O2 - BHO: Colej_uk Design Toolbar Helper - {54F3259F-8CF4-496a-9ECC-857410855A50} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            O2 - BHO: (no name) - {554A64A5-4E29-48F0-A729-BDF50CE38199} - C:\WINDOWS\system32\pmkhe.dll (file missing)
            O2 - BHO: WarningBHO Class - {56FA7933-DC3E-403b-8D47-BB5E3F345A21} - C:\Program Files\AntiSpyCheck\IEWarning.dll (file missing)
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - (no file)
            O2 - BHO: Video BHO - {681147C4-D615-461A-960F-655871E315C3} - C:\WINDOWS\pnop64.dll
            O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
            O2 - BHO: (no name) - {99BA268B-4021-4739-9945-3C774217FE75} - C:\Program Files\NetProject\sbmdl.dll
            O2 - BHO: Colej_uk Design Toolbar Helper - {A62CB71D-6EC8-4065-8EEC-07B224364A2B} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\fccyvuu.dll (file missing)
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
            O2 - BHO: (no name) - {DE965520-995B-40B9-B0BA-840F79BCCCC7} - (no file)
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            O3 - Toolbar: (no name) - {C6139A57-16FB-4FA4-8045-A847FBFFD695} - (no file)
            O3 - Toolbar: (no name) - {2E608F70-C430-4bc5-96F6-608E02EBA5B2} - (no file)
            O3 - Toolbar: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
            O3 - Toolbar: Colej_uk Design Toolbar - {A45D8289-FFA3-4cd8-B83A-F84F7173B2CE} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            O3 - Toolbar: (no name) - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - (no file)
            O3 - Toolbar: (no name) - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - (no file)
            O3 - Toolbar: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
            O3 - Toolbar: The bonsws - {CBF19702-9D5B-44E7-8F8A-6750209B76F3} - C:\WINDOWS\bonsws.dll
            O3 - Toolbar: Colej_uk Design Toolbar - {7E895BD9-C3B7-4bc2-A7B8-758531866F00} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O3 - Toolbar: Internet Service - {51D81DD5-55B7-497F-95DB-D356429BB54E} - C:\Program Files\NetProject\wamdl.dll
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\VirtualDrive\VHD\RDTask.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
            O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
            O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe
            O4 - HKLM\..\Run: [Maplom] "C:\Program Files\SlySoft\Game Jackal\GameJackal.exe" /silent
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe"
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
            O4 - HKLM\..\Run: [BOC-426] C:\PROGRA~1\Comodo\CBOClean\BOC426.exe
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [cnfgCav] "C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe"
            O4 - HKLM\..\Run: [cavUPSDBMaker] "C:\Program Files\Comodo\Comodo AntiVirus\UPSDBMaker.exe"
            O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZK
            O9 - Extra button: (no name) - Software - (no file)
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
            O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, VERSION 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://activation.alltel.com/wizlet/ALLTEL/static/controls/WebflowActiveXInstaller_2-0-0.cab
            O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
            O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?972760012750
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138820922273
            O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
            O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
            O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.0/installer.exe
            O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4661/mcfscan.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CCS\Services\Tcpip\..\{5662E96D-9C96-43F6-A6DC-939C5998F76B}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CCS\Services\Tcpip\..\{6B86BE84-DF68-4669-AF92-F283A0FA8B24}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS1\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS2\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS3\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS4\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
            O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O20 - Winlogon Notify: fccyvuu - fccyvuu.dll (file missing)
            O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
            O20 - Winlogon Notify: monln - C:\WINDOWS\SYSTEM32\monln.dll
            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
            O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
            O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
            O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
            O23 - Service: Comodo Anti-Virus and Anti-Spyware Service - Comodo Inc. - C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
            O23 - Service: DomainService - - C:\WINDOWS\system32\hcekpaim.exe
            O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
            O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
            O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
            O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
            O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
            O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
            O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
            O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
            O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

            Moved to new topic.

            It's always best to start a new topic. It gets too confusing working in someone elses thread.

            Open Hijackthis and select Do a system scan only then place a check mark next to the following entries.

            • R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
            • R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            • O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            • O2 - BHO: Seekmo /fleok=1D8A83A5C5E3147799AB6B2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
            • O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
            • O2 - BHO: (no name) - {184746EC-9E9D-4C7D-B9E7-9039EBD801A9} - (no file)
            • O2 - BHO: MSVPS System - {2D42D689-4B94-4734-92C2-606FC5F4C15D} - C:\WINDOWS\oprevtdp.dll
            • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
            • O2 - BHO: Colej_uk Design Toolbar Helper - {54F3259F-8CF4-496a-9ECC-857410855A50} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            • O2 - BHO: (no name) - {554A64A5-4E29-48F0-A729-BDF50CE38199} - C:\WINDOWS\system32\pmkhe.dll (file missing)
            • O2 - BHO: WarningBHO Class - {56FA7933-DC3E-403b-8D47-BB5E3F345A21} - C:\Program Files\AntiSpyCheck\IEWarning.dll (file missing)
            • O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - (no file)
            • O2 - BHO: Video BHO - {681147C4-D615-461A-960F-655871E315C3} - C:\WINDOWS\pnop64.dll
            • O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
            • O2 - BHO: (no name) - {99BA268B-4021-4739-9945-3C774217FE75} - C:\Program Files\NetProject\sbmdl.dll
            • O2 - BHO: Colej_uk Design Toolbar Helper - {A62CB71D-6EC8-4065-8EEC-07B224364A2B} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            • O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\fccyvuu.dll (file missing)
            • O2 - BHO: (no name) - {DE965520-995B-40B9-B0BA-840F79BCCCC7} - (no file)
            • O3 - Toolbar: (no name) - {C6139A57-16FB-4FA4-8045-A847FBFFD695} - (no file)
            • O3 - Toolbar: (no name) - {2E608F70-C430-4bc5-96F6-608E02EBA5B2} - (no file)
            • O3 - Toolbar: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
            • O3 - Toolbar: Colej_uk Design Toolbar - {A45D8289-FFA3-4cd8-B83A-F84F7173B2CE} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            • O3 - Toolbar: (no name) - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - (no file)
            • O3 - Toolbar: (no name) - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - (no file)
            • O3 - Toolbar: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
            • O3 - Toolbar: Colej_uk Design Toolbar - {7E895BD9-C3B7-4bc2-A7B8-758531866F00} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            • O9 - Extra button: (no name) - Software - (no file)
            • O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            • O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            • O20 - Winlogon Notify: fccyvuu - fccyvuu.dll (file missing)
            .
            Now close all windows except for Hijackthis and click Fix checked

            Exit Hijackthis and run CCleaner.

            ----------

            Extra cleaning...

            Delete TEMPORARY FILES

            Go to:
            • Start
            • Run
            • type: CLEANMGR.EXE
            • Press Enter.
            When prompted select the C: drive and click OK.
            Check the boxes for:
            • Temporary Internet Files
            • Downloaded Program Files
            • Recycle Bin
            • Temporary Files
            Click OK or Enter

            ----------

            Download FixWareout by LonnyRJonesfrom one of the two below links and save it to your desktop.
            • Run Fixwareout.
            • Click Next
            • then Install
            • Make sure Run fixit is checked
            • Click Finish.
            • The fix will begin; follow the prompts.
            • You will be asked to reboot your computer; please do so.
            • Your system may take longer than usual to load; this is normal.
            When you run fixwareout, just follow the prompts, you will need to restart when prompted.

            After rebooting (restart) back into normal boot mode. Make sure you have all web browsers closed.
            • Go into Control Panel > Network Connections.
            • Right click on your connection
            • and click Properties.
            • On the Properties page, highlight Internet Protocol(TCP/IP)
            • Click Properties. This will bring up another page.
            • Select Obtain DNS Server Automatically.
            • Click the ok button. The page will close.
            • Press ok on the page in front of you.
            • Restart the computer.
            • Reconnect to the Internet using Internet Explorer.
            • Add the log from fixwareout in your next reply.
            • It will be located at c:\fixwareout\report.txt
            .
            ----------

            Download SDFix.exe and save it to your Desktop.

            Double click SDFix.exe and it will extract the files to %systemdrive%
            (Drive that contains the Windows Directory, typically C:\SDFix)

            Now then reboot your computer in Safe Mode by doing the following:
            • Restart your computer
            • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
            • Instead of Windows loading as normal, the Advanced Options Menu should appear;
            • Select the first option, to run Windows in Safe Mode, then press Enter.
            • Choose your usual account.
            • Open the extracted SDFix folder and double click RunThis.bat to start the script.
            • Type Y to begin the cleanup process.
            • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
            • Press any Key and it will restart the PC.
            • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
            • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
              (Report.txt will also be copied to Clipboard).
            • Finally copy and paste the contents of the results file Report.txt with a NEW HijackThis log in your next reply.
            .
            If SDFix won't run or you get errors, follow the link for instructions on running SDFix. How to use SDFix

            ----------

            Before running HJT please install and rename the new version.

            Download and rename TrendMicro HijackThis.exe (HJT)

            ----------

            Next post add
            fixwareout log
            SDFix log
            New HJT log
            It doesn't seem to have worked. The blue screen keeps coming up.


            Heres the FixWareOut log.

            ~~~~~ Prerun check

            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
            "nameserver"="85.255.115.59 85.255.112.133" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}
            "nameserver"="85.255.115.59,85.255.112.133" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{5662E96D-9C96-43F6-A6DC-939C5998F76B}
            "nameserver"="85.255.115.59,85.255.112.133" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{6B86BE84-DF68-4669-AF92-F283A0FA8B24}
            "nameserver"="85.255.115.59,85.255.112.133" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{950BAE7D-BAD5-4015-9AEC-1E59874A9BF2}
            "DhcpNameServer"="85.255.115.59,85.255.112.133"
            Could not flush the DNS Resolver Cache: Function failed during execution.


            System was rebooted successfully.

            ~~~~~ Postrun check
            HKLM\SOFTWARE\~\Winlogon\ "System"=""
            ....
            ....
            ~~~~~ Misc files.
            ....
            ~~~~~ Checking for older varients.
            ....

            ~~~~~ Current runs (hklm hkcu "run" Keys Only)
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
            65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
            "VirtualDrive"="\"C:\\Program Files\\FarStone\\VirtualDrive\\VDTask.exe\" /AutoRestore"
            "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe\""
            "StorageGuard"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
            "RAMDrive"="\"C:\\Program Files\\FarStone\\VirtualDrive\\VHD\\RDTask.exe\""
            "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
            "PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
            "MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwsoemon.exe"
            "Motive SmartBridge"="C:\\PROGRA~1\\ALLTEL~1\\SMARTB~1\\MotiveSB.exe"
            "Maplom"="\"C:\\Program Files\\SlySoft\\Game Jackal\\GameJackal.exe\" /silent"
            "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
            "HP Software Update"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
            "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
            "Corel Photo Downloader"="\"C:\\Program Files\\Corel\\Corel Photo Album 6\\MediaDetect.exe\""
            "AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"
            "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
            "SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"
            "BOC-426"="C:\\PROGRA~1\\Comodo\\CBOClean\\BOC426.exe"
            "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
            "cnfgCav"="\"C:\\Program Files\\Comodo\\Comodo AntiVirus\\CMain.exe\""
            "cavUPSDBMaker"="\"C:\\Program Files\\Comodo\\Comodo AntiVirus\\UPSDBMaker.exe\""

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            ....
            Hosts file was reset, If you use a custom hosts file please replace it...
            ~~~~~ End report ~~~~~

            I'm not sure, but this seems to be the SDFix report.

            tchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-07-11 14:31:28
            Windows 5.1.2600 Service Pack 2 NTFS

            scanning hidden files ...

            IPC error: 2 The system cannot find the file specified.
            scan completed successfully
            hidden files: 0Quote from: nightscout on July 11, 2008, 02:21:51 PM
            It doesn't seem to have worked. The blue screen keeps coming up.

            This is going to take multiple steps, so we are likely far from complete.

            The SDFix log is incomplete.

            Install the new version of Hjackthis but don't run it YET. Instead now run DSS and post the logs.

            Download Deckard's System Scanner (DSS) to your Desktop.
            Note: You must be logged onto an account with administrator privileges.
            Vista users Right click DSS and Run as Administrator.

            • Close all applications and windows.
            • Double-click on dss.exe to run it, and follow the prompts.
            • When the scan is complete, two text files will open.
              • main.txt <- this one will be maximized
              • extra.txt <- this one will be minimized
            • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply.
            I can't post either of them all at once. So I'll have to split them up.

            Heres the first half of the main one.

            Deckard's System Scanner v20071014.68
            Run by Glen on 2008-07-11 16:41:36
            Computer is in Safe Mode with Networking.
            --------------------------------------------------------------------------------

            -- System Restore --------------------------------------------------------------

            Unable to create WMI object; The operation completed successfully.


            Backed up registry hives.
            Performed disk cleanup.



            -- HijackThis (run as Glen.exe) ------------------------------------------------

            Logfile of HijackThis v1.99.1
            Scan saved at 4:43:14 PM, on 7/11/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\SYSTEM32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            C:\Program Files\Virtual Villagers - The Secret City\Virtual Villagers - The Secret City.exe
            C:\Program Files\Virtual Villagers - The Secret City\Virtual Villagers - The Secret City.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\Glen\Desktop\dss.exe
            C:\PROGRA~1\HIJACK~1\Glen.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\VirtualDrive\VHD\RDTask.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
            O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
            O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe
            O4 - HKLM\..\Run: [Maplom] "C:\Program Files\SlySoft\Game Jackal\GameJackal.exe" /silent
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe"
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
            O4 - HKLM\..\Run: [BOC-426] C:\PROGRA~1\Comodo\CBOClean\BOC426.exe
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [cnfgCav] "C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe"
            O4 - HKLM\..\Run: [cavUPSDBMaker] "C:\Program Files\Comodo\Comodo AntiVirus\UPSDBMaker.exe"
            O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
            O4 - HKLM\..\RunOnce: [SDFix] C:\SDFix\RunThis.bat /second
            O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZK
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\WINDOWS\System32\shdocvw.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\cavemlsp.dll
            O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
            O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://activation.alltel.com/wizlet/ALLTEL/static/controls/WebflowActiveXInstaller_2-0-0.cab
            O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
            O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?972760012750
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138820922273
            O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
            O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
            O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install3.0/installer.exe
            O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4661/mcfscan.cab
            O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS1\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.115.59 85.255.112.133
            O17 - HKLM\System\CS4\Services\Tcpip\..\{012B82A0-78A8-4153-8FED-9AD0B15B07F9}: NameServer = 85.255.115.59,85.255.112.133
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
            O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
            O20 - Winlogon Notify: monln - C:\WINDOWS\SYSTEM32\monln.dll
            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
            O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
            O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
            O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
            O23 - Service: Comodo Anti-Virus and Anti-Spyware Service - Comodo Inc. - C:\Program Files\Comodo\common\CAVASpy\cavasm.exe
            O23 - Service: DomainService - - C:\WINDOWS\system32\hcekpaim.exe
            O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
            O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
            O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
            O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
            O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
            O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
            O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
            O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
            O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


            -- HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) --------------------

            backup-20080711-135433-149 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            backup-20080711-135433-369 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
            backup-20080711-135433-452 R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
            backup-20080711-135433-492 O2 - BHO: (no name) - {184746EC-9E9D-4C7D-B9E7-9039EBD801A9} - (no file)
            backup-20080711-135433-500 O2 - BHO: (no name) - {554A64A5-4E29-48F0-A729-BDF50CE38199} - C:\WINDOWS\system32\pmkhe.dll (file missing)
            backup-20080711-135433-608 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
            backup-20080711-135433-745 O2 - BHO: Colej_uk Design Toolbar Helper - {54F3259F-8CF4-496a-9ECC-857410855A50} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            backup-20080711-135433-752 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
            backup-20080711-135433-793 O2 - BHO: Seekmo /fleok=1D8A83A5C5E3147799AB6B2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
            backup-20080711-135433-822 O2 - BHO: MSVPS System - {2D42D689-4B94-4734-92C2-606FC5F4C15D} - C:\WINDOWS\oprevtdp.dll
            backup-20080711-135434-105 O3 - Toolbar: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
            backup-20080711-135434-154 O3 - Toolbar: (no name) - {2E608F70-C430-4bc5-96F6-608E02EBA5B2} - (no file)
            backup-20080711-135434-203 O3 - Toolbar: Colej_uk Design Toolbar - {7E895BD9-C3B7-4bc2-A7B8-758531866F00} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            backup-20080711-135434-244 O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            backup-20080711-135434-270 O2 - BHO: Video BHO - {681147C4-D615-461A-960F-655871E315C3} - C:\WINDOWS\pnop64.dll
            backup-20080711-135434-282 O3 - Toolbar: (no name) - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - (no file)
            backup-20080711-135434-317 O2 - BHO: WarningBHO Class - {56FA7933-DC3E-403b-8D47-BB5E3F345A21} - C:\Program Files\AntiSpyCheck\IEWarning.dll (file missing)
            backup-20080711-135434-340 O3 - Toolbar: (no name) - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - (no file)
            backup-20080711-135434-382 O3 - Toolbar: (no name) - {C6139A57-16FB-4FA4-8045-A847FBFFD695} - (no file)
            backup-20080711-135434-574 O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
            backup-20080711-135434-593 O20 - Winlogon Notify: fccyvuu - fccyvuu.dll (file missing)
            backup-20080711-135434-676 O9 - Extra button: (no name) - Software - (no file)
            backup-20080711-135434-679 O2 - BHO: Colej_uk Design Toolbar Helper - {A62CB71D-6EC8-4065-8EEC-07B224364A2B} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)
            backup-20080711-135434-720 O3 - Toolbar: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - (no file)
            backup-20080711-135434-743 O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\fccyvuu.dll (file missing)
            backup-20080711-135434-810 O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.ietoolpro.com/redirect.php (file missing)
            backup-20080711-135434-822 O2 - BHO: (no name) - {DE965520-995B-40B9-B0BA-840F79BCCCC7} - (no file)
            backup-20080711-135434-840 O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - (no file)
            backup-20080711-135434-849 O2 - BHO: (no name) - {99BA268B-4021-4739-9945-3C774217FE75} - C:\Program Files\NetProject\sbmdl.dll
            backup-20080711-135434-987 O3 - Toolbar: Colej_uk Design Toolbar - {A45D8289-FFA3-4cd8-B83A-F84F7173B2CE} - C:\Program Files\Colej_uk Design Toolbar\v2.0.0.5\Colej_uk_Design_Toolbar.dll (file missing)

            -- File Associations -----------------------------------------------------------

            All associations okay.


            -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

            2 atksgt - c:\windows\system32\drivers\atksgt.sys
            1 AvgLdx86 (AVG Free AVI Loader Driver x86) - c:\windows\system32\drivers\avgldx86.sys (file missing)
            1 AvgMfx86 (AVG Free On-access Scanner Minifilter Driver x86) - c:\windows\system32\drivers\avgmfx86.sys (file missing)
            2 AvgTdiX (AVG Free8 Network Redirector) - c:\windows\system32\drivers\avgtdix.sys (file missing)
            3 BW2NDIS5 - system32\drivers\bw2ndis5.sys (file missing)
            3 catchme - c:\docume~1\glen\locals~1\temp\catchme.sys (file missing)
            0 Cavasm - c:\windows\system32\drivers\cavasm.sys
            3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
            3 L2XPSR - c:\progra~1\effici~1\tangom~1\app\l2xpsr.sys (file missing)
            2 lirsgt - c:\windows\system32\drivers\lirsgt.sys
            3 nenum13E - c:\docume~1\mawmaw\locals~1\temp\nenum13e.sys (file missing)
            2 npkcrypt - c:\program files\triglowpictures\pristontale\npkcrypt.sys (file missing)
            1 OMCI - c:\windows\system32\drivers\omci.sys
            1 oreans32 - c:\windows\system32\drivers\oreans32.sys
            0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
            0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys

            -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

            2 Apple Mobile Device - c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
            2 avg8emc (AVG Free8 E-mail Scanner) - c:\progra~1\avg\avg8\avgemc.exe (file missing)
            2 avg8wd (AVG Free8 WatchDog) - c:\progra~1\avg\avg8\avgwdsvc.exe (file missing)
            2 Comodo Anti-Virus and Anti-Spyware Service - c:\program files\comodo\common\cavaspy\cavasm.exe
            2 DomainService - c:\windows\system32\hcekpaim.exe
            4 gusvc (Google Updater Service) - c:\program files\google\common\google updater\googleupdaterservice.exe (file missing)
            2 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe
            4 usprserv (User Privilege Service) - c:\windows\system32\svchost.exe
            And heres the second half.



            -- Device Manager: Disabled ----------------------------------------------------

            Unable to create WMI object.

            -- Scheduled Tasks -------------------------------------------------------------

            2008-04-01 01:00:02 352 --a------ C:\WINDOWS\Tasks\McQcTask.job
            2007-12-29 18:10:15 350 --a------ C:\WINDOWS\Tasks\McDefragTask.job


            -- Files created between 2008-06-11 and 2008-07-11 -----------------------------

            2008-07-11 16:18:38 0 d-------- C:\Program Files\Virtual Villagers - The Secret City
            2008-07-11 16:07:39 0 dr-h----- C:\Documents and Settings\Glen\Recent
            2008-07-11 14:29:08 0 d-------- C:\Program Files\Trend Micro
            2008-07-11 14:24:15 0 d-------- C:\WINDOWS\ERUNT
            2008-07-11 14:16:33 0 d-------- C:\Program Files\SUPERAntiSpyware
            2008-07-11 14:16:32 0 d-------- C:\Documents and Settings\Glen\Application Data\SUPERAntiSpyware.com
            2008-07-11 13:58:06 0 d-------- C:\Program Files\CCleaner
            2008-07-11 10:26:22 186400 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
            2008-07-11 10:02:51 0 d-------- C:\Documents and Settings\Glen\Application Data\Malwarebytes
            2008-07-11 10:02:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
            2008-07-11 10:02:40 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
            2008-07-11 09:24:28 0 d-------- C:\Documents and Settings\Glen\Application Data\MailFrontier
            2008-07-11 09:06:13 73728 --a------ C:\WINDOWS\system32\CavEmLSP.dll
            2008-07-11 09:06:07 102400 --a------ C:\WINDOWS\system32\drivers\cavasm.sys
            2008-07-11 09:06:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Comodo
            2008-07-11 09:05:58 216576 --a------ C:\WINDOWS\system32\monln.dll
            2008-07-11 09:03:52 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
            2008-07-11 09:03:46 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
            2008-07-11 09:02:56 0 d-------- C:\WINDOWS\system32\ZoneLabs
            2008-07-11 09:02:04 0 d-------- C:\WINDOWS\Internet Logs
            2008-07-11 08:54:01 0 d-------- C:\Documents and Settings\All Users\Application Data\BOC426
            2008-07-11 08:53:54 0 d-------- C:\Program Files\Comodo
            2008-07-10 10:31:43 45056 --a------ C:\WINDOWS\system32\Fsinst32.dll
            2008-07-10 10:31:43 86016 --a------ C:\WINDOWS\system32\Dversion.dll
            2008-07-10 10:31:43 110592 --a------ C:\WINDOWS\system32\DVC.dll
            2008-07-10 10:31:41 5120 --a------ C:\WINDOWS\system32\Fsinst16.DLL
            2008-07-10 09:34:22 0 d-------- C:\Program Files\AVG
            2008-07-10 09:34:22 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
            2008-06-25 22:17:28 0 d-------- C:\Documents and Settings\Administrator\Application Data\SiteAdvisor
            2008-06-25 22:16:30 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
            2008-06-15 12:31:40 0 d-------- C:\Program Files\FunWebProducts
            2008-06-15 12:26:57 0 d-------- C:\Documents and Settings\MawMaw\Application Data\DNA
            2008-06-15 01:13:41 8704 --a------ C:\WINDOWS\system32\tdidrv32.sys
            2008-06-15 01:13:37 0 d-------- C:\WINDOWS\system32\162123
            2008-06-15 01:13:13 0 d-------- C:\Program Files\NetProject
            2008-06-12 11:11:21 0 d-------- C:\Program Files\Common Files\Stardock


            -- Find3M Report ---------------------------------------------------------------

            2014-09-22 00:00:00 56320 --a----c- C:\WINDOWS\gendel32.exe
            2008-07-11 16:35:26 0 d-------- C:\Documents and Settings\Glen\Application Data\BitTorrent
            2008-07-11 09:57:22 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
            2008-07-10 15:47:06 0 d-------- C:\Documents and Settings\Glen\Application Data\LimeWire
            2008-07-10 14:35:18 0 d-------- C:\Program Files\Steam
            2008-07-10 10:37:09 0 d-------- C:\Documents and Settings\Glen\Application Data\DNA
            2008-07-10 09:16:52 0 d-------- C:\Documents and Settings\Glen\Application Data\Adobe
            2008-07-09 20:19:41 0 d-------- C:\Program Files\DAEMON Tools Pro
            2008-06-16 14:03:29 0 d-------- C:\Documents and Settings\Glen\Application Data\SiteAdvisor
            2008-06-14 21:51:46 13312 --a-s---- C:\WINDOWS\system32\kfcpnd.dll
            2008-06-12 11:11:21 0 d-------- C:\Program Files\Common Files
            2008-06-12 11:07:53 0 d-------- C:\Program Files\Stardock
            2008-06-11 08:09:43 0 d---s---- C:\Program Files\Xfire
            2008-06-11 01:06:46 0 d-------- C:\Documents and Settings\Glen\Application Data\Xfire
            2008-06-10 07:48:29 0 d-------- C:\Program Files\GameSpy Arcade
            2008-06-09 18:03:11 0 d-------- C:\Documents and Settings\Glen\Application Data\FarStone
            2008-06-09 17:54:55 0 d-------- C:\Program Files\Alcohol Soft
            2008-06-09 17:49:49 261 --a----c- C:\inVHDDrvLog.dat
            2008-06-09 17:45:07 0 d-------- C:\Program Files\FarStone
            2008-06-09 16:14:28 0 d-------- C:\Documents and Settings\Glen\Application Data\DAEMON Tools Pro
            2008-06-09 14:37:36 0 d-------- C:\Program Files\MagicISO
            2008-06-09 13:26:40 0 d-------- C:\Program Files\AdVantage
            2008-06-09 12:48:55 0 d-------- C:\Documents and Settings\Glen\Application Data\DAEMON Tools
            2008-06-09 11:49:06 0 d--h----- C:\Program Files\InstallShield Installation Information
            2008-06-09 10:52:27 0 d-------- C:\Documents and Settings\Glen\Application Data\InstallShield
            2008-06-08 17:25:23 0 d-------- C:\Program Files\BitTorrent
            2008-06-04 10:58:05 0 d-------- C:\Documents and Settings\Glen\Application Data\Sun
            2008-06-04 10:35:22 0 d-------- C:\Program Files\LimeWire
            2008-06-03 07:17:30 0 d-------- C:\Program Files\SiteAdvisor
            2008-05-30 17:03:56 0 d-------- C:\Program Files\DNA
            2008-05-30 13:14:33 0 d-------- C:\Documents and Settings\Glen\Application Data\teamspeak2
            2008-05-29 18:05:44 0 d-------- C:\Documents and Settings\Glen\Application Data\Macromedia
            2008-05-23 17:56:31 0 d-------- C:\Documents and Settings\Glen\Application Data\WinRAR
            2008-05-16 20:04:49 0 d-------- C:\Program Files\Common Files\Motive
            2008-05-16 19:57:19 0 d-------- C:\Program Files\Yahoo!
            2008-05-16 19:57:17 0 d-------- C:\Program Files\Weather Studio
            2008-05-16 19:57:14 0 d-------- C:\Program Files\QuickTime
            2008-05-16 19:57:12 0 d-------- C:\Program Files\McAfee
            2008-05-16 19:57:11 0 d-------- C:\Program Files\Google
            2008-05-16 19:57:10 0 d-------- C:\Program Files\DivX
            2008-05-16 18:34:59 0 d-------- C:\Documents and Settings\Glen\Application Data\Mozilla
            2008-05-16 18:32:21 0 d-------- C:\Documents and Settings\Glen\Application Data\ATI
            2008-05-16 18:31:51 0 d-------- C:\Documents and Settings\Glen\Application Data\Webroot
            2008-05-16 18:31:39 0 d-------- C:\Documents and Settings\Glen\Application Data\Sonic
            2008-05-16 18:31:13 0 d-------- C:\Documents and Settings\Glen\Application Data\Identities
            2008-04-30 16:52:22 53858 --a------ C:\WINDOWS\system32\dcads-remove.exe
            2008-04-30 07:34:20 433664 --a------ C:\WINDOWS\system32\nsh1DB.dll


            -- Registry Dump ---------------------------------------------------------------

            *Note* empty entries & legit default entries are not shown


            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
            "VirtualDrive"="C:\Program Files\FarStone\VirtualDrive\VDTask.exe" [07/18/2007 12:55 AM]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
            "StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [02/13/2003 02:01 AM]
            "RAMDrive"="C:\Program Files\FarStone\VirtualDrive\VHD\RDTask.exe" []
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/08/2006 01:14 PM]
            "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 08:47 PM]
            "MyWebSearch Email Plugin"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe" [08/31/2007 12:08 PM]
            "Motive SmartBridge"="C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe" []
            "Maplom"="C:\Program Files\SlySoft\Game Jackal\GameJackal.exe" []
            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/23/2006 04:45 PM]
            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/17/2005 12:11 AM]
            "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [01/12/2005 03:54 PM]
            "Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [02/09/2006 05:34 PM]
            "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" []
            "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [01/02/2006 04:41 PM]
            "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [10/01/2007 05:40 PM]
            "BOC-426"="C:\PROGRA~1\Comodo\CBOClean\BOC426.exe" [04/10/2008 11:08 AM]
            "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07/09/2008 09:05 AM]
            "cnfgCav"="C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe" [07/11/2008 09:05 AM]
            "cavUPSDBMaker"="C:\Program Files\Comodo\Comodo AntiVirus\UPSDBMaker.exe" [07/11/2008 09:05 AM]
            "SDFix"="C:\SDFix\RunThis.bat /second" []

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
            "SDFix"=C:\SDFix\RunThis.bat /second

            [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
            "MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
            C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\monln]
            monln.dll 07/11/2008 09:05 AM 216576 C:\WINDOWS\system32\monln.dll

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
            "Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmkhe.dll

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
            @=""

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
            @="Service"

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tdidrv32.sys]
            @="Driver"

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
            @="Service"

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
            @="Service"

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
            @="Volume shadow copy"


            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
            AutoRun\command- I:\NoAutoRun.exe

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
            AutoRun\command- J:\AutoRun.exe

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
            AutoRun\command- K:\NoAutoRun.exe

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
            AutoRun\command- L:\NoAutoRun.exe




            -- End of Deckard's System Scanner: finished at 2008-07-11 16:44:08 ------------
            Heres the first half of the Extra.

            Deckard's System Scanner v20071014.68
            Extra logfile - please post this as an attachment with your post.
            --------------------------------------------------------------------------------

            -- System Information ----------------------------------------------------------

            Unable to create WMI object.

            Architecture: X86; Language: English

            Percentage of Memory in Use: 35%
            Physical Memory (total/avail): 638 MiB / 414.02 MiB
            Pagefile Memory (total/avail): 1561.62 MiB / 1361.68 MiB
            Virtual Memory (total/avail): 2047.88 MiB / 1938.12 MiB

            A: is Removable (No Media)
            C: is Fixed (NTFS) - 38.28 GiB total, 21.42 GiB free.
            D: is CDROM (CDFS)
            E: is CDROM (No Media)
            F: is CDROM (No Media)


            -- Security Center -------------------------------------------------------------

            AUOptions is scheduled to auto-install.
            Windows Internal Firewall is enabled.

            Unable to create WMI object.

            -- Environment Variables -------------------------------------------------------

            ALLUSERSPROFILE=C:\Documents and Settings\All Users
            APPDATA=C:\Documents and Settings\Glen\Application Data
            CLIENTNAME=Console
            COLLECTIONID=COL8143
            CommonProgramFiles=C:\Program Files\Common Files
            COMPUTERNAME=JIMMY-ZMTCUWPG3
            ComSpec=C:\WINDOWS\system32\cmd.exe
            FP_NO_HOST_CHECK=NO
            HMSERVER=https://wwss1proa.cce.hp.com/wuss/servlet/WUSSServlet
            HOMEDRIVE=C:
            HOMEPATH=\Documents and Settings\Glen
            ITEMID=dj-22741-15
            LANG=1033
            LOGONSERVER=\\JIMMY-ZMTCUWPG3
            NUMBER_OF_PROCESSORS=1
            OS=Windows_NT
            OSVER=winXPH
            Path=C:\WINDOWS\SYSTEM32;%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\;C:\PROGRAM FILES\SMART PROJECTS\ISOBUSTER;C:\PROGRA~1\FARSTONE\VIRTUA~1\;C:\WINDOWS;C:\WINDOWS\SYSTEM32\WBEM;C:\PROGRAM FILES\FARSTONE\VIRTUALDRIVE\VDP;C:\PROGRA~1\FARSTONE\VIRTUA~1\DVDCRE~1;
            PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            PROCESSOR_ARCHITECTURE=x86
            PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
            PROCESSOR_LEVEL=15
            PROCESSOR_REVISION=0209
            ProgramFiles=C:\Program Files
            PROMPT=$P$G
            SAFEBOOT_OPTION=NETWORK
            SESSIONID=1165343229926htx60566ef76f:10f53de9c73:-7196
            SESSIONNAME=Console
            SWUTVER=1.0.22.20030804
            SystemDrive=C:
            SystemRoot=C:\WINDOWS
            TEMP=C:\DOCUME~1\Glen\LOCALS~1\Temp
            TIMEOUT=0
            TMP=C:\DOCUME~1\Glen\LOCALS~1\Temp
            TOOLPATH=/C:\Program%20Files\HP\HP%20Software%20Update\install.htm
            tvdumpflags=8
            UPDATEDIR=C:\DOCUME~1\MawMaw\LOCALS~1\Temp\rad3674A.tmp
            USERDOMAIN=JIMMY-ZMTCUWPG3
            USERNAME=Glen
            USERPROFILE=C:\Documents and Settings\Glen
            VERSION=3.0.5.001
            windir=C:\WINDOWS
            __COMPAT_LAYER=EnableNXShowUI


            -- User Profiles ---------------------------------------------------------------

            Owner (admin)
            Glenn (admin)
            Glenn (admin)
            MawMaw (admin)
            Glen (admin)
            Administrator (admin)


            -- Add/Remove Programs ---------------------------------------------------------

            --> C:\PROGRA~1\ACCELE~1\ANTI-V~1\regsvr32.exe /u /s C:\PROGRA~1\ACCELE~1\ANTI-V~1\ssupload.dll
            --> C:\PROGRA~1\ACCELE~1\ANTI-V~1\regsvr32.exe /u /s C:\PROGRA~1\ACCELE~1\ANTI-V~1\vclnr.dll
            --> C:\PROGRA~1\ACCELE~1\ANTI-V~1\WS_UNI~1.EXE -s
            --> C:\PROGRA~1\ALLTEL~1\bin\CustomUninstall.exe ALLTEL
            --> C:\PROGRA~1\COMMON~1\EACCEL~1\SysSnap\syssnap.exe -UnregServer
            --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Total War\Medieval - Total War (Demo Version)\Uninst.isu"
            --> C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
            --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
            --> MsiExec /X{65F1CF63-31E0-450B-96F3-4A88BE7361A6}
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D5DFD1A-5B25-48B7-B4D5-E04778BDC676}\Setup.exe" -l0x9
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x9 -removeonly
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x9 -removeonly
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x9 -removeonly
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x9 -removeonly
            --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            3D Groove Playback Engine --> RunDll32 C:\WINDOWS\DOWNLO~1\GrooveAX.dll,[emailprotected]
            Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
            Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
            Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
            AdVantage (Powering DAEMON Tools) --> "C:\Program Files\AdVantage\AdVUninst.exe" /r DAEM /d "AdVantage (Powering DAEMON Tools)" /m "AdVantage is safe advertising software that supports Freeze.com.\nAdVantage is certified by TRUSTe as a Trusted Download.\n\nAre you sure you want to uninstall AdVantage support for DAEMON Tools?"
            AGEIA PhysX v7.07.09 --> MsiExec.exe /X{65F1CF63-31E0-450B-96F3-4A88BE7361A6}
            AIM 6 --> C:\Program Files\AIM6\uninst.exe
            Alltel DSL Installer Agent --> "C:\Program Files\Common Files\Motive\McciBootStrapper.exe" /url="-url=file://C:\Program Files\Common Files\Motive\ReportAgent_Remove.html" /browsertype=CustomMSIE /browserpath="C:\Program Files\Common Files\Motive\MotiveBrowser.exe" /hidden
            AntiSpyCheck 2.1.0 --> C:\Program Files\AntiSpyCheck\uninst.exe
            Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
            Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
            ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
            ATI Catalyst Control Center --> MsiExec.exe /I{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}
            ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[emailprotected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
            ATI Parental Control & Encoder --> MsiExec.exe /I{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}
            Avernum 2 --> C:\WINDOWS\iun504.exe C:\Program Files\Avernum 2\irunin.ini
            AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
            BitComet 0.63 --> "C:\WINDOWS\BitComet_Toolbar_Uninstaller_7296.exe" -hu _?=C:\Program Files\BitComet Toolbar
            BitComet Toolbar --> "C:\WINDOWS\BitComet_Toolbar_Uninstaller_7296.exe" _?=C:\Program Files\BitComet Toolbar
            BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
            Black & White® 2 Battle of the Gods --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10631C28-62E5-477C-9B40-40C5EA8219BE}\setup.exe" -l0x9 -removeonly
            BOClean --> C:\WINDOWS\UNBOC.EXE
            Broadcom 440x 10/100 Integrated Controller --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{52504CE6-E909-4113-B232-4AFEC6543A61} /l1033
            Browser Optimizer Dcads --> C:\WINDOWS\system32\dcads-remove.exe
            CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
            CIF USB Camera (2110A) --> C:\WINDOWS\CleanDev.exe C:\WINDOWS\DC2110a.ini
            Comodo AntiVirus Beta 2.0 --> C:\Program Files\Comodo\Comodo AntiVirus\UninstallCAVS.exe
            Corel Photo Album 6 --> MsiExec.exe /X{8A9B8148-DDD7-448F-BD6C-358386D32354}
            Cry of the Infected Demo --> C:\Program Files\Cry of the Infected Demo\Uninstal.exe
            Cult II - Federal Crime --> C:\WINDOWS\ST5UNST.EXE -n "C:\Program Files\Cult II - Federal Crime\ST5UNST.LOG"
            CureROM Pro 1.3.0b --> C:\Program Files\CureROM\uninst.exe
            Dawn of War - Winter Assault Demo --> MsiExec.exe /X{F72C032A-A0FB-49A9-86A1-188E4724EF1D}
            Dcads Advanced Toolbar --> C:\Program Files\Dcads Advanced Toolbar\uninstall.exe
            Dcads Games Collection --> C:\Program Files\Dcads Games Collection\uninstall.exe
            Dealio Toolbar --> MsiExec.exe /X{3F896597-76C2-4136-97B2-03CA9B04D6AD}
            Dell Media Experience --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
            Dell ResourceCD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
            Desktop Weather by The Weather Channel --> C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
            DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
            DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
            DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
            DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
            DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
            eAcceleration --> C:\PROGRA~1\COMMON~1\EACCEL~1\INSTAL~1\eaccelsetup.exe -AddRemove
            EAX Unified --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\EAX Unified\Uninst.isu"
            Enhancement Browser Tools Superiorads --> C:\WINDOWS\system32\superiorads-uninst.exe
            Fantasy Mod v 0.7.7 for 0.808 --> C:\Program Files\Mount&Blade\Modules\Fantasy_Mod\uninst.exe
            Feeding Frenzy(TM) --> C:\PROGRA~1\SHOCKW~1.COM\FEEDIN~1\UNWISE.EXE C:\PROGRA~1\SHOCKW~1.COM\FEEDIN~1\INSTALL.LOG
            Free Download Manager 2.1 --> "C:\Program Files\Free Download Manager\unins000.exe"
            Free Download Manager Archive Pack --> "C:\WINDOWS\unins000.exe"
            Galactic Civilizations II - Gold Edition --> C:\PROGRA~1\Stardock\TOTALG~1\GalCiv2\UNWISE.EXE C:\PROGRA~1\Stardock\TOTALG~1\GalCiv2\INSTALL.LOG
            Galactic Civilizations II - Gold Edition Demo --> C:\PROGRA~1\Stardock\TOTALG~1\GC2GOL~1\UNWISE.EXE C:\PROGRA~1\Stardock\TOTALG~1\GC2GOL~1\INSTALL.LOG
            Game Jackal v3.0.1.6 (32 bit) --> "C:\Program Files\SlySoft\Game Jackal\unins000.exe"
            GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
            HijackThis 1.99.1 --> C:\Program Files\HijackThis\HijackThis.exe /uninstall
            Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            HP Image Zone 3.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
            HP PSC & OfficeJet 3.5 --> "C:\Program Files\HP\Digital Imaging\{18E0918E-1060-48f3-925C-56C82E88551B}\setup\hpzscr01.exe" -datfile hposcr03.dat
            HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
            HP Unload DLL Patch --> MsiExec.exe /X{595D0DE8-C38A-4432-B851-47DECC1A99BD}
            HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
            HP Wireless Rechargeable Optical Mouse --> Pmuninst.exe MouseSuite98
            IExplorer Security Plug-in --> "C:\Program Files\Video ActiveX Access\iesunst.exe"
            IGN Download Manager 2.1.2 --> C:\Program Files\IGN\Download Manager\uninst.exe
            Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
            IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe
            J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
            Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
            Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
            Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
            Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
            Leylines --> C:\WINDOWS\iun504.exe C:\Program Files\Leylines\data\irunin.ini
            LimeWire 4.18.1 --> "C:\Program Files\LimeWire\uninstall.exe"
            Magic ISO Maker v5.4 (build 0239) --> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
            McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
            Messenger Service --> "C:\Program Files\Video ActiveX Access\imsunst.exe"
            Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft DirectX Media 6.0 SDK --> undxmsdk.exe
            Microsoft DirectX Transform optional components --> RUNDLL32.EXE ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\DXTXTRA.INF,UNINSTALL.NT,12
            Microsoft Halo --> "C:\Program Files\Microsoft Games\Halo\UNINSTAL.EXE" /runtemp /addremove
            Microsoft Office 2000 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
            Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Windows Media Video 9 VCM --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
            MostFun Game Player --> MsiExec.exe /I{2BD2069A-A865-432A-86B8-1151BB0526CC}
            Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
            MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
            MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
            My Web Search (Webfetti) --> rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll,O
            MySpaceIM --> C:\Program Files\MySpace\IM\Uninstall.exe
            Nethergate --> MsiExec.exe /X{05A17FEA-ED98-40F3-A9D8-6AB1E56F5FCF}
            Notification Utility -->
            OpenAL --> "C:\Program Files\OpenAL\oalinst.exe" /U
            overland --> MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
            PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
            RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            Red Faction --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47E6B460-04BA-4215-9F5D-3858BF920D07}\setup.exe" anything
            Sam and Max - Situation Comedy 1.0 --> C:\Program Files\Telltale Games\Sam and Max - Situation Comedy\Uninstall Sam and Max - Situation Comedy.exe
            Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Sonic DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
            Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
            Sony Picture Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x9 /removeonly uninstall -removeonly
            Heres the second half.

            Sony USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\Setup.exe" UNINSTALL
            SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe"
            Spy Sweeper --> "C:\Program Files\Webroot\Spy Sweeper\unins000.exe"
            Star Wars Empire at War --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}\Setup.exe" -l0x9 -removeonly
            Star Wars Empire at War Forces of Corruption --> C:\Program Files\InstallShield Installation Information\{6592FDEC-2C1A-413A-9985-25FEC2F0848D}\setup.exe -runfromtemp -l0x0009 -removeonly
            Stardock Central --> C:\PROGRA~1\Stardock\SDCENT~1\UNWISE.EXE C:\PROGRA~1\Stardock\SDCENT~1\INSTALL.LOG
            Starscape V1.6 --> "C:\Program Files\Starscape\unins000.exe"
            Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
            SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
            TeamSpeak 2 RC2 --> "C:\Program Files\Teamspeak2_RC2\unins000.exe"
            TF2 --> "C:\Program Files\Team Fortress 2\unins000.exe"
            v1.0.26d --> "C:\Program Files\PT\unins000.exe"
            VideoCap ActiveX Control --> "C:\Program Files\VideoCap ActiveX Control\unins000.exe"
            Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
            Virtual Villagers - The Lost Children (remove only) --> C:\Program Files\Virtual Villagers - The Lost Children\Uninstall.exe
            Virtual Villagers - The Secret City 1.0 --> C:\Program Files\Virtual Villagers - The Secret City\uninst.exe
            WarGames --> C:\WINDOWS\IsUninst.exe -fC:\WarGames\Uninst.isu
            Wazzal --> "C:\Program Files\Wazzal\Uninstall.exe" "C:\Program Files\Wazzal\install.log"
            Weather Services --> C:\WINDOWS\system32\control.exe C:\WINDOWS\system32\wxfw.cpl,4
            Weather Studio 3.3.2.0 --> C:\Program Files\Weather Studio\WeatherStudioUninstall.exe
            Web Application --> "C:\Program Files\NetProject\scu.exe"
            Westwood Shared Internet Components --> C:\Westwood\Internet\UnstllAP.EXE
            WildTangent Web Driver --> C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
            Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
            Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
            Worm Wars III 1.0 --> "C:\WINDOWS\Colej_uk_Design_Toolbar_Uninstaller_9062.exe" -hu _?=C:\Program Files\Colej_uk Design Toolbar
            Worm Wars III Colej_uk Design Toolbar --> "C:\WINDOWS\Colej_uk_Design_Toolbar_Uninstaller_9062.exe" _?=C:\Program Files\Colej_uk Design Toolbar
            Worm Wars IV 1.0 --> C:\Program Files\Worm Wars IV\uninst.exe
            Xfire (remove only) --> "C:\Program Files\Xfire\uninst.exe"
            XML Paper Specification Shared Components Pack 1.0 -->
            XviD MPEG-4 Video Codec --> "C:\Program Files\XviD\unins000.exe"
            Yahoo! Anti-Spy --> C:\PROGRA~1\Yahoo!\Common\unypsr.exe
            Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\unyext.exe
            Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
            Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
            Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
            Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
            ZoneAlarm --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe


            -- Application Event Log -------------------------------------------------------

            No Errors/Warnings found.


            -- Security Event Log ----------------------------------------------------------

            No Errors/Warnings found.


            -- System Event Log ------------------------------------------------------------

            No Errors/Warnings found.


            -- End of Deckard's System Scanner: finished at 2008-07-11 16:44:08 ------------

            You just installed Virtual Villagers - The Secret City? Plese do as little on the PC as possible until we can get this cleared up.

            Ok....You have two antivirus installed. This is never advised and could be a big part of the problems. We will also uninstall Zone Alarm as there have been internet connection issues with it lately.

            Go to add/remove programs and uninstall:

            AntiSpyCheck 2.1.0 <- This is a rouge program and should not be trusted.
            Comodo AntiVirus Beta 2.0
            Enhancement Browser Tools Superiorads
            HijackThis 1.99.1 <- Please install the new version - TrendMicro HijackThis.exe (HJT)
            My Web Search (Webfetti)
            Viewpoint Media Player
            WildTangent Web Driver
            ZoneAlarm

            ----------

            Restart the computer now and see if you can get to normal boot mode and run Malwarebytes. If you can't get to normal boot mode then try to run it anyway and post the log when complete.

            ----------

            After you are done with MBAM run a new Hijackthis scan and post the log from it along with the MBAM scan log.

            2881.

            Solve : Computer continually locks up?

            Answer»

            This actually may be good news, because it means "sfc" found some corrupted files.
            You'll have slipstream SP2, and create bootable CD. Here it's how to do it: http://www.helpwithwindows.com/WindowsXP/winxp-sp2-bootcd.htmlIn the link you posted, when it says copy the DISC to my computer, does that mean make an image of the CD or just select everything in Windows Explorer?You mean this?
            QUOTE

            Next copy your Windows XP CD to your hard drive. Just create a folder (I used \XP-CD), and copy all the contents of your Windows XP CD in that folder.
            Yes. I assume it meas to just copy the files.Yes.I followed the guide from the link you provided and successfully burned a slipstream SP2 disc. I still have a PROBLEM though. It still will not except the disc. I'm thinking its because the XP disc I used was a XP Home disc. It wants an XP Professional one instead. I do not have any XP Professional discs, only Home ones. Will I have to just buy one instead? Thanks again for your continued help on this.Quote
            I'm thinking its because the XP disc I used was a XP Home disc. It wants an XP Professional one instead.
            You're correct. To run "sfc", it has to be exact version, and exact SP.
            Maybe, you can borrow one. Nothing ILLEGAL here.No one that I know of has an XP Professional SP2 disc. They either have a Mac, a different version of Windows, or no disc at all. I guess I'll have to look on Amazon or eBay where I can hopefully get XP Professional SP2 pretty cheap. Strangely, I was able to get the system to run normally for about a 1.5 days without problem. Now I'm back in safe mode again. Thanks for all the help provided.Call the PC manufacturer or go to their web site. Have your Product ID ready. They will be able to ship you your install disk. They may charge shipping but it's cheaper then buying a new OS.Can it be guaranteed that it will be SP2? I don't see why it wouldn't be.Depends on what was SHIPPED on the PC I think.
            2882.

            Solve : Nod 32 or Bitdefender??

            Answer»

            Here is some interesting trivia: I have installed trial versions of Bitdefender and Nod32 on my systems. I only run one at a TIME.
            When I disable Nod 32, Bitdefender will run perfectly and not jam up. When I exit out of bitdefender and use Nod 32 the entire system freezes. I know you are not supposed to run two AV's at the same time, but does this ALSO mean not having two installed on my system at the same time?

            What I'm trying to do is compare them side by side. Run Nod and see how it reacts to virus's then turn it off and run Bitdefender and see how it goes. Both have worked quite well although I noticed when I CLICK on a virus Bitdefender will say it has blocked it, but will still come up with those 'Run or Save' options, while Nod will just stop it completely (Nods test was done before downloading Bitdefender trial). On the other hand Bitdefender FOUND 2 infected items on its first quick scan (Netsonic adware, and something else) that Nod missed.(Again Nods Full scan was done before Bitdefender was downloaded) Full Scan time for nod is 41 mins which is about 1/2 of Norton (Norton is completly off the system)*Yay* I have yet to do a full scan of with Bitdefender but will report BACK when I do. (In the next 24 hours)Quote

            I know you are not supposed to run two AV's at the same time, but does this also mean not having two installed on my system at the same time?
            Yes. Even disabled antivirus programs may still run some services, which may interfere with another antivirus.Ok I have taken Nod off my system, and everything goes. Seems a bit slow though but I'm not sure if this is because of me fiddling around or Bitdefender. I will do another antispyware/malware run then defrag and see what happens. Scan times are 48 mins for Nod, nothing discovered, and 1:05hr for Bitdefender, and its always finding stuff.based on my experience comparing nod32 and bitdefender , bitdefender is the best your using trial version at this moment and yet, you can see it runs perfectly what if you're already using bitdefender(not trial version) . im using this almost 2 1/2 yrs and it runs perfectly.In my opinion, any antivirus program, as long, as it's not called Norton, or McAfee, is fine. I tried number of them, and I see no difference.
            Oh, don't get me started on any ratings "thingy". They're more, or less worthless.Lol, yeah thats why I wanted to test the AV's myself. I found that bitdefender was slower than Nod 32 so I'll Nod to Nod That sorts out this stage of my computers development.

            Thanks everyone for your help!
            2883.

            Solve : automatic updates turning of automatically?

            Answer»

            Windows XP automatic updates is turning off automatically. I get a message, please turn automatic updates on manually. I do so, and it changes for a few seconds, then turns off again. No viruses. dowload hijackthis program from here http://download.hijackthis.eu/HJTInstall.exe and run.

            post logs back to here.Quote

            copy and paste your LOG here
            Just post them hereThanks for the intended help.

            I installed MICROSOFT LiveCare and it found a trojan and removed the problem.

            Thanks againIf you don't WANT us to make sure your computer is 100% clean, thats fine.

            Quote
            copy and paste your log here - then ANALYZE
            Please, do NOT advice anyone to analyze HJT log by themselves! It's dangerous!Quote from: Broni on July 07, 2008, 10:51:37 PM
            Quote
            copy and paste your log here - then analyze
            Please, do NOT advice anyone to analyze HJT log by themselves! It's dangerous!
            Noted, thanksNo problem
            2884.

            Solve : Can you help me please??

            Answer»

            I had a trojan virus (perhaps multiple I don't know much about these things) on my computer. A friend told me about this site so I am asking for help.

            I have already performed all the steps found here, and have attached all the logs I was asked to create to this post.

            The viruses that were on my computer as defined by AVG are as follows;

            Trojan Horse Generic10.ASBQ
            Trojan Horse Generic10.ASFN
            Trojan Horse Generic10.ASPK
            Trojan Horse Generic10.ATLN
            Trojan Horse Generic10.ATPA
            Trojan Horse Generic10.AVJA
            Trojan Horse Generic10.AVUU
            Trojan Horse Generic10.AVID
            Trojan Horse Generic10.AWVP
            Trojan Horse Generic10.AXQR
            Trojan Horse Generic10.BABF
            Trojan Horse Downloader.Zlob.XTN
            Trojan Horse Downloader.Zlob
            Trojan Horse Downloader.Generic7.XBU
            Trojan Horse Agent.XGB
            Trojan Horse SHeur.BSKV
            Trojan Horse SHeur.BROU
            Trojan Horse BHO.EPI
            Trojan Horse BHO.EQL
            Potential harmful program Fake_AntiSpyware.WI

            Thanks for your help.

            [recovering disk space -- attachment deleted by admin]Looks like the scans got rid of the majority of malware but there is still some work to do.

            Open Hijackthis and select Do a system scan only then place a check mark next to:

            - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            - O4 - Startup: PowerReg Scheduler.exe
            - O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-be3dfe2fec863c6b.spaces.live.com/PhotoUpload/MsnPUpld.cab
            - O20 - Winlogon Notify: tuvWNFYr - tuvWNFYr.dll (file missing)

            Now close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis and run CCleaner.

            ----------

            Download SDFix.exe and save it to your Desktop.

            Double click SDFix.exe and it will extract the files to %systemdrive%
            (Drive that contains the Windows Directory, typically C:\SDFix)

            Now then reboot your computer in Safe Mode by doing the following:

            • Restart your computer
            • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
            • Instead of Windows loading as normal, the Advanced Options Menu should appear;
            • Select the first option, to run Windows in Safe Mode, then press Enter.
            • Choose your usual account.
            • Open the extracted SDFix folder and double click RunThis.bat to start the script.
            • Type Y to begin the cleanup process.
            • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
            • Press any Key and it will restart the PC.
            • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
            • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
              (Report.txt will also be copied to Clipboard).
            • Finally copy and paste the contents of the results file Report.txt with a NEW HijackThis log in your next reply.
            If SDFix won't run or you get errors, follow the link for instructions on running SDFix. How to use SDFix

            ----------

            Next post add SDFix log.

            Also let me know how everything is now.I have done as you said and have attached the relevant logs to this post. Everything seems to be working much better now and Windows even updates again! Yay! lol.

            Thank you for your help so far and please let us know if I need to do anything more.

            PS: Also, can you let me know if I need to leave these programs (CCleaner, SuperAntiSpyware, MalwareBytes etc.) on my computer or can they be uninstalled after the problem is fixed?

            [recovering disk space -- attachment deleted by admin]Keep CCleaner and run it every other day or so to keep the PC clean of clutter.

            SuperAntiSpyware and MalwareBytes are good to keep and run every other week or so to make sure nothing nasty has gotten into your PC. Be sure to update each program before running them.

            ----------

            Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop.

            1. Double click OTMoveIt2.exe to launch it.
            If using Vista Right-Click OTMoveIt and choose Run As Administrator
            2. Click on the CleanUp! button.
            3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
            4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
            • When finished exit out of OTMoveIt2
            .
            ----------

            Go to:
            • Start
            • Run
            • type: CLEANMGR.EXE
            • Press Enter.
            .
            When prompted select the C: drive and click OK.
            Check the boxes for:
            • Temporary Internet Files
            • Downloaded Program Files
            • Recycle Bin
            • Temporary Files
            .
            Click OK or Enter

            ----------

            Use the Kaspersky Online Scanner

            You must use Internet Explorer.
            • Click Accept.
            • Answer Yes, when prompted to install an ActiveX component.
            • The program will then begin downloading the latest definition files.
            • Once the files have been downloaded click on NEXT
            • Locate the Scan Settings button & configure to:
              • Scan using the following Anti-Virus database:
                • Extended
              • Scan Options:
                • Scan Archives
                • Scan Mail BASES
                • Click OK & have it scan My Computer
                When the scan is done, in the Scan is complete window (below), any infection is displayed.
                There is no option to clean/disinfect, however, we need to analyze the information on the report.

                To obtain the report:
                Click on: Save Report As...



                • Next, in the Save as prompt, Save in area, select: Desktop.
                • In the File name area, use KScan, or something similar.
                • In Save as type: click the drop arrow and select: Text file [*.txt]
                • Then, click: Save


                Copy and paste the Kaspersky Online Scanner Report in your next reply.

                ---------------

                Next post add
                Kaspersky log


                Here is the Kaspersky scan report.

                [recovering disk space -- attachment deleted by admin]
                  If you don't use the iMesh or would rather not use it as it is spyware follow these instructions to remove it.

                  Download
                OTMoveIt2 by OldTimer
                • Save it to your desktop.
                • Double-click OTMoveIt2.exe to run it.
                • Copy the lines in the codebox below.
                Code: [Select][kill explorer]
                C:\Documents and Settings\Martin\Desktop\Martin\Install Files\Copy of iMeshV7.exe
                C:\Documents and Settings\Martin\Desktop\Martin\Install Files\iMeshV7.exe
                EmptyTemp
                [start explorer]
                • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
                • Click the red Moveit! button.
                • Copy everything in the Results window (under the green bar) and paste it in your next reply.
                • Close OTMoveIt2
                .
                ----------

                How is everything now?My computer is running much better now thank you. Everything seems to be fine which is a big relief.

                Also, I have attached the log for OTmoveit2.

                Once again, thanks.

                [recovering disk space -- attachment deleted by admin]1. Double click OTMoveIt2.exe to launch it.
                Vista users right click and choose Run As Administrator
                2. Click on the CleanUp! button.
                3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                5. Once complete exit out of OTMoveIt2

                Set a New Restore Point to prevent possible reinfection from an old one
                Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                • Go to Start &GT; Programs > Accessories > System Tools and click System Restore
                • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                • The new restore point will be stamped with the current date and TIME. Keep a log of this so you can find it easily should you need to use System Restore.
                • Next go to Start > Run and type Cleanmgr
                • Click OK
                • Click the More Options Tab.
                • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                You can find instructions on how to enable and re-enable system restore here:

                Windows XP System Restore Guide or Windows Vista System Restore Guide
                .
                ----------

                Use the Secunia Software Inspector to check for out of date software.
                • Click Start Now
                • Check the box next to Enable thorough system inspection.
                • Click Start
                • Allow the scan to finish and scroll down to see if any updates are needed.
                • Update anything listed.
                .
                ----------

                Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other SECURITY threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                ----------

                Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

                Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                To prevent unknown applications from being installed on your computer install WinPatrol 2008
                Using Winpatrol to protect your computer from malicious software

                Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                *Using SpywareBlaster to protect your computer from Spyware and Malware
                *If you don't know what ActiveX CONTROLS are, see here

                Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
                2885.

                Solve : Hope!?

                Answer»

                To all with a computer PROBLEM, stay with this site and follow the instructions given to you. I had a problem, and thought it was not FIXABLE, but, to my amazement, it was FIXED!!! I recommend you all stick with it and have patience. Take care and GOOD luck to you all.Thank you for accolades

                2886.

                Solve : All of my Icons and my tool bar are missing from my desktop "start" is gone(2)?

                Answer»

                Hi!!! I'm having the exact same problem!!!
                Icons, Toolbar won't load...
                Only way to get around it is like they said ctrl, alt, delete, run new task
                It's rather annoying...
                and i get an userinit error and a rundll.exe error

                Please help...

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 11:02:04 PM, on 7/7/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxddserv.exe
                C:\WINDOWS\system32\lxddcoms.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\explorer.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                C:\Program Files\Flock\flock\flock.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\msiexec.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                O2 - BHO: {c1ae7fc7-b4b9-f878-9134-94e2b184eaf6} - {6fae481b-2e49-4319-878f-9b4b7cf7ea1c} - C:\WINDOWS\system32\kktjxygu.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O2 - BHO: (no name) - {9914230F-8C55-45A5-9D8B-599153897A7C} - C:\WINDOWS\system32\iifddbcD.dll (file missing)
                O2 - BHO: (no name) - {A40C6E93-B163-4F6D-B71F-89662A0534A8} - C:\WINDOWS\system32\efcARkkH.dll (file missing)
                O2 - BHO: (no name) - {AC213B6E-001F-40B3-AFDE-DF964289B9E5} - C:\WINDOWS\system32\tuvWqNFw.dll
                O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
                O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
                O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
                O4 - HKLM\..\Run: [dbar_starter] C:\Documents and Settings\Mark Buffaloe\Application Data\Deskbar_{9B45545C-9B0B-4caf-A30B-F21C4128173D}\starter.exe
                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [BM834b42a3] Rundll32.exe "C:\WINDOWS\system32\ocwecxja.dll",s
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [8078713f] rundll32.exe "C:\WINDOWS\system32\rbqmcwih.dll",b
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Setup.exe" "/SCANUPREBOOT /temp /patched"
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                O20 - AppInit_DLLs: fdpssmsh.dll
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe
                O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

                --
                End of file - 7180 bytes
                Next time, start your own topic. I just CREATED it for you, this time.Is your Norton paid for, and up to date, because it doesn't look active to me?Yes, we installed it about two MONTHS ago and it automatically updates.There is some infection.

                Print these instructions out.

                1. Download SUPERAntiSpyware Free for Home Users:
                http://www.superantispyware.com/

                * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                * An icon will be created on your desktop. Double-click that icon to launch the program.
                * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                * Close SUPERAntiSpyware.

                PHYSICALLY DISCONNECT FROM THE INTERNET

                Restart computer in Safe Mode.
                To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                * Open SUPERAntiSpyware.
                * Under "Configuration and Preferences", click the Preferences button.
                * Click the Scanning Control tab.
                * Under Scanner Options make sure the following are checked (leave all others unchecked):
                o Close browsers before scanning.
                o Scan for TRACKING cookies.
                o Terminate memory threats before quarantining.
                * Click the "Close" button to leave the control center screen.
                * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                * On the left, make sure you check C:\Fixed Drive.
                * On the right, under "Complete Scan", choose Perform Complete Scan.
                * Click "Next" to start the scan. Please be patient while it scans your computer.
                * After the scan is complete, a Scan Summary box will appear with POTENTIALLY harmful items that were detected. Click "OK".
                * Make sure everything has a checkmark next to it and click "Next".
                * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                * If asked if you want to reboot, click "Yes".
                * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                o Click Preferences, then click the Statistics/Logs tab.
                o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                o Please copy and paste the Scan Log results in your next reply.
                * Click Close to exit the program.
                Post SUPERAntiSpyware log.

                RECONNECT TO THE INTERNET

                RESTART COMPUTER!

                2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                * Double-click mbam-setup.exe and follow the prompts to install the program.
                * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                * If an update is found, it will download and install the latest version.
                * Once the program has loaded, select Perform full scan, then click Scan.
                * When the scan is complete, click OK, then Show Results to view the results.
                * Be sure that everything is checked, and click Remove Selected.
                * When completed, a log will open in Notepad.
                * Post the log back here.

                The log can also be found here:
                C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                RESTART COMPUTER!

                3. Post new HijackThis log.Going on to step two...


                SUPERAntiSpyware Scan Log
                http://www.superantispyware.com

                Generated 07/09/2008 at 03:08 PM

                Application Version : 4.15.1000

                Core Rules Database Version : 3501
                Trace Rules Database Version: 1492

                Scan type : Complete Scan
                Total Scan Time : 01:08:49

                Memory items scanned : 430
                Memory threats detected : 0
                Registry items scanned : 4172
                Registry threats detected : 0
                File items scanned : 37625
                File threats detected : 77

                Adware.Tracking Cookie
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][4].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\mark [emailprotected]
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][3].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected]tclick[2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt

                Adware.Vundo Variant
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010895.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010896.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013978.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014046.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014063.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\AUOCPKIW.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\RDGVSCNJ.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\VPWMHASN.DLL.VIR

                Trojan.Dropper/Gen-Packed
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010901.EXE

                Unclassified.Unknown Origin
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013993.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013995.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\ENTZHG.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\GAAKSKWY.DLL.VIR

                Trojan.Unknown Origin
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014050.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\RVGIJKMB.DLL.VIR

                Adware.Vundo-Variant/I
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017264.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017265.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017266.DLL

                Trojan.Dropper/Gen-MultiPacked
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\BVCTWWEB.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\HCUYSFKU.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\KSBPJSYA.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MDMBITSN.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MJUSEIIJ.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NHMJLHBB.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NJPNWELS.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PYUBDMPT.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\XXDUGQNI.DLL.VIR
                SUPERAntiSpyware Scan Log
                http://www.superantispyware.com

                Generated 07/09/2008 at 03:08 PM

                Application Version : 4.15.1000

                Core Rules Database Version : 3501
                Trace Rules Database Version: 1492

                Scan type : Complete Scan
                Total Scan Time : 01:08:49

                Memory items scanned : 430
                Memory threats detected : 0
                Registry items scanned : 4172
                Registry threats detected : 0
                File items scanned : 37625
                File threats detected : 77

                Adware.Tracking Cookie
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][4].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\mark [emailprotected]
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][3].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][1].txt
                C:\Documents and Settings\Mark Buffaloe\Cookies\[emailprotected][2].txt

                Adware.Vundo Variant
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010895.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010896.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013978.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014046.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014063.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\AUOCPKIW.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\RDGVSCNJ.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\VPWMHASN.DLL.VIR

                Trojan.Dropper/Gen-Packed
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP12\A0010901.EXE

                Unclassified.Unknown Origin
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013993.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013995.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\ENTZHG.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\GAAKSKWY.DLL.VIR

                Trojan.Unknown Origin
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014050.DLL
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\RVGIJKMB.DLL.VIR

                Adware.Vundo-Variant/I
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017264.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017265.DLL
                C:\SYSTEM VOLUME INFORMATION\_RESTORE{2BC39B7D-A042-4934-938E-CF559E073197}\RP19\A0017266.DLL

                Trojan.Dropper/Gen-MultiPacked
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\BVCTWWEB.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\HCUYSFKU.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\KSBPJSYA.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MDMBITSN.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MJUSEIIJ.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NHMJLHBB.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\NJPNWELS.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PYUBDMPT.DLL.VIR
                C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\XXDUGQNI.DLL.VIR
                Topics merged, please keep all replies in the same thread.

                Go to Start > Run and type c:\combofix.txt then click OK.

                Post the contents of the log back here.You posted Superantispyware log twice.
                I need Malwarebytes, and HJT logs.Malwarebytes' Anti-Malware 1.20
                Database version: 937
                Windows 5.1.2600 Service Pack 3

                6:59:02 AM 7/10/2008
                mbam-log-7-10-2008 (06-59-02).txt

                Scan type: Full Scan (C:\|)
                Objects scanned: 70384
                Time elapsed: 36 minute(s), 17 second(s)

                Memory Processes Infected: 0
                Memory Modules Infected: 0
                Registry Keys Infected: 4
                Registry Values Infected: 1
                Registry Data Items Infected: 0
                Folders Infected: 5
                Files Infected: 9

                Memory Processes Infected:
                (No malicious items detected)

                Memory Modules Infected:
                (No malicious items detected)

                Registry Keys Infected:
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\DBReg (Adware.SoftMate) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

                Registry Values Infected:
                HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> Quarantined and deleted successfully.

                Registry Data Items Infected:
                (No malicious items detected)

                Folders Infected:
                C:\WINDOWS\system32\1036a (Trojan.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\MUI2 (Trojan.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\spoolX (Trojan.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\winRem (Trojan.Agent) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\cdfig (Trojan.Agent) -> Quarantined and deleted successfully.

                Files Infected:
                C:\System Volume Information\_restore{2BC39B7D-A042-4934-938E-CF559E073197}\RP15\A0013899.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0013964.dll (Adware.SoftMate) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014007.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2BC39B7D-A042-4934-938E-CF559E073197}\RP16\A0014014.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\QooBox\Quarantine\C\Program Files\dbar\deskbar.dll.vir (Adware.SoftMate) -> Quarantined and deleted successfully.
                C:\QooBox\Quarantine\C\WINDOWS\system32\icetublt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\QooBox\Quarantine\C\WINDOWS\system32\jnvhfc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\WINDOWS\BM834b42a3.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 7:15:39 AM, on 7/10/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxddserv.exe
                C:\WINDOWS\system32\lxddcoms.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                C:\Program Files\Lexmark 2500 Series\lxddmon.exe
                C:\Program Files\Lexmark 2500 Series\lxddamon.exe
                C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                C:\WINDOWS\system32\sistray.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Program Files\Flock\flock\flock.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\SoftwareDistribution\Download\Install\windows-kb890830-v2.0-delta.exe
                c:\3aa1db0dd83b3e7e2467f3\mrtstub.exe
                C:\WINDOWS\system32\MRT.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
                O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Setup.exe" "/SCANUPREBOOT /temp /patched"
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                O20 - AppInit_DLLs: fdpssmsh.dll
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe
                O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

                --
                End of file - 6910 bytes
                *** Download, and run CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
                The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is also an option to restore the original one.
                Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

                *** You need to update Java:
                http://java.sun.com/javase/downloads/index.jsp
                Java Runtime Environment (JRE) 6 Update 7
                Uninstall all previous versions of Java through Add\Remove.

                1. Print this post out, since you won't have an access to it, at some point.

                2. Close all windows, except for HijackThis.

                3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable UNNECESSARY startups; in those cases [marked with *], no actual program will be removed):

                - *O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Support\SymLnch\SymLnch.exe " "C:\Documents and Settings\Mark Buffaloe\Application Data\Symantec\Layouts\NSW-Norton AntiVirus\15.0\SymAllLanguages\NAVCD_RETAIL\20070826\Setup.exe" "/SCANUPREBOOT /temp /patched"
                - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                - *O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                - *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                - O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                - O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk (file missing)
                - O20 - AppInit_DLLs: fdpssmsh.dll

                4. Click on Fix checked button.

                5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                7. Delete following files/folders (if present):

                - search your computer for fdpssmsh.dll, and delete all instances

                8. Restart in Normal Mode.

                9. Post new HijackThis log.

                2887.

                Solve : No toolbar or desktop icons? Please help!?

                Answer»

                Yesterday morning, I woke up to the computer being turned off (in my house, it's almost always left on). When I turned it on and logged onto the main account, the toolbar and desktop icons flashed on and then were gone. I tried unplugging and restarting the computer, alas neither worked. I'm at a loss for what to do!

                If anyone has a chance, I would appreciate it if they would kindly help me solve this problem. It's frustrating me very much.

                Thank you for your time!What information should I ADD when submitting a question?Quote from: Broni on July 03, 2008, 08:30:27 PM

                What information should I add when submitting a question?

                Ah! I'm terribly sorry. D:

                The computer is a Dell, Dimension E510 and it runs on Microsoft Windows XP. I don't know anything about RAM or CPU. Sorry.

                As for the problem, it began Wednesday morning. No new software was installed that I know of. As I said before, I turned on the computer, logged in, and the toolbar and desktop icons were there, but soon disappeared. The only thing that appears is the wallpaper. I can run certain things by bringing up the Windows Task Manager and running programs like Firefox and iTunes, but I can't open folders or the control panel.

                If there's anything else you need to know, please tell me!hi, i have the same problem with ONE of my computers, i know how to restore the icon etc, press ctrl+alt+delete, then click file, click run, and then type control and enter. this is as far as i have gotten, i plan to just run a malware seacher to REMOVE the virus. let me know how you go!
                charlieQuote
                I can run certain things by bringing up the Windows Task Manager and running programs like Firefox and iTunes,
                Using the same technique here, run Explorer.exe

                Try that and post back. Quote from: blasterrider on July 04, 2008, 06:07:20 PM
                hi, i have the same problem with one of my computers, i know how to restore the icon etc, press ctrl+alt+delete, then click file, click run, and then type control and enter. this is as far as i have gotten, i plan to just run a malware seacher to remove the virus. let me know how you go!
                charlie

                My gosh! That worked! You're brilliant! The only thing is, now it kind of "blinks" on and off. I can't have My Documents or any folder like that open for more than a few seconds.

                Do you SUPPOSE there is some kind of malware manifesting somewhere?Was it the Explorer.exe thing that got it working?Quote from: Carbon Dudeoxide on July 04, 2008, 07:58:46 PM
                Was it the Explorer.exe thing that got it working?

                Both "Explore.exe" and "Control" seem to have worked the same.All Right. Quote from: Carbon Dudeoxide on July 04, 2008, 08:10:00 PM
                All Right.

                Call me dumb, but I don't understand why the toolbar and icons disappear when I have a My Documents or other folder up. Is there any way I can fix this?Wait, so it HAPPENS every time?Quote from: Carbon Dudeoxide on July 04, 2008, 08:14:23 PM
                Wait, so it happens every time?

                Every time I'm in some type of folder? Yes. Can you try doing a System Restore to a date before this problem started happening?Sure! Could you tell me how to do that? I'm not exactly what you'd call computer wise.Go to Start --> All Programs --> Acessories --> System Tools --> System Restore.

                Then basically follow the steps.
                2888.

                Solve : Virus? Port 1214 oddness to 15.192.45.139?

                Answer»

                Hello,

                I just pulled 6 computers out of operation that got nailed by a virus that appeared to be dormant for 2 years and triggered on 7/4. Bought a Windows XP Key Finder from a guy on ebay for like $3 2 years ago and this program was clean and ran clean up until its recent ATTACK on systems.

                Up until now it has operated correctly in displaying the Key for auditing systems to make sure that no 2 systems have the same XP key.

                Recently on 7/4 this was now tagged as viral by Norton Corporate Edition 10 with latest definitions, as well as a Cruzer Mini Thumb Drive utility that was backed up in teh archive of software, HP Drivers to a HP 1320TN printer, and a few other programs that were clean and now infected according to NAV.

                Looking up this Windows XP Key Finder on google I found that there are numerous complaints about dirty copies of it with Trojans and a Trojan is what I had in my quarantine..... But what makes no sense is how a file in an Read-Only archive SINCE August 2006 all of a sudden WENT viral on 7/4 according to Symantecs Virus scan, along with other drivers. And this file had to have been scanned hundreds of times over the last 2 years without any issue.

                Using Wireshark to probe the corporate network to see if there are any other troubled systems out there, I found that Wireshark displayed Kazaa port 1214 to 15.192.45.139 , so I looked up the IP to see where 15.192.45.139 resides and it hits as www.hp.com ??

                Google search for Port 1214 shows it being used maliciously as well as with Kazaa, but no links to HP using port 1214? So What is going on here???

                The system at 192.168.5.114 should be a clean system being that its NAV definitions up to date and the system scan is clean and is running correctly.

                Any suggestions to why HP would use port 1214 and what for when the browser is not open to the HP site? Any suggestions on any better network probes other than Wireshark?

                The computer by the way is a HP Compaq, but the systems were built clean to XP Pro SP2 and not the MFR image that use to be on the HP before RIS clean to XP Pro SP2 slip stream clean install. The HP MFR images to their drives usually have bundled crap with it like adware/spyware, and crappy registries.

                Thanks,

                DaveQuote

                Any suggestions to why HP would use port 1214 and what for when the browser is not open to the HP site? Any suggestions on any better network probes other than Wireshark?

                You will probably be better off taking this question to the Networking forum.


                Keyfinders use "covert" methods that some AVs will flag as suspicious or even malicious. Why it took 2 years I'm not sure but I would think it's a false positive. Do you mind saying the name of the keyfinder?

                Kazaa is adware and you are right it could have easily been bundled with the fresh install. I wouldn't worry to much about it as it can usually be removed in add/remove programs.

                What you can do is go to UploadMalware.com, follow the directions to have the keyfinder file analyzed by the team there.
                2889.

                Solve : virus or spyware??

                Answer»

                My task manager Is showing that I have Isass.exe running. Is this Bad, relative to being a virus or SPYWARE. Are you sure it's Isass and not Lsass.Hmmm, I think your on to something. It Is Lsass ( SHOWS up like this-lsass). So Is lsass good or bad?Lsass is good.

                Isass is the Sasser worm. But any PC with Windows SP1 and above should never be infected by the Sasser worm. MS has released multiple patches so USERS won't get infected by it.

                Thanks again evilfantasy.No problem.

                2890.

                Solve : Computer mouse sets off alarm?

                Answer»

                since it's so LATE TONIGHT, i'll have to finished the scan tomorrow. but as soon as i do i'll send you the new log. THANKS so MUCH for all your HELP!!No problem

                2891.

                Solve : Malware Removal completed?

                Answer»

                Go to add/remove programs and uninstall:

                PC-Doctor 5 for Windows < See if the performance improves after REMOVING this. It has been known to be a resource hog.

                ----------

                We can cut down on some of the startup programs to see if it helps.

                Open Hijackthis and select Do a system SCAN only.

                Place a check mark next to the following entries: (if there)

                O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - GLOBAL Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)


                Close all windows except for Hijackthis and then click Fix checked.

                Exit Hijackthis and run CCLEANER.

                Go to Start &GT; Run and then type or copy and paste:

                sc stop MyWebSearchService

                Then press Enter on the keyboard.

                Next go to Start > Run and do the same with:

                sc delete MyWebSearchService

                Restart the computer.

                Has anything improved?



                2892.

                Solve : AVG Update Promblem??

                Answer»

                Yesterday and today I have not been able to update AVG. I try to do so by right clicking the icon in the taskbar, left click update (Same as usual!). But after a few minutes a box comes up telling me the update failed saying:
                "Update Manager:
                @ update_result_Short_missing_ctf"
                Nothing changed on my computer recently. All scans in safe mode show it to be clear of malware . I am not sure what to try now except just leave it another day? All other programs update okay.

                Win XP Pro SP2
                Online Armor Free Firewall
                AVG free Antivirus 8.0.134
                Spyware Blaster
                WinPatrol
                Malwarebytes
                A-Squared free
                Super Anti-Spyware
                Advanced Windows Care V2
                CCleanerI have had the same problem earlier today. I kept trying and eventually it did update.

                Now my problem is that it keeps saying update needs to restart my comp and I have already restarted twice and did one complete shut down yet it still tells me I need to restart.Looks like it is not just me? I have had the same thing, restarting three times, and then tells me again as above.AVG ver. 8.0 has been having all kind of problems, since the day one, it was released.
                It's advisable to switch to some other free antivirus program:
                - AVAST! free antivirus: http://filehippo.com/download_avast_antivirus/
                - Avira free antivirus: http://www.free-av.com/en/download/index.html
                Thanks BroniYou're welcome Thanks for the info Broni. I will give one of the ones you suggest a try.Sure thing Hello Forum: I also am having a problem with AVG 8.0 I am running a Dell dimension 2400 WinXP, IE6.0 . Also using AdAware, CCleaner, SpywareBlaster and have all the latest updates for Windows and other programs. After I downloaded the latest AVG update a popup said I must restart computer. I did(5X)!. Yet AVG the tray icon kept warning that Update Manager was not up to date. I kept UPDATING it but the problem remained. After a day of this I decided to Uninstall AVG and download a new copy. AVG Uninstall would not work. Kept getting message " Warning, internal error, Dialog with ID 'AVG4ESDLG' was not found in Setup". Now what? I downloaded REVO. It REMOVED AVG 8. I downloaded another copy of AVG from Download.com in order to obtain it from another source other than AVG. All was well so far. I checked the AVG uninstall UTILITY and it was working. No more error message. But then AVG told me to update latest definitions. After I downloaded the following update the problems with update manager and AVG Uninstall reappeared. This is a 6.9 or 7.9 MB update: "update/F8UI134R100vibin 15/16" Anybody have any ideas.? Will AVG update a fix? OBTW , REVO did the job when Windows ADD/Remove couldn't. Thanks. Any HELP is appreciated.See my reply #3.
                That's all I can say in this matter.I know you warned me before about AVG, Broni. I really had no problem with AVG until this latest download. It seems like all definitions are downloading properly. I think it is a problem with the User Interface feature: Update Manager. It really bugs me that the Uninstall feature won't work. But I guess I can REVO it again. Also I did download Avast. I ran it once and then Uninstalled it ,so as to not have 2 antivirus programs running simultaneaously. I still have the Setup file on my desktop. Is the Avira program as good or better than Avast?. I had a little problem navigating with Avast. I guess I can get used to it. Thanks for your help.My credo: if any program doesn't want to work properly, I don't use it, if I have other options.
                In this case, you have other options, so why bother with AVG.
                Avira, and Avast are both very good programs. I have no preferences.I will re-install Avast. Thanks again for your helpYou're welcome

                2893.

                Solve : The Trojan Horse Agent 2JCS?

                Answer»

                First of all, THANK YOU for this website and I have LEARNED so much from this experience although this virus STUFF has alarmed me, as I use all freebies with virus protection.

                Like a similar topic, I have this trojan horse agent 2 JCS affecting my C:\Windows\system 32\logagent.exe

                I found it using AVG 8.5 free software. As similarly reported, I couldnt remove it either. I have run all the steps that evilfantasy said, from the CCLeaner to the Hijack this programs. I have all the logs to report here. But have read in the other topic concerning this that it is a false positive. Does that mean that it isnt really on my computer or just not on the other ones that you have looked at? If this is really a trojan, I will begin the log reporting etc. If not, then, at least this has led me to having found a great new website to learn more about computers from...

                Thanks for your replies to this,

                highpoint7Yes it's a false positive. An update fixing this false is currently being prepared and should be released soon if not already. You might try updating AVG as it should be released by now.Thanks again for your help and for this website!!! I believe these websites where everyone works together to fight malware is the key to ending them quicker. It causes novices like me to learn what is going on and take an active role in what is going on with fixing the problems. It shares computer knowledge as opposed to just taking your computer in to a shop and having someone else just "fix" the problem. I learned so much from just reading the issues you have solved with other folks on this potential problem and LOOK FORWARD to reading others issues and LEARNING as well.

                Thanks evilfantasy for your time and to the others as well for creating this website.

                - highpoint7Your welcome!

                2894.

                Solve : I hate being redirected...can you help??

                Answer»

                Everytime I click a click on a link from Google I get redirected to some advertisement. I can mange to open the links in a new window by right clicking on them and opening them in a new window/tab. I do not get redireted when I'm using Yahoo. And I seem to have another symptom...random out of no where popups. This started in Firefox and I was still able to USE IE. But after I ran my AVG and restarted my computer IE started doing the same thing. I downloaded Superantispyware and malwarebytes, but neither of them will run. HijackThis worked, though. Here is the log from that:

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 9:33:29 PM, on 6/4/2009
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                C:\WINDOWS\dhcp\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\System32\avast!Antivirus.exe
                C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                C:\Program Files\Bradford Networks\Client Security Agent\bndaemon.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\HPZipm12.exe
                C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                C:\WINDOWS\system32\sopidkc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\PROGRA~1\AVG\AVG8\avgemc.exe
                C:\WINDOWS\ehome\mcrdsvc.exe
                C:\Program Files\AVG\AVG8\avgcsrvx.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\explorer.exe
                C:\WINDOWS\System32\alg.exe
                C:\WINDOWS\ehome\ehtray.exe
                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                C:\WINDOWS\stsystra.exe
                C:\WINDOWS\system32\igfxtray.exe
                C:\WINDOWS\system32\hkcmd.exe
                C:\WINDOWS\system32\igfxpers.exe
                C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                C:\WINDOWS\system32\igfxsrvc.exe
                C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                C:\Program Files\Logitech\QuickCam\Quickcam.exe
                C:\Program Files\Bradford Networks\Client Security Agent\bncsaui.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\PROGRA~1\AVG\AVG8\avgtray.exe
                C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
                C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
                C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\system32\msiexec.exe
                C:\Program Files\Internet Explorer\Iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6930
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=JBRm44EO4OUF2SEqTaREOszWL1k
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                O4 - HKLM\..\Run: [bncsaui.exe] %ProgramFiles%\Bradford Networks\Client Security Agent\bncsaui.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
                O4 - HKCU\..\Run: [A00F637369.exe] C:\WINDOWS\TEMP\_A00F637369.exe
                O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -P 0x092e -f video -m logitech -d 11.1.0.2016 (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x092e -f video -m logitech -d 11.1.0.2016 (User 'Default user')
                O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                O20 - Winlogon Notify: __c0086B90 - C:\WINDOWS\system32\__c0086B90.dat
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: avast!antivirus - Unknown owner - C:\WINDOWS\System32\avast!Antivirus.exe
                O23 - Service: avast!avscontrolservice - Unknown owner - C:\WINDOWS\System32\avast!AVSControlService.exe (file missing)
                O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
                O23 - Service: Client Security Agent Service (BNPagent) - Bradford Networks - C:\Program Files\Bradford Networks\Client Security Agent\bndaemon.exe
                O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Dhcp server (dhcpsrv) - Unknown owner - C:\WINDOWS\dhcp\svchost.exe
                O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
                O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\WINDOWS\system32\sopidkc.exe
                O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

                --
                End of file - 10348 bytes

                Can you help me?

                Thanks,
                KatThe logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

                There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. TRYING to fix this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information.

                Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

                Backing up files before formatting

                If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

                Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

                I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.

                -) Dr.Web CureIt!
                -) AVG Win32/Virut Removal Tool
                -) Symantwc W32.Virut Removal Tool
                -) McAfee Avert Stinger
                -) Microsoft Windows Malicious Software Removal Tool

                If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

                Very important, do the following immediately or as soon as POSSIBLE!

                If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.

                From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, EBAY, online credit card companies and any online forums or groups you belong to etc.

                DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.Thanks bunches...I'll get right now it.

                2895.

                Solve : something about files..?

                Answer»

                Well what am I supposed to click so i can check that when Hijackthis comes up?Say again, please. I'm not sure, I understand your question.You want me to check those things in Hijack this to get fixed. Well, when I open up Hijack this, what do I click so I can do that? These are the things I get:

                Do a system scan and save a log file
                Do a system scan only
                View the list of backups
                Open the Misc Tools section
                Open online HijackThis QuickStart
                None of the above, just start the programYou go:
                Do a system scan onlyLogfile of Trend Micro HijackThis v2.0.2
                Scan saved at 9:50:40 PM, on 1/23/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                C:\WINDOWS\ehome\ehtray.exe
                c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                C:\WINDOWS\ehome\ehtray .exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
                C:\Program Files\iTunes\iTunesHelper .exe
                C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                C:\Program Files\BigFix\BigFix.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
                C:\PROGRA~1\McAfee.com\Agent\mcagent .exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                C:\WINDOWS\eHome\ehmsas.exe
                C:\WINDOWS\system32\dllhost.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
                R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                F2 - REG:system.ini: UserInit=userinit.exe
                O3 - Toolbar: &AMP;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1195723428\EE\AOLHostManager.exe
                O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
                O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
                O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
                O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAGE~1.EXE
                O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [QuickTime TASK] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
                O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
                O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
                O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
                O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
                O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
                O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

                --
                End of file - 8443 bytes
                It looks much better....

                DOWNLOAD Combofix.exe(http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your desktop.
                PHYSICALLY disconnect from the internet.
                Now STOP all your monitoring programs (FIREWALL, Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
                Double click combofix.exe, and follow the prompts.
                A window will open with a warning. Type "1" (and Enter) to start the fix.
                When the scan completes it will open a text window.
                Please attach that log back here together with a fresh HJT log.
                Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

                Combofix will automatically save the log file to C:\combofix.txt
                Attach its log.Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 6:25:33 PM, on 1/27/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                C:\WINDOWS\ehome\ehtray.exe
                C:\WINDOWS\eHome\ehmsas.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\WINDOWS\system32\dllhost.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\BigFix\BigFix.exe
                C:\Program Files\McAfee\MSC\mcuimgr.exe
                C:\WINDOWS\system32\notepad.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
                R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1195723428\EE\AOLHostManager.exe
                O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
                O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
                O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
                O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAGE~1.EXE
                O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
                O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
                O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
                O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
                O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
                O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
                O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
                O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
                O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim .exe
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

                --
                End of file - 9103 bytes


                [file cleanup - saving space - attachment deleted by admin]It looks nice, and clean.

                Last step...
                1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                2. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

                Report back about your computer overall behavior.For the last like day and a half it seems to be running fine now. The bottom taskbar isn't disappearing and I don't have to restart every five minutes, so hopefully it's fixed. Great! Happy computing, then...

                2896.

                Solve : windows in XP shake rapidly when opened (maximized)?

                Answer»

                I have a laptop running XP Pro. I suspect that there is a virus/spyware that has gotten passed me in my hunt to fix this problem. I have installed Trend Micro anti-virus the latest version and run several scans, ran HJT and fixed what I thought to be APPROPRIATE issues, and ran a free version of AVG anti-spyware and rid the system of them. After all that any windwo that I open up will start to SHAKE rapidly like its trying to maximize but cant do it successful.

                BTW the shaking also occurs in safe mode.

                Any suggestions?Hi Waiakead2, WELCOME to the CH forums.
                Go through the steps listed here.
                And then make a post with the requested logs.
                Sounds like a video CARD problem to me, but without seeing any logs or an example of the problem, it's DIFFICULT to say for sure.

                2897.

                Solve : HijackThis wants to use svchost to connect to web. Why??

                Answer»

                Depending on which version of HijackThis you've been using, the activity might be harmless.To further elaborate on CBMATT's reply...

                HijackThis has been acquired by Trend Micro...you may want to read their Press Release.

                Within that press release you'll SEE this information...
                Quote

                Other DEVELOPMENTS include an “AnalyzeThis” function that allows users to see how prevalent the THREATS detected on their PC’s are when compared to other HijackThis users.

                So, basically...it's like a tool within HijackThis that AIDS Trend Micro and HijackThis users by comparing logs.

                This is probably why you're getting that warning from Comodo...and again...like CBMatt stated...it's probably harmless and depends on what version of HijackThis you're using.
                2898.

                Solve : Super Bowl Malware redirect?

                Answer» StoryThose sites seem to be gone, by now:


                [file cleanup - saving space - attachment deleted by admin]I found one that's still active and there's probably more. Their RANKINGS are just so low that no one is EVER GOING to ACTUALLY visit them.

                This is not mentioned in the Trend Micro article but the EXPLOIT is Javascript based (as usual) so Firefox users with NoScript installed will be safe (as usual).
                2899.

                Solve : Need help, CPU infected!?

                Answer»

                First off, Im not too familiar with computers so I starting searching and found evilfantasy's step-by-step tutorial. I ran all programs listed and attached the logs to my post. If anyone can please help it would be greatly appreciated.
                I noticed on my Task Manager; there is an "IEXPLORE.EXE" but I have NO VISIBLE WINDOWS. I have no clue whats going on.. Trojan horses, adware, SPYWARE, viruses whatever it may be. I need help getting rid of it. If i can provide you with any further INFORMATION i will do my best.. Do i have any options other than "reformat of hard drive"?

                [file cleanup - saving space - attachment deleted by admin]Where is this Windows XP VERSION from?
                We have no Service Pack 1, no Service Pack 2, no antivirus, no firewall.
                Some explanation needed.

                To start with...
                Download, and install AVG FREE antivirus: http://free.grisoft.com/
                Download, and install Comodo free firewall: http://www.personalfirewall.comodo.com/

                You need to update your Java: http://www.java.com/en/download/index.jsp
                Uninstall all previous versions of Java through Add\Remove.

                Post back, when you're done, and we'll go from there.

                2900.

                Solve : Unhappy computer adventure.. Please help!?

                Answer»

                --------------------------------------------------------------------------------

                Here goes nothing.

                I have suddenly became aware that i must have broke my computer!
                first of all It constantly signs me in and out of Windows Live Messenger (msn) saying i lost the connection every minute or so. As if that isnt irritating enough its only a matter of time before my entire screen becomes a blur of rectangular colors that consume whatever i am doing. they START colorful and rapidly turn into a mass blur or red or blue or GRAY. Nothing works. so i restart the computer.
                sometimes this end result comes faster than before but it always comes..
                i have tried the system restore point..
                and i THOUGHT it was gone but sure enough, it happened again.

                also, when i log back onto the computer it shows the desktop background as the "active desktop recovery" and when i try to restore my desktop it wont let me. It says an error has occurred in the script on the page.
                : on line - 65
                Char: 1
                Code:0
                URL: file:///C:/Documents%20and%20Settings/Briell/Application%20Data/Microsoft/Internet%20Explorer/Desktop.htt

                im not sure if that has any significance, but im sure its not good! cos it wont go away.

                well.. this is pretty much what i know in a nut shell guys.
                if you got any suggestions or know whats happening, you will be my hero.

                and if not, THANKS so much for taking the time to let it cross your mind, i appreciate it.

                have a lovely evening.

                -BriellWhat Windows version? How are your security tools?How many forums are you posting this at and then not answering when someone tries to help you? Now, we know...I've SEEN two...Actually it is now being taken care of at another forum.