Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2951.

Solve : Hijackthis report?

Answer»

Could someone please look at my hijack this report and tell me if there is anything I need to delete. Thanks.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:29 AM, on 6/9/2008
Platform: WINDOWS XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Randy\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\sstqn.exe
O4 - HKLM\..\Run: [BM3ff3e73f] Rundll32.exe "C:\WINDOWS\system32\ewqblist.dll",s
O4 - HKLM\..\Run: [3cc0d4a3] rundll32.exe "C:\WINDOWS\system32\mntgbdvn.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - EXTRA context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no NAME) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File IMPORT Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\rtejexaxa.html

--
End of file - 5922 bytes
You are infected. Start HEREEvil, I think Randy took his machine to a repair shop. I noticed 018-Filter hijack. Was I correct?No, I didn't take it to a machine shop. I am going to try what Evil replied with, I just haven't had time. Do you have any other suggestions?Quote from: evilfantasy on June 09, 2008, 04:39:37 PM

You are infected. Start HERE

That's it for now.Sorry, Randy. I thought you weren't coming back. You're in good hands with Evil.
2952.

Solve : Is this a virus or a trojan or something??

Answer»

Hi....

I see "rundll32.exe C:\WINDOWS\system32\drvriw.dll,startup" ---> it's something like this sometimes it;'s drvriw.dll, or drvrph or something else similar and there is also something to do with MSDisp32 on my computer.

I deleted the referencing startup entry from system startup using CCleaner and problem seems to go away. Another time I started computer, similar problem appear. Problem doesn't occur every boot but it happens now and then so I wonder what's going on

I wonder how to fix this problem? I used malwarebyte's antimalware and AVG 8.0 free on my computer and have deleted all problematic things both have discovered.

----------------------------------------

Windows Vista w/ SP1
AVG8.0 free installed, updated.
Malwarebyte's AntiMalware free version updated.
Windows Firewall enabled --> I would be using Commodo firewall but I didn't like all the popups that tell me to approve/block some new software or process.



Thanks!


Download and rename TrendMicro HijackThis.exe (HJT)

  • Double-click on HJTInstall.
  • Click on the Install button.
  • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
  • Upon install, HijackThis should open for you.
  • Close HijackThis and rename it.
  • Go to C:\Program Files\Trend Micro\HijackThis.exe
  • Right click on HijackThis.exe and select Rename.
  • Type in sniper.exe and press Enter.
  • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
  • From the desktop open Hijackthis.
  • If using Windows Vista, Right-click and Run As Administrator.
  • Click on the Do a system scan and save a log file button
  • Hijackthis will scan and then a log will open in notepad.
  • Copy and then paste the entire contents of the log in your post.
  • Do not have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
Although we have renamed Hijackthis to sniper, we will still refer to it as Hijackthis or HJT.
Hi evilfantasy ....

I posted HJT log so please check it. I hope my computer is all clean now so that I may go about doing what I was doing

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:00:22 PM, on 6/25/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Ad Muncher\AdMunch.exe
C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Windows\MSAgent\agentsvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\PROGRA~1\SPEEDB~1\proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS BROWSER Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Ad Muncher] "C:\Program Files\Ad Muncher\AdMunch.exe" /bt
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google IME Autoupdater] "C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SpeedBitVideoAccelerator] "C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [MSSMSGS] rundll32.exe windig32.rom,FFdRun
O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Office Groove Audit Service - Unknown owner - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe

--
End of file - 9736 bytes

-------



[recovering disk space -- attachment deleted by admin]Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
  • O4 - HKCU\..\Run: [MSSMSGS] rundll32.exe windig32.rom,FFdRun
[/b]
Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Download, install and run CCleaner

# Double click the CCleaner shortcut on the desktop to start the program.
# On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
# If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
# Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."

# Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
# After CCleaner has completed its process exit CCleaner.

----------

Download Malwarebytes' Anti-Malware from here or here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

----------

Next post add
MBAM log
A NEW Hijackthis log
1. I booted my computer a few minutes ago and I see some drvbock.dll detected by AVG and AVG says it's a possible unwanted program or something like that and I pressed move to vault.

2. ok. I have done the Hijackthis system scan. Both entries you mentioned existed, so I fixed all as you recommended.

3. I have done the CCleaner cleanup.

4. I have not yet done the Malwarebyte check.... will do that later.



I'm moving this to the Computer viruses and spyware forum.

drvbock.dll is an unknown virus which is why AVG isn't fixing it. If MBAM doesn't get it we will go to more powerful tools.

Don't worry, we'll get it!!! I scanned with spybot S&D program and I see MSDSip registry entries detected under VIRTUMONDE error.

I will double check TOMORROW with the MBAM program and also with Spybot. Spybot said some of the virtumonde errors can't be fixed as they are detected to be in use in the memory and now I have to restart and have Spybot scan and clean before computer loads otherwise it might fail again.

Also, like I said, drvbock.dll came up this time. drvriw.dll came up last time and if this problem still goes on, it might report a different dll is problematic.

I think AVG isn't fixing the dll problems. But it knows it's problematic which is why i think the dll can't run error comes up-- AVG blocks it. Without following through on my instructions we will end up making this a very long process when it doesn't need to be.

You'll notice that with every step I request it produces a log to be posted. Without "seeing" whats going on it's all just debate and guess work. I have to find the location of the infected file(s) to be able to know how to get rid of them.Hi evilfantasy, sorry I did not follow your directions. After all, you're the PC doctor and now, hopefully, we can get my computer healthy and back to sanity again,

Anyway, here are a few things for you:

1. a MBAM Log (MBAM found 2 trojans)
3. new HJT log.
3. a AVG threat popup that appeared when MBAM scan completed. (I provided screenshot for you to look at and I clicked on 'move to vault' already)

All three are attached with this message.... so check the attachments included

[recovering disk space -- attachment deleted by admin]OK, we need to do another more thorough scan. This one won't take long.

Download Combofix by sUBs from one of the below links.

Important! Combofix.exe MUST be saved to and ran from the Desktop.
  • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
  • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
    • Click this link to see a list of security programs that should be disabled and how to disable them.
    • If yours is not listed and you don't know how to disable it, please ask.
  • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
  • Double click combofix.exe & follow the prompts.
    • Choose Yes to accept the Disclaimers.
  • When finished, it will produce a log for you.
  • Post that log in your next reply.
Warning: Do not mouseclick Combofix's window while it is running. That may cause it to stall
  • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
  • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
If needed, see this Combofix tutorial with screenshots that will detail more thoroughly the downloading and running of Combofix.

----------

Next post add
Combofix log
combofix wouldn't run on my computer.

But anyway, I have reinstalled windows and all is okay now. Thanks for all the help earlier.Thanks for the update.
I was curious why combofix would not run. I had double clicked it like any normal proram and the loading bar appeared and it stopped there, nothing going on but I could use my computer as noirmal.

Anyhow, yeah no problem. thanks again evilfantasy for your help and I am happy that my computer is all good again
2953.

Solve : Hijack This Log Help?

Answer»

Any change with CCleaner?

Download ATF Cleaner by Atribune.
Note: Vista users must use Run As Administrator

  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main MENU to close the program.sorry for the delay...i didn't see your reply earlier. so sorry!

no, no change with ccleaner. i downloaded the atf cleaner, and that has HELPED somewhat, thanks.

but things still run horrifically slow at times. most of the time actually.

don't know if this has anything to do with anything, but checking the task manager, when things are running at or near 100%, the main taker is a program "svchost.exe" - what is that and can i just get rid of it?

and last (and again, could be completely unrelated), as i am a goof and have somehow managed to lose my cellphone recharger, today i plugged my phone into my computer via a usb cable to recharge it that way. then i noticed my phone started making calls! forgive my complete naivetè, but was that some spyware thing trying to phone home?

thanks so much. Download Malwarebytes' Anti-Malware from here or here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then SHOW Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to EITHER and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

----------

Also let me know how things are now.here's the malwarebyte's log:

Malwarebytes' Anti-Malware 1.18
Database version: 875

0.36.11 25/06/2008
mbam-log-6-25-2008 (00-36-11).txt

Scan type: Quick Scan
Objects scanned: 39982
Time elapsed: 30 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



I find it really hard to believe it didn't find anything....things are not so good. I'm constantly getting kicked offline, and when I try watch a video or something like that, things get really slow.

I'm praying to win something on a lottery ticket, so I can just go out and buy a Mac, and be done with this silliness... perhaps I was impulsive by doing this, but I've found that after I run Fixwareout, things run exceptionally well...for a little while. I just ran one now, and here's the log for that too, if this helps:

Username "user" - 25/06/2008 0.48.51 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

Svuotata la cache del resolver DNS.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"DSLSTATEXE"="C:\\Program Files\\Hamlet\\Adsl\\dslstat.exe icon"
"DSLAGENTEXE"="C:\\Program Files\\Hamlet\\Adsl\\dslagent.exe"
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~



ciao and thanks Run this online scan. Requires Internet Explorer

Use the ESET Nod32 Online Scanner
1. Check the BOX next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next replyhi again

did the eset scan, and because i'm an idiot or for some other reason i can't pull up the log file. when i try it says that file is non-existent.

at any rate, the scan said that after searching over 21,000 files, nothing harmful was found.

in other news, i plugged my phone into the computer last night before going to bed, and when i woke, it had dialed 16 different numbers before morning....

what is that???

as always, thanks for your enduring patience and generous assistanceInstall the a-squared Anti-Dialer (freeware)

Downlaod link > http://download6.emsisoft.com/a2AntiDialerSetup.exe

Homepage > http://www.emsisoft.com/en/software/antidialer/

-----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

How are things now?
2954.

Solve : Something New From AVG?

Answer»

Security is no LAUGHING matter, but AVG Technologies (http://www.avg.com) knows how to have fun with a serious topic. The company RECENTLY launched its “Hugs for Hackers” CAMPAIGN, aimed at educating IT pros about current Web threats. At the Hugs for Hackers Web site (http://www.hugsforhackers.org), you can find out about top threats, learn how to avoid getting hacked, and watch some videos that ILLUSTRATE recent hacks—for example, the Major League Baseball Web site hack, and ALICIA Keys’ MySpace site hack. The entire Hugs for Hackers site is rather tongue-in-cheek, but the message isn’t: Hackers are constantly trying to break into networks and steal information, and you need to protect yourself and your organization more than ever before.

2955.

Solve : userinit.exe - application error?

Answer»

Hi,

I have a Dell laptop with what seems like multiple virus infections. To start with , it wouldn't boot, and gave the error 'userinit.exe - application error' when a user logged on. I could get around this by launching task manager, then running explorer.exe.

I have scanned the laptop, and attached the requested logs. It seems to be ok now, maybe someone could check it out for me.

Thanks

Nick

[recovering disk space -- attachment deleted by admin]OPEN Hijackthis and select Do a system scan only then place a check mark next to:

O2 - BHO: {bba0e06c-f06e-f59a-2f84-ef5f3f054ed5} - {5de450f3-f5fe-48f2-a95f-e60fc60e0abb} - C:\WINDOWS\system32\qtaegaoc.dll (file missing)

Close all windows and click Fix checked.

Exit Hijackthis and run CCLEANER.

----------

Final steps and suggestions.

Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find INSTRUCTIONS on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

----------

Make sure all of your security programs are up to date and run scans with them regularly. Once or twice a week minimum.

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

To prevent unknown applications from being installed on your computer install WinPatrol 2008
Using Winpatrol to protect your computer from malicious software

Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*Using SpywareBlaster to protect your computer from Spyware and Malware
*If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for TIPS and free tools to keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks, all sorted now.
2956.

Solve : Error messages during startup?

Answer»

I've just returned the PC to my friend, as I have tested it whole day since the last post, and it seems to work just fine, except a video controller issue, which I leave it to the shop where she bought the PC from, since it's still under warranty.

Thanks a lot, you've been a great help.

Have a nice day.You too
What's the story about that video controller?Well, the mobo has a onboard VGA, but the shop was still recommended her a graphic card, which she did not realize it was unnecessary.
All the while she was using the onboard one rather than the card with no issue.
Until last week, the computer did not give any display with CPU running.
So I guess it was something wrong with the controller.
When I plugged the monitor to the card instead of the onboard one, the SCREEN came up.
After a few tests, it seems that the onboard VGA will only work if the graphic card is removed.
However, with the card presents and the onboard one not working, the card sometimes does not work too, though only once in few tries. When that happens, I just press the reset button and everything goes well as usual.
So I suspect they must be something not RIGHT with both the graphic card and onboard VGA.
And that is beyond my capability to fix it, so I asked her to bring the PC back to the shop as it is still under warranty.
Michael
You can't have on-board, and real video card working at the same time. It's either this, or that.
When you install real video card, on-board video is either automatically disabled (newer cards), or has to be disabled in BIOS.
I don't think, you have to go back to the shop, and I don't see anything wrong with shop people. Maybe they saw on-board video FAILING, and that's why they recommended real video card.
BTW, real video card is always better, then on-board video. In most cases, it has better specs, than on-board video, and what's more important, it doesn't use computer's memory (RAM), because it has its own RAM.Yes I know that only either shall be working.
When I first check out the status of both, I found that the driver for the graphic card was not installed.
That means when the shop /sold passed the brand new PC to my friend 3 months ago, it was configured to use the onboard VGA and the graphic card was presented for no purpose.
And yes, I know that graphic card's spec is always better than the onboard one, so I suggested to my friend and she agreed to use the card.
After I've installed the driver for the graphic card, sometimes it still GIVES a blank screen (no signal). So I guessed the onboard one has to be disable manually. I went into bios, and it was set to PCIeX , so the onboard one has already been disabled.
One of my computer tech friend suggested that there may be a jumper on the board to enable/disable the onboard VGA, which I didn't look for.
Since I'm not competent enough to do that, that is the reason why I suggest my friend to have the shop fix it for her.
At the moment, from the feedback from my friend, the graphic card is working fine, except once in a while it gives a blank screen, and back to normal after reset. Same situation as I've tested. She is yet to send the PC back to the shop.
Thanks. Bad, brand new video cards happen.That could be a possibility. Only an identical card can confirm that.
But I know sometimes THINGS like that do happen. Just luck.
I used to work in the rework team for serverboards, so I know what's in the market ;-)

2957.

Solve : Preventing Virtumonde?

Answer»

Is there any programme that can sucessfully prevent Virtumode and its variations there seems to be plenty of advice on removing these pests but I am looking for s programme that prevents them in the first place. I run XP Pro with PC Guard, Spyblaster,Spybot.Spyhunter,Trojanhunter,WINDOWS Defender. They all find parts of Virtumonde but none seems to prvent it.I think you're looking for an Antivirus software, not Antispyware software.

I suggest going with AVG 8.0. It is free and HIGHLY recommended here in the FORUMS to users without antivirus software.Throwing the mouse in the trash is the only way to prevent it. Don't click on ANYTHING you aren't completely sure is safe and you will reduce the chances of having any problems with it.

2958.

Solve : Monthly Check.?

Answer»

I scanned with hijackthis in normal mode , if you would like one done in safe mode let me know . Theres currently no anti virus installed on my system im still trying to find the right one .

What is in installed :

Superantispyware
Trojanhunter
Spyboy search and destroy

I just WANTED someone to look through the log to see if theres anything bad there , and COULD somoene please link me to the LATEST version of vundofix.

Thanks.

[recovering disk space -- attachment deleted by admin]The log is CLEAN, but you've been playing with fire, by not USING any antivirus program.
Please, install one of these:
Avast! free antivirus: http://filehippo.com/download_avast_antivirus/
Avira free antivirus: http://www.free-av.com/en/download/index.html

2959.

Solve : Pop ups please help?

Answer»

I did a AVG scan and Symanatc.

Attached is my hijack this. Thanks for the help.

[recovering space - attachment deleted by admin]You're running two antivirus. This is never advised and just leads to problems. Uninstall one of them before continuing.

Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O4 - HKLM\..\Run: [7069579c] rundll32.exe "C:\WINDOWS\system32\ybsehhnh.dll",b

Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Download OTMoveIt2 by OldTimer

  • Save it to your desktop.
  • Double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

Code: [Select]C:\WINDOWS\system32\ybsehhnh.dll
    • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the Yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the Green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt2
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Next post please add the OTMoveIt log.

    I copy and pasted the under the green. Is that what you meant by my log?

    DllUnregisterServer procedure not found in C:\WINDOWS\system32\ybsehhnh.dll
    C:\WINDOWS\system32\ybsehhnh.dll NOT unregistered.
    C:\WINDOWS\system32\ybsehhnh.dll moved successfully.

    OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05232008_182632
    Download Malwarebytes' Anti-Malware from here or here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be PRESENTED with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

    How is everything now?It appears that the pop ups have stopped. Thanks for your help.

    Which virus scan should i get rid of? Symantac or AVG?

    Here is my Malaware log:

    Malwarebytes' Anti-Malware 1.12
    Database version: 783

    Scan type: Quick Scan
    Objects scanned: 37453
    Time elapsed: 9 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 13
    Registry Values Infected: 3
    Registry Data Items Infected: 0
    Folders Infected: 1
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\oiiotefd.dll (Trojan.Vundo) -> Unloaded module successfully.

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{f9df827a-8fa7-48a3-b268-ca4db563ea40} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f9df827a-8fa7-48a3-b268-ca4db563ea40} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\7069579c (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{f9df827a-8fa7-48a3-b268-ca4db563ea40} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM735a6400 (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\WINDOWS\system32\logXv01 (Trojan.Agent) -> Quarantined and deleted successfully.

    Files Infected:
    C:\WINDOWS\system32\oiiotefd.dll (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\system32\dfetoiio.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\kewdecsi.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
    Quote
    Which virus scan should i get rid of? Symantac or AVG?

    Avast or AVG Free...use the Norton Removal Tooll to get rid of Symantec.

    EF will let you know when you are finished even though the popups have stopped...follow thru to the end of the process.
    But you can take care of your AV situation in the meantime...Following patios advice...

    Download ATF Cleaner by Atribune.
    Note: Vista users must use Run As Administrator
    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.

    ----------

    1. Double click OTMoveIt2.exe to launch it.
    Vista users right click and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list DOWNLOADED, Do you want to begin cleanup process?)
    5. Once complete exit out of OTMoveIt2

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    .
    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable THOROUGH system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .

    Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
    2960.

    Solve : bigtime virus/trojon/downloader problem?

    Answer»

    Some stubborn ones to get rid of.

    Now download The Avenger by Swandog46 and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Code box below, and paste it into the INPUT script here window:
    Code: [Select]Comment:

    Registry values to delete:

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate

    Note: the above instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system


    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    • Add the Avenger log in your next post.
    .
    ----------

    Your Java is out of date.
    Older versions of Java have vulnerabilities that malware can use to infect your system.
    Please follow these steps to remove older version(s) of Java components and update.

    Step 1 - Get the new version
    • Go to the Sun Java Download Page
    • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
    • Click the button and choose the options.
      • Platform Windows
      • Language English
      • Next place a check mark in the box to agree to the License Agreement.
    • "I agree to the Java SE Runtime Environment 6 License Agreement"
    • Click Continue
    • Click on the link to download Windows Offline Installation and save to your desktop.
    • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
    • Follow the prompts to complete the installation.
    Step 2 - Remove old version(s)
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
    • Do not remove Java 6 Update 6
      • Uninstall all of these.
      • J2SE Runtime Environment 5.0 Update 10
      • J2SE Runtime Environment 5.0 Update 2
      • J2SE Runtime Environment 5.0 Update 4
      • J2SE Runtime Environment 5.0 Update 7
      • J2SE Runtime Environment 5.0 Update 8
      • J2SE Runtime Environment 5.0 Update 9
      • Java 2 Runtime Environment, SE v1.4.2_03
      • Java 2 Runtime Environment, SE v1.4.2_05
      • Java 2 Runtime Environment, SE v1.4.2_06
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each old Java version.
    • Restart your computer once all Java components are removed.
    Step 3 - Remove old folder(s)
    • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
    • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
    .
    ----------

    Also uninstall Viewpoint Media Player

    See Viewpoint to Plunge Into Adware

    ----------

    Next post add
    Avenger log


    Hopefully the boot times will start to improve.

    Let me know how everything is now.Boot time was a little improved but I think a scan is running every time I boot up. In the task manager it's called DoScan? After doing the avenger, on the reboot several pop up errors with the title of "no disk" kept appearing which was very odd. Here's the log...

    //////////////////////////////////////////
    Avenger Pre-Processor log
    //////////////////////////////////////////

    Platform: Windows XP (build 2600, Service Pack 2)
    Sun May 25 01:12:33 2008

    01:12:10: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd"
    Skipping line. (Registry value deletion mode)
    01:12:12: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd"
    Skipping line. (Registry value deletion mode)
    01:12:13: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi"
    Skipping line. (Registry value deletion mode)
    01:12:21: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd"
    Skipping line. (Registry value deletion mode)
    01:12:22: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0"
    Skipping line. (Registry value deletion mode)
    01:12:24: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA"
    Skipping line. (Registry value deletion mode)
    01:12:25: Error: Invalid syntax in command:
    "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate"
    Skipping line. (Registry value deletion mode)


    //////////////////////////////////////////


    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!


    Completed script processing.

    *******************

    Finished! Terminate.


    [recovering space - attachment deleted by admin] Look here for information on the DoScan.

    For some reason the reg values aren't going away with any of the tools used....yet!

    ----------

    Open Hijackthis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - C:\WINDOWS\system32\ScsiAcc.exe
    - R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 216.133.248.230:80 <<--Unless you did this yourself
    - O2 - BHO: (no name) - SOFTWARE - (no file)
    - O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm
    - O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
    - O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAcc.exe


    Important: Close all windows except for Hijackthis and then click Fix checked.

    Exit Hijackthis.

    ----------

    Download OTMoveIt2 by OldTimer
    • Save it to your desktop.
    • Double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code: [Select]C:\WINDOWS\system32\ScsiAcc.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate
    • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the Yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the Green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt2
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    ----------

    Next post add
    OTMoveIt log


    Here's the log:

    C:\WINDOWS\system32\ScsiAcc.exe moved successfully.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd\\ deleted successfully.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd\\ deleted successfully.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi\\ not found.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd\\ not found.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0 >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0\\ deleted successfully.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA\\ deleted successfully.
    < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate >
    Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate \\ not found.

    OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05252008_131353
    Let's clear out the programs we've been using to clean up your computer, they are not suitable for
    general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
    .
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • MAKE sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .

      1. Double click OTMoveIt2.exe to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      5. Once complete exit out of OTMoveIt2

      Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      .
      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable THOROUGH system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .

      How is everything now?
      2961.

      Solve : Help! Obvioulsy infected with something?

      Answer» yama. now what?

      Secunia report

      Detection Statistics:

      14 Applications DETECTED in Total
      0 INSECURE Versions Detected
      14 Secure Versions Detected

      Running For:
      1 Minute, 6 Seconds

      Errors Detected:
      0 Errors Detected
      Enable thorough system inspection
      Enable the Secunia ONLINE Software Inspector to search for software installed in non-default locations.

      Did you find this scan useful?
      Then you might find it even more useful to run our POWERFUL installable programs, capable of conducting very thorough and indepth scans.
      Personal Edition (free) | Business Edition


      Status / Currently Processing:

      Detection completed successfully

      Good job!

      Everything running OK now?Everything seems tip top. The pop-ups have disappeared. Are there any other steps I need in the process?Looks good to me, you can read through the other links when you get a chance.

      Other than that.....Safe SURFING Thank you very much, evilfantasy

      you were a great help


      2962.

      Solve : Internet Explorer &-infections!?

      Answer»

      I've been using internet explorer 7 for quite some time now.A few weeks ago I reset it and evreything is RUNNING much better.The only thing is, whenever I do a scan,there are more infections than there were before.I've checked the privacy etc settings which are the same as previously,I'm visiting the same sites as I was before and I haven't altered my virus protection settings or anything like that.

      Does any one have any idea what could be causing this and how I could fix it?

      Thank you

      Lotti.List your protection package and we'll determine if this needs help in the Virus and Spyware section.Thank you for replying-please bear with me as I'm not very good with these things! I'm not quite sure what information you need.I have McAfee Security Centre,firewall and virusscan.

      LottiPrint these instructions out.

      1. Download SUPERAntiSpyware Free for Home Users:
      http://www.superantispyware.com/

      * Double-click SUPERAntiSpyware.exe and USE the default settings for installation.
      * An icon will be created on your desktop. Double-click that icon to launch the program.
      * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
      * Close SUPERAntiSpyware.

      Restart computer in Safe Mode.
      To ENTER Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four CORNERS of your screen

      * Open SUPERAntiSpyware.
      * Under "Configuration and Preferences", click the Preferences button.
      * Click the Scanning Control tab.
      * Under Scanner Options make sure the following are checked (leave all others unchecked):
      o Close browsers before scanning.
      o Scan for tracking cookies.
      o Terminate memory threats before quarantining.
      * Click the "Close" button to leave the control center screen.
      * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
      * On the left, make sure you check C:\Fixed Drive.
      * On the right, under "Complete Scan", choose Perform Complete Scan.
      * Click "Next" to start the scan. Please be patient while it scans your computer.
      * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
      * Make sure everything has a checkmark next to it and click "Next".
      * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
      * If asked if you want to reboot, click "Yes".
      * To retrieve the removal information after reboot, launch SUPERAntispyware again.
      o Click Preferences, then click the Statistics/Logs tab.
      o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      o Please copy and paste the Scan Log results in your next reply.
      * Click Close to exit the program.
      Post SUPERAntiSpyware log.

      RESTART COMPUTER!

      2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

      * Double-click mbam-setup.exe and FOLLOW the prompts to install the program.
      * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      * If an update is found, it will download and install the latest version.
      * Once the program has loaded, select Perform full scan, then click Scan.
      * When the scan is complete, click OK, then Show Results to view the results.
      * Be sure that everything is checked, and click Remove Selected.
      * When completed, a log will open in Notepad.
      * Post the log back here.

      The log can also be found here:
      C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
      Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

      RESTART COMPUTER!

      3. Download HijackThis:
      http://www.snapfiles.com/get/hijackthis.html
      Post HijackThis log.

      2963.

      Solve : The logs from my computer?

      Answer»

      ok i have windows xp sp2 and i followed all the steps and i've attached my logs...all the popups have finally stopped.
      if someone could help me and make sure everything that needed to removed was, i'd appreciate it. Thanks.

      [recovering space - attachment deleted by admin]Good job so far, but there is still some work to do.

      Open Hijackthis and SELECT Do a system scan only.

      Place a check mark next to the following entries: (if there)

      - O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
      - O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
      - O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
      - O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
      - O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
      - O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
      - O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
      - O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
      - O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
      - O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
      - O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
      - O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
      - O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)


      Important: Close all windows except for Hijackthis and then click Fix checked.

      Exit Hijackthis.

      ----------

      Download Combofix by sUBs from one of the below links.
      (Try all three if necessary)

      Important! Combofix.exe MUST be saved to and ran from the Desktop.
      • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
      • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
        • Click this link to see a list of security programs that should be disabled and how to disable them.
        • If yours is not listed and you don't know how to disable it, please ask.
      • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
      • Double click combofix.exe & follow the prompts.
        • Choose Yes to accept the Disclaimers.
        • When finished, it will produce a log for you.
        • Post that log in your next reply.
        Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
        • If Combofix runs into difficulty and terminates PREMATURELY, the connection can be manually restored by restarting your computer.
        • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
        CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

        If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly.

        ----------

        Next post add
        Combofix log
        thanks and sorry it took so long but i had to go to sleep then to work
        I have attached the combofix log below.

        [recovering space - attachment deleted by admin]Delete these files/folders, as follows:

        1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
        It must be Notepad, not Wordpad.
        • Click Start , then Run
        • Type notepad.exe in the Run Box.
        2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

        Code: [Select]KillAll::

        Folder::
        C:\WINDOWS\astctl32.ocx
        C:\WINDOWS\rundll32.vbe
        C:\WINDOWS\system32\vntiho06
        C:\WINDOWS\system32\hI2
        C:\WINDOWS\system32\at1
        C:\WINDOWS\system32\1064a
        C:\temp\vtmp2

        File::
        C:\WINDOWS\system32\spywarewarning2.mht
        C:\WINDOWS\system32\beep.sys
        C:\WINDOWS\system32\hljwugsf.bin
        C:\WINDOWS\system32\vntiho06\vntiho061083.exe
        3. Go to the Notepad window and click Edit > Paste
        4. Then click File > Save
        5. Name the file CFScript.txt - Save the file to your Desktop
        6. Then drag the CFScript (hold the left mouse BUTTON while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



        ComboFix will begin to execute, just follow the prompts.
        After reboot (in case it asks to reboot), it will produce a log for you.
        Post that log (Combofix.txt) in your next reply.

        Note: Do not mouseclick combofix's window while it is running. That may cause your system to freezeok here is that log:

        [recovering space - attachment deleted by admin]Next:

        Go to Start > Control Panel > Internet Options
        In the General tab, Temporary Internet Files, click:Delete Files
        When prompted, check:Delete all offline content
        You can also check: Delete Cookies (You will have to re-enter passwords at websites that require them.)
        Click OK

        Then, go to Start > Run and enter: cleanmgr
        Select the drive to clean: C:\
        Check the following boxes and then press OK to remove:
        • Temporary Files
        • Temporary Internet Files
        • RecycleBin
        Agree to the prompt to perform the action...


        Next:

        Download ATF Cleaner by Atribune and save it to your Desktop
        Follow the instructions for the browser you use.
        Read the instructions about the cookies. Delete what you do not need.

        Double click ATF-Cleaner.exe to run the program.
        Check the boxes to the left of:
        • Windows Temp
        • Current User Temp
        • All Users Temp
        • Temporary Internet Files
        • Java Cache
        The rest are optional - if you want to remove everything, check Select All
        Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.
        If you use the Firefox or OPERA browsers, you can use this program as a quick way to tidy those up as well.
        When you have finished, click on the Exit button in the Main menu.

        How is everything now?okay, everything seems to be working fine now
        thanks a bunch! i appreciate your help Let's clear out the programs we've been using to clean up your computer, they are not suitable for
        general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
        .
        • Click START then RUN
        • Now type Combofix /U in the runbox
        • Make sure there's a space between Combofix and /u
        • Then hit Enter.
        .
        .
        The above procedure will:
        • Delete:
          • ComboFix and its associated files and folders.
          • VundoFix backups, if present
          • The C:\Deckard folder, if present
          • The C:_OtMoveIt folder, if present
          • Reset the clock settings.
          • Hide file extensions, if required.
          • Hide System/Hidden files, if required.
          • Set a new, clean Restore Point.
          .

          Set a New Restore Point to prevent possible reinfection from an old one
          Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
          • Go to Start > Programs > Accessories > System Tools and click System Restore
          • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
          • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
          • Next go to Start > Run and type Cleanmgr
          • Click OK
          • Click the More Options Tab.
          • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
          .
          Use the Secunia Software Inspector to check for out of date software.
          • Click Start Now
          • Check the box next to Enable thorough system inspection.
          • Click Start
          • Allow the scan to finish and scroll down to see if any updates are needed.
          • Update anything listed.
          .

          Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

          Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
          2964.

          Solve : Espynow 200?

          Answer»

          I ran dss and for some reason after it was done it only gave me the main.txt LOG

          [recovering space - attachment deleted by admin]Thats OK it's all I needed.

          The slowdown MAY be due to AVG. I have seen complaints of this happening. MAYBE you could uninstall it and try www.avast.com Home Free Edition.ok HUN ..I will do tht

          2965.

          Solve : Slow cmputer/ breaking sound... help guys!!!!?

          Answer»

          Well, computer still running slow but not as before, sound still breaking...!!! What else you think can be happening???

          Also i attached the new log

          [recovering space - attachment deleted by admin]Not sure what is going on. Do you think it is the sound driver? Have you tried reinstalling it?

          Lets do some cleanup and updating to see if it helps.

          Have Hijackthis fix this entry.

          O3 - TOOLBAR: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

          ----------

          Let's clear out the programs we've been using to clean up your computer, they are not suitable for
          general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have DONE.
          .

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • MAKE sure there's a space between Combofix and /u
          • Then hit Enter.
          .
          .
          The above procedure will:
          • Delete:
            • ComboFix and its associated files and folders.
            • VundoFix backups, if present
            • The C:\Deckard folder, if present
            • The C:_OtMoveIt folder, if present
            • Reset the clock settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .
            Set a New Restore Point to prevent possible reinfection from an old one
            Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
            • Go to Start > Programs > Accessories > System Tools and click System Restore
            • Choose the radio button marked CREATE a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
            • The new restore point will be stamped with the current date and time. Keep a log of this so you can FIND it easily should you need to use System Restore.
            • Next go to Start > Run and type Cleanmgr
            • Click OK
            • Click the More Options Tab.
            • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
            .
            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .

            Let me know how things are now.Hello again:

            I really appreciate all your the help, thank you so much!!!! . I run the updates that the computer needed , but even do, still with the sound problem... I don't know what else to do...

            Do you have more suggestions???I'm not sure what it could be. Maybe make a post in the Software forum.
            2966.

            Solve : Background issue?

            Answer»

            My background changed to a spyware warning so I ran a virus and spyware scan and I got rid of something, but I can't seem to change my background back. I tried the usual way. What should I do?Print these instructions out.

            1. Download SUPERAntiSpyware Free for Home Users:
            http://www.superantispyware.com/

            * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
            * An icon will be created on your DESKTOP. Double-click that icon to launch the program.
            * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
            * Close SUPERAntiSpyware.

            DISCONNECT PHYSICALLY FROM THE INTERNET

            Restart computer in Safe Mode.
            To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

            * Open SUPERAntiSpyware.
            * Under "Configuration and Preferences", click the Preferences button.
            * Click the Scanning Control tab.
            * Under Scanner Options make sure the following are checked (leave all others unchecked):
            o Close browsers before scanning.
            o Scan for tracking cookies.
            o Terminate memory threats before quarantining.
            * Click the "Close" button to leave the control center screen.
            * Back on the main screen, under "Scan for Harmful SOFTWARE" click Scan your computer.
            * On the left, make sure you check C:\Fixed Drive.
            * On the right, under "Complete Scan", choose Perform Complete Scan.
            * Click "Next" to start the scan. Please be patient while it scans your computer.
            * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
            * Make sure everything has a checkmark next to it and click "Next".
            * A NOTIFICATION will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
            * If asked if you want to reboot, click "Yes".
            * To retrieve the removal information after reboot, launch SUPERAntispyware again.
            o Click Preferences, then click the Statistics/Logs tab.
            o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
            o If there are SEVERAL logs, click the current dated log and press View log. A text file will open in your default text editor.
            o Please copy and paste the Scan Log results in your next reply.
            * Click Close to exit the program.
            Post SUPERAntiSpyware log.

            RECONNECT TO THE INTERNET

            RESTART COMPUTER!

            2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

            * Double-click mbam-setup.exe and follow the prompts to INSTALL the program.
            * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
            * If an update is found, it will download and install the latest version.
            * Once the program has loaded, select Perform full scan, then click Scan.
            * When the scan is complete, click OK, then Show Results to view the results.
            * Be sure that everything is checked, and click Remove Selected.
            * When completed, a log will open in Notepad.
            * Post the log back here.

            The log can also be found here:
            C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
            Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

            RESTART COMPUTER!

            3. Download HijackThis:
            http://www.snapfiles.com/get/hijackthis.html
            Post HijackThis log.Since I have nothing better to do...

            Usually when your background changes to an adware or spyware warning, its from the adware/spyware itself.

            Avoid clicking on any warnings located on the desktop background, as it will most likely take you to more spyware, as well as any popups that warn about spyware or a virus being on your system, unless they belong to SUPERAntiSpyware, Malwarebytes Anti-Malware, or your own virus protection.

            2967.

            Solve : Hijack this log..... do i need this??

            Answer»

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:38:03 PM, on 5/25/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\wltrysvc.exe
            C:\WINDOWS\System32\bcmwltry.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            C:\Program Files\Trend Micro\BM\TMBMSRV.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ehome\ehtray.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
            C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\WINDOWS\system32\wltray.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\AIM6\aim6.exe
            C:\Program Files\Logitech\SetPoint\KEM.exe
            C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
            C:\Program Files\AIM6\aolsoftware.exe
            C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
            C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
            C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
            C:\Program Files\Pinnacle\Studio 10\programs\Watchu.exe
            C:\Program Files\Pinnacle\Studio 10\programs\UMI.EXE
            C:\Program Files\Pinnacle\Studio 10\programs\RM.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O4 - HKLM\..\RUN: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
            O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
            O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
            O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
            O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.yorkphoto.com/YorkActivia.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
            O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
            O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
            O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
            O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
            O23 - Service: Webroot Spy Sweeper ENGINE (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

            --
            End of file - 7462 bytes


            I deleted verizon servicepoint or w/e its called, but its still in the LOG......can i remove it?nvr mind i think i need itWell I deleted it from add/remove programs....however it is still on my computer in program files... and when i went to remove it... it said its bein used. If i had deleted it and i need it(like how i deeted it from add/remove), but its still there, is that ok?
            If you don't use Verizon Servicepoint then you can remove it.

            Fix this entry with Hijackthis.
            O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"

            Download OTMoveIt2 by OldTimer

            • Save it to your desktop.

              • Double-click OTMoveIt2.exe to run it.
              • Copy the lines in the codebox below.
            Code: [Select]C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
            • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
            • Click the red Moveit! button.
            • Copy everything in the Results window (under the green bar) and paste it in your next reply.
            • Close OTMoveIt2
            .

            Now go in and delete this folder
            C:\Program Files\Verizonso is the verizon stuff USEFUL? i still use verizon
            I don't know if you need it or not.

            The process Verizon Servicepoint Application belongs to the software Verizon Servicepoint or Verizon Online Help and Support by Verizon.File/Folder C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe not found.

            OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05252008_235848


            I went into program files b4 this and got rid of it.... iahd to go into task manager and cancel servicepoint, then I deleted it....now will delete the folder
            Anything else I can remove from the following list? it was faster at first, but seems a little bit slower now....

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:06:09 AM, on 5/26/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\wltrysvc.exe
            C:\WINDOWS\System32\bcmwltry.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            C:\Program Files\Trend Micro\BM\TMBMSRV.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ehome\ehtray.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
            C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\WINDOWS\system32\wltray.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\AIM6\aim6.exe
            C:\Program Files\Logitech\SetPoint\KEM.exe
            C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
            C:\Program Files\AIM6\aolsoftware.exe
            C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
            O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
            O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
            O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
            O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.yorkphoto.com/YorkActivia.cab
            O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
            O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
            O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
            O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
            O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
            O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
            O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

            --
            End of file - 7182 bytes
            Looks like it is gone now.is there anything else i can remove from the log to make my start-up a little bit quicker?Have HJT fix these.

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE

            O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

            O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe\"

            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

            thank you
            2968.

            Solve : Request for assistance with virus/malware/who knows what?

            Answer»

            I am NEW to this site after a recommendation from a friend.
            I have a "cannot find sscvihost.exe" problem showing up with every reboot.
            I am not new to computers, I had my first email address in 1985. But we were running Unix systems which needed to be rebooted a few times a year rather than a few times a DAY! I don't know who I should be venting at, but Microsoft usually gets the bad press. Rather than computer viruses, wouldn't the name more correctly be Microsoft viruses?
            Anyway, interesting forum. Thanks for any help.
            Attachments: logs as requested.

            [recovering space - attachment deleted by admin]Welcome to CH

            This looks like it may be a company machine, I need to know if this is the case. It has no bearing on me helping you I just need to understand what I am seeing in the logs.

            Download SDFix.exe and save it to your Desktop.

            Double click SDFix.exe and it will extract the files to %systemdrive%
            (Drive that contains the Windows Directory, typically C:\SDFix)

            Now then reboot your computer in Safe Mode by doing the following:

            • Restart your computer
            • After hearing your computer beep once during startup, but before the Windows icon appears, TAP the F8 key continually;
            • Instead of Windows loading as normal, the Advanced Options Menu should appear;
            • Select the first option, to run Windows in Safe Mode, then press Enter.
            • Choose your usual account.
            • Open the extracted SDFix folder and double click RunThis.bat to start the script.
            • Type Y to begin the cleanup process.
            • It will remove any Trojan SERVICES and Registry Entries that it finds then prompt you to press any key to Reboot.
            • Press any Key and it will restart the PC.
            • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
            • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
              (Report.txt will also be copied to Clipboard).
            • Finally add the contents of the Report.txt in your next post.
            If SDFix won't run or you get errors, follow the link for instructions on running SDFix. How to use SDFix


            Next post please add
            SDFix log
            Thank you for your quick response.
            In answer to your question "Is this a business machine?". the answer is "No, this is not a business machine".
            requested log to follow.
            Thanks again
            DonAs requested, SDfix.log is attached.
            Thanks again
            Don

            [recovering space - attachment deleted by admin]Use the Kaspersky Online Scanner
            • Click Accept.
            • Answer Yes, when prompted to install an ActiveX component.
            • The program will then begin downloading the latest definition files.
            • Once the files have been downloaded click on NEXT
            • Locate the Scan Settings button & configure to:
              • Scan using the following Anti-Virus database:
                • Extended
              • Scan Options:
                • Scan Archives
                • Scan Mail Bases
                • Click OK & have it scan My Computer
                When the scan is done, in the Scan is complete window (below), any infection is displayed.
                There is no option to clean/disinfect, however, we need to analyze the information on the report.

                To OBTAIN the report:
                Click on: Save Report As...



                • Next, in the Save as prompt, Save in area, select: Desktop.
                • In the File name area, use KScan, or something similar.
                • In Save as type: click the drop arrow and select: Text file [*.txt]
                • Then, click: Save


                Please copy and PASTE the Kaspersky Online Scanner Report in your next post.[/list]
                2969.

                Solve : Randomly got infected?

                Answer»

                No idea how it happened. Kaspersky started popping up randomly and I blocked everything. Then I did a scan with it, and it FOUND nothing. Now, I did a scan with superantispyware and it found 4 things: Adware.Tracking Cookie, Adware.Vundo-Variant/J, Trojan.Dropper/MSPrint-Fake, and Trojan.Unclassified/GTS. Hijackthis log attached.

                [recovering space - attachment deleted by admin]I see no INFECTION, but...

                Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                * Double-CLICK mbam-setup.exe and follow the prompts to install the program.
                * At the END, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                * If an update is found, it will download and install the latest version.
                * Once the program has loaded, select Perform full scan, then click Scan.
                * When the scan is complete, click OK, then Show Results to view the results.
                * Be sure that everything is checked, and click Remove Selected.
                * When completed, a log will open in Notepad.
                * Post the log back here.

                The log can also be found here:
                C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                Post new HJT log.I haven't got around to malwarebytes' yet, I will probably use it today. But just now, kaspersky found Trojan.Win32.VapSup.fog in C:\System Volume Information\_restore{B779814F-9A1D-491F-919B-18573AAB5004}\RP218\A0091868.exe. I'm assuming I should clear all system restore points after malwarebytes'?Follow the steps one at a time...there's a reason they are done in a certain order...Quote

                I should clear all system restore points after malwarebytes'?
                As PATIO said...Logs attached.

                [recovering space - attachment deleted by admin]1. Print this post out, since you won't have an access to it, at some point.

                2. Close all windows, except for HijackThis.

                3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                - O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                - *O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                - *O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                - *O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                - *O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                - O4 - Global Startup: 802.11g Wireless Client Utility.lnk = ?

                4. Click on Fix checked button.

                5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                7. Delete following files/folders (if present):

                - ALCMTR.EXE file from C:\Windows

                8. Restart in Normal Mode.

                9. Post new HijackThis log.Done. I didn't delete the MSN entry because I use that a lot.

                [recovering space - attachment deleted by admin]I missed one unnecessary startup:
                - *O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                Click "Fix checked".

                Other, then that....

                Your computer is clean

                1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                Run CCleaner.

                2. Turn off System Restore:

                - Windows XP:
                1. Click Start.
                2. Right-click the My Computer icon, and then click Properties.
                3. Click the System Restore tab.
                4. Check "Turn off System Restore".
                5. Click Apply.
                6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                7. Click OK.
                - Windows Vista:
                1. Click Start.
                2. Right-click the Computer icon, and then click Properties.
                3. Click on System Protection under the Tasks column on the left side
                4. Click on Continue on the "User Account Control" window that pops up
                5. Under the System Protection tab, find Available Disks
                6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                8. Click OK

                3. Restart computer.

                4. Turn System Restore on.

                5. Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                6. Read So how did I get infected in the first place?: http://www.castlecops.com/postlite7736-.html

                7. Let me know, how your computer is doing.

                I already have ccleaner, system restore cleared. The computer is doing well, Kaspersky hasnt popped up. Very well
                2970.

                Solve : HELP! Vundo!?

                Answer»

                I've located a Vundo TROJAN in my system32 directory. It's taken me awhile to figure out what and where it was but now that I've located it, I'm not sure if I can fix it! Moving it to the vault causes my computer to shut itself down. I'm worried that if I download a Vundo remover it will do the same but irreversibly.

                I would really really prefer to not have to do a full system restore because that'll just wipe hundreds of dollars in software that I cant get back!

                Any ideas or information I could use?Print these instructions out.

                1. Download SUPERAntiSpyware Free for Home Users:
                http://www.superantispyware.com/

                * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                * An icon will be created on your desktop. Double-click that icon to launch the program.
                * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and UNZIP them from here: http://www.superantispyware.com/definitions.html.)
                * Close SUPERAntiSpyware.

                DISCONNECT PHYSICALLY FROM THE INTERNET

                Restart computer in Safe Mode.
                To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; SELECT Safe Mode; you'll see "Safe Mode" in all four corners of your SCREEN

                * Open SUPERAntiSpyware.
                * Under "Configuration and Preferences", click the Preferences button.
                * Click the Scanning Control tab.
                * Under Scanner Options make sure the following are checked (LEAVE all others unchecked):
                o Close browsers before scanning.
                o Scan for tracking cookies.
                o Terminate memory threats before quarantining.
                * Click the "Close" button to leave the control center screen.
                * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                * On the left, make sure you check C:\Fixed Drive.
                * On the right, under "Complete Scan", choose Perform Complete Scan.
                * Click "Next" to start the scan. Please be patient while it scans your computer.
                * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                * Make sure everything has a checkmark next to it and click "Next".
                * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                * If asked if you want to reboot, click "Yes".
                * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                o Click Preferences, then click the Statistics/Logs tab.
                o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                o Please copy and paste the Scan Log results in your next reply.
                * Click Close to exit the program.
                Post SUPERAntiSpyware log.

                RECONNECT TO THE INTERNET

                RESTART COMPUTER!

                2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                * Double-click mbam-setup.exe and follow the prompts to install the program.
                * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                * If an update is found, it will download and install the latest version.
                * Once the program has loaded, select Perform full scan, then click Scan.
                * When the scan is complete, click OK, then Show Results to view the results.
                * Be sure that everything is checked, and click Remove Selected.
                * When completed, a log will open in Notepad.
                * Post the log back here.

                The log can also be found here:
                C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                RESTART COMPUTER!

                3. Download HijackThis:
                http://www.snapfiles.com/get/hijackthis.html
                Post HijackThis log.

                2971.

                Solve : very bad computer infection!!! HELP!!?

                Answer»

                the first two have the error message that says I cant rename them before they even get put on the desktop
                yeah man I just cant seem to get either of the first two to work I dont understand what the error message means. Maybe is there a website I can just go to and find combofix maybe google it
                Trying to understand whats going on.

                Are you reading the directions correctly?
                Quote

                Download Combofix by sUBs from ONE of the below links.

                You don't need all three, multiple links are given in case one doesn't work.

                Delete all but one and try to run it.

                I KNOW, I tried to download the first link it when to download and I tried to click "run"
                and thats when the error mesage popped upHave you tried double clicking it to see if it will run that way?it never makes it to the desktop
                the error message pops up before the shortcut is created
                Lets do this.

                Download Deckard's System Scanner (DSS) and save it to your Desktop.
                • Close all other windows before proceeding.
                • Double-click on dss.exe and follow the prompts.
                • When it has finished, dss will open two Notepads main.TXT and extra.txt
                • Add the contents of main.txt and extra.txt in your next reply.
                I couldnt fit it all here so the main txt and the extra txt are attached here

                [recovering space - attachment deleted by admin]You need to enable all of AVG's services. You aren't protected running so few.


                Copy this file path C:\WINDOWS\etkq.exe (highlight and press ctrl+C)

                Go to www.viruschief.com

                Paste the file path in the window under QUICK Scan: (press ctrl+V on the keyboard to paste)

                Click Scan.

                You will see a message:
                ENG: It can take up to 1 minute before your scan starts, please wait!
                GER: Es kann bis zu einer Minute dauern bis Ihr Scan startet, bitte warten!

                Once the scan is complete, copy the text in the window under BB Code and paste it into the next post.
                Heres that BB code Info

                Antivir: Nothing found
                ArcaVir: Nothing found
                Avast: Nothing found
                AVG: Nothing found
                BitDefender: Nothing found
                F-Prot: Nothing found
                Norman: Nothing found
                Rising: Nothing found
                VirusBlokAda32: Nothing found
                VirusBuster: Nothing found

                Report overview
                Scanned by viruschief.com
                Delete this folder C:\Program Files\Antivirus 2008 PRO

                ----------

                Your Java is out of date.
                Older versions of Java have vulnerabilities that malware can use to infect your system.
                Please follow these steps to remove older version(s) of Java components and update.

                Step 1 - Get the new version
                • Go to the Sun Java Download Page
                • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
                • Click the button and choose the options.
                  • Platform Windows
                  • Language English
                  • Next place a check mark in the box to agree to the License Agreement.
                • "I agree to the Java SE Runtime Environment 6 License Agreement"
                • Click Continue
                • Click on the link to download Windows Offline Installation and save to your desktop.
                • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
                • Follow the prompts to complete the installation.
                Step 2 - Remove old version(s)
                • Close any programs you may have running - especially your web browser.
                • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
                • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
                • Do not remove Java 6 Update 6
                • Click the Remove or Change/Remove button.
                • Repeat as many times as necessary to remove each old Java version.
                • Restart your computer once all Java components are removed.
                Step 3 - Remove old folder(s)
                • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
                • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
                .
                ----------

                Run CCleaner.

                ----------

                This scanner works with Internet Explorer only
                Go to the BitDefender Online Scanner
                Click I Agree to the license and then install the ActiveX control.
                Please DO NOT change the Scanning Options.
                That will make your logs huge and we don't need to see clean files.

                Select Start Scan to begin.
                This scan can take a while so please be patient and let it complete.

                Once Bitdefender completes the scan:
                Click-on the Detected Problems tab.
                Then select Click here to export the scan report



                When the window comes up to save the report, change the Save as type: box to:
                Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save



                This will save a file named bdscan.txt. I WOULD suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

                This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

                If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us

                Post the bdscan.txt in the next post.
                2972.

                Solve : Avast Virus alert?

                Answer»

                My chum just CALLED me in quite a panic. Two pop-ups appeared on his monitor and he didn't know what to do. I had him do a screen PRINT and send it to me so I could try to figure out what he was talking about. First of all, he has a SuperAntiSpyware alert stating that it has detected and blocked a potential harmful application from running. The second is a Avast Virus alert stating that a virus was found. The File name is C:\Program files\ SuperAntiSpyware\SuperAntiSpyware.exe. The MALWARE name is Win32 Trojan-gen and the Malware type is Virus/Worm. I won't be able to check it until sometime tomorrow but I was wondering why a Virus/Worm would show up in this particular file or is Avast being too aggressive?It's a false positive with Avast and SUPERAntiSpyware 4.0. Make sure he has the NEW version of SUPERAntiSpyware 4.1. More info HERE

                Update. Make sure he has the latest updates for Avast as well.

                Quote from: Maxx_original link http://forum.avast.com/index.php?topic=35852.msg301049#msg301049

                this problem is solved with the last VPS afaik..
                I know that he gets the updates for Avast but I'll DL the new SuperAntiSpyware and see what happens. Thanks, guys.
                2973.

                Solve : isass.exe?

                Answer»

                According to Process Library, isass.exe is a virus. States: "issass.exe is REGISTERED as the Optix.pro virus which carries in it's payload the ability to disable firewalls and local security protections and a BACKDOOR capability."

                Disable and remove immediately!

                When I go to Task manager and click on isass.exe and try to end the process I get
                this message: "This is a critical systems process. Task manager cannot end this process."

                How can I get rid of this?
                Thanks, CumquatFirst of all...make SURE you don't have lsass.exe and isass.exe confused.

                lsass.exe is a critical windows component, but can also be misread...as in Isass.exe where the first letter is a capital "I". Two different animals...

                The latter (with an "i"), is trojan related...so make sure...if you did a scan...you do not have the two confused.Savior, Thanks. I had the two confused.
                You're WELCOME...'twas no problem at all...

                2974.

                Solve : Very bad Vundo-variant attack!?

                Answer»

                The computer seems to be working fine, thank you very much!
                The Genuine Windows was unable to validate. And the phrase "VIRUS ALERT!" is still in the taskbar next to the clock, which interestingly now READS in 24 hour time.What is the validation assistant saying?

                Is your Windows a paid copy? I don't care if it is or not but I need to know so I can give the right advice.

                Post a screenshot of the VIRUS ALERT so I can tell what it is.
                How to take a screen shot

                • Open up your Web Browser.
                • Or from the desktop. (for desktop screenshots)
                • Look on your keyboard and there should be a button (usually in the top right corner) that reads PrtSc or Print Screen, press that button.
                • Once the PrtSc button is pressed, Open up MICROSOFT Paint.
                  • Click Start
                  • Click Run
                  • Type in MSpaint
                  • Press Ok.
                • Once Paint is open
                • On the Menu bar click Edit > Paste
                • On the menu bar click File > Save as...
                • Choose the Save as type click the drop arrow, and choose Jpeg
                • Choose the save to location as the Desktop.
                • The click Save.
                .
                Add it as an attachment or host it online and post it in the thread. http://www.screenshots.cc/

                ----------

                To change military time to standard time

                Go to Start > Control Panel > Regional and Language Options
                Click the Customize button
                Select the Time tab
                In the Time Format area use the down arrow to select: h:mm:ss tt
                Click Apply
                Click OK
                Click Apply
                Click OK

                You may need to restart the computer to take effect.I purchased my Windows XP as an upgrade version. The computer was originally bought as a rebuilt with Windows 2000 already installed, so I don't know where that Windows came from.

                I can attach the "Failed Validation" screenshot if needed.

                [recovering space - attachment deleted by admin]Let's try to get the clock straightened out.

                1. Using your mouse, Highlight and then Right-click | Copy the entire contents of the Code box below. Do not change anything.

                Code: [Select]REGEDIT4

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
                "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Software Notifier]
                "InstallationID"=-

                [HKEY_CURRENT_USER\Control Panel\Colors]
                "Background"="0 78 152"

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "WallpaperStyle"="0"

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "TileWallpaper"="0"

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "Wallpaper"=" "

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "OriginalWallpaper"=""

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "ConvertedWallpaper"=-

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                "ctfmona"=-

                [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srservice]
                "Start"=dword:00000002

                [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sr]
                "Start"=dword:00000000

                [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sr]
                "ImagePath"="system32\DRIVERS\sr.sys"

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore]
                "DisableSR"=dword:00000000

                [HKEY_CURRENT_USER\Control Panel\Desktop]
                "SCRNSAVE.EXE"=-

                [-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop\General]
                "WallpaperFileTime"=-
                "WallpaperLocalFileTime"=-

                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                "NoDispAppearancePage"=-
                "NoDispBackgroundPage"=-

                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
                "NoFolderOptions"=-
                "NoControlPanel"=-
                "DisableLocalMachineRun"=-
                "DisableLocalMachineRunOnce"=-
                "DisableCurrentUserRun"=-
                "DisableCurrentUserRunOnce"=-
                "NoControlPanel"=-
                "NoWindowsUpdate"=-
                "NoFind"=-
                "NoRun"=-
                "HideClock"=-
                "NoTrayContextMenu"=-
                "NoTrayItemsDisplay"=-
                "NoSetFolders"=-

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
                "NoFolderOptions"=-
                "NoControlPanel"=-
                "DisableLocalMachineRun"=-
                "DisableLocalMachineRunOnce"=-
                "DisableCurrentUserRun"=-
                "DisableCurrentUserRunOnce"=-
                "NoControlPanel"=-
                "NoWindowsUpdate"=-
                "NoFind"=-
                "NoRun"=-
                "HideClock"=-
                "NoTrayContextMenu"=-
                "NoTrayItemsDisplay"=-
                "NoSetFolders"=-

                [HKEY_CURRENT_USER\ControlPanel\International]
                "sTimeFormat"="h:mm:ss tt"

                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
                "NoActiveDesktopChanges"=-
                "ForceActiveDesktopOn"=-
                Open a new Notepad It must be Notepad. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled.
                Right-click | Paste the Code box contents from above into Notepad. Click File, Save as..., and enter (including quotation marks) as the filename: "Fixreg.REG". Exit Notepad.

                Double click your new file and agree to the registry merge when asked. You can then delete this new file.

                Let me know if this worked.OK, I had to check a few different places on this one. You have a very new form of malware.

                Go HERE to get your Product ID issue straightened out (scroll down a bit). It also has another method for fixing the clock.

                Let me know if you have any questions and when you get done post a fresh Hijackthis log so we can see what all needs to be done to finish up.

                Also let me know how things are after the fixes are done.Miekiemoes' blog completed the last few minor repairs. The machine seems to be running fine.
                Thank you for all of your time and help. Your breadth of knowlege is staggering.


                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 10:28:22 PM, on 5/28/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [Auto EPSON Stylus CX3800 Series on DISH] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P39 "Auto EPSON Stylus CX3800 Series on DISH" /O15 "\\DISH\EPSONSty" /M "Stylus CX3800"
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
                O16 - DPF: ConferenceRoom Java Client - http://java.financialchat.com:8000/java/cr.cab
                O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
                O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
                O16 - DPF: {0D859AF0-C75E-11D4-B760-00E0B81077E8} (FileCruiser Class) - http://coop.mlxchange.com/Control/FileCruiser.cab
                O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
                O16 - DPF: {13D448F2-4D80-40BD-B1D7-25A9B7CB1474} (PMSImage Control) - http://24.75.126.108/install/PMSImage.ocx
                O16 - DPF: {16FD824B-8E7B-11D2-9855-00802962956C} (Specfile Control) - http://coop.mlxchange.com/Control/Specfile.cab
                O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
                O16 - DPF: {284DAE3C-A691-11D3-AD58-00E0B8107A24} (SISCtrl Class) - http://coop.mlxchange.com/Control/SISC.cab
                O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
                O16 - DPF: {4063B398-3FC7-433E-B23B-0460CE7EDC27} (MaxisMakinMagicTeleX Control) - http://thesims.ea.com/teleport/makinmagic/MaxisMakinMagicTeleX.cab
                O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://coop.mlxchange.com/Control/MultiSelectComboBox.cab
                O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://support.rexplorer.net/iftw_install//iftwclix.cab
                O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
                O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://coop.mlxchange.com/Control/MLXClientUtils.cab
                O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab
                O16 - DPF: {78523E50-56EB-11D3-B739-CAA1986A452F} (LiteGridCtl Class) - http://coop.mlxchange.com/Control/LiteGrid.cab
                O16 - DPF: {7A7537FC-5988-11D3-8B33-00104B9E5A4A} (IRCWwwPrint Class) - http://coop.mlxchange.com/Control/IRCWebPrint.cab
                O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://ctmls.mlxchange.com/4.2.06.26/Control/IRCSharc.cab
                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?AuthParam=1211955591_0bef0b16a370840ba69aa7314db5214e&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab&File=jinstall-6u6-windows-i586-jc.cab
                O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
                O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
                O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                O16 - DPF: {B151B524-F451-4036-9663-B3944FA710DF} (ExecuteAgent2p Class) - http://www.ct-mls.com/dss/ENUclientPro.cab
                O16 - DPF: {B198A72B-B4C3-42B5-B8DA-B364E76429AA} (Cerebus Class) - http://coop.mlxchange.com/Control/WebDog.cab
                O16 - DPF: {BC8E0F3E-2A7F-11D4-A0F2-0001022F24B8} (LIte Class) - http://coop.mlxchange.com/Components/OutlookXtract.cab
                O16 - DPF: {C7E73900-EF7C-4E63-B36E-E8EEE1CD7DA5} (MPGridControl Class) - http://coop.mlxchange.com/Components/MPGridControl.cab
                O16 - DPF: {F060A272-A18A-11D3-B75B-00E0B81077E8} (DropList Class) - http://coop.mlxchange.com/Control/AspCustomCtrls.cab
                O23 - SERVICE: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
                O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
                O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
                O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
                O24 - Desktop Component 4: (no name) - http://ctmls.mlxchange.com/

                --
                End of file - 8999 bytes


                This was a real head twister. That was a new infection that i haven't seen before.

                Looks like we both learned some new tricks today

                ----------

                Run Hijackthis and have it fix this entry unless you set it yourself.

                O24 - Desktop Component 4: (no name) - http://ctmls.mlxchange.com/

                ----------

                Final cleanup steps.

                Let's clear out the programs we've been using to clean up your computer, they are not suitable for
                general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
                .
                • Click START then RUN
                • Now type Combofix /u in the runbox
                • Make sure there's a space between Combofix and /u
                • Then hit Enter.
                .
                .
                The above procedure will:
                • Delete:
                  • ComboFix and its associated files and folders.
                  • VundoFix backups, if present
                  • The C:\Deckard folder, if present
                  • The C:_OtMoveIt folder, if present
                  • Reset the clock settings.
                  • Hide file extensions, if required.
                  • Hide System/Hidden files, if required.
                  • Set a new, clean Restore Point.
                  .
                  Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

                  1. Double click OTMoveIt2.exe to launch it.
                  Vista users right click and choose Run As Administrator
                  2. Click on the CleanUp! button.
                  3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                  4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                  5. Once complete exit out of OTMoveIt2

                  Set a New Restore Point to prevent possible reinfection from an old one
                  Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working STATE if needed.
                  • Go to Start > Programs > Accessories > System Tools and click System Restore
                  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                  • Next go to Start > Run and type Cleanmgr
                  • Click OK
                  • Click the More Options Tab.
                  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                  .

                  Now run CCleaner.


                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything LISTED.
                  .
                  Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  To prevent unknown applications from being installed on your computer install WinPatrol 2008

                  Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

                  Using SpywareBlaster to protect your computer from Spyware and Malware

                  Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                  Let us know if anything else comes up.
                  2975.

                  Solve : Windows XP Program Files?

                  Answer»

                  what is programfiles\commonfiles\paretologic\uus2\uus.dll this has been coming up on a daily basis 2-3 times a day for the last month. Thank you.You possibly have a spyware infection.
                  Do\did you have any ParetoLogic: http://www.paretologic.com/products/index.aspx product installed?No I don't have any paretologic software installed. Thanks for the help. Searched everything and nothing comes up.
                  I mentioned spyware because I did a google and found that there is a known virus that disguises itself as uus.dll and even creates a folder named C:\Program Files\Common Files\ParetoLogic\UUS\ to hide in.

                  It is sometimes called Trojan.Virtumonde or Vundo, and is difficult to remove. Spybot finds & deletes it but it returns in many cases.

                  I suggest that malware specialists be consulted.







                  We better check...

                  Print these instructions out.

                  1. Download SUPERAntiSpyware Free for Home Users:
                  http://www.superantispyware.com/

                  * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                  * An icon will be created on your desktop. Double-click that icon to launch the program.
                  * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                  * Close SUPERAntiSpyware.

                  Restart computer in Safe Mode.
                  To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                  * Open SUPERAntiSpyware.
                  * Under "Configuration and Preferences", click the Preferences button.
                  * Click the Scanning Control tab.
                  * Under Scanner Options make sure the following are checked (leave all others unchecked):
                  o Close browsers before scanning.
                  o Scan for tracking cookies.
                  o Terminate memory threats before quarantining.
                  * Click the "Close" button to leave the control center screen.
                  * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                  * On the left, make sure you check C:\Fixed Drive.
                  * On the right, under "Complete Scan", choose Perform Complete Scan.
                  * Click "Next" to start the scan. Please be patient while it scans your computer.
                  * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                  * Make sure everything has a checkmark next to it and click "Next".
                  * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                  * If asked if you want to reboot, click "Yes".
                  * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                  o Click Preferences, then click the Statistics/Logs tab.
                  o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                  o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                  o Please copy and paste the Scan Log results in your next reply.
                  * Click Close to exit the program.
                  Post SUPERAntiSpyware log.

                  RESTART COMPUTER!

                  2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                  * Double-click mbam-setup.exe and follow the prompts to install the program.
                  * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                  * If an update is found, it will download and install the latest version.
                  * Once the program has loaded, select Perform FULL scan, then click Scan.
                  * When the scan is complete, click OK, then Show Results to view the results.
                  * Be sure that everything is checked, and click Remove Selected.
                  * When completed, a log will open in Notepad.
                  * Post the log back here.

                  The log can also be found here:
                  C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                  Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                  RESTART COMPUTER!

                  3. Download HIJACKTHIS:
                  http://www.snapfiles.com/get/hijackthis.html
                  Post HijackThis log.Here is the first scan from Super Antispyware

                  The only thing I had was Cookies but I deleted everything anyway. Will be sent in 2 parts

                  SUPERAntiSpyware Scan Log
                  http://www.superantispyware.com

                  Generated 05/27/2008 at 01:25 AM

                  Application Version : 4.1.1046

                  Core Rules Database Version : 3459
                  Trace Rules Database Version: 1450

                  Scan type : Complete Scan
                  Total Scan Time : 03:19:08

                  Memory items scanned : 165
                  Memory threats detected : 0
                  Registry items scanned : 5241
                  Registry threats detected : 0
                  File items scanned : 78839
                  File threats detected : 276

                  Adware.Tracking Cookie
                  C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected]er[2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][4].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  Here is the 2nd part for the SuperAntispyware scan:

                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected]12.2o7[1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][4].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][6].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][7].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][8].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][4].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][6].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][7].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][4].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][5].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][7].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\ow[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
                  C:\Documents and Settings\Owner\My Documents\My Documents\Documents and Settings\Owner\Cookies\[emailprotected][1].txt


                  Here's the log from Malwarebytes:

                  Malwarebytes' Anti-Malware 1.12
                  Database version: 790

                  Scan type: Full Scan (C:\|D:\|)
                  Objects scanned: 122955
                  Time elapsed: 1 hour(s), 1 minute(s), 12 second(s)

                  Memory Processes Infected: 0
                  Memory Modules Infected: 0
                  Registry Keys Infected: 0
                  Registry Values Infected: 0
                  Registry Data Items Infected: 0
                  Folders Infected: 0
                  Files Infected: 0

                  Memory Processes Infected:
                  (No malicious items detected)

                  Memory Modules Infected:
                  (No malicious items detected)

                  Registry Keys Infected:
                  (No malicious items detected)

                  Registry Values Infected:
                  (No malicious items detected)

                  Registry Data Items Infected:
                  (No malicious items detected)

                  Folders Infected:
                  (No malicious items detected)

                  Files Infected:
                  (No malicious items detected)


                  ThanksHere is the hijackthis log THANKS

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 3:27:39 PM, on 5/27/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
                  C:\Program Files\Microsoft Windows OneCare Live\winss.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\PROGRA~1\Yahoo!\browser\ycommon.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
                  C:\Program Files\Yahoo!\browser\ybrwicon.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab
                  O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gsn.worldwinner.com/games/v47/shared/FunGamesLoader.cab
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
                  O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202183579750
                  O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
                  O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://games.bigfishgames.com/en_mysterysolitairese/online/SpinTopGamesLauncher.cab
                  O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab
                  O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v46/sol/sol.cab
                  O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
                  O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

                  --
                  End of file - 7045 bytes
                  Logs are clean.

                  Open Windows Explorer, navigate to:
                  C:\WINDOWS\Tasks, and see, if you have an entry, or sub-folder, named:
                  Pareto UNS.job
                  If so, delete it.

                  Let me know.There is a Paretologic registration under tasks I have deleted it. Don't know how it got there. Thank you very much for your help. Every once in awhile I run into something that I just can't figure out. I will keep your website on HAND just in case. Glad it was a bug or anything. Thanks again JNAN1954I'm glad, it's fixed
                  Possibly, it was "drive-by-install", while installing some other program.

                  2976.

                  Solve : Another issue with AVG 8.0?

                  Answer»

                  I just found this one: http://windowsbbs.com/showthread.php?t=73794
                  Quote

                  I RECENTLY downloaded the new free avg 8.0 and ever since when my security CHECK is being carried out ,at the end it says . The system has detected tampering with your registered product type, this is a violation of your software license, tampering with product type is not permitted.
                  Under the heading of Windows license violation.
                  Sounds like they have an illegal copy of something installed.the only thing i can think of is you messed around with regedit but i dont know if that would cause a problem. and i really dont recommend AVG i had problem after problem when i used that. http://support.microsoft.com/kb/260525well AVG worked well with my system and I have no complaints about it.

                  Maybe you uninstall the old AVG first and clear out all traces of it in the registry and then get the new one installed?My friend just brought me his XP computer today. He installed AVG 8.0 last night, and his computer got stuck on Compaq logo screen. I tried to help him last night over the phone, but he's not to computer savvy, and nothing worked.
                  Finally, I was able to get to Safe Mode, and uninstall it from there.
                  I restarted in Normal Mode, but the computer was very slow. Surely enough there was a bunch of registry leftovers.
                  It toook me some time to trace all of them.
                  Installed 7.5, and things are back to normal.Quote from: Broni on May 27, 2008, 06:35:46 PM
                  My friend just brought me his XP computer today. He installed AVG 8.0 last night, and his computer got stuck on Compaq logo screen. I tried to help him last night over the phone, but he's not to computer savvy, and nothing worked.
                  Finally, I was able to get to Safe Mode, and uninstall it from there.
                  I restarted in Normal Mode, but the computer was very slow. Surely enough there was a bunch of registry leftovers.
                  It toook me some time to trace all of them.
                  Installed 7.5, and things are back to normal.

                  The makers of AVG will stop supporting AVG 7.5 starting on May 30th, 2008. So if you want AVG, then you'll have to upgrade to the AVG 8.0 version. I suppose that you can try clicking the upgrade link in the message box telling you that AVg 7.5 will expire and install it as then. Maybe'll it work smoother and who knows?

                  By the way, I had not installed AVG 7.5 prior to installing the AVG 8.0 since I had reformatted computer once before.Ever since I upgraded to AVG 8.0 I've been having problems. First it was freezing up and then I was getting a weird error message and now tonight I can't use my email program. Any solutions?Quote
                  The makers of AVG will stop supporting AVG 7.5 starting on May 30th, 2008. So if you want AVG, then you'll have to upgrade to the AVG 8.0 version. I suppose that you can try clicking the upgrade link in the message box telling you that AVg 7.5 will expire and install it as then. Maybe'll it work smoother and who knows?

                  AVG 7.5 support was recently extended to the end of this year...
                  I believe this product ( both FREE and Paid ) was rushed to market prematurely...Quote
                  you can try clicking the upgrade link in the message box telling you that AVg 7.5 will expire and install it as then
                  This is exactly what my friend did, and got fried.

                  pepper
                  Uninstall, and go back to 7.5.
                  As patio said, updates will run until the end of the year, and maybe longer, if Grisoft won't CLEAN up 8.0 problems, SOON.
                  2977.

                  Solve : WHEN DO VIRUSES GET IN??

                  Answer»

                  sorry to keep going but I can't use secunia because the START button on the website is Java, and my browser wont let me use any java buttons, even though its updated, clean, and enabled>??Download the SECUNIA PSI - https://psi.secunia.com/Thanks for the diligent help EvilFantasy, but still not working- I cant get secunia PSI to work, just keeps saying "Interface is Loading"- hours. I dont know if all the problems are going back to the one problem, but if its gone from a malware problem to a software problem I can switch threads- you're the boss, whatever you say I'll do. I wonder if I let ccleaner's reg cleaner take out a vital peice of a program without saving a backup? CCleaner is normally very safe, I have used it fo ryears with no problems.

                  Do you have an XP CD?

                  If so, place it in your CD ROM drive and follow the instructions below:

                  • CLICK on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
                    • Let this run undisturbed until the window with the blue progress bar goes away
                  SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

                  If you want to see what was replaced, right-click My Computer and click on Manage.
                  In the NEW window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System.--OK I loaded the xp cd in and ran it LIKE you said, but it everything is as before. I'll post the log from the action just in case, its weird to read going from log.file to txt. I also cut it down to only actions with todays date 5-25
                  Here are a list of things I've come across without actually searching that aren't working

                  anything "Java"
                  "search" in start menu
                  "user accounts" in control panel

                  in search and user accounts, window comes up but are just blank

                  [recovering space - attachment deleted by admin]Not sure whats going on. I will do some looking around also and see if I can find a possible solution.thanks man- I'll pop over and drop a post in the software spot too and see what they say
                  I feel you pain man HOPE you get it fixed. After I download something I scan it firstThats a pretty loud signature there Pink Please see his sigI'm doing some of the last minute cleanup that you asked but I'm not sure what to do with the results that I get from Secunia. I have 1 end-of-life, 6 insecure, and 49 patched. The total score is 87%. Scroll down the page and it will show what needs updated.
                  2978.

                  Solve : I downloaded limewire basic and I see problems.?

                  Answer»

                  I will go over the spyware blaster material again.

                  Once again my system is running like brand new, thanks for your HELP and superantispyware. The only thing around here that doesn't run like new anymore is me.

                  As said earlier, I couldn't find the 'shout' or 'guest sign in box' in your blog. Send a link.

                  I have to go PICK up the 9 year old one from schoool now. I have those FEATURES on this blog HTTP://evilspages.blogspot.com/ Scroll down a little and look in the side bar.

                  It is in the side bar, both the shout and guestbook.

                  You could dig it here >>http://digg.com/security/BareWitness<< if you use Digg. Thanks!!!'Digg' sounds familiar besides just a cliche'. Isn't it a video sharing SITE? Usually if I can't see or experience an instant reward (mostly humor) by visiting a site; it takes longer to get out of it. I can dig it as we use to say back in the 70's when we new we were cool. Lol, I digg where you're coming from! Digg.com is a social bookmarking site, lots of interesting (and lame) stories about just about everything.

                  Catch You On The Flip~side < More 70's....

                  2979.

                  Solve : slow computer and "security checking" box at start up?

                  Answer»

                  I have been through the 6 steps on malware removal, GREAT success. do I need to keep the 3 spyware programs? Hijack, Super spyware & Malware removals, the logs are attached

                  [recovering space - attachment deleted by admin]Quote from: Chap on May 27, 2008, 11:18:07 PM

                  I have been through the 6 steps on malware removal, great success. do I need to keep the 3 spyware programs? Hijack, Super spyware & Malware removals, the logs are attached


                  [recovering space - attachment deleted by admin]The logs look fine. You can keep MBAM and SAS, they are free and good to run now and then to check to see if anything has crept in.

                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and SCROLL down to see if any updates are needed.
                  • Update anything listed.
                  .
                  Here are some great tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  To PREVENT unknown applications from being installed on your computer install WinPatrol 2008

                  Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for these ACTIVEX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

                  Using SpywareBlaster to protect your computer from Spyware and Malware

                  Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
                  2980.

                  Solve : Malware scan logfiles?

                  Answer»

                  SUPERAntiSpyware Scan Log
                  http://www.superantispyware.com

                  Generated 05/29/2008 at 02:00 AM

                  Application Version : 4.1.1046

                  Core Rules Database Version : 3469
                  Trace Rules Database Version: 1460

                  Scan type : Complete Scan
                  Total Scan Time : 00:20:28

                  Memory items scanned : 395
                  Memory threats detected : 0
                  Registry items scanned : 3370
                  Registry threats detected : 28
                  File items scanned : 20510
                  File threats detected : 20

                  Rogue.WinIFixer
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\HKCU\RunOnce
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\HKCU
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\HKLM\RunOnce
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\HKLM
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\StartMenuAllUsers
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun\StartMenuCurrentUser
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Autorun
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\BrowserObjects
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine\Packages
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer\Quarantine
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com\WinIFixer
                  C:\Documents and Settings\DRAGO\Application Data\WinIFixer.com
                  C:\Program Files\WinIFixer\MFC71.dll
                  C:\Program Files\WinIFixer\MFC71ENU.DLL
                  C:\Program Files\WinIFixer\msvcp71.dll
                  C:\Program Files\WinIFixer\msvcr71.dll
                  C:\Program Files\WinIFixer\WinIFixer.exe
                  C:\Program Files\WinIFixer\WinIFixerSkin.dll
                  C:\Program Files\WinIFixer
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run#WinIFixer [ C:\Program Files\WinIFixer\WinIFixer.exe ]
                  HKLM\Software\winifixer.com
                  HKLM\Software\winifixer.com#MGuid
                  HKLM\Software\winifixer.com\WinIFixer
                  HKLM\Software\winifixer.com\WinIFixer#RegistrationUrl
                  HKLM\Software\winifixer.com\WinIFixer#RegistrationDiscUrl
                  HKLM\Software\winifixer.com\WinIFixer#ADVid
                  HKLM\Software\winifixer.com\WinIFixer#InstallDir
                  HKLM\Software\winifixer.com\WinIFixer#domain
                  HKLM\Software\winifixer.com\WinIFixer#SoftID
                  HKLM\Software\winifixer.com\WinIFixer#DatabaseVersion
                  HKLM\Software\winifixer.com\WinIFixer#ProgramVersion
                  HKLM\Software\winifixer.com\WinIFixer#EngineVersion
                  HKLM\Software\winifixer.com\WinIFixer#GuiVersion
                  HKLM\Software\winifixer.com\WinIFixer#ProxyName
                  HKLM\Software\winifixer.com\WinIFixer#ProxyPort
                  HKLM\Software\winifixer.com\WinIFixer#ScanPriority
                  HKLM\Software\winifixer.com\WinIFixer#DaysInterval
                  HKLM\Software\winifixer.com\WinIFixer#ScanDepth
                  HKLM\Software\winifixer.com\WinIFixer#ScanSystemOnStartup
                  HKLM\Software\winifixer.com\WinIFixer#AutomaticallyUpdates
                  HKLM\Software\winifixer.com\WinIFixer#MinimizeOnStart
                  HKLM\Software\winifixer.com\WinIFixer#BackgroundScan
                  HKLM\Software\winifixer.com\WinIFixer#BackgroundScanTimeout
                  HKLM\Software\winifixer.com\WinIFixer#InstallationID
                  HKLM\Software\winifixer.com\WinIFixer#LastTimeStamp
                  HKLM\Software\winifixer.com\WinIFixer#LastUpdateDate
                  HKLM\Software\winifixer.com\WinIFixer\Settings

                  Trojan.Unknown Origin
                  C:\WINDOWS\SYSTEM32\CTFMONB.BMP
                  Malwarebytes' Anti-Malware 1.12
                  Database version: 794

                  Scan type: Quick Scan
                  Objects scanned: 38348
                  Time elapsed: 3 minute(s), 6 second(s)

                  Memory Processes Infected: 0
                  Memory Modules Infected: 0
                  Registry Keys Infected: 2
                  Registry Values Infected: 7
                  Registry Data Items Infected: 0
                  Folders Infected: 5
                  Files Infected: 6

                  Memory Processes Infected:
                  (No malicious items detected)

                  Memory Modules Infected:
                  (No malicious items detected)

                  Registry Keys Infected:
                  HKEY_CURRENT_USER\Software\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

                  Registry Values Infected:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\RegistrySmart\ (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\RegistrySmart\Microsoft.VC80.MFC\ (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\RegistrySmart\Microsoft.VC80.CRT\ (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Control Panel\Desktop\OriginalWallpaper (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Control Panel\Desktop\ConvertedWallpaper (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                  Registry Data Items Infected:
                  (No malicious items detected)

                  Folders Infected:
                  C:\Program Files\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Program Files\RegistrySmart\Microsoft.VC80.CRT (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Program Files\RegistrySmart\Microsoft.VC80.MFC (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

                  Files Infected:
                  C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\blackster.scr (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart\Log\2007 Oct 03 - 12_09_38 PM_421.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart\Log\2007 Oct 03 - 12_09_39 PM_906.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart\Log\2007 Oct 03 - 12_48_37 PM_812.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\DRAGO\Application Data\RegistrySmart\Log\2007 Oct 03 - 12_48_38 PM_984.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 2:31:10 AM, on 5/29/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\WINDOWS\System32\WLTRYSVC.EXE
                  C:\WINDOWS\System32\bcmwltry.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
                  C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
                  C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\WgaTray.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                  C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
                  C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                  O4 - GLOBAL STARTUP: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
                  O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                  O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191431293484
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191431278781
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
                  O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
                  O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
                  O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
                  O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
                  O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

                  --
                  End of file - 5670 bytes
                  Open Hijackthis and select Do a system scan only.

                  Place a check mark next to the following entries: (if there)

                  O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)

                  Important: Close all windows except for Hijackthis and then click Fix checked.

                  Exit Hijackthis.

                  ----------

                  Download ATF Cleaner by Atribune.
                  Note: Vista users must use Run As Administrator

                  • Double-click ATF-Cleaner.exe to run the program.
                    Under Main choose: Select All
                    Click the Empty Selected button.
                  If you use Firefox browser
                  • Click Firefox at the top and choose: Select All
                    Click the Empty Selected button.
                    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
                  If you use Opera browser
                  • Click Opera at the top and choose: Select All
                    Click the Empty Selected button.
                    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
                  Click Exit on the Main menu to close the program.

                  ----------

                  How is everything now?Everything is running better than ever! Thank you!Final steps...

                  Set a New Restore Point to prevent possible reinfection from an old one
                  Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                  • Go to Start > Programs > Accessories > System Tools and click System Restore
                  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you NEED to use System Restore.
                  • Next go to Start > Run and type Cleanmgr
                  • Click OK
                  • Click the More Options Tab.
                  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                  .
                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  To prevent unknown applications from being installed on your computer install WinPatrol 2008

                  Another thing I would SUGGEST installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

                  Using SpywareBlaster to protect your computer from Spyware and Malware

                  Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
                  2981.

                  Solve : Another malware problem...?

                  Answer»

                  Here are the scan logs you need:


                  SUPERAntiSpyware Scan Log
                  http://www.superantispyware.com

                  Generated 05/28/2008 at 01:58 AM

                  Application Version : 4.1.1046

                  Core Rules Database Version : 3469
                  Trace Rules Database Version: 1460

                  Scan type : Complete Scan
                  Total Scan Time : 02:14:28

                  Memory items scanned : 560
                  Memory threats detected : 0
                  Registry items scanned : 6816
                  Registry threats detected : 3
                  File items scanned : 224157
                  File threats detected : 1

                  Browser Hijacker.Internet Explorer Settings Hijack
                  HKU\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\Main#Start Page [ C:\WINDOWS\system32\spywarewarning.mht ]
                  HKU\S-1-5-20_Classes\Software\Microsoft\Internet Explorer\Main#Start Page [ C:\WINDOWS\system32\spywarewarning.mht ]
                  HKU\S-1-5-21-2494176788-1489953485-1697586048-1005_Classes\Software\Microsoft\Internet Explorer\Main#Start Page [ C:\WINDOWS\system32\spywarewarning.mht ]

                  Rogue.SpywareIsolator
                  C:\WINDOWS\system32\spywarewarning.mht


                  Malwarebytes' Anti-Malware 1.12
                  Database version: 793

                  Scan type: Quick Scan
                  Objects scanned: 41113
                  Time elapsed: 6 minute(s), 1 second(s)

                  Memory Processes Infected: 0
                  Memory Modules Infected: 0
                  Registry Keys Infected: 0
                  Registry Values Infected: 12
                  Registry Data Items Infected: 0
                  Folders Infected: 0
                  Files Infected: 4

                  Memory Processes Infected:
                  (No malicious items detected)

                  Memory Modules Infected:
                  (No malicious items detected)

                  Registry Keys Infected:
                  (No malicious items detected)

                  Registry Values Infected:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\IEUpdate (Trojan.Agent) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run\IEUpdate (Trojan.Agent) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\IEUpdate (Trojan.Agent) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\OLE\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.

                  Registry Data Items Infected:
                  (No malicious items detected)

                  Folders Infected:
                  (No malicious items detected)

                  Files Infected:
                  C:\Documents and Settings\Erick\Local Settings\Temp\3866689405.exe (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\acluik.exe (Trojan.Agent) -> Delete on reboot.
                  C:\WINDOWS\system32\accessh.exe (Worm.Sdbot) -> Delete on reboot.
                  C:\WINDOWS\system32\spywarewarning.mht (Trojan.FakeAlert) -> Delete on reboot.
                  Logfile of TREND Micro HijackThis v2.0.2
                  Scan saved at 7:32:24 AM, on 5/28/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\RUNDLL32.EXE
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Vongo\Tray.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                  C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Vongo\VongoService.exe
                  C:\WINDOWS\system32\mqsvc.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\WINDOWS\system32\mqtgsvc.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  O1 - Hosts: 124.217.251.159 google.dk
                  O1 - Hosts: 124.217.251.159 google.se
                  O1 - Hosts: 124.217.251.159 google.co.nz
                  O1 - Hosts: 124.217.251.159 google.cn
                  O1 - Hosts: 124.217.251.159 google.com.pr
                  O1 - Hosts: 124.217.251.159 google.com.ca
                  O1 - Hosts: 124.217.251.159 google.com.ch
                  O1 - Hosts: 124.217.251.159 google.fi
                  O1 - Hosts: 124.217.251.159 google.co.in
                  O1 - Hosts: 124.217.251.159 google.co.uk
                  O1 - Hosts: 124.217.251.159 google.lv
                  O1 - Hosts: 124.217.251.159 google.co.hu
                  O1 - Hosts: 124.217.251.159 google.lk
                  O1 - Hosts: 124.217.251.159 google.com.au
                  O1 - Hosts: 124.217.251.159 *Blocked Russian URL*
                  O1 - Hosts: 124.217.251.159 google.nl
                  O1 - Hosts: 124.217.251.159 google.be
                  O1 - Hosts: 124.217.251.159 google.de
                  O1 - Hosts: 124.217.251.159 gogle.de
                  O1 - Hosts: 124.217.251.159 googel.de
                  O1 - Hosts: 124.217.251.159 google.ro
                  O1 - Hosts: 124.217.251.159 google.kz
                  O1 - Hosts: 124.217.251.159 google.by
                  O1 - Hosts: 124.217.251.159 google.no
                  O1 - Hosts: 124.217.251.159 google.pl
                  O1 - Hosts: 124.217.251.159 google.com.pl
                  O1 - Hosts: 124.217.251.159 google.es
                  O1 - Hosts: 124.217.251.159 google.pt
                  O1 - Hosts: 124.217.251.159 google.com.br
                  O1 - Hosts: 124.217.251.159 google.vc
                  O1 - Hosts: 124.217.251.159 google.co.za
                  O1 - Hosts: 124.217.251.159 google.tm
                  O1 - Hosts: 124.217.251.159 google.com.my
                  O1 - Hosts: 124.217.251.159 google.bg
                  O1 - Hosts: 124.217.251.159 google.co.jp
                  O1 - Hosts: 124.217.251.159 google.ie
                  O1 - Hosts: 124.217.251.159 google.co.ck
                  O1 - Hosts: 124.217.251.159 google.com.mx
                  O1 - Hosts: 124.217.251.159 google.com.om
                  O1 - Hosts: 124.217.251.159 google.fr
                  O1 - Hosts: 124.217.251.159 google.mu
                  O1 - Hosts: 124.217.251.159 google.com.ph
                  O1 - Hosts: 124.217.251.159 google.com.jm
                  O1 - Hosts: 124.217.251.159 google.com
                  O1 - Hosts: 124.217.251.159 google.us
                  O1 - Hosts: 124.217.251.159 google.ro
                  O1 - Hosts: 124.217.251.159 www.google.dk
                  O1 - Hosts: 124.217.251.159 www.google.se
                  O1 - Hosts: 124.217.251.159 www.google.co.nz
                  O1 - Hosts: 124.217.251.159 www.google.cn
                  O1 - Hosts: 124.217.251.159 www.google.com.pr
                  O1 - Hosts: 124.217.251.159 www.google.com.ca
                  O1 - Hosts: 124.217.251.159 www.google.com.ch
                  O1 - Hosts: 124.217.251.159 www.google.fi
                  O1 - Hosts: 124.217.251.159 www.google.co.in
                  O1 - Hosts: 124.217.251.159 www.google.co.uk
                  O1 - Hosts: 124.217.251.159 www.google.lv
                  O1 - Hosts: 124.217.251.159 www.google.co.hu
                  O1 - Hosts: 124.217.251.159 www.google.lk
                  O1 - Hosts: 124.217.251.159 www.google.com.au
                  O1 - Hosts: 124.217.251.159 *Blocked Russian URL*
                  O1 - Hosts: 124.217.251.159 www.google.nl
                  O1 - Hosts: 124.217.251.159 www.google.be
                  O1 - Hosts: 124.217.251.159 www.google.de
                  O1 - Hosts: 124.217.251.159 www.gogle.de
                  O1 - Hosts: 124.217.251.159 www.googel.de
                  O1 - Hosts: 124.217.251.159 www.google.ro
                  O1 - Hosts: 124.217.251.159 www.google.kz
                  O1 - Hosts: 124.217.251.159 www.google.by
                  O1 - Hosts: 124.217.251.159 www.google.no
                  O1 - Hosts: 124.217.251.159 www.google.pl
                  O1 - Hosts: 124.217.251.159 www.google.com.pl
                  O1 - Hosts: 124.217.251.159 www.google.es
                  O1 - Hosts: 124.217.251.159 www.google.pt
                  O1 - Hosts: 124.217.251.159 www.google.com.br
                  O1 - Hosts: 124.217.251.159 www.google.vc
                  O1 - Hosts: 124.217.251.159 www.google.co.za
                  O1 - Hosts: 124.217.251.159 www.google.tm
                  O1 - Hosts: 124.217.251.159 www.google.com.my
                  O1 - Hosts: 124.217.251.159 www.google.bg
                  O1 - Hosts: 124.217.251.159 www.google.co.jp
                  O1 - Hosts: 124.217.251.159 www.google.ie
                  O1 - Hosts: 124.217.251.159 www.google.co.ck
                  O1 - Hosts: 124.217.251.159 www.google.com.mx
                  O1 - Hosts: 124.217.251.159 www.google.com.om
                  O1 - Hosts: 124.217.251.159 www.google.fr
                  O1 - Hosts: 124.217.251.159 www.google.mu
                  O1 - Hosts: 124.217.251.159 www.google.com.ph
                  O1 - Hosts: 124.217.251.159 www.google.com.jm
                  O1 - Hosts: 124.217.251.159 www.google.com
                  O1 - Hosts: 124.217.251.159 www.google.us
                  O1 - Hosts: 124.217.251.159 www.google.ro
                  O1 - Hosts: 124.217.251.159 www.video.google.com
                  O1 - Hosts: 124.217.251.159 www.maps.google.com
                  O1 - Hosts: 124.217.251.159 www.groups.google.com
                  O1 - Hosts: 124.217.251.159 www.news.google.com
                  O1 - Hosts: 124.217.251.159 www.images.google.com
                  O1 - Hosts: 124.217.251.159 www.earth.google.com
                  O1 - Hosts: 124.217.251.159 www.code.google.com
                  O1 - Hosts: 124.217.251.159 www.directory.google.com
                  O1 - Hosts: 124.217.251.159 www.labs.google.com
                  O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                  O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                  O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                  O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                  O4 - HKCU\..\RunServices: [IEUpdate] C:\WINDOWS\system32\acluik.exe
                  O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                  O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                  O4 - Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe
                  O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                  O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                  O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                  O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
                  O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin OBJECT) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210812860062
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
                  O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                  O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

                  --
                  End of file - 17126 bytes
                  Download SDFix.exe and save it to your Desktop.

                  Double click SDFix.exe and it will extract the files to %systemdrive%
                  (Drive that contains the Windows Directory, typically C:\SDFix)

                  Now then reboot your computer in Safe Mode by doing the following:

                  • Restart your computer
                  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
                  • Select the first option, to run Windows in Safe Mode, then press Enter.
                  • Choose your usual account.
                  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
                  • Type Y to begin the cleanup process.
                  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
                  • Press any Key and it will restart the PC.
                  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
                    (Report.txt will also be copied to Clipboard).
                  • Finally add the contents of the Report.txt in your next post along with a NEW Hijackthis log.

                  SDFix: Version 1.186
                  Run by Erick on Wed 05/28/2008 at 02:08 PM

                  Microsoft Windows XP [Version 5.1.2600]
                  Running From: C:\SDFix

                  Checking Services :


                  Restoring Windows Registry Values
                  Restoring Windows Default Hosts File

                  Rebooting


                  Checking Files :

                  Trojan Files Found:

                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
                  C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
                  C:\WINDOWS\system32\spywarewarning2.mht - Deleted





                  Removing Temp Files

                  ADS Check :



                  Final Check :

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-05-28 14:22:15
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0


                  Remaining Services :




                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
                  "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
                  "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                  "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
                  "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
                  "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpiscnapp.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
                  "C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
                  @=""
                  "C:\\Program Files\\Vongo\\VongoService.exe"="C:\\Program Files\\Vongo\\VongoService.exe:*:enabled:VongoService"

                  Remaining Files :


                  File Backups: - C:\SDFix\backups\backups.zip

                  Files with Hidden Attributes :

                  Thu 29 Jun 2006 0 A.SH. --- "C:\WINDOWS\SMINST\HPCD.SYS"
                  Wed 21 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                  Tue 20 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d820fbd6e1527bc9c51d0c3b240b96fd\BIT47.tmp"

                  Finished!

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 2:42:26 PM, on 5/28/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                  C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Vongo\VongoService.exe
                  C:\WINDOWS\system32\mqsvc.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\WINDOWS\system32\mqtgsvc.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\system32\RUNDLL32.EXE
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                  C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                  C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Vongo\Tray.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                  O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                  O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                  O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                  O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                  O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                  O4 - Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe
                  O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                  O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                  O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                  O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
                  O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210812860062
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
                  O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                  O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

                  --
                  End of file - 12703 bytes
                  The log looks OK now, are you still having any problems?every thing seems to be good now! THANK YOU!!! ONCE AGAIN!!!Set a New Restore Point to prevent possible reinfection from an old one
                  Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                  • Go to Start > Programs > Accessories > System Tools and click System Restore
                  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                  • The new restore point will be STAMPED with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                  • Next go to Start > Run and type Cleanmgr
                  • Click OK
                  • Click the More Options Tab.
                  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                  .
                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  Here are some GREAT FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  To prevent unknown applications from being installed on your computer install WinPatrol 2008

                  Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                  SpywareBlaster - Secure your Internet Explorer to MAKE it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

                  Using SpywareBlaster to protect your computer from Spyware and Malware

                  Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
                  2982.

                  Solve : wcmdmgr...cant find entry point?

                  Answer»

                  a window comes up with this or two other alerts every 10 min. i have a non licenced version of windows xp.(that MIGHT be the problem) ill write down the alerts and post them. help!!!!!!!!!!!The only thing we can recommend is for you to obtain a licensed copy of your operating sytem.Unless it's a virus of some SORT....

                  Have a look here:
                  http://www.microsoft.com/genuine/downloads/FAQ.aspx?displaylang=enWell...let's say it is a virus of some sort...

                  Having an unlicensed copy of an OS, should not be supported here...IMHO. There will be further PROBLEMS down the road...and suporting a non-licensed version of any Windows operating system, to me anywaay, is SUPPORTING warez.Get genuine: How can I take advantage of the Microsoft genuine Windows offer?

                  2983.

                  Solve : Avast Downloaded: Suggestions??

                  Answer»

                  Hi,

                  I have downloaded AVAST on my LAPTOP. I have few questions. Virus updates are automatic? Virus scanning only manual?

                  I have set it up. Do you have some SUGGESTIONS?

                  Thank you.

                  airUpdates are automatic.

                  Look here for instructions on SCHEDULING a ScanGo to program settings and be sure you got it all set up as automatic and then it's truly automatic for the updates. Thank you.
                  air

                  2984.

                  Solve : new computer; various problems!!!?

                  Answer»

                  Download OTMoveIt2 by OldTimer

                  • Save it to your desktop.

                    • Double-click OTMoveIt2.exe to RUN it.
                    • Copy the lines in the codebox below.
                  Code: [Select]C:\Users\All Users\xkhgzgvk
                  C:\Users\All Users\guqwlhse
                  C:\ProgramData\xkhgzgvk
                  C:\ProgramData\guqwlhse
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uvxttdix
                  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
                  • Click the red Moveit! button.
                  • Copy everything in the Results window (under the green bar) and paste it in your next reply.
                  • Close OTMoveIt2
                  I 'm so THANKFUL you're sticking in there with me to get through all this , what I call computer madness.

                  well here is what I got after the steps you requested. Hope it helps you help me.

                  Then maybe we can fix my other problems and I can enjoy using my computer.

                  [recovering space - attachment deleted by admin]Use the Kaspersky Online Scanner
                  • Click Accept.
                  • Answer Yes, when prompted to install an ActiveX component.
                  • The program will then begin downloading the latest definition files.
                  • Once the files have been downloaded click on NEXT
                  • Locate the Scan SETTINGS button & configure to:
                    • Scan using the following Anti-Virus database:
                      • Extended
                    • Scan Options:
                      • Scan Archives
                      • Scan Mail Bases
                      • Click OK & have it scan My Computer
                      When the scan is done, in the Scan is complete window (below), any infection is displayed.
                      There is no option to clean/disinfect, however, we need to analyze the information on the report.

                      To obtain the report:
                      Click on: Save Report As...



                      • Next, in the Save as prompt, Save in area, select: Desktop.
                      • In the File name area, use KScan, or something similar.
                      • In Save as type: click the drop arrow and select: Text file [*.txt]
                      • Then, click: Save


                      Please copy and paste the Kaspersky Online Scanner Report in your next post.finally found this text , IE put it in temp files and had to learn how to find it.

                      Sorry it took so long, hope this helps you.

                      P.S Trojan.WIN32.Blackbird still on desktop even though report says no infection, Is that not one?

                      [recovering space - attachment deleted by admin]Can you ATTACH a screenshot of the desktop?

                      How to take a screen shot
                      • Open up your Web Browser.
                      • Or from the desktop. (for desktop screenshots)
                      • Look on your keyboard and there should be a button (usually in the top right corner) that reads PrtSc or Print Screen, press that button.
                      • Once the PrtSc button is pressed, Open up Microsoft Paint.
                        • Click Start
                        • Click Run
                        • Type in MSpaint
                        • Press Ok.
                      • Once Paint is open
                      • On the Menu bar click Edit > Paste
                      • On the menu bar click File > Save as...
                      • Choose the Save as type click the drop arrow, and choose Jpeg
                      • Choose the save to location as the Desktop.
                      • The click Save.
                      WOW! THANX Evilfantasy That was cool learning how to take a screen shot of my desktop. hope I remember for future reference.

                      Yeah for the other stuff too.

                      here is the attachment.

                      after combofix I still haven't gotten bac regular time and my regular goggle toolbar with access to browse my timeline , where I can see the sites my kids have visited. That was a important bar for me. it did not return after did the system restore point
                      just a quick mention. If this is something that we will tackle after wards, sorry for the mention.

                      [recovering space - attachment deleted by admin]Right click it and choose Properties.

                      Take a screenshot of the properties box and post it here.

                      [recovering space - attachment deleted by admin]I hope this is what you mean or I lost.

                      [recovering space - attachment deleted by admin]It's just a picture file. Right click it and choose delete. Then run CCleaner.

                      ----------

                      Let's clear out the programs we've been using to clean up your computer, they are not suitable for
                      general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
                      .
                      • Click START then RUN
                      • Now type Combofix /u in the runbox
                      • Make sure there's a space between Combofix and /u
                      • Then hit Enter.
                      .
                      .
                      The above procedure will:
                      • Delete:
                        • ComboFix and its associated files and folders.
                        • VundoFix backups, if present
                        • The C:\Deckard folder, if present
                        • The C:_OtMoveIt folder, if present
                        • Reset the clock settings.
                        • Hide file extensions, if required.
                        • Hide System/Hidden files, if required.
                        • Set a new, clean Restore Point.
                        .
                        ----------

                        1. Double click OTMoveIt2.exe to launch it.
                        Vista users right click and choose Run As Administrator
                        2. Click on the CleanUp! button.
                        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                        5. Once complete exit out of OTMoveIt2

                        ----------

                        Clear your infected System restore points. See HERE for instructions.

                        ----------

                        Use the Secunia Software Inspector to check for out of date software.
                        • Click Start Now
                        • Check the box next to Enable thorough system inspection.
                        • Click Start
                        • Allow the scan to finish and scroll down to see if any updates are needed.
                        • Update anything listed.
                        .
                        Here are some great tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                        To prevent unknown applications from being installed on your computer install WinPatrol 2008

                        Another thing I WOULD suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                        SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.

                        Using SpywareBlaster to protect your computer from Spyware and Malware

                        Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                        Let me know how everthing is now.

                        OK did I misunderstand, did you say you wanted this properties screenshot or was the one I attached in post #37 correct.

                        [recovering space - attachment deleted by admin]Well did the Secunia scan, results say needed the macromedia flash player 9, but looked for it site only says adobe flash player.

                        Are adobe and macromedia the same.
                        tried to install, not successful.

                        still no toolbar to browse timeline

                        sorry I think It's called the google toolbar, has the icon to seach web pages and browse timeline throug google desktop.Use the Adobe Online Uninstaller to get rid of all old remnants.

                        Then install a Fresh Version

                        Try reinstalling the Google toolbar or Google desktop, or both.

                        That last screenshot is different from the first. Is the shortcut still there?

                        I have Adobe Flash Player ActiveX

                        Adobe Reader 8.1.2
                        and Adobe Shockwave Player
                        do I get rid of these?

                        got bac my google tool bar and have desktop, you're the best Evilfantasy.

                        shortcut of TrojanWIN32Blackbird still there, will use cleaner to rid and also delete it.Just do these two steps and everything will be OK.

                        Adobe Online Uninstaller

                        Then install a Fresh VersionEvery thing seems to be OK you truly have been a tremendous help to me Evilfantasy.

                        I'm so extremely happy I found this site, had those pesky files on my desktop for weeks, did'nt know what it meant but thankful for the help



                        Will carefully go throug your tips and try to stay safe.

                        Do I keep the other programs on the desktop and run how often , not sure?
                        Super-anti spyware , Mallwarebytes and ccleaner?


                        Should I also delete logs on desktop?

                        Are you done with me ? do you have suggestions for hooking up printer or should I continue to search data base? You're truly the BEST!!!!!!


                        MORE THANX FOR YOUR HELP.
                        2985.

                        Solve : Computer Infected with Vista Antivirus Malware?

                        Answer»

                        Do I restart after I fix checked on hijack this?If it asks you to then yes.Logfile of The Avenger Version 2.0, (c) by Swandog46
                        http://swandog46.geekstogo.com

                        Platform: Windows XP

                        *******************

                        Script file opened successfully.
                        Script file read successfully.

                        Backups directory opened successfully at C:\Avenger

                        *******************

                        Beginning to process script file:

                        Rootkit scan active.
                        No rootkits found!


                        Error: could not open file "C:\Program Files\VAV\vav.exe"
                        Deletion of file "C:\Program Files\VAV\vav.exe" failed!
                        Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
                        --> bad path / the parent directory does not exist


                        Error: folder "C:\Program Files\VAV" not found!
                        Deletion of folder "C:\Program Files\VAV" failed!
                        Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                        --> the object does not exist


                        Completed script processing.

                        *******************

                        Finished! Terminate.
                        combofix u did not repair clock but let me do the dss now Deckard's System Scanner v20071014.68
                        Main txt
                        Run by Compaq_Owner on 2008-07-30 23:08:21
                        Computer is in Normal Mode.
                        --------------------------------------------------------------------------------

                        -- System Restore --------------------------------------------------------------

                        Successfully created a Deckard's System Scanner Restore Point.


                        -- Last 2 Restore Point(s) --
                        2: 2008-07-31 03:08:25 UTC - RP1032 - Deckard's System Scanner Restore Point
                        1: 2008-07-31 02:57:33 UTC - RP1031 - System Checkpoint


                        Backed up registry hives.
                        Performed disk cleanup.

                        Total Physical Memory: 504 MiB (512 MiB recommended).


                        -- HijackThis (run as Compaq_Owner.exe) ----------------------------------------

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 23:09, on 2008-07-30
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\windows\system\hpsysdrv.exe
                        C:\HP\KBD\KBD.EXE
                        C:\WINDOWS\system32\igfxtray.exe
                        C:\WINDOWS\system32\hkcmd.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\Program Files\Common Files\AOL\1102902052\ee\AOLSoftware.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
                        C:\Program Files\McAfee.com\Agent\mcagent.exe
                        C:\Program Files\Microsoft IntelliType Pro\itype.exe
                        C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                        C:\Program Files\Common Files\AOL\Loader\aolload.exe
                        c:\program files\common files\aol\1102902052\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
                        C:\Program Files\Common Files\AOL\1102902052\EE\aolsoftware.exe
                        C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                        C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        c:\program files\common files\mcafee\mna\mcnasvc.exe
                        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\Program Files\McAfee\MPF\MPFSrv.exe
                        C:\WINDOWS\system32\sdpasvc.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\wanmpsvc.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        c:\PROGRA~1\mcafee\msc\mcuimgr.exe
                        C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
                        C:\PROGRA~1\TRENDM~1\Sniper.exe\Compaq_Owner.exe

                        R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
                        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
                        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
                        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                        O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102902052\ee\AOLSoftware.exe
                        O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
                        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                        O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: AutorunsDisabled
                        O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                        O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
                        O8 - Extra context menu item: Dogpile Cursor Search - C:\Documents and Settings\All Users\Application Data\Infospace\DogpileToolbar\contextsearch.htm
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
                        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
                        O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
                        O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
                        O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O15 - Trusted Zone: http://*.mcafee.com
                        O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommon/download/FIOS/tgctlcm.cab
                        O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                        O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                        O23 - Service: AOL TopSpeed MONITOR (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
                        O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
                        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                        O23 - Service: SDPAUMS server service (SDPASVC) - Matsushita Electric Industrial Co.,Ltd. - C:\WINDOWS\system32\sdpasvc.exe
                        O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

                        --
                        End of file - 10324 bytes

                        -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\Sniper.exe\backups\) ---------

                        backup-20080730-222639-100 O20 - Winlogon Notify: mlJBSJDS - mlJBSJDS.dll (file missing)
                        backup-20080730-222639-277 O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
                        backup-20080730-222639-341 O1 - Hosts: localhost 127.0.0.1
                        backup-20080730-222639-415 O2 - BHO: (no name) - {C7BA181A-E13D-4E4F-9EDB-24EBE0B34FFD} - C:\WINDOWS\system32\rqRLffca.dll (file missing)
                        backup-20080730-222639-528 O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
                        backup-20080730-222639-726 O2 - BHO: (no name) - {FBF85A20-FF88-4C46-90FB-B023E5C4ECA0} - C:\WINDOWS\system32\mlJBSJDS.dll (file missing)
                        backup-20080730-222642-209 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        backup-20080730-222642-409 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

                        -- File Associations -----------------------------------------------------------

                        .reg - regfile - shell\open\command - regedit.exe "%1" %*
                        .scr - scrfile - shell\open\command - "%1" %*


                        -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

                        S3 catchme - c:\combofix\catchme.sys (file missing)
                        S3 EraserUtilRebootDrv - c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys (file missing)


                        -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

                        R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe"
                        R2 SDPASVC (SDPAUMS server service) - c:\windows\system32\sdpasvc.exe -service

                        S4 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe"


                        -- Device Manager: Disabled ----------------------------------------------------

                        No disabled devices found.


                        -- Scheduled Tasks -------------------------------------------------------------

                        2008-05-01 01:00:00 366 --a------ C:\WINDOWS\Tasks\McQcTask.job
                        2008-03-23 11:02:44 364 --a------ C:\WINDOWS\Tasks\McDefragTask.job
                        2007-12-05 21:06:09 314 --ah----- C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job
                        2007-12-05 21:06:09 304 --ah----- C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job


                        -- Files created between 2008-06-30 and 2008-07-30 -----------------------------

                        2008-07-30 21:48:21 0 d-------- C:\Program Files\Trend Micro
                        2008-07-30 21:42:50 0 dr-h----- C:\Documents and Settings\Compaq_Owner\Recent
                        2008-07-30 21:23:07 0 d-------- C:\Program Files\Sun
                        2008-07-30 20:49:51 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
                        2008-07-30 20:49:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                        2008-07-30 20:49:44 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
                        2008-07-30 18:47:21 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
                        2008-07-30 18:47:11 0 d-------- C:\Program Files\SUPERAntiSpyware
                        2008-07-30 18:47:11 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com
                        2008-07-30 18:46:31 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
                        2008-07-30 18:36:47 0 d-------- C:\Program Files\CCleaner
                        2008-07-30 06:11:25 99456 --a------ C:\WINDOWS\system32\cnuxtest.dll
                        2008-07-29 12:48:16 0 d-------- C:\WINDOWS\system32\CatRoot_bak


                        -- Find3M Report ---------------------------------------------------------------

                        2008-07-30 21:39:04 0 d-------- C:\Program Files\Java
                        2008-07-30 18:46:31 0 d-------- C:\Program Files\Common Files
                        2008-07-30 18:24:32 0 d-------- C:\Program Files\Viewpoint
                        2008-05-30 11:57:48 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SiteAdvisor


                        -- Registry Dump ---------------------------------------------------------------

                        *Note* empty entries & legit default entries are not shown


                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
                        "KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02]
                        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 09:03]
                        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 08:59]
                        "AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]
                        "PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13]
                        "HostManager"="C:\Program Files\Common Files\AOL\1102902052\ee\AOLSoftware.exe" [2007-10-08 17:50]
                        "AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 08:50]
                        "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-02 21:08]
                        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
                        "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-12 01:58]
                        "SiteAdvisor"="C:\Program Files\SiteAdvisor\6009\SiteAdv.exe" [2006-11-18 08:46]
                        "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33]
                        "itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 21:08]
                        "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 19:52]
                        "RegistryMechanic"="" []
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27]

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00]
                        "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33]

                        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
                        Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50]
                        Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "DisableRegistryTools"=0 (0x0)
                        "HideLegacyLogonScripts"=0 (0x0)
                        "HideLogoffScripts"=0 (0x0)
                        "RunLogonScriptSync"=1 (0x1)
                        "RunStartupScriptSync"=0 (0x0)
                        "HideStartupScripts"=0 (0x0)

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                        "HideLegacyLogonScripts"=0 (0x0)
                        "HideLogoffScripts"=0 (0x0)
                        "RunLogonScriptSync"=1 (0x1)
                        "RunStartupScriptSync"=0 (0x0)
                        "HideStartupScripts"=0 (0x0)
                        "DisableRegistryTools"=0 (0x0)

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                        C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                        "Authentication Packages"= msv1_0 C:\WINDOWS\system32\rqRLffca

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                        SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
                        @=""

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
                        @=""

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windi04.sys]
                        @="Driver"


                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b6e7ac2c-9c5a-11db-9416-00038a000015}]
                        AutoRun\command- J:\LaunchU3.exe -a




                        -- End of Deckard's System Scanner: finished at 2008-07-30 23:10:56 ------------

                        Deckard's System Scanner v20071014.68
                        Extra logfile - please post this as an attachment with your post.
                        --------------------------------------------------------------------------------

                        -- System Information ----------------------------------------------------------

                        Microsoft Windows XP Home Edition (build 2600) SP 2.0
                        Architecture: X86; Language: English

                        CPU 0: Intel(R) Celeron(R) CPU 2.93GHz
                        Percentage of Memory in Use: 57%
                        Physical Memory (total/avail): 503.49 MiB / 214.87 MiB
                        Pagefile Memory (total/avail): 1230.19 MiB / 863.84 MiB
                        Virtual Memory (total/avail): 2047.88 MiB / 1933.13 MiB

                        C: is Fixed (NTFS) - 74.56 GiB total, 61.02 GiB free.
                        D: is CDROM (No Media)
                        E: is CDROM (Unformatted)
                        F: is Removable (No Media)
                        G: is Removable (No Media)
                        H: is Removable (No Media)
                        I: is Removable (No Media)

                        \\.\PHYSICALDRIVE0 - SAMSUNG SP0802N - 74.56 GiB - 1 partition
                        \PARTITION0 (bootable) - Installable File System - 74.56 GiB - C:

                        \\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

                        \\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

                        \\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

                        \\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device



                        -- Security Center -------------------------------------------------------------

                        AUOptions is scheduled to auto-install.
                        Windows Internal Firewall is disabled.

                        FirstRunDisabled is set.
                        AntiVirusDisableNotify is set.

                        FW: McAfee Personal Firewall v (McAfee)
                        FW: Norton Internet Security 2006 v2006 (Symantec Corporation)
                        AV: McAfee VirusScan v (McAfee) Disabled

                        [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
                        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 6.2"
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                        [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"="C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe:*:Enabled:BackWeb for Presario"
                        "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
                        "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
                        "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
                        "C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
                        "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
                        "C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
                        "C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
                        "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Disabled:Earthlink"
                        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 6.2"
                        "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
                        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
                        "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                        "C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
                        "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                        "C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\aolsoftware.exe:*:Enabled:AOL Shared Components"
                        "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe:*:Enabled:AOL TopSpeed"
                        "C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\AOLDesktop.exe"="C:\\Program Files\\Common Files\\AOL\\1102902052\\EE\\AOLDesktop.exe:*:Enabled:AOL Desktop"
                        "C:\\Program Files\\TurboTax\\Deluxe 2007\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Deluxe 2007\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
                        "C:\\Program Files\\TurboTax\\Deluxe 2007\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Deluxe 2007\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
                        "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"


                        -- Environment Variables -------------------------------------------------------

                        ALLUSERSPROFILE=C:\Documents and Settings\All Users
                        APPDATA=C:\Documents and Settings\Compaq_Owner\Application Data
                        CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
                        CLIENTNAME=Console
                        CommonProgramFiles=C:\Program Files\Common Files
                        COMPUTERNAME=CATHY
                        ComSpec=C:\WINDOWS\system32\cmd.exe
                        FP_NO_HOST_CHECK=NO
                        HOMEDRIVE=C:
                        HOMEPATH=\Documents and Settings\Compaq_Owner
                        LOGONSERVER=\\CATHY
                        NUMBER_OF_PROCESSORS=1
                        OS=Windows_NT
                        Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystem
                        PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                        PROCESSOR_ARCHITECTURE=x86
                        PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel
                        PROCESSOR_LEVEL=15
                        PROCESSOR_REVISION=0304
                        ProgramFiles=C:\Program Files
                        PROMPT=$P$G
                        QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
                        SESSIONNAME=Console
                        SystemDrive=C:
                        SystemRoot=C:\WINDOWS
                        TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
                        TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
                        USERDOMAIN=CATHY
                        USERNAME=Compaq_Owner
                        USERPROFILE=C:\Documents and Settings\Compaq_Owner
                        windir=C:\WINDOWS


                        -- User Profiles ---------------------------------------------------------------

                        Compaq_Owner (admin)
                        Administrator (admin)


                        -- Add/Remove Programs ---------------------------------------------------------

                        --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
                        --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                        --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
                        --> c:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                        --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe"
                        --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe"
                        --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe"
                        --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                        Adobe Acrobat 6.0 Professional --> MsiExec.exe /I{AC76BA86-1033-0000-7760-000000000001}
                        Adobe Atmosphere Player for Acrobat and Adobe Reader --> C:\WINDOWS\atmoUn.exe
                        Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                        Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                        Adobe Photoshop Album 2.0 Starter Edition --> MsiExec.exe /I{11B569C2-4BF6-4ED0-9D17-A4273943CB24}
                        Adobe Reader 7.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
                        Agere Systems PCI Soft Modem --> agrsmdel
                        AnswerWorks 4.0 Runtime - English --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}\setup.exe" -l0x9 -removeonly
                        AOL Coach Version 1.0(Build:20030807.3) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
                        AOL Coach Version 2.0(Build:20041026.5 en) --> C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP
                        AOL Registration --> "C:\Program Files\AOL\RC\uninstall.exe"
                        AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
                        Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
                        Bonjour --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{E0A96F36-D546-4A2A-BDAA-2A2A578B2C0D} /l1033
                        CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
                        Citrix ICA Web Client --> C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
                        Citrix ICA Web Client (Minimal Installation) --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wficac.inf,DefaultUninstall
                        Compaq Connections --> C:\WINDOWS\BWUnin-6.3.2.62.exe -AppId 6750491
                        DATA BECKER Complete Home Designer 4.0 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\DATA BECKER\Complete Home Designer\446832.isu"
                        Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                        Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
                        Help and Support Additions --> C:\PROGRA~1\HELPAN~1\UNWISE.EXE C:\PROGRA~1\HELPAN~1\INSTALL.LOG
                        High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
                        HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                        Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
                        InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
                        iPod Updater 2004-11-15 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{06E73C0B-7DE7-4F41-860B-587033B75BD9} /l1033
                        iTunes --> MsiExec.exe /I{885894A5-BA0A-460E-AB4C-96C5C9B2C5E2}
                        Java(TM) 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                        KBD --> C:\HP\KBD\KBD.EXE uninstalled
                        Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
                        Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                        McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
                        Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
                        Microsoft Plus! Dancer LE --> MsiExec.exe /X{1A103D70-5C9B-4E1A-B306-5106C68F9914}
                        Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
                        Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
                        Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
                        MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                        MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
                        OpenOffice.org Installer 1.0 --> MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
                        PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe"
                        PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\pSetup.exe" -uninstall
                        PowerPlugs: Charts --> C:\Program Files\PowerPlugs\Charts\UnInstall PPCharts.exe
                        PS2 --> C:\WINDOWS\system32\ps2.exe uninstall
                        Python 2.2 combined Win32 extensions --> C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log
                        Python 2.2.1 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
                        QuickTime --> MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
                        RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                        Registry Cleaner 4.0 --> "C:\Program Files\Registry Cleaner Retail\unins000.exe"
                        Registry Mechanic 7.0 --> "C:\Program Files\Registry Mechanic\unins000.exe"
                        RTA Fleet Management Software Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92AD1034-DA95-4054-9791-DBC0DFEE7F5A}\setup.exe" -l0x9 Uninstall -removeonly
                        Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                        Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                        Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                        Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                        Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                        SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
                        TurboTax Deluxe 2005 --> C:\Program Files\TurboTax\Deluxe 2005\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2005\Uninstall.log" -NoGui
                        TurboTax Deluxe 2007 --> C:\Program Files\TurboTax\Deluxe 2007\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2007\Uninstall.log" -NoGui
                        TurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}
                        Verizon FiOS Activation --> "C:\WINDOWS\FIOS\unins000.exe"
                        WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
                        Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\WINDOWS\cache\YINSTH~1.DLL
                        Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
                        Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
                        Yahoo! Messenger Explorer Bar --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\MESSEN~1\YHEXBM~1.DLL
                        Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


                        -- Application Event Log -------------------------------------------------------

                        Event Record #/Type19699 / Error
                        Event Submitted/Written: 07/30/2008 08:11:15 AM
                        Event ID/Source: 1002 / Application Hang
                        Event Description:
                        Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

                        Event Record #/Type19693 / Error
                        Event Submitted/Written: 07/30/2008 07:52:27 AM
                        Event ID/Source: 1002 / Application Hang
                        Event Description:
                        Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

                        Event Record #/Type19692 / Error
                        Event Submitted/Written: 07/30/2008 07:15:38 AM
                        Event ID/Source: 1002 / Application Hang
                        Event Description:
                        Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

                        Event Record #/Type19691 / Error
                        Event Submitted/Written: 07/30/2008 07:08:09 AM
                        Event ID/Source: 1001 / Application Hang
                        Event Description:
                        Fault bucket 126637809.

                        Event Record #/Type19690 / Error
                        Event Submitted/Written: 07/30/2008 07:08:02 AM
                        Event ID/Source: 1002 / Application Hang
                        Event Description:
                        Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.



                        -- Security Event Log ----------------------------------------------------------

                        No Errors/Warnings found.


                        -- System Event Log ------------------------------------------------------------

                        Event Record #/Type7926 / Error
                        Event Submitted/Written: 07/30/2008 10:50:39 PM
                        Event ID/Source: 7022 / Service Control Manager
                        Event Description:
                        The Bonjour Service service hung on starting.

                        Event Record #/Type7925 / Error
                        Event Submitted/Written: 07/30/2008 10:50:21 PM
                        Event ID/Source: 10010 / DCOM
                        Event Description:
                        The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register with DCOM within the required timeout.

                        Event Record #/Type7924 / Error
                        Event Submitted/Written: 07/30/2008 10:49:41 PM
                        Event ID/Source: 10010 / DCOM
                        Event Description:
                        The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register with DCOM within the required timeout.

                        Event Record #/Type7895 / Error
                        Event Submitted/Written: 07/30/2008 10:38:07 PM
                        Event ID/Source: 7022 / Service Control Manager
                        Event Description:
                        The Bonjour Service service hung on starting.

                        Event Record #/Type7894 / Error
                        Event Submitted/Written: 07/30/2008 10:37:46 PM
                        Event ID/Source: 10010 / DCOM
                        Event Description:
                        The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register with DCOM within the required timeout.



                        -- End of Deckard's System Scanner: finished at 2008-07-30 23:10:56 ------------

                        These fixes will not harm the software it is related to. They are not necessary to run at startup and this will help the performance of the computer.

                        Open HijackThis and select Do a system scan only.

                        Place a check mark next to the following entries: (if there)

                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


                        Important: Close all windows except for HijackThis and then click Fix checked.

                        Exit HijackThis.

                        ----------

                        • Run avenger.exe by double-clicking on it.
                        • Do not change any check box options!!
                        • Copy everything in the Code box below, and paste it into the Input script here window:
                        [/list]Code: [Select]Comment:

                        Files to delete:
                        C:\WINDOWS\system32\cnuxtest.dll
                        C:\WINDOWS\system32\CatRoot_bak

                        Note: the above instructions were created specifically for this user. If you are not this user, DO NOT follow these DIRECTIONS as they could damage the workings of your system


                        • Now click the Execute button.
                        • Click Yes to the prompt to confirm you want to execute.
                        • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
                        • Your PC should reboot, if not, reboot it yourself.
                        • A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
                        • Add the Avenger log in your next post.
                        .
                        ----------

                        Go to Start > Run and type notepad.exe then click OK

                        Copy the text in the Code box below and paste it into Notepad.

                        Code: [Select]REGEDIT4

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
                        "QuickTime Task"=-
                        "TkBellExe"=-
                        "iTunesHelper"=-
                        "IgfxTray"=-

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                        "Authentication Packages"= msv1_0
                        In Notepad go to File > Save as...

                        Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the desktop.

                        There should now be a file on the Desktop that looks like this

                        Double-click fixme.reg it and allow it to merge with the Registry.

                        You MAY not see anything happen but give it a few seconds or so to finish.

                        Now delete the fixme.reg file from the desktop.

                        ----------

                        To change military time to standard time

                        Go to Start > Control Panel > Regional and Language Options
                        Click the Customize button
                        Select the Time tab
                        In the Time Format area use the down arrow to select: h:mm:ss tt
                        Click Apply
                        Click OK
                        Click Apply
                        Click OK

                        Restart the computer.

                        ----------

                        Let me know how everything is now.Logfile of The Avenger Version 2.0, (c) by Swandog46
                        http://swandog46.geekstogo.com

                        Platform: Windows XP

                        *******************

                        Script file opened successfully.
                        Script file read successfully.

                        Backups directory opened successfully at C:\Avenger

                        *******************

                        Beginning to process script file:

                        Rootkit scan active.
                        No rootkits found!

                        File "C:\WINDOWS\system32\cnuxtest.dll" deleted successfully.

                        Error: "C:\WINDOWS\system32\CatRoot_bak" is a folder, not a file!
                        Deletion of file "C:\WINDOWS\system32\CatRoot_bak" failed!
                        Status: 0xc00000ba (STATUS_FILE_IS_A_DIRECTORY)
                        --> use "Folders to delete:" instead of "Files to delete:" to delete a directory


                        Completed script processing.

                        *******************

                        Finished! Terminate.
                        I screwed that up. Please run The Avenger one more time and input these lines.

                        Code: [Select]Folders to delete:
                        C:\WINDOWS\system32\CatRoot_bakLogfile of The Avenger Version 2.0, (c) by Swandog46
                        http://swandog46.geekstogo.com

                        Platform: Windows XP

                        *******************

                        Script file opened successfully.
                        Script file read successfully.

                        Backups directory opened successfully at C:\Avenger

                        *******************

                        Beginning to process script file:

                        Rootkit scan active.
                        No rootkits found!

                        Folder "C:\WINDOWS\system32\CatRoot_bak" deleted successfully.

                        Completed script processing.

                        *******************

                        Finished! Terminate.Thanks, and sorry about that!Thank you so much, you completely repaired my computer, it is working so much faster and I just hope I can protect it using the tools you helped me acquire. Do you have any written instructions for maintaining the files and preventing malware and virus entries? I cannot thank you enough, you put so much time into helping me. I will refer this site to all of my friends and family... Take care...You did finish the rest of the instructions?

                        Final cleanup and advice. Let me know if you have any questions.

                        Delete ALL temporary files

                        Go to:
                        • Start
                        • Run
                        • type: CLEANMGR.EXE
                        • Press Enter.
                        When prompted select the C: drive and click OK.
                        Check the boxes for:
                        • Temporary Internet Files
                        • Downloaded Program Files
                        • Recycle Bin
                        • Temporary Files
                        Click OK or Enter

                        ----------

                        Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

                        1. Double click OTMoveIt2.exe to launch it.
                        Vista users right click and choose Run As Administrator
                        2. Click on the CleanUp! button.
                        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                        5. Once complete exit out of OTMoveIt2

                        ----------

                        Set a New Restore Point to prevent possible reinfection from an old one
                        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                        • Go to Start > Programs > Accessories > System Tools and click System Restore
                        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                        • Next go to Start > Run and type Cleanmgr
                        • Click OK
                        • Click the More Options Tab.
                        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                        You can find instructions on how to enable and re-enable system restore here:

                        Windows XP System Restore Guide or Windows Vista System Restore Guide
                        .
                        ----------

                        Use the Secunia Software Inspector to check for out of date software.
                        • Click Start Now
                        • Check the box next to Enable thorough system inspection.
                        • Click Start
                        • Allow the scan to finish and scroll down to see if any updates are needed.
                        • Update anything listed.
                        .
                        ----------

                        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                        ----------

                        Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                        To prevent unknown applications from being installed on your computer install WinPatrol 2008
                        * Using Winpatrol to protect your computer from malicious software

                        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                        * Using SpywareBlaster to protect your computer from Spyware and Malware
                        * If you don't know what ActiveX controls are, see here

                        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                        Use only trusted security software like the programs listed on this page. Trusted security tools & resources
                        2986.

                        Solve : Computer freezing up!?

                        Answer»

                        Hi Guys
                        Im having problems with my computer freezing, and error reports!
                        I have done logs for Anti SPYWARE, Malwarebytes, Hijack This.
                        Can you plaease have a look at them? it SEMS ok at the moment!
                        But you guys know what you doing, and helped me before.

                        [recovering disk space -- attachment DELETED by admin]Here's the other things you might require!

                        http://www.superantispyware.com

                        Generated 08/01/2008 at 00:14 AM

                        Application Version : 4.15.1000

                        Core Rules Database Version : 3522
                        Trace Rules Database Version: 1512

                        Scan type : Quick Scan
                        Total Scan Time : 00:38:20

                        Memory items scanned : 470
                        Memory threats detected : 0
                        Registry items scanned : 529
                        Registry threats detected : 1
                        File items scanned : 30559
                        File threats detected : 32

                        Adware.Tracking Cookie
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][3].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\steven westwood\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][2].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][3].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][3].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][4].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][5].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][7].txt
                        C:\Documents and Settings\michelle kenney\Cookies\[emailprotected][1].txt

                        Unclassified.PC MightyMax
                        HKU\S-1-5-21-962222287-2876006701-2902360359-1008\Software\PC MightyMax
                        And the other!

                        Database version: 1012
                        Windows 5.1.2600 Service Pack 2

                        11:28:58 PM 31/07/2008
                        mbam-log-7-31-2008 (23-28-58).txt

                        Scan type: Quick Scan
                        Objects scanned: 65299
                        Time elapsed: 22 MINUTE(s), 38 second(s)

                        Memory Processes Infected: 0
                        Memory Modules Infected: 0
                        Registry Keys Infected: 0
                        Registry Values Infected: 0
                        Registry Data Items Infected: 0
                        Folders Infected: 0
                        Files Infected: 0

                        Memory Processes Infected:
                        (No malicious items detected)

                        Memory Modules Infected:
                        (No malicious items detected)

                        Registry Keys Infected:
                        (No malicious items detected)

                        Registry Values Infected:
                        (No malicious items detected)

                        Registry Data Items Infected:
                        (No malicious items detected)

                        Folders Infected:
                        (No malicious items detected)

                        Files Infected:
                        (No malicious items detected)
                        I don't see any MALWARE in the HJT log. You may want to post in the Microsoft Windows forum for advice.

                        2987.

                        Solve : %systemroot%\system32\cmd.exe? Policies Changed/locked Out Of Installing/cpu Hi?

                        Answer»

                        I have been attempting to troubleshoot this for a week USING your guides. Here is the log in normal boot from today. The initial reference safe-mode Hijack log is attached. Please let me know how I can clean up and find leaks in my system. I tried to run Deckard earlier this morning, but I feared changing anything else in fear of damage. Thank you.

                        Whatever is on my computer deleted MBAM - and won't allow me to reinstall. Here is the most recent Hijack thist.

                        Logfile of Trend MICRO HijackThis v2.0.2
                        Scan saved at 10:15:32 AM, on 7/31/2008
                        Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\msdtc.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
                        C:\WINDOWS\system32\cisvc.exe
                        C:\WINDOWS\system32\crypserv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\WINDOWS\system32\inetsrv\inetinfo.exe
                        C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\netdde.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        C:\WINDOWS\System32\snmp.exe
                        c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\Program Files\ThreatFire\TFService.exe
                        C:\WINDOWS\system32\wdfmgr.exe
                        C:\Program Files\Apoint\Apoint.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                        C:\WINDOWS\system32\ICO.EXE
                        C:\Program Files\Common Files\Sony Shared\VAIO ENTERTAINMENT Platform\VCSW\VCSW.exe
                        C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                        C:\WINDOWS\system32\wbem\wmiapsrv.exe
                        C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                        C:\WINDOWS\System32\dmadmin.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\WINDOWS\system32\netdde.exe
                        C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE
                        C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                        C:\WINDOWS\system32\igfxext.exe
                        C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
                        C:\WINDOWS\system32\igfxsrvc.exe
                        C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                        C:\Program Files\Apoint\Apntex.exe
                        C:\Program Files\Apoint\Apvfb.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\WINDOWS\system32\cidaemon.exe
                        C:\WINDOWS\system32\cidaemon.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\explorer.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\tcpsvcs.exe
                        C:\TrendAccessCheck\HJT.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (disabled by BHODemon)
                        O2 - BHO: Google Update Helper - {A4CC8907-3EA6-49EE-8B74-D09660120910} - C:\Program Files\Google\Update\1.2.121.9\GoopdateBho.dll
                        O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.3.24.3\gears.dll
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                        O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                        O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
                        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                        O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                        O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
                        O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                        O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
                        O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [PPWebCap] C:\Program Files\Scansoft\PaperPort\PPWebCap.exe
                        O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
                        O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                        O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
                        O4 - Global Startup: AutorunsDisabled
                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                        O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.3.24.3\gears.dll
                        O9 - Extra 'Tools' menuitem: &Google Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.3.24.3\gears.dll
                        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{9DC9C4C6-FD4E-4538-BBC9-1F8F1CF66193}: NameServer = 66.174.92.14 69.78.96.14
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
                        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
                        O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                        O23 - Service: Google Update Service (gupdate1c8a0cc9aee1188) (gupdate1c8a0cc9aee1188) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                        O23 - Service: QPQDFUTP - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Toni\LOCALS~1\Temp\QPQDFUTP.exe
                        O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                        O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                        O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                        O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                        O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
                        O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                        O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                        O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                        O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                        O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                        O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                        O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                        O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                        O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                        O24 - Desktop Component 0: (no name) - (no file)

                        --
                        End of file - 11495 bytes



                        [recovering disk space -- attachment deleted by admin]Disable Spybot's TeaTimer

                        While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with normal Windows functions. Disable TeaTimer and see if you get your functions back.

                        1. Right CLICK Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
                        2. Run Spybot S&D
                        3. Go to the Mode menu, and make sure Advanced Mode is selected.
                        4. On the left hand side, choose Tools > Resident
                        uncheck Resident TeaTimer and OK any promptand Restart your computer.

                        Note:
                        If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

                        With both TeaTimer and Spybot closed download ResetTeaTimer.zip to the Desktop.
                        Unzip the file to the Desktop.
                        Double click ResetTeaTimer.bat to remove all entries set by Spybot's TeaTimer.
                        Please don't forget this step to disable TeaTimer.
                        Delete ResetTeaTimer.zip when complete.


                        If this doesn't help then run the SUPERAntiSpyware scan and post the log.

                        2988.

                        Solve : Problem with comodo firewall apparently??

                        Answer»

                        The attatched image shows what I mean. Why does it say that? I click run diagnostics but nothing is fixed-it just says that defense is not functioning properly?!? Also, How do I viw recent events-like when it ASKS for ALLOWING internet and stuff? I have clicked all the "event" things I could find, but none shows what I'm looking for.(the requests and what my answer was).

                        Thanks ahead...

                        [recovering disk space -- attachment deleted by admin]I have read that Defense + is a PAIN and many choose to turn it off and use ThreatFire instead.Aw, amn ...another AV?? Or can I download just the firewall??What about avir AV?? Can I use both Avira and threatfire without difficulty?It's not actually an AV. It's a behavior blocker. It's designed to run alongside you antivirus.Ok I'll try it, but it looks like an AV.

                        http://www.threatfire.com/download/

                        I'll uninstall comodo and install threatfire to see how it goes. Does it ahve realtime protection and internet connection detection stuff?
                        And some more help if you can... I'm have a problem with peergaurdian. Whenever I enable it, this message pops up non-stop till I exit PG. Can it be fixed?

                        [recovering disk space -- attachment deleted by admin]Sorry I wasn't clear. I meant to turn off just the Defense + and use ThreatFire in it's place. Keep the rest of Comodo installed. During the install choose to just install the Firewall and not the Firewall with Defense +. Also (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")

                        I'm not sure about the PeerGuardian issue.

                        OK I installed Comodo to check it out. Once you have it installed right click the icon in the task bar and choose Firewall Security Level &GT; Training Mode. This will make it to where you aren't warned all of the time with the pop-ups. It "teaches" itself whats good and bad for a 30 day period. You will only get the pop-up if something suspicious is trying to connect.So still install both threatfire and comodo?? Because I uninstalled comodo now, so i'll reinstall it.Yep, you just need the firewall though and not the extras.Alrighty-O It's up and running!!

                        2989.

                        Solve : How many wrong things can happen for having facebook??

                        Answer»

                        Well anyone that have ideas would be greatly accepted!! I use facebook but Im new with it. When I did start using it I saw warnings about people actually peoples names. And it cross my mind theft identity. But here is a problem the news or post that you read aren't exactly accurate to tell what is wrong or symptoms to sound more LIKE a doctor All I know for now is that if a friend or you have a friend called Luisa Ledezma. That hacker that horrible person will format your PC and stole your mail password. And can do it to their friends. It almost sounds like a jackpot for a thief of identities. I sincerely don't think a hacker can be that dumb. So lets start discussing just how many things can happen with hackers on the loose inside FACEBOOK. Thanks to anyone who wants to share info!! I have absolutely no idea what you mean.

                        Quote

                        hat hacker Angry that horrible person will format your PC and stole your mail password.
                        Through Facebook? What?Ok I gather some more info. Sorry that the first reply is not clear enough but is what I first got. I also dont understand. Even I wrote it n I say.. w th #$! Here is what happens a hacker from facebook becomes your friend or becomes a friend to any of your friends. After that I still dont know what happens. Merlin said that I should read more about Activex. It help a lot so Merlin THANK you If you use IE or the person that have this hacker as a friend and uses IE(Internet Explorer) it allows the hacker to let a spyware get in the persons PC. Still sounds tricky but that is all I got. Basic you get spyware if you or your friend allows the hacker to be your friend. Just for using IE. Facebook is a breeding ground for malware. Keep your antivirus up to date and use a good firewall if you visit social sites like facebook or myspace. Use the same rules you do with regular email. Don't open anything if you don't know what it is.

                        Hackers Exploiting Facebook, MySpace Plug-ins - http://blog.washingtonpost.com/securityfix/2008/02/hackers_exploiting_facebook_my.html

                        Secret Crush: First Serious Facebook Hack? - http://mashable.com/2008/01/04/secret-crush-first-serious-facebook-hack/

                        http://mashable.com/2007/07/10/facebook-malware/

                        Social sites a breeding ground for malware: report - http://www.theregister.co.uk/2006/08/10/social_sites_breed_malware/

                        Storm (worm) spoofs FBI via Facebook - http://www.securecomputing.net.au/News/118229,storm-spoofs-fbi-via-facebook.aspx

                        Thanx for the HEADS up, my wife lives on facebook, and I have noticed an increase in malware and such on her computer, no matter what protection I have I cant seem to keep it off her computer....Quote from: fullbug on July 30, 2008, 06:51:00 PM
                        no matter what protection I have I cant seem to keep it off her computer....

                        Antivirus protection is rendered almost useless when you click on malware links. Some malware WRITERS design it to not install until the PC is shutting down or as it starts up. Basically it doesn't install except for whenever the antivirus isn't running so it can't be stopped.FEDS Combing Facebook for Terrorists, Storm Says

                        Quote
                        Can it be true that even terrorists are hooked on Facebook? And that the Feds are scouring the social networking site looking for them?

                        Storm Worm puppet-masters seem to think so, or they just want everyone to go and find out if it’s true.

                        Senior Threat Researcher David Sancho has recently discovered a spam run that supposedly tells about the FBI investigating possible terrorists in the popular social networking site Facebook.

                        Full Story
                        2990.

                        Solve : Help EvilFantasy please(sorta)?

                        Answer»

                        Quote from: Mr. Google on July 31, 2008, 11:29:30 AM

                        Ok, I'm going to remove them because I need to hurry...
                        Nevermind. None of them are there, so I'm presuming the virus is destroyed...Log looks fine.

                        Set a New Restore Point to prevent possible reinfection from an old one
                        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                        • Go to Start > Programs > Accessories > System Tools and click System Restore
                        • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                        • Next go to Start > Run and type Cleanmgr
                        • Click OK
                        • Click the More Options Tab.
                        • Click Clean Up in the System Restore section to remove all previous restore points except the NEWLY created clean one.
                        You can find instructions on how to enable and re-enable system restore here:

                        Windows XP System Restore Guide or Windows Vista System Restore Guide
                        .
                        ----------

                        Use the Secunia Software Inspector to check for out of date software.
                        • Click Start Now
                        • Check the box next to Enable thorough system inspection.
                        • Click Start
                        • Allow the scan to finish and scroll down to see if any updates are needed.
                        • Update anything LISTED.
                        .
                        ----------

                        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                        ----------

                        PLEASE keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less EFFECTIVE. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                        To prevent unknown applications from being installed on your computer install WinPatrol 2008
                        * Using Winpatrol to protect your computer from malicious software

                        I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                        * Using SpywareBlaster to protect your computer from Spyware and Malware
                        * If you don't know what ActiveX controls are, see here

                        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                        Use only trusted security software like the programs listed on this page. Trusted security tools & resourcesThanks, I am back at my own pc, but-luckily I did most of those things already. So thanks alot for your help!!No problem Hmmmm...I came here because, from the TITLE, I thought that Evil needed help; obviously not!lolBa -doom - pishhh

                        Yeah, well, I was a bit concerned with the "sorta."
                        2991.

                        Solve : Log Reports...RE: Computer Runs slowly and freezes up.?

                        Answer»

                        Evilfantasy,

                        I am thankful to you for helping me out and glad to hear that you see progress.

                        Attached is the Kaspersky Online Scanner Report.

                        Thank You

                        [recovering disk space -- attachment deleted by admin]This scanner works with Internet Explorer only

                        Go to the BitDefender Online Scanner
                        Click I Agree to the license and then install the ActiveX control.
                        Please DO NOT change the Scanning Options.
                        That will make your logs huge and we don't need to see clean files.

                        Select Start Scan to begin.
                        This scan can take a while so please be patient and let it complete.

                        Once Bitdefender completes the scan:
                        Click-on the Detected Problems tab.
                        Then select Click here to export the scan report



                        When the window comes up to save the report, change the Save as type: box to:
                        Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save



                        This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

                        This bdcan.txt file will actually contain HTML CODE that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

                        Add the bdscan.txt as an attachment in the next post.

                        If the log is too big to attach use the below site to host the file.

                        Upload the file to Savefile.com
                        There is no need to Register
                        Select Browse and locate the file.
                        Fill in the Title and Description and security code then click Upload
                        Copy the download link next to Your link to the file: and post the link back here.Evilfantasy,

                        Here is the bdscan as you requested.

                        Thanks

                        [recovering disk space -- attachment deleted by admin]OK please run a new Kaspersky scan now and post the log.Evilfantasy,

                        Here is the new Kaspersky log.

                        --------------------------------------------------------------------------------
                        KASPERSKY ONLINE SCANNER 7 REPORT
                        Thursday, JULY 31, 2008
                        Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
                        Kaspersky Online Scanner 7 version: 7.0.25.0
                        Program database last update: Wednesday, July 30, 2008 18:33:58
                        Records in database: 1030144
                        --------------------------------------------------------------------------------

                        Scan settings:
                        Scan using the following database: extended
                        Scan archives: yes
                        Scan mail databases: yes

                        Scan area - My Computer:
                        A:\
                        C:\
                        D:\
                        E:\
                        F:\
                        G:\

                        Scan statistics:
                        Files scanned: 73333
                        Threat name: 12
                        Infected objects: 14
                        Suspicious objects: 0
                        Duration of the scan: 05:52:23


                        File name / Threat name / Threats count
                        C:\Documents and Settings\Michelle Thomas\Application Data\vmntoolbar\vmntoolbar_151.zipInfected: not-a-virus:AdWare.Win32.MegaSearch.j1
                        C:\Documents and Settings\Michelle Thomas\Incomplete\T-328472-02 - sun eyed girl _192kbps_ 29.wmaInfected: Trojan-Downloader.WMA.Wimad.d1
                        C:\Documents and Settings\Michelle Thomas\Shared\(1) evernescence 16.wmaInfected: Trojan-Downloader.WMA.Wimad.d1
                        C:\Documents and Settings\Michelle Thomas\Shared\beck sun eyed girl.wmInfected: Trojan-Downloader.WMA.Wimad.m1
                        C:\Program Files\vmntoolbar\VMNTOO~11.oldInfected: not-a-virus:AdWare.Win32.MegaSearch.j1
                        C:\WINDOWS\system32\bdeinsta3.dllInfected: not-a-virus:AdWare.Win32.Altnet.a1
                        C:\WINDOWS\system32\cashbar.dllInfected: Trojan-Dropper.Win32.Small.so1
                        C:\WINDOWS\system32\cexwxfst.sysInfected: Trojan-Clicker.Win32.VB.bip1
                        C:\WINDOWS\system32\SS001.dllInfected: Trojan-Dropper.Win32.Mudrop.w1
                        C:\WINDOWS\system32\sxwand.sysInfected: Trojan.Win32.DNSChanger.fgv1
                        C:\WINDOWS\system32\tmpxr_184699820684.bkInfected: Trojan.Win32.Agent.vvx1
                        C:\WINDOWS\system32\wfallsfreems.exeInfected: not-a-virus:AdWare.Win32.SaveNow.e1
                        C:\WINDOWS\system32\wfallsfreems.exeInfected: not-a-virus:AdWare.Win32.SaveNow.bl1
                        C:\WINDOWS\system32\yaxcnxd.sysInfected: Trojan.Win32.DNSChanger.fiw1

                        The selected area was scanned.


                        Thank You

                          Download
                        OTMoveIt2 by OldTimer
                        • Save it to your desktop.
                        Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

                        • Double-click OTMoveIt2.exe to run it.
                        • Copy the lines in the codebox below.
                        Quote
                        [kill explorer]
                        C:\Documents and Settings\Michelle Thomas\Application Data\vmntoolbar\vmntoolbar_151.zip
                        C:\Documents and Settings\Michelle Thomas\Incomplete\T-328472-02 - sun eyed girl _192kbps_ 29.wma
                        C:\Documents and Settings\Michelle Thomas\Shared\(1) evernescence 16.wma
                        C:\Documents and Settings\Michelle Thomas\Shared\beck sun eyed girl.wm
                        C:\Program Files\vmntoolbar\VMNTOO~11.old
                        C:\WINDOWS\system32\bdeinsta3.dll
                        C:\WINDOWS\system32\cashbar.dll
                        C:\WINDOWS\system32\cexwxfst.sys
                        C:\WINDOWS\system32\SS001.dll
                        C:\WINDOWS\system32\sxwand.sys
                        C:\WINDOWS\system32\tmpxr_184699820684.bk
                        C:\WINDOWS\system32\wfallsfreems.exe
                        C:\WINDOWS\system32\wfallsfreems.exe
                        C:\WINDOWS\system32\yaxcnxd.sys
                        EmptyTemp
                        [start explorer]
                        • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
                        • Click the red Moveit! button.
                        • Copy everything in the Results window (under the green bar) and paste it in your next reply.
                        • Close OTMoveIt2
                        [/list]Evilfantasy,

                        The log you requested.


                        Explorer killed successfully
                        C:\Documents and Settings\Michelle Thomas\Application Data\vmntoolbar\vmntoolbar_151.zip moved successfully.
                        C:\Documents and Settings\Michelle Thomas\Incomplete\T-328472-02 - sun eyed girl _192kbps_ 29.wma moved successfully.
                        C:\Documents and Settings\Michelle Thomas\Shared\(1) evernescence 16.wma moved successfully.
                        C:\Documents and Settings\Michelle Thomas\Shared\beck sun eyed girl.wm moved successfully.
                        C:\Program Files\vmntoolbar\VMNTOO~11.old moved successfully.
                        C:\WINDOWS\system32\bdeinsta3.dll NOT unregistered.
                        C:\WINDOWS\system32\bdeinsta3.dll moved successfully.
                        C:\WINDOWS\system32\cashbar.dll unregistered successfully.
                        C:\WINDOWS\system32\cashbar.dll moved successfully.
                        C:\WINDOWS\system32\cexwxfst.sys moved successfully.
                        C:\WINDOWS\system32\SS001.dll unregistered successfully.
                        C:\WINDOWS\system32\SS001.dll moved successfully.
                        C:\WINDOWS\system32\sxwand.sys moved successfully.
                        C:\WINDOWS\system32\tmpxr_184699820684.bk moved successfully.
                        C:\WINDOWS\system32\wfallsfreems.exe moved successfully.
                        File/Folder C:\WINDOWS\system32\wfallsfreems.exe not found.
                        C:\WINDOWS\system32\yaxcnxd.sys moved successfully.
                        < EmptyTemp >
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\tmp10D.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\tmp115.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\tmp126.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\tmp127.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\tmpD8.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\~DF8411.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\~DFFC3F.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\~DFFC4C.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\History\History.IE5\MSHist012008073120080801\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\HQEB7EJ6\all[2].htm scheduled to be deleted on reboot.
                        Temp folders emptied.
                        IE temp folders emptied.
                        Explorer started successfully

                        OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07312008_173152
                        Looks good. The next log won't be needed.

                        I think you are finally malware free

                        Final steps. Let me know if you have any questions.

                        1. Double click OTMoveIt2.exe to launch it.
                        Vista users right click and choose Run As Administrator
                        2. Click on the CleanUp! button.
                        3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                        4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                        5. Once complete exit out of OTMoveIt2

                        ----------

                        Set a New Restore Point to prevent possible reinfection from an old one
                        Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                        • Go to Start > Programs > Accessories > System Tools and click System Restore
                        • Choose the radio button marked CREATE a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                        • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                        • Next go to Start > Run and type Cleanmgr
                        • Click OK
                        • Click the More Options Tab.
                        • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                        You can find instructions on how to enable and re-enable system restore here:

                        Windows XP System Restore Guide or Windows Vista System Restore Guide
                        .
                        ----------

                        Use the Secunia Software Inspector to check for out of date software.
                        • Click Start Now
                        • Check the box next to Enable thorough system inspection.
                        • Click Start
                        • Allow the scan to finish and scroll down to see if any updates are needed.
                        • Update anything listed.
                        .
                        ----------

                        Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                        If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                        ----------

                        Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                        Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                        Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                        To prevent unknown applications from being installed on your computer install WinPatrol 2008
                        * Using Winpatrol to protect your computer from malicious software

                        I suggest using SiteAdvisor. SiteAdvisor RATES sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                        * Using SpywareBlaster to protect your computer from Spyware and Malware
                        * If you don't know what ActiveX controls are, see here

                        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                        Use only trusted security software like the programs listed on this page. Trusted security tools & resourcesEvilfantasy,

                        Thank you sooooo much for getting me to this point but I do have a question.

                        After I created the New restore point you say to

                        Go to Start > Run and type Cleanmgr
                        Click OK

                        When I do this I do not get an option to Click More Options tab

                        Instead I get a pop up box that says:

                        Select the Drive you want to clean up:

                        What do I do here?

                        Thank You
                        No problem. It's a little different for XP Home.

                        Disable the System Restore Utility to prevent re-infection from an old one

                        1) Right click the My Computer icon on the Desktop and click on Properties.
                        2) Click on the System Restore tab.
                        3) Put a check mark next to Turn off System Restore on All Drives
                        4) Click the OK button.
                        5) You will be prompted to restart the computer. Click the Yes button.

                        Now re-enable System Restore

                        To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

                        1) Right click the My Computer icon on the Desktop and click on Properties.
                        2) Click on the System Restore tab.
                        3) Remove the check mark next to Turn off System Restore on All Drives
                        4) Click the OK button.Evilfantasy,

                        Thank You I disabled and re-enabled the system restore per your instructions. So if I need to go back to a clean working state I will have my Restore point that I created. Hopefully I won't need it though....But I will definitely utilize all your suggestions to keep my computer clean from the bad stuff.

                        I will definitely recommend this site to all my friends and I think you all do a wonderful thing here in helping all of us out who would not know any better.

                        Thank YouNo problem. Glad we got you cleaned up!

                        Safe surfing.............@mthomas: Now back to the original problem - is your computer running faster?My computer is running faster indeed....I still need to use the compressed air to clean out the inside....That is definite, but Internet explorer moves faster from website to website and just an overall great improvement on speed.

                        I have another issue but I will post a new thread for this one.

                        Thank You
                        2992.

                        Solve : Computer virus and spyware?

                        Answer»

                        Which ones? There should be HJT, MBAM and SAS. You can uninstall HJT but keep MBAM and SAS and run scans with them occasionally. here is a list, Software inspecter, Malware bytes, Moa2008use.exe, Superantispyware, Windowsxp-kb884020-x86-enu.exe, software inspector, Tinsetup, CCleaner, Noscript.
                        ANOTHER strange thing is happening. When I GO to "MEDIA CENTRE" and then close it I end up with a MSN MESSENGER icon on the bottom right which says not signed in when I put the cursor on it. If I log off and back on it is gone. I was having trouble with email but now is OK. I am prevented from using youtubr and similar sites
                        You can use the online Software inspecter so you don't need to have it installed.

                        Malware bytes & Superantispyware - Keep and run a scan occasionally, every two weeks or more if you think you need to. Remember to update before scanning.

                        That is an installer for something, but not anything I had you use I don't think. Delete it.

                        Windowsxp-kb884020-x86-enu.exe - Is an update for Windows XP Service PACK 2 (KB884020) - Did you already install it?

                        Tinsetup - I don't have a clue what this is. Nothing we use here.

                        Noscript - That is a Firefox add-on. Where do you see it at?

                        ----------

                        Run this Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.

                        Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

                        Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

                        Exit out of MessengerDisable then delete the two files that were put on the Desktop.

                        See if that takes care of the Messenger pop-up in Media Center.

                        ----------

                        Quote

                        I am prevented from using youtubr and similar sites

                        How are you prevented? What EXACTLY happens?



                        the tinsetup ia winpatrol.
                        I have avast antivirus will any of these other programs malwarebytes or superantispyware conflict.This is the message I get. I know I have the latest version of flash player. Sorry This is the message I get "Hello, you either have JavaScript turned off or an old version of Adobe's Flash Player. " I have the problem under control now. Everything seems to be fine It was the firefox no script. I had to learn how to allowstuff. Thanks again. You have been awsome . I am telling people good things about this site.
                        Have a great life
                        Quote from: Robinhood on July 29, 2008, 08:38:52 AM
                        the tinsetup ia winpatrol.
                        I have avast antivirus will any of these other programs malwarebytes or superantispyware conflict.

                        If you have any old setup files on the desktop you can safely delete them.

                        The programs will not conflict with Avast!.Everything is still good. Thanks so much.
                        2993.

                        Solve : Java really slow!?!?!??

                        Answer»

                        For some reason, after I installed the new java-it's been REALLY slow and it's making the whole computer freeze up when its running. Does anyone know how I can fix this??

                        ThanksWell I know when I installed it, it takes a few more secs. for pages to load at first in new tabs, but nothin else has slowed down. which one did you download?See if it clears up after a couple of restarts. If not post a new HJT log.Alright, thanks EF and the other guy..... Alright, I restarted(only once ), but here's a HJT log anways:

                        Code: [Select]Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 8:21:18 PM, on 31/07/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\System32\SCardSvr.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        H:\Program Files\Comodo\Firewall\cmdagent.exe
                        C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\WINDOWS\system32\svchost.exe
                        H:\Program Files\ThreatFire\TFService.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                        C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                        C:\Program Files\lg_fwupdate\fwupdate.exe
                        C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
                        C:\Program Files\Nero\Nero 7\InCD\InCD.exe
                        C:\Program Files\FlashGet\FlashGet.exe
                        C:\WINDOWS\system32\fppsys.exe
                        C:\WINDOWS\System32\svchost.exe
                        H:\Program Files\WINPATROL\winpatrol.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        H:\Program Files\Comodo\Firewall\cfp.exe
                        H:\Program Files\ThreatFire\TFTray.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
                        C:\Program Files\PeerGuardian2\pg2.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\mdm.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Trend Micro\HijackThis\sniper.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1561552
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                        O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                        O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                        O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                        O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                        O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                        O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
                        O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
                        O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\FlashGet.exe /min
                        O4 - HKLM\..\Run: [Warning: do not remove it! (system)] fppsys.exe
                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                        O4 - HKLM\..\Run: [WinPatrol] H:\Program Files\WinPatrol\winpatrol.exe -expressboot
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [COMODO Firewall Pro] "H:\Program Files\Comodo\Firewall\cfp.exe" -h
                        O4 - HKLM\..\Run: [ThreatFire] H:\Program Files\ThreatFire\TFTray.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                        O4 - HKCU\..\Run: [WeatherAloud] C:\Program Files\WeatherAloud\WeatherAloud.exe -auto
                        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
                        O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
                        O4 - HKCU\..\Run: [ares vista] "H:\Program Files\Ares Vista\Ares.exe" -h
                        O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                        O4 - Global Startup: Adobe Reader SPEED Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe
                        O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
                        O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
                        O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                        O8 - Extra context menu item: Download all with Free Download MANAGER - file://C:\Garrick's songs\dvd cover\Free Download Manager\dlall.htm
                        O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Garrick's songs\dvd cover\Free Download Manager\dlselected.htm
                        O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Garrick's songs\dvd cover\Free Download Manager\dlpage.htm
                        O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                        O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                        O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
                        O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                        O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                        O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                        O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                        O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                        O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                        O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
                        O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129926551234
                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://putfile.com/includes/ImageUploader4.cab
                        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                        O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - H:\Program Files\Comodo\Firewall\cmdagent.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
                        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                        O23 - Service: ThreatFire - PC Tools - H:\Program Files\ThreatFire\TFService.exe

                        --
                        End of file - 12911 bytes
                        And all PROGRAMS seem to be taking a long time to start up including mozilla. And Avira anti-virus and threatfire didn't even show up in the system tray when I restarted?!!?We're going to fix all of the programs that are running at startup that don't need to run full time. It won't effect them you just have to launch them manually when you use them.

                        Open HijackThis and select Do a system scan only.

                        Place a check mark next to the following entries: (if there)

                        • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1561552
                        • O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        • O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        • O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        • O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                        • O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        • O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
                        • O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
                        • O4 - HKCU\..\Run: [ares vista] "H:\Program Files\Ares Vista\Ares.exe" -h
                        • O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                        • O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        • O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe
                        .
                        Important: Close all windows except for HijackThis and then click Fix checked.

                        Exit HijackThis.

                        ----------

                        Go to Start > Run and type notepad.exe then click OK

                        Copy the text in the Code box below and paste it into Notepad.

                        Code: [Select]REGEDIT4

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
                        "iTunesHelper"=-
                        "QuickTime Task"=-
                        "TkBellExe"=-
                        "SunJavaUpdateSched"=-
                        "RoboForm"=-
                        "PeerGuardian"=-
                        "ares vista"=-
                        "Picasa Media Detector"=-
                        In Notepad go to File > Save as...

                        Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop.

                        There should now be a file on the Desktop that looks like this

                        Double-click fixme.reg it and allow it to merge with the Registry.

                        You may not see anything happen but give it a few seconds or so to finish.

                        Now delete the fixme.reg file from the Desktop.

                        Restart the computer and let me know how things are now.



                        Thanks alot, that made the reboot amazingly faster. But mozilla still takes a bit long to open up. The internet is supr fast. But the initial startup of mozilla takes a while. But thanks alot! The Firefox issue is a known one. Everybody suffers the same wait when they launch it. Not much you can (safely) do to fix that.
                        2994.

                        Solve : A-Squared Anti-Malware FREEE?

                        Answer»

                        Is this a good software?? It's free TODAY from:

                        www.giveawayoftheday.com

                        Should I GET it?? Is it good?With all that you already have it really isn't necessary.The site you posted came up red on the SiteAdvisor. You can get it free direct from the publisher: A=Squared

                        Quote

                        Is this a good software??

                        Seems to be. I RUN command line version occasionally on-demand.

                        Quote from: evilfantasy on August 02, 2008, 12:15:22 PM
                        With all that you already have it really isn't necessary.


                        Alright, cool. Sidewinder, that's thef ree version. This ONE's the paid version.
                        2995.

                        Solve : task manager & programs button missing?

                        Answer»

                        My CLOCK shows TIME as
                        e.g 12:22: VIRUS ALERT

                        Also when i right click on taskbar, the task manager option is not visible,it has been disabled,
                        I have 5 partitions on my hard disk, C,D,E,F,G. . But now when i click My computer, I can see partions E,F,G only being displayed

                        Can anyone help me options other than re-installing XP again
                        Welcome to the CH forums.

                        Please wait for ONE of the CH authorised Malware Removal Specialists to advise. Someone will be along shortly.

                        Good luck.Welcome to CH.

                        Please follow these steps in order.

                        Download Malwarebytes' Anti-Malware (MBAM)

                        • Double-click mbam-setup.exe and follow the prompts to install the program.
                        • At the end, be sure a checkmark is placed next to the following:
                          • Update Malwarebytes' Anti-Malware
                          • Launch Malwarebytes' Anti-Malware
                          • Then click Finish.
                          • If an update is found, it will download and install the latest version.
                          • Once the program has loaded, select Perform quick scan, then click Scan.
                          • When the scan is complete, click OK, then Show Results to view the results.
                          • Be sure that everything is checked, and click Remove Selected.
                          • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
                          • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
                          • Copy and Paste the entire report in your next reply.
                          Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

                          ----------

                          Download and rename TrendMicro HijackThis.exe (HJT)

                          • Double-click on HJTInstall.
                          • Click on the Install button.
                          • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
                          • Upon install, HijackThis should open for you.
                          • Close HijackThis and rename it.
                          • Go to C:\Program Files\Trend Micro\HijackThis.exe
                          • Right click on HijackThis.exe and select Rename.
                          • Type in sniper.exe and press Enter.
                          • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
                          • From the desktop open HijackThis.
                          • Important! If using WINDOWS Vista, Right-click and Run As Administrator
                          • Click on the Do a system scan and save a log file button
                          • HijackThis will scan and then a log will open in notepad.
                          • Copy and then paste the entire contents of the log in your post.
                          • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
                          Although we have renamed HijackThis to sniper, we will still refer to it as HijackThis or HJT.

                          ----------

                          Next post please add
                          MBAM log
                          HijackThis log
                          2996.

                          Solve : Winspyware protect removal tool?

                          Answer» NONE that I am aware of, machine has only been used sparsley today, mainly per instructions. We are able to log onto mail accounts and ONLINE banking as before.
                          I thank you very much for your knowledge, patience and especially your help.Final steps to help secure everything and some advice.

                          Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

                          1. Double click OTMoveIt2.exe to launch it.
                          Vista users right click and choose Run As Administrator
                          2. Click on the CleanUp! BUTTON.
                          3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                          4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                          5. Once COMPLETE exit out of OTMoveIt2

                          ----------

                          Set a New Restore Point to prevent possible reinfection from an old one
                          Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                          • Go to Start > Programs > Accessories > System Tools and click System Restore
                          • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                          • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                          • Next go to Start > Run and type Cleanmgr
                          • Click OK
                          • Click the More Options Tab.
                          • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                          You can find instructions on how to enable and re-enable system restore here:

                          Windows XP System Restore Guide or Windows Vista System Restore Guide
                          .
                          ----------

                          Use the Secunia Software Inspector to check for out of date software.
                          • Click Start Now
                          • Check the box next to Enable thorough system inspection.
                          • Click Start
                          • Allow the scan to finish and scroll down to see if any updates are needed.
                          • Update anything listed.
                          .
                          ----------

                          Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                          If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                          ----------

                          Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                          Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                          Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                          To prevent unknown applications from being installed on your computer install WinPatrol 2008
                          * Using Winpatrol to protect your computer from malicious software

                          I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and SPAM. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                          SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                          * Using SpywareBlaster to protect your computer from Spyware and Malware
                          * If you don't know what ActiveX controls are, see here

                          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                          Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                          Use only trusted security software like the programs listed on this page. Trusted security tools & resourcesI have created a new restore point, I will continue with the remainder of your advise.......tomorrow, bedtime now.
                          I do however wish to take a moment and thank you for your knowledge, patience and especially your help in this issue. I would have sat and watched my system get corrupted beyond repair on my own. Therefore I am left with nothing but thanks to you and the other specialists who administer this site, great job.....I'm glad everything worked out and thank you for hanging in there

                          Let us know if anything else comes up.

                          Safe surfing.............
                          2997.

                          Solve : Virus and Reboot issues?

                          Answer»

                          I am in desparate need of help! I spent 10 hours over the weekend on the phone with Dell and Charter Communications (internet & security suite). I have VIRUS and after 4 hours Dell said they couldn't help - to CONTACT Charter Security Suite since their security allowed the virus. After 5 hours and 5 different people with Charter they said I needed to run their virus scan - it wouldn't let me. They said to uninstall Charter Security Suite, and McAfee and Symantec - they said I had fragments of McAfee & Symantec LEFT in my computer from probably a free trial or something. Well since I couldnl't get into the internet to get the "uninstall tool". Anyway - long story short - my brother told me to just reboot the computer and it would start "ANEW" and it would be like having a "new computer again" All problems would go away. WRONG!!! I rebooted the computer - went thru several testings and now my screen is b&W asking for my password. I am not able to type in a password or do anything. Computer is frozen. I've turned off & on -no luck. I tried inserting my reinstall disk from Dell - it does nothing. Is my computer a goner? Please help me. I am at my wits end!!! I ended up in tears. I

                          I forgot to add I "HAD" Windows XP and above where it says Enter Password it says something to the effect "not finding floppy DISKETTE"
                          Welcome to CH.

                          If you think this is virus related then we need the logs from this threadWhat is SP1 and SP2? If you read my message, at this point I am unable to install, uninstall or "look" at anything on my computer -it is frozen. I had Charter Security Suite as an antivirus protection - they told me to uninstall it which I did and they said I had "fragments of McAfee & Symantec" that I needed to "uninstall" - but I never got that far. Please explain furtherI am sending these messages via work computer - since my computer at home is frozen.Quote

                          Please explain further

                          I can't explain their explanation.....

                          Do you have your Install CD?Yes I tried to use it and it did nothing.I means please explain what SP1 and SP2 are? SP = Service Pack. They are Windows updates.

                          Have you tried a Repair Install. Instructions here: http://www.michaelstevenstech.com/XPrepairinstall.htm

                          Note: A Repair Install will replace the system files with the files on the XP CD used for the Repair Install. It will leave your applications and settings intact, but Windows updates will need to be reapplied. No I don't think I've tried this - will it work even if the computer/keyboard is frozen at this point?You will need to follow the guide starting HERE and see if it works. Hopefully the keyboard will work while the computer is booting up.THANK YOU FOR ALL YOUR HELP - I WILL TRY IT - I will be on vacation until Monday and depending if I get it running at home - I will keep you posted.!!!
                          2998.

                          Solve : Modems, Drivers and Internet Security?

                          Answer»

                          What are the current issues with your computer?AVG is showing a "Threat Detected !" box.

                          It says : "While opening file : C:\\WINDOWSS\System32\0qamSHR6.exe
                          Trojan horse Downloader.Generic7AACU"

                          I can choose to Ignore/Get Info/Heal/Move to Vault.

                          I would like to know which I should choose and what I should do about the files that I listed that are already in the AVG Vault and that are unhealable as I would like to remove AVG and switch to another AV program which would be Avast unless you would recommend something else.

                          Is it important that the F-Secure online Scan did not/ could not scan a handful of named files ?

                            Download
                          OTMoveIt2 by OldTimer
                          • Save it to your desktop.
                          Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

                          • Double-click OTMoveIt2.exe to run it.
                          • Copy the lines in the codebox below.
                          Code: [Select][kill explorer]
                          C:\\WINDOWSS\System32\0qamSHR6.exe
                          EmptyTemp
                          [start explorer]
                          • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
                          • Click the red Moveit! button.
                          • Copy everything in the Results window (under the green bar) and paste it in your next reply.
                          • Close OTMoveIt2
                          Hi. Thank you for your advise.

                          As my OTMoveIt2 results appeared, Spybot Search and Destroy asked my permission to allow a change detailed as follows -->

                          Category = System startup global entry
                          Change = Value added
                          Entry = OTScanIt

                          New Data = C:\Document and Settings\Username\Desktop\OTMoveIt2.exe

                          I am yet to click on the "Allow Change" box but this information appeared in the green Results section :

                          Explorer killed successfully
                          C:\\WINDOWS\System32\0qamSHR6.exe moved successfully.
                          < EmptyTemp >
                          File delete failed. C:\DOCUME~1\PORTAB~1\LOCALS~1\Temp\~ROMFN_00000F88 scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_704.dat scheduled to be deleted on reboot.
                          Temp folders emptied.
                          IE temp folders emptied.
                          Explorer started successfully

                          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07302008_222342

                          The PC is prompting me to re-boot to remove these files.

                          I haven't told AVG Anti-Virus how I would like it to respond to the Downloader.Generic7.AACU

                          Should I tell AVG to "Ignore" it, "Allow change" at Spybot Search and Destroy and then re-boot the machine ?
                          Allow the change with Spybot. Reboot to register the changes made by OTMoveIt2.

                          Just ignore AVG for now and see if the warning returns after restarting the computer.

                          Post a new HijackThis log after the reboot please.Upon re-booting I was immediately automatically presented with an OTMoveIt2 Log stating -->

                          ---------------------------------------------------------------------------------------------------------------------------------------
                          Explorer killed successfully
                          C:\\WINDOWS\System32\0qamSHR6.exe moved successfully.
                          < EmptyTemp >
                          File delete failed. C:\DOCUME~1\PORTAB~1\LOCALS~1\Temp\~ROMFN_00000F88 scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_704.dat scheduled to be deleted on reboot.
                          Temp folders emptied.
                          IE temp folders emptied.
                          Explorer started successfully

                          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07302008_222342

                          Files moved on Reboot...
                          File C:\DOCUME~1\PORTAB~1\LOCALS~1\Temp\~ROMFN_00000F88 not found!
                          File C:\WINDOWS\temp\Perflib_Perfdata_704.dat not found!

                          -----------------------------------------------------------------------------------------------------------------------------------

                          Does this mean it was unable to delete the files that it wanted to because it could not find them ? Might there be an issue with the truncated file path names ?

                          --------------------------------------------------------------------------------------------------------------------------------------
                          I have run a new HiJackThis Scan. It shows -->

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 22:58:23, on 30/07/2008
                          Platform: Windows XP (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 (6.00.2600.0000)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                          C:\Program Files\Comodo\CBOClean\BOCORE.exe
                          C:\PROGRA~1\Iomega\System32\AppServices.exe
                          C:\Program Files\Kontiki\KService.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\Wacom_Tablet.exe
                          C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
                          C:\Program Files\Iomega\AutoDisk\ADService.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\WTablet\Wacom_TabletUser.exe
                          C:\WINDOWS\System32\Wacom_Tablet.exe
                          C:\WINDOWS\notepad.exe
                          C:\WINDOWS\System32\ezSP_Px.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\WINDOWS\System32\WLANSTA.EXE
                          C:\WINDOWS\System32\TPWRTRAY.EXE
                          C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
                          C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
                          C:\WINDOWS\System32\TFNF5.exe
                          C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
                          C:\WINDOWS\System32\TDispVol.exe
                          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
                          C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
                          C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
                          C:\WINDOWS\System32\00THotkey.exe
                          C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                          C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
                          C:\Program Files\Kontiki\KHost.exe
                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - Default URLSearchHook is missing
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O4 - HKLM\..\Run: [CrazyTalk Serve] rundll32.exe C:\WINDOWS\System32\CrazyTalk.dll,DllServeMediaFile
                          O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
                          O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
                          O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
                          O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
                          O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
                          O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
                          O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
                          O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03
                          O4 - HKLM\..\Run: [tdispVol] TDispVol.exe
                          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                          O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
                          O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
                          O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
                          O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
                          O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
                          O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
                          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
                          O4 - HKLM\..\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
                          O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                          O4 - HKLM\..\Run: [EnGraph QuickTimeKiller] C:\Program Files\EnGraph\QuickTimeKiller\QuickTimeKiller.exe
                          O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
                          O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
                          O8 - Extra CONTEXT menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~4\Office\1033\phdintl.dll/phdContext.htm
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                          O16 - DPF: {13149882-F480-4F6B-8C6A-0764F75B99ED} (CrazyTalk4 Control) - http://plug-in.reallusion.com/CrazyTalk4.cab
                          O16 - DPF: {1CC506A7-1B8D-11D4-BDD5-0060977007E0} (CrazyTalk Player) - http://plug-in.reallusion.com/CrazyTalk.cab
                          O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
                          O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
                          O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
                          O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
                          O23 - Service: Cepstral License Server - Cepstral, LLC - C:\Program Files\Cepstral\lib\LicenseServer.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\System32\Wacom_Tablet.exe
                          O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
                          O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

                          --
                          End of file - 8724 bytes

                          ----------------------------------------------------------------------------------------------------------------------------------
                          Thank you for looking at this.Quote
                          C:\\WINDOWS\System32\0qamSHR6.exe moved successfully.

                          Thats the file that was important to be deleted and it was.

                          Quote
                          File C:\WINDOWS\temp\Perflib_Perfdata_704.dat not found!

                          That is not important. It's just a Temporary file that was either deleted when Windows shut down or was over written and renamed. No big deal either way.

                          ----------

                          Open HijackThis and select Do a system scan only.

                          Place a check mark next to the following entries: (if there)

                          O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

                          Important: Close all windows except for HijackThis and then click Fix checked.

                          Exit HijackThis.

                          ----------

                          Go to Start > Run and type Notepad.exe then click OK.

                          Copy and paste the following text within the code box into the new Notepad file.

                          Code: [Select]@ECHO OFF
                          sc stop Automatic LiveUpdate Scheduler
                          sc delete Automatic LiveUpdate Scheduler
                          exit
                          In Notepad select File and Save as
                          Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files.

                          Next double click fixservice.bat to run it.
                          A black box should open and close after a short time, this is normal.
                          Do not continue until the black box has closed
                          Delete fixservice.bat from the Desktop.

                          ----------

                          Download the Norton Removal Tool (SymNRT) to your Desktop.

                          Once downloaded please close ALL open browsers, also save any work because this may require a restart.

                          • Go to your desktop and double click on the removal tool and then click Setup.
                          • Once open Click Next
                          • Accept the license agreement and click Next
                          • Type in the letters/numbers that you see into the text box then click Next.
                          • Then click Next and the tool will start running.
                          • Once finished restart the PC and run the tool again to ensure everything has been removed.
                          ----------

                          You are using an outdated version of Internet Explorer. Go to http://www.windowsupdate.com/ and check for updates. You don't have to update to IE 7 but the version of IE 6 you are using is old.

                          ----------

                          Run the Kaspersky Online Scanner

                          In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.

                          • Click on SCAN NOW
                          • Click Accept.
                          • The program will then begin downloading the latest definition files.
                          • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
                          • The scan will take a while, so be patient and let it finish.
                          When the scan is done, in the Scan is complete window, any infection is displayed.
                          There is no option to clean/disinfect, however, we need to analyze the information on the report.

                          To obtain the report:
                          Click on: Save Report As
                          • Next, in the Save as prompt, Save in area, select: Desktop.
                          • In the File name area use KScan, or something similar.
                          • In Save as type: click the drop arrow and select: Text file [*.txt]
                          • Then, click: Save


                          Copy and paste the Kaspersky Online Scanner Report in your next reply.Hi

                          I have just completed the Kaspersky Online Scan. Before running it, I closed BOClean, Spybot and AVG from my Task Bar. Earlier I had followed your steps to try to FULLY remove Norton. I made the fixme.bat (which kept the name fixme.bat - I never saw anything that said fixservice.bat), ran that and went through the Tool process twice. The Norton Removal Tool took about ten minutes to show its first screen after I pressed "Setup" each time.

                          Upon re-booting after each attempt I was sent to a Symantec web-page that wanted me to Reinstall their latest product.

                          I'm mentioning all of this as background to my Kaspersky results which have shown that I am INFECTED.

                          The Threat Name is : Trojan-Dropper.Win32.joiner.fa

                          Here is the text from the Report ---->
                          --------------------------------------------------------------------------------
                          KASPERSKY ONLINE SCANNER 7 REPORT
                          Thursday, July 31, 2008
                          Operating System: Microsoft Windows XP Home Edition (build 2600)
                          Kaspersky Online Scanner 7 version: 7.0.25.0
                          Program database last update: Thursday, July 31, 2008 10:08:13
                          Records in database: 1033103
                          --------------------------------------------------------------------------------

                          Scan settings:
                          Scan using the following database: extended
                          Scan archives: yes
                          Scan mail databases: yes

                          Scan area - My Computer:
                          C:\
                          D:\
                          E:\

                          Scan statistics:
                          Files scanned: 132419
                          Threat name: 1
                          Infected objects: 1
                          Suspicious objects: 0
                          Duration of the scan: 02:57:49


                          File name / Threat name / Threats count
                          C:\System Volume Information\_restore{A9C47B8A-3CBA-4B5E-AC85-6D30CE725E70}\RP3\A0000125.exeInfected: Trojan-Dropper.Win32.Joiner.fa1

                          The selected area was scanned.

                          ---------------------------------------------------------------------------------------------------------------------------------
                          Thanks again for your assistance. It's wonderful to find a community of kind people here who know so many angles to approach these problems from.
                          The Kaspersky report shows an infected restore point which is EASY to cure.

                          Turn OFF System Restore

                          • On the Desktop, right-click My Computer
                          • Click Properties
                          • Click the System Restore tab.
                          • Check Turn off System Restore
                          • Click Apply, and then click OK
                          .
                          Restart your computer

                          Turn ON System Restore
                          • On the Desktop, right-click My Computer
                          • Click Properties
                          • Click the System Restore tab.
                          • UN-Check Turn off System Restore
                          • Click Apply, and then click OK
                          .
                          System Restore will now be active again

                          ----------

                          1. Double click OTMoveIt2.exe to launch it.
                          Vista users right click and choose Run As Administrator
                          2. Click on the CleanUp! button.
                          3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                          4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                          5. Once complete exit out of OTMoveIt2

                          ----------

                          Use the Secunia Software Inspector to check for out of date software.
                          • Click Start Now
                          • Check the box next to Enable thorough system inspection.
                          • Click Start
                          • Allow the scan to finish and scroll down to see if any updates are needed.
                          • Update anything listed.
                          .
                          ----------

                          How is everything now?
                          Hi

                          I've given things a couple of days so as not to jump ahead of myself with an over-hasty "all clear" - although things are certainly far, far better now ALL thanks to the help I have recieved at this brilliant forum.

                          T H A N K Y O U
                          I am now able to type this message from the computer that was infected and it's wonderful that the horrible problem with my modem being messed around with has stopped. If that hadn't happened to me, I would have carried on unaware of an infiltration.

                          I'm using Firefox 3 instead of IE6 now.

                          It has frozen up a couple of times but I'm assuming that that sort of thing CAN happen "naturally" on an old, tired five and a half year old laptop and needn't have to be suspicious.Firefox can be buggy for some. IE 7 is more secure then IE 6 so that is an option as well.

                          Here are some more free low resource tools.

                          Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                          If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                          ----------

                          Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become LESS effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                          Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                          Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                          To prevent unknown applications from being installed on your computer install WinPatrol 2008
                          * Using Winpatrol to protect your computer from malicious software

                          I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                          SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                          * Using SpywareBlaster to protect your computer from Spyware and Malware
                          * If you don't know what ActiveX controls are, see here

                          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                          Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                          Use only trusted security software like the programs listed on this page. Trusted security tools & resources
                          2999.

                          Solve : COmputer dying all of the sudden!?

                          Answer»

                          It all started last night.......

                          I had my computer in stand-by for the day and when i turned it BACK on, everything lagged, some programs wouldn't open, and it was DOWNRIGHT unusable. I couldn't open any of the scanners because the froze when I was trying to open them.

                          I have a COMPAQ presario r3200 with....

                          AMD Athlon XP-MOBILE 1.6ghz

                          512mb RAM

                          Winxp home sp3

                          avast antivirus

                          superantispyware

                          spyware terminator

                          zone alarm firewall

                          and yes, I did restart many times......Still the same problemGuest?hes gone?Quote from: patio

                          We ALSO request patience. The Experts here are Volunteers and are not here 24/7. This is not a live session EITHER. If it takes a few hours or overnight for them to get back to you, trust me it is worth the wait.

                          Looks like the wait was too long for free help.
                          3000.

                          Solve : Re: file will not delete?

                          Answer»

                          i was trying to download a song at it came up as a *censored* video and now it wont delete ive tryed LOADS ive EVEN avg scanned itand that says there nothing wrong but when i try to delete it it says there has been a SHARING violation the source or destination file MAY be in useMoved the to Computer VIRUSES and spyware forum

                          Welcome to CH jacklufc.

                          Please start here.

                          Post the logs when complete to finish the malware removal process.