Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3051.

Solve : Frozen!!!!?

Answer»

Yes sir!!

Thankyou sir!!You're very welcome, my yuckkkkkkkkkkkkkkkkssssss she's sooooo eegghhhh.....

Have you ever seen how I LOOK!!!!!!!!!!

Oh boy!!!!!

I'd rather be the princess if thats how queens look!!Well, for someone born in 1926, I'd say she looks pretty good! (Her mother died in 2002, at age 101.)

I'm sure Queen IVY remembers these small facts.Nope I didn't know NOTHING of that sort, shorryy!!

But its your duty to remind me of these things noble Knight... Quote

Have you ever seen how I look!!!!!!!!!!
May I?



Better?::: NUDGES Broni, whispers ::: She's already a princess. Yup I like that.

You may make it as your new avatar
3052.

Solve : got around 500 viruses on my pc?

Answer»

Looks good now.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for
general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a SPACE between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER CLEANING your system will ENABLE your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current DATE and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    Using Winpatrol to protect your computer from malicious software

    Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

    SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    Using SpywareBlaster to protect your computer from Spyware and Malware

    Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thanks so much my computers now running so much faster than it was before!

    i will be sure to tell anyone i know having computer problems to try out this site, and i will do the last set of instructions when i get home

    i found this site so helpful on my computer i have decided to use it on my girlfriends laptop too (the laptop runs soooo slowly and im sure it must have something to do with her having viruses on it)

    the problem is she uses windows vista, and im used to windows XP, although i didnt think i would have any problem finding the add/remove programs it doesnt seem to be on the computer... (im going through the instructions i did last time to sort my own)

    any help would be greatly appreciated never mind found it
    3053.

    Solve : Spyguarder removal?

    Answer»

    Somehow I have downloaded something called spyguarder, it tells me my computer is infected with all sorts and every page I try to enter is an infected site.

    Remove programme wont get rid of it as it tells you that you cannot remove the programme whilst in use but there is no way of getting out of it.

    Can any one tell me what to do. Im on windows xp home edition.Print these INSTRUCTIONS out.

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your DESKTOP. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * CLOSE SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under SCANNER Options make sure the following are checked (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are SEVERAL logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.

    3054.

    Solve : new threat?

    Answer»

    when ever i start my computer (after windows opening) two dialogue box open and says that " script file c:\heap41a\ script1.txt does not exist creat it now" and other one TELLING that "script file c:\heap41a\ reproduce.txt does not exist creat it now" how can i ruled out this Do you use a FLASH drive? If so.

    Download Flash_Disinfector.exe by sUBs and save it to your desktop:

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and ICONS may disappear. This is normal.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.
    NOTE: Flash Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive PLUGGED in when you ran it. Don't delete this folder...it will help protect your drives from future infection.Running sUBs Flash Disinfector will target alot of auto run infections and create a hidden folder named autorun.inf on each partition and any USB drive you plug in, these dummy autorun.inf files will help protect your PC from reinfection because if the infected flash drive is then inserted, autorun looks for autorun.inf which would normally run the worm but its then prevented by the dummy autorun.inf that is in place. If you have any USB drives please insert them when prompted when running the tool.

    ----------

    Please go to this thread and read the instructions for posting the required logs.

    Once the logs are posted a malware specialist will be along to assist you in further removal instructions.
    3055.

    Solve : Help Me please!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!?

    Answer»
    i need some help from you if you can help me !

    My computer is infected with NVMINI.SYS
    I cant remove it ,I ccannttt...
    I scaned my Pc with regrun but with out succses
    If you have just few minuts to tell me what will i do to remove that *censored* virus that will be good .

    GoodBay
    Need...more...info...gasp

    Operating system / antivirus & antispyware protection / service packs installed / when did it start happening / did it ever work right / installed any new software / tried booting into Safe Mode and running your antivirus/antispyware programs / tried booting into SM and doing a system restore to a date before this happened?

    Alan <>< First, watch your language, please!

    Print these instructions out.

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; SELECT Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory THREATS before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/LOGS tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text FILE will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.
    3056.

    Solve : help fixing computer problem?

    Answer»
    - About a month ago, my antivirus program(Avast) said it detected a virus in memory.
    - Suggested I shut computer down and reboot.
    - Did so.
    - Everything WENT fine with no resulting errors or messages.

    - When attempted to return MS-DOS prompt level, received message that it couldn't fine
    the .pif file.
    - Researched and found it still there.

    - Tryed to recreate an ms-dos prompt.
    - Then receive message that system couldn't find command.com.
    - Tryed c:\windows\system32\command.com.
    - System still couldn't find it, even though file is there.

    - Then ran virus check; spybot checkers(Adaware, Spybot, SpyDoctor, etc.), etc.
    - They did find instances of viruses, etc. and removed them.

    - Ran defrag, checkdisk, scandisk, etc. etc.
    - Check registery for .exe and exefile settings. All o.k. here
    - Rebooted computer.
    - Tryed other user logons.
    - Tryed creating new user logon.

    - Still same results.

    - Did extension research into problem.
    - Can't find anything that works.
    - Did EXTENSIVE research on this board concerning MS-DOS.
    - Have not found anything new that is helping.


    - NOTE:
    ----
    - Can get cmd command to work and get me to DOS level.
    - However that are certain dos command I use frequently such as 'edit' 'fd(changes date of file(s))', etc.
    - These are not working.


    - I don't want to do a system restore at this point. I just want to fix the problem.

    - B-T-W.
    - Have Compaq Presario V5305.
    - WINDOWS XP MEDIA EDITION - VERSION 2002 - SERVICE PACK 2
    - Only have restored disk - did not come with OEM disks.

    - Any suggestions......

    -thanks
    -dan
    System Restore won't do any good, because it'd bring back all viruses.

    Let see, if your computer is clean...

    Print these instructions out.

    1. Download SUPERAntiSpyware Free for Home Users:
    HTTP://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options MAKE sure the following are CHECKED (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.
    3057.

    Solve : Virus Affecting Search Engines??

    Answer»

    I am using IE 7 on xp with Windows Live OneCare. Every time I type something into Google, Yahoo, Ask...etc the page loads with results but when I click on one it takes me to an online store of some kind related to what I typed in. Any help would be great. Welcome to CH.


    Download and rename HijackThis (HJT)

    • Double-click on HJTInstall.
    • Click on the Install button.
    • It will AUTOMATICALLY place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
    • Upon install, HijackThis should open for you.
      • Close HijackThis and rename it.
      • Go to C:\Program Files\Trend Micro\HijackThis.exe
      • Right click on HijackThis.exe and select Rename.
      • Type in sniper.exe and press Enter.
      • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
    • From the desktop open Hijackthis.
    • If using Windows Vista, Right-click and Run As Administrator.
    • Click on the Do a system scan and save a log file button
    • Hijackthis will scan and then a log will open in notepad.
    • Copy and then paste the entire contents of the log in your post.
      • Do not have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
      Although we have renamed Hijackthis to sniper, we will still refer to it as Hijackthis or HJT.

      Post the Hijackthis log in the next reply please.
    Thanks here it is.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:47:01 PM, on 5/6/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
    C:\Program Files\Microsoft Windows OneCare Live\winss.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\ARPWRMSG.EXE
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\HP DVD\Umbrella\DVDTray.exe
    C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
    C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\DOCUME~1\HP_ADM~1\APPLIC~1\YSTEM~1\lsass.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\UPDATES from HP\9972322\Program\Updates from HP.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
    O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI
    O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
    O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
    O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Scbu] "C:\DOCUME~1\HP_ADM~1\APPLIC~1\YSTEM~1\lsass.exe" -vt yazb
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB
    O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/games/ricochet-lost-worlds/en/ReflexiveWebGameLoader.cab
    O16 - DPF: {B3E0F81F-73F8-470B-A56B-D895EFF19260} (ATLF3D Class) - http://www.famous3d.com/viewer/latest/axf3d.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

    --
    End of file - 10741 bytes
    Couldn't tell much from that log. Don't worry, we'll find it.

    First:

    Your Java is out of date.
    Older versions of Java have vulnerabilities that malware can use to infect your system.
    Please follow these steps to remove older version(s) of Java components and update.

    Step 1 - Get the new version
    • Go to the Sun Java Download Page
    • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
    • Click the button and choose the options.
      • Platform Windows
      • Language English
      • Next place a check mark in the box to agree to the License Agreement.
    • "I agree to the Java SE Runtime Environment 6 License Agreement"
    • Click Continue
    • Click on the link to download Windows Offline Installation and save to your desktop.
    • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
    • Follow the prompts to complete the installation.
    Step 2 - Remove old version(s)
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Do not remove Java 6 Update 6
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each old Java version.
    • Restart your computer once all Java components are removed.
    Step 3 - Remove old folder(s)
    • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
    • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
    .
    Second:

    Please download COMBOFIX by sUBs from one of the below links.
    (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
    • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
    • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
      • Click this link to see a list of security programs that should be disabled and how to disable them.
      • If yours is not listed and you don't know how to disable it, please ask.
    • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
    • Double click combofix.exe & follow the prompts.
      • Choose Yes to accept the Disclaimers.[
      • When finished, it will produce a log for you.
      • Post that log in your next reply.
      Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
      • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
      • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
      .
      If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly.

      ----------

      Next post please add:
      Combofix log
      thanks i removed the javas but none of the links for ComboFix work. I tried to find it online but none of those worked either. Are there any other links to it?Try this.

      http://download.bleepingcomputer.com/sUBs/ComboFix.exeIt said the page cannot be displayed...OK try this one. If you get it to run then try the Combofix again after posting the log from SDFix.

      Download SDFix.exe and save it to your Desktop.

      Double click SDFix.exe and it will extract the files to %systemdrive%
      (Drive that contains the Windows Directory, typically C:\SDFix)

      Please then reboot your computer in Safe Mode by doing the following:

      • Restart your computer
      • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
      • Instead of Windows loading as normal, the Advanced Options Menu should appear;
      • Select the first option, to run Windows in Safe Mode, then press Enter.
      • Choose your usual account.
      • Open the extracted SDFix folder and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
        (Report.txt will also be copied to Clipboard).
      • Finally add the contents of the Report.txt in your next post.
      Thanks heres the report.

      SDFix: Version 1.180
      Run by HP_Administrator on Tue 05/06/2008 at 10:40 PM

      Microsoft Windows XP [Version 5.1.2600]
      Running From: C:\SDFix

      Checking Services :


      Restoring Windows Registry Values
      Restoring Windows Default Hosts File

      Rebooting


      Checking Files :

      Trojan Files Found:

      C:\WINDOWS\SYSTEM32\LSPRST7.DLL - Deleted
      C:\Program Files\Common Files\Yazzle1552OinAdmin.exe - Deleted
      C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe - Deleted
      C:\WINDOWS\system32\000060.exe - Deleted
      C:\WINDOWS\system32\000090.exe - Deleted





      Removing Temp Files

      ADS Check :



      Final Check :

      catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-05-06 22:53:59
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clb.dll]
      "0"=hex:00,00,28,0a,01,00,05,00
      "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clbcatex.dll]
      "0"=hex:2a,00,3e,11,0c,00,d1,07
      "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\clbcatq.dll]
      "0"=hex:2a,00,3e,11,0c,00,d1,07
      "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmdesched.sys]
      @="driver"
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vmdesched.sys]
      @="driver"
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clbdriver]
      "start"=dword:00000001
      "type"=dword:00000001
      "imagepath"=str(2):"\??\globalroot\systemroot\system32\drivers\vmdesched.sys"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clb.dll]
      "0"=hex:00,00,28,0a,01,00,05,00
      "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clbcatex.dll]
      "0"=hex:2a,00,3e,11,0c,00,d1,07
      "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\clbcatq.dll]
      "0"=hex:2a,00,3e,11,0c,00,d1,07
      "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\vmdesched.sys]
      @="driver"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\vmdesched.sys]
      @="driver"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\clbdriver]
      "start"=dword:00000001
      "type"=dword:00000001
      "imagepath"=str(2):"\??\globalroot\systemroot\system32\drivers\vmdesched.sys"

      scanning hidden registry entries ...

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\clbImageData]
      "affid"="7"
      "subid"="run02"
      "control"=hex:1a,00,15,13,07,11,5b,1b,1e,1b,0b,15,08,13,1b,0a,0b,f2,e0,ec,f0,..
      "prov"="10010"
      "googleadserver"="pagead2.googlesyndication.com"
      "FLAGGED"=dword:00000001

      scanning hidden files ...

      C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll 110080 bytes executable
      C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll 498688 bytes executable
      C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 110080 bytes executable
      C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 501248 bytes executable
      C:\WINDOWS\system32\clb.dll 10752 bytes executable
      C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable
      C:\WINDOWS\system32\clbcatq.dll 498688 bytes executable
      C:\WINDOWS\system32\cdosys.dll 35328 bytes executable
      C:\WINDOWS\system32\clbinit.dll 1695 bytes
      C:\WINDOWS\system32\drivers\vmdesched.sys 6656 bytes executable
      C:\WINDOWS\system32\dllcache\clb.dll 10752 bytes executable
      C:\WINDOWS\system32\dllcache\clbcatex.dll 110080 bytes executable
      C:\WINDOWS\system32\dllcache\clbcatq.dll 498688 bytes executable
      C:\Program Files\Common Files\Real\Plugins\clbascauth.dll 41023 bytes executable
      C:\Program Files\HP Rhapsody\plugins\clbascauth.dll 26112 bytes executable

      scan completed successfully
      hidden processes: 0
      hidden services: 1
      hidden files: 15


      Remaining Services :




      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
      "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
      "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
      "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
      "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
      "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe:*:Enabled:Render Manager"
      "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe:*:Enabled:Studio"
      "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
      "C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"="C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe:*:Enabled:umi"
      "C:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"="C:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe:*:Enabled:Sentinel Protection Server"
      "C:\\Program Files\\WildTangent Games\\Polar Bowler\\Polar.exe"="C:\\Program Files\\WildTangent Games\\Polar Bowler\\Polar.exe:*:Enabled:Polar"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
      "C:\\3dsmax7\\3dsmax.exe"="C:\\3dsmax7\\3dsmax.exe:*:Enabled:3ds max 7"
      "C:\\Program Files\\backburner 2\\monitor.exe"="C:\\Program Files\\backburner 2\\monitor.exe:*:Enabled:backburner 2.3 monitor"
      "C:\\Program Files\\backburner 2\\manager.exe"="C:\\Program Files\\backburner 2\\manager.exe:*:Enabled:backburner 2.3 manager"
      "C:\\Program Files\\backburner 2\\server.exe"="C:\\Program Files\\backburner 2\\server.exe:*:Enabled:backburner 2.3 server"
      "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

      Remaining Files :


      File Backups: - C:\SDFix\backups\backups.zip

      Files with Hidden Attributes :

      THU 27 Jul 2006 211 A.SHR --- "C:\BOOT.BAK"
      Tue 1 Aug 2006 22 A.SH. --- "C:\WINDOWS\SMINST\HPCD.sys"
      Sun 31 Dec 2006 350 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti1F9.tmp"
      Tue 15 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
      Sun 4 May 2008 89,088 ..SHR --- "C:\Documents and Settings\HP_Administrator\Application Data\?ystem\lsass.exe"
      Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT400.tmp"
      Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\HP_Administrator\Application Data\U3\temp\Launchpad Removal.exe"
      Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL"
      Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL"
      Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL"
      Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL"
      Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL"
      Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL"
      Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL"
      Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL"
      Tue 8 Aug 2006 11,115 A.SH. --- "C:\Documents and Settings\HP_Administrator\My Documents\My DVDs\My Music\License Backup\drmv2key.bak"
      Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch1\lock.tmp"
      Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch2\lock.tmp"
      Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch3\lock.tmp"
      Wed 5 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch4\lock.tmp"
      Thu 6 Dec 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\Microsoft\OC\Channels\ch5\lock.tmp"

      Finished!

      Will the Combofix download now?No but i have a question. My firewall keeps asking me about "lsass". I looked it up and found that it is a secuirty program but can be a virus, spyware, or worm. I searched for lsass and found two programs that had last been modified in 2004 and one that had last been modified today. Is there any way to tell?lsass has been known to be exploitable by malware and 'can' be a big problem. I need more information in the form of logs to determine if it is legitimate or not.

      Use the Kaspersky Online Scanner
      • Click Accept.
      • Answer Yes, when prompted to install an ActiveX component.
      • The program will then begin downloading the latest definition files.
      • Once the files have been downloaded click on NEXT
      • Locate the Scan Settings button & configure to:
        • Scan using the following Anti-Virus database:
          • Extended
        • Scan Options:
          • Scan Archives
          • Scan Mail Bases
          • Click OK & have it scan My Computer
          When the scan is done, in the Scan is complete window (below), any infection is displayed.
          There is no option to clean/disinfect, however, we need to analyze the information on the report.

          To obtain the report:
          Click on: Save Report As...



          • Next, in the Save as prompt, Save in area, select: Desktop.
          • In the File name area, use KScan, or something similar.
          • In Save as type: click the drop arrow and select: Text file [*.txt]
          • Then, click: Save


          Please copy and paste the Kaspersky Online Scanner Report in your next post.The kaspersky page wont load either. Try running the WinSockFix utility to repair your connection and also HostsXpert. Then try to download Combofix again.

          .
          Download HostsXpert
          • Unzip the HostsXpert file and double click on HostsXpert.exe
          • Press Restore Original Hosts and press OK
          • Exit HostsXpert.
          Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.
          If you do not know what a HOSTS file is, you are most likely not using a custom one.
          3058.

          Solve : AVG 8.0.1 Preventing attachment and torrent file downloads?

          Answer»

          Hi FOLKS,

          I have a VISTA Home Premium 32 bit PC. Windows VERSION 6. (I have no idea what that MEANS)
          I downloaded the newer version of AVG Free 8.0.1.
          And it looks fantastic and is far more user friendly.
          Except....I can't download my email attachments or torrent files.
          I can download images....the right click save to desktop.
          I have headed to tools/advanced settings I have turned off search-shield via the link scanner and turned off the email scanner.
          I have no idea why this is not working...(ha ha Thats why I am asking you clever GUYS and girls for help)
          Any assistance would be great! I have some work files I need to download....and not sure that AVG is GOING to give me a free pass with the boss for a lazy weekend.

          Cheers

          GidzQuote

          I can't download my email attachments or torrent files.
          What exactly happens?What happens...

          Okay...I click on the link where it will say download attachment or download torrent etc.
          It brings up the box where I get to choose the location where the file needs to be saved to.
          I point to a folder, desktop etc...and then click OK/Save
          From there it looks as though its going to dlownload, there are few kbs of data downloaded and then it shuts down. Nothing is saved and no messages pop up stating that the dnload was blocked.
          I also noticed that the new chat function on FACEBOOK has stopped working for aswell.
          I just uninstalled AVG and restared nd everything is working again...except that I am now unprotected.
          I hope this helps explain my situation.

          Cheers
          There has been a lot of problems reported around the net about new AVG. I had serious installation problems myself.
          Try free Avast: http://www.avast.com/http://www.avast.com/ I had trouble with AVG also and downloaded avast and think I like it better than avg.
          3059.

          Solve : AVG and WIN98??

          Answer»

          I have been using AVG 7.5 on both my main and back up COMPUTERS. But have received the notice that AVG will soon STOP updates for 7.5 and I have to change to 8.0. No problem with the main COMPUTER running Win XP Pro, but the back up is Win 98 and AVG 8.0 does not run on that apparently.
          I tried installing Avast on the spare, but it froze. So put back AVG 7.5 for now. Is there another free ANTI virus that you would recommend for Win 98 please?AVG 7.5 will be supported until the end of this year.
          Avast would be your only other, free choice.Thanks Broni. I will leave AVG on it for now and try Avast again when AVG stops being supported.

          3060.

          Solve : Rundll system error system32/bxlghumi.dll?

          Answer»

          Hi,
          I recently found many VIRUSES on my computer and deleted them. Now I am getting two rundll error messages everytime I turn on my computer. One reads

          Error loading C:/WINDOWS/systme32/bxlghumi.dll
          The specified module could not be found.

          And

          Error loading C:/WINDOWS/system32/{afdb6c83-10d3-c922-bcda-9c83b9fb91f8}.dll
          The specified module could not be found.

          What should I do?

          Thanks!!Print these instructions out.

          1. Download SUPERAntiSpyware Free for Home Users:
          http://www.superantispyware.com/

          * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
          * An icon will be created on your desktop. Double-click that icon to launch the program.
          * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
          * Close SUPERAntiSpyware.

          Restart computer in Safe Mode.
          To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

          * Open SUPERAntiSpyware.
          * Under "Configuration and Preferences", click the Preferences button.
          * Click the Scanning Control tab.
          * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
          * Click the "Close" button to leave the control center screen.
          * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
          * On the left, make sure you check C:\Fixed Drive.
          * On the right, under "Complete Scan", choose Perform Complete Scan.
          * Click "Next" to start the scan. Please be patient while it scans your computer.
          * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
          * Make sure everything has a checkmark next to it and click "Next".
          * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
          * If asked if you want to reboot, click "Yes".
          * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
          * Click Close to exit the program.
          Post SUPERAntiSpyware log.

          RESTART COMPUTER!

          2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

          * Double-click mbam-setup.exe and follow the prompts to install the program.
          * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
          * If an update is found, it will download and install the latest version.
          * Once the program has loaded, select Perform full scan, then click Scan.
          * When the scan is complete, click OK, then Show Results to view the results.
          * Be sure that everything is checked, and click Remove Selected.
          * When completed, a log will open in Notepad.
          * Post the log back here.

          The log can also be found here:
          C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
          Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

          RESTART COMPUTER!

          3. Download HijackThis:
          http://www.snapfiles.com/get/hijackthis.html
          Post HijackThis log.Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:14:06 PM, on 5/12/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          RUNNING processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\zHotkey.exe
          C:\Program Files\Digital Media Reader\shwiconem.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
          C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
          C:\Program Files\QUICKTIME\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\Belkin\F5D8051v2\Belkinwcui.exe
          C:\Program Files\Belkin\F5D8051v2\chkdev.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          C:\WINDOWS\system32\dlcxcoms.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\WINDOWS\system32\inetsrv\inetinfo.exe
          C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cmich.edu/portal/portal_welcome.asp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.com/
          O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {4829CE73-E1B5-4F77-B44E-DDD70246951D} - C:\WINDOWS\system32\qoMgfGXp.dll (file missing)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: superiorads browser optimizer - {af1beead-8595-9e09-50c2-bbcc7ed8e26b} - C:\WINDOWS\system32\{afdb6c83-10d3-c922-bcda-9c83b9fb91f8}.dll (file missing)
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
          O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
          O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
          O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
          O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
          O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[emailprotected]
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [fcd9ef24] rundll32.exe "C:\WINDOWS\system32\bxlghumi.dll",b
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKLM\..\Policies\Explorer\Run: [MHilJTloPl] C:\Documents and Settings\All Users\Application Data\efcxanuv\inylirij.exe
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
          O4 - Global Startup: Belkin Wireless Networking Utility.lnk = ?
          O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\My Backup -- 28-05-07 1814\Program Files\AIM\aim.exe
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188030619140
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O20 - Winlogon Notify: jkkIayya - C:\WINDOWS\
          O21 - SSODL: SysKbd - {69d864a8-f4f6-4b39-adc9-975837a2a674} - C:\WINDOWS\Resources\SysKbd.dll (file missing)
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

          --
          End of file - 9863 bytes
          okay half way there I did all the steps and now the only eror found at startup is the system32/bxlghumi.dll*** Is Windows firewall on?

          *** Check your Java version: http://www.java.com/en/download/installed.jsp
          Update, if necessary. Uninstall all other Java versions thorugh Add\Remove.

          *** Disable Windows Defender, as it'll interfere with cleaning process:
          * Open Windows Defender
          * Click Tools
          * Click General Settings
          * Scroll down to Real Time Protection Options
          * Uncheck Turn on Real Time Protection
          * After you uncheck this, click on the Save button
          * Close Windows Defender



          1. Print this post out, since you won't have an access to it, at some point.

          2. Close all windows, except for HijackThis.

          3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

          - O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
          - O2 - BHO: (no name) - {4829CE73-E1B5-4F77-B44E-DDD70246951D} - C:\WINDOWS\system32\qoMgfGXp.dll (file missing)
          - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          - O2 - BHO: superiorads browser optimizer - {af1beead-8595-9e09-50c2-bbcc7ed8e26b} - C:\WINDOWS\system32\{afdb6c83-10d3-c922-bcda-9c83b9fb91f8}.dll (file missing)
          - *O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          - *O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          - *O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
          - *O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
          - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          - O4 - HKLM\..\Run: [fcd9ef24] rundll32.exe "C:\WINDOWS\system32\bxlghumi.dll",b
          - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          - O4 - HKLM\..\Policies\Explorer\Run: [MHilJTloPl] C:\Documents and Settings\All Users\Application Data\efcxanuv\inylirij.exe
          - O4 - Global Startup: Belkin Wireless Networking Utility.lnk = ?
          - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          - O20 - Winlogon Notify: jkkIayya - C:\WINDOWS\

          4. Click on Fix checked button.

          5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

          6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

          7. Delete following files/folders (if present):

          - qoMgfGXp.dll, bxlghumi.dll files from C:\WINDOWS\system32
          - efcxanuv folder from C:\Documents and Settings\All Users\Application Data
          - jkkIayya file from C:\WINDOWS

          8. Restart in Normal Mode.

          9. Post new HijackThis log.firewall is on should i turn it off?NO! Just checking...Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 10:56:53 PM, on 5/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Digital Media Reader\shwiconem.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\system32\dlcxcoms.exe
          C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\zHotkey.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\WINDOWS\system32\inetsrv\inetinfo.exe
          C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\dllhost.exe

          O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

          --
          End of file - 1735 bytes
          This is not a whole log.Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:15:41 PM, on 5/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Digital Media Reader\shwiconem.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\system32\dlcxcoms.exe
          C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\zHotkey.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\WINDOWS\system32\inetsrv\inetinfo.exe
          C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cmich.edu/portal/portal_welcome.asp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.com/
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
          O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,[emailprotected]
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
          O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
          O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
          O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdS7_0_0
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
          O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\My Backup -- 28-05-07 1814\Program Files\AIM\aim.exe
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188030619140
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
          O21 - SSODL: SysKbd - {69d864a8-f4f6-4b39-adc9-975837a2a674} - C:\WINDOWS\Resources\SysKbd.dll (file missing)
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

          --
          End of file - 8297 bytes


          sorryYour computer is clean is clean

          1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
          Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
          Run CCleaner.

          2. Turn off System Restore:

          - Windows XP:
          1. Click Start.
          2. Right-click the My Computer icon, and then click Properties.
          3. Click the System Restore tab.
          4. Check "Turn off System Restore".
          5. Click Apply.
          6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
          7. Click OK.
          - Windows Vista:
          1. Click Start.
          2. Right-click the Computer icon, and then click Properties.
          3. Click on System Protection under the TASKS column on the left side
          4. Click on Continue on the "User Account Control" window that pops up
          5. Under the System Protection tab, find Available Disks
          6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
          7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
          8. Click OK

          3. Restart computer.

          4. Turn System Restore on.

          5. Let me know, how your computer is doing.
          my computer is running a lot smoother, no problems at the last startup! Thank you sooo much! Good
          Keep it this way...

          3061.

          Solve : Looking for help with a virus from you smart people?

          Answer»

          You'll have to make a Bootable WINDOWS 2000 CD with Service PACK INTEGRATED: http://old.bink.nu/bootcd/

          3062.

          Solve : problems uninstalling AVG 7.5 + problems with tabbed browsing in Firefox?

          Answer»

          I'm glad, things are BACK to normal
          You MAY WANT to CHECK your monitor on another computer.

          3063.

          Solve : Internet connection is driving me nuts!?

          Answer»

          I'm GLAD, your internet is back, but still, I'd like to SEE those three logs to see, if your COMPUTER is CLEAN, and it won't happen again.

          3064.

          Solve : Roomie's computer infected now...HJT log included.?

          Answer»

          I was helping my coworker with her infection when evilfantasy determined that her situation was devastating.

          So now my roomie's computer got infected. His, however, is not nearly as bad as hers was. He can still connect to the internet, can still download, etc, but I've so far seen SIGNS of SysCleaner and at least one other trojan on the computer. So...here's your HJT log. Anyone help me finish this cleanup?





          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:09:16 AM, on 5/9/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\System32\ibmpmsvc.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\IBM\IBM RAPID Restore Ultra\rrpcsb.exe
          C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\system32\TpKmpSVC.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\system32\TpShocks.exe
          C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
          C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
          C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\IBMTOOLS\UTILS\ibmprc.exe
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
          C:\Program Files\Winamp\winampa.exe
          C:\WINDOWS\TPPALDR.EXE
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\DOCUMENTS and Settings\Hotsync.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
          C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Norton AntiVirus\navapsvc.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: (no name) - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - (no file)
          O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
          O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
          O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
          O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
          O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
          O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
          O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
          O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
          O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
          O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Digital Line Detect.lnk = ?
          O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\Hotsync.exe
          O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe
          O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
          O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
          O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
          O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
          O9 - Extra 'Tools' menuitem: GigaSize Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
          O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [JAVA_IBM] Java (IBM)
          O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
          O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://www.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
          O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by133fd.bay133.hotmail.msn.com/resources/MsnPUpld.cab
          O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
          O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
          O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
          O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
          O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
          O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
          O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
          O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
          O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

          --
          End of file - 13757 bytes
          I don't see any malware, just a few unnecessary (deactivated) items to fix.

          We can also run another more thorough scan to see what all else may be hiding.

          Open Hijackthis and select Do a system scan only.

          Place a check mark next to the following entries: (if there)

          O2 - BHO: (no name) - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - (no file)
          O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
          O9 - Extra 'Tools' menuitem: GigaSize Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)


          Important: Close all windows except for Hijackthis and then click Fix checked.

          Exit Hijackthis.

          ----------

          Download Deckard's System Scanner (DSS) from here or here to your Desktop.
          Note: You must be logged onto an account with administrator privileges.

          • Close all applications and windows.
          • Double-click on dss.exe to run it, and follow the prompts.
          • When the scan is complete, two text files will open
            • main.txt <- this one will be maximized
            • extra.txt <- this one will be minimized
            • Add the contents of main.txt in your post.
            • Also add extra.txt to your post.
            • Note: The text from these files may exceed the maximum post length for this forum, and may need to be sent over 2 or more posts. Please ensure all text is posted.
            .
            What DSS will do:
            • Create a new System Restore point in Windows XP and Vista.
            • Clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
            • Check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
            .
            Next post please add
            DSS Main & Extra text logs.


            Almost missed this...

            Your Java is out of date.
            Older versions of Java have vulnerabilities that malware can use to infect your system.
            Please follow these steps to remove older version(s) of Java components and update.

            Step 1 - Get the new version
            • Go to the Sun Java Download Page
            • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
            • Click the button and choose the options.
              • Platform Windows
              • Language English
              • Next place a check mark in the box to agree to the License Agreement.
            • "I agree to the Java SE Runtime Environment 6 License Agreement"
            • Click Continue
            • Click on the link to download Windows Offline Installation and save to your desktop.
            • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
            • Follow the prompts to complete the installation.
            Step 2 - Remove old version(s)
            • Close any programs you may have running - especially your web browser.
            • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
            • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
            • Do not remove Java 6 Update 6
            • Click the Remove or Change/Remove button.
            • Repeat as many times as necessary to remove each old Java version.
            • Restart your computer once all Java components are removed.
            Step 3 - Remove old folder(s)
            • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
            • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
            I updated Java. Here's the DSS:

            Deckard's System Scanner v20071014.68
            Run by CATANYAG on 2008-05-10 00:46:03
            Computer is in Normal Mode.
            --------------------------------------------------------------------------------

            -- System Restore --------------------------------------------------------------

            Successfully created a Deckard's System Scanner Restore Point.


            -- Last 5 Restore Point(s) --
            68: 2008-05-10 07:46:08 UTC - RP1250 - Deckard's System Scanner Restore Point
            67: 2008-05-10 07:38:18 UTC - RP1249 - Installed Java(TM) 6 Update 5
            66: 2008-05-10 07:11:20 UTC - RP1248 - System Checkpoint
            65: 2008-05-08 22:01:29 UTC - RP1247 - Software Distribution Service 3.0
            64: 2008-05-08 06:35:07 UTC - RP1246 - System Checkpoint


            -- First Restore Point --
            1: 2008-03-06 12:03:06 UTC - RP1183 - System Checkpoint


            Backed up registry hives.
            Performed disk cleanup.



            -- HijackThis (run as CATANYAG.exe) --------------------------------------------

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:48:08 AM, on 5/10/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\System32\ibmpmsvc.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
            C:\Program Files\Norton AntiVirus\navapsvc.exe
            C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\WINDOWS\system32\TpKmpSVC.exe
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\system32\TpShocks.exe
            C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\IBMTOOLS\UTILS\ibmprc.exe
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
            C:\Program Files\Winamp\winampa.exe
            C:\WINDOWS\TPPALDR.EXE
            C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
            C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\Documents and Settings\Hotsync.exe
            C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Documents and Settings\CATANYAG\Desktop\dss.exe
            C:\PROGRA~1\TRENDM~1\HIJACK~1\CATANYAG.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
            O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
            O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
            O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
            O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
            O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
            O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
            O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
            O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
            O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
            O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Digital Line Detect.lnk = ?
            O4 - Global Startup: HotSync Manager.lnk = C:\Documents and Settings\Hotsync.exe
            O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe
            O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
            O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
            O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [JAVA_IBM] Java (IBM)
            O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cab
            O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://www.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
            O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by133fd.bay133.hotmail.msn.com/resources/MsnPUpld.cab
            O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
            O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
            O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
            O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
            O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
            O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
            O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
            O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

            --
            End of file - 13451 bytes

            -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

            backup-20080510-004336-415 O9 - Extra 'Tools' menuitem: GigaSize Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
            backup-20080510-004336-509 O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
            backup-20080510-004336-592 O2 - BHO: (no name) - {B8A7839C-51E8-4067-ADA3-CA74BABC1976} - (no file)-- File Associations -----------------------------------------------------------

            .reg - regfile - shell\open\command - regedit.exe "%1" %*
            .scr - scrfile - shell\open\command - "%1" %*


            -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

            R0 Shockprf - c:\windows\system32\drivers\shockprf.sys
            R1 SbcpHid - c:\windows\system32\drivers\sbcphid.sys
            R1 Smapint - c:\windows\system32\drivers\smapint.sys
            R1 TDSMAPI - c:\windows\system32\drivers\tdsmapi.sys
            R1 TPHKDRV - c:\windows\system32\drivers\tphkdrv.sys
            R1 TPPWR - c:\windows\system32\drivers\tppwr.sys
            R1 TSMAPIP - c:\windows\system32\drivers\tsmapip.sys
            R2 EGATHDRV (IBM Access Support) - c:\windows\system32\egathdrv.sys
            R2 ibmfilter - c:\windows\system32\drivers\ibmfilter.sys
            R2 PMEM - c:\windows\system32\drivers\pmemnt.sys
            R2 ShockMgr - c:\windows\system32\drivers\shockmgr.sys
            R3 ASAPIW2k - c:\windows\system32\drivers\asapiw2k.sys

            S3 CBTNDIS5 (CBTNDIS5 NDIS Protocol Driver) - c:\windows\system32\cbtndis5.sys
            S3 IPN2220 (Wireless-G Notebook Adapter ver.4.0 Driver) - c:\windows\system32\drivers\i2220ntx.sys (file missing)
            S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys (file missing)
            S3 psadd (IBM PSA Access Driver) - c:\windows\system32\drivers\psadd.sys
            S3 stusb2ir (USB 2.0 IrDA Bridge) - c:\windows\system32\drivers\stusb2ir.sys
            S3 ZD1211U(WLAN) (IEEE 802.11g USB Wireless LAN Driver(WLAN)) - c:\windows\system32\drivers\zd1211u.sys
            S3 ZDBRGSYS (ZDBRGSYS NDIS Protocol Driver) - c:\windows\system32\zdbrgsys.sys
            S3 ZDPNDIS5 (ZDPNDIS5 NDIS Protocol Driver) - c:\windows\system32\zdpndis5.sys


            -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

            R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe"
            R2 IBM Rapid Restore Ultra Service - c:\program files\ibm\ibm rapid restore ultra\rrpcsb.exe
            R2 RegSrvc (Intel(R) PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe
            R2 TpKmpSVC (IBM KCU Service) - c:\windows\system32\tpkmpsvc.exe

            S2 NICSer_WPC54G - c:\program files\linksys\wireless-g notebook adapter\nicserv.exe
            S3 PsaSrv (IBM PSA Access Driver Control) - c:\windows\system32\psasrv.exe (file missing)


            -- Device Manager: Disabled ----------------------------------------------------

            No disabled devices found.


            -- Scheduled Tasks -------------------------------------------------------------

            2008-05-09 23:58:28 380 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
            2008-05-09 23:10:45 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
            2008-05-07 10:14:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
            2008-05-02 22:39:54 536 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - CATANYAG.job
            2007-11-24 09:37:55 506 --a------ C:\WINDOWS\Tasks\BMMTask.job


            -- Files created between 2008-04-10 and 2008-05-10 -----------------------------

            2008-05-09 00:09:04 0 d-------- C:\Program Files\Trend Micro
            2008-05-08 23:59:54 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Malwarebytes
            2008-05-08 23:59:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
            2008-05-08 23:59:49 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
            2008-05-08 23:16:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
            2008-05-08 22:43:14 5276 --a------ C:\WINDOWS\system32\tmp.reg
            2008-05-08 22:38:29 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
            2008-05-08 22:38:29 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe
            2008-05-08 22:38:29 86528 --a------ C:\WINDOWS\system32\VACFix.exe
            2008-05-08 22:38:29 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe
            2008-05-08 22:38:29 53248 --a------ C:\WINDOWS\system32\Process.exe http://www.beyondlogic.org; Command Line Process Utility>
            2008-05-08 22:38:29 82944 --a------ C:\WINDOWS\system32\IEDFix.exe
            2008-05-08 22:38:29 51200 --a------ C:\WINDOWS\system32\dumphive.exe
            2008-05-08 22:38:29 82944 --a------ C:\WINDOWS\system32\404Fix.exe
            2008-05-08 06:22:58 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Google
            2008-05-08 06:18:13 0 d-------- C:\Documents and Settings\UST TRAINING\Application Data\Google
            2008-05-08 06:16:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
            2008-05-07 23:53:20 0 d-------- C:\Documents and Settings\UST TRAINING\Application Data\Adobe
            2008-05-07 00:25:42 0 d-------- C:\Program Files\Enigma Software Group
            2008-05-07 00:02:07 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
            2008-05-06 23:58:36 0 d-------- C:\Documents and Settings\LocalService\Desktop
            2008-05-06 17:41:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
            2008-05-06 17:30:38 0 d-------- C:\Program Files\Windows Defender
            2008-05-01 21:58:03 0 d-------- C:\Documents and Settings\LocalService\Application Data\Intel
            2008-05-01 12:01:31 0 d-------- C:\WINDOWS\system32\FxsTmp
            2008-04-22 17:30:55 0 d-------- C:\Program Files\iTunes
            2008-04-22 17:28:40 0 d-------- C:\Program Files\QuickTime


            -- Find3M Report ---------------------------------------------------------------

            2008-05-10 00:39:30 0 d-------- C:\Program Files\Java
            2008-05-10 00:13:49 0 d-------- C:\Program Files\Common Files
            2008-05-08 19:58:25 0 d-------- C:\Program Files\Common Files\Symantec Shared
            2008-05-08 17:37:43 0 d-------- C:\Program Files\Absolute Poker
            2008-05-08 09:07:02 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Yahoo!
            2008-05-08 06:20:04 0 d-------- C:\Program Files\Google
            2008-05-06 17:23:38 0 d-------- C:\Program Files\Symantec
            2008-04-22 17:31:08 0 d-------- C:\Program Files\iPod
            2008-04-22 17:23:25 0 d-------- C:\Program Files\Apple Software Update
            2008-04-17 00:06:14 0 d-------- C:\Documents and Settings\CATANYAG\Application Data\Adobe


            -- Registry Dump ---------------------------------------------------------------

            *Note* empty entries & legit default entries are not shown


            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "S3TRAY2"="S3Tray2.exe" [10/11/2001 11:32 PM C:\WINDOWS\system32\S3Tray2.exe]
            "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [11/19/2003 09:56 AM]
            "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/19/2003 09:56 AM]
            "ATIModeChange"="Ati2mdxx.exe" [09/04/2001 01:24 PM C:\WINDOWS\system32\Ati2mdxx.exe]
            "BluetoothAuthenticationAgent"="irprops.cpl" [08/04/2004 12:56 AM C:\WINDOWS\system32\irprops.cpl]
            "TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [10/23/2003 11:39 PM]
            "TpShocks"="TpShocks.exe" [12/17/2003 11:12 AM C:\WINDOWS\system32\TpShocks.exe]
            "TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [03/10/2004 10:10 AM]
            "BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [12/25/2003 01:36 AM]
            "BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [12/25/2003 01:36 AM]
            "TP4EX"="tp4ex.exe" [09/04/2002 01:05 AM C:\WINDOWS\system32\TP4EX.exe]
            "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [12/25/2003 02:04 AM]
            "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [02/10/2004 09:10 PM]
            "UC_Start"="C:\Program Files\IBM\Updater\\ucstartup.exe" [09/30/2003 03:39 PM]
            "UC_SMB"="" []
            "UpdateManager"="c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 01:01 AM]
            "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [10/22/2003 01:04 AM]
            "IBMPRC"="C:\IBMTOOLS\UTILS\ibmprc.exe" [03/19/2004 12:12 PM]
            "BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [12/25/2003 01:36 AM]
            "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 05:32 PM]
            "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [05/06/2008 05:23 PM]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [04/13/2005 04:48 AM]
            "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 12:50 PM]
            "PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" []
            "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [02/13/2007 11:29 AM]
            "TPP Auto Loader"="C:\WINDOWS\TPPALDR.EXE" [10/05/2001 12:54 PM]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
            "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM]

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "IBM RecordNow!"="" []
            "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
            "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [07/14/2005 10:35 PM]
            "Aim6"="" []
            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
            "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]

            C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
            Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 5:44:06 AM]
            Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/2/2004 6:51:35 PM]
            HotSync Manager.lnk - C:\Documents and Settings\Hotsync.exe [6/9/2004 2:16:08 PM]
            Wireless-G Notebook Adapter Utility.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe [10/13/2004 10:17:35 PM]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
            "Notification Packages"= scecli pwdmon

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
            SecurityProvidersmsapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
            @="Service"

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
            @="Volume SHADOW copy"




            -- End of Deckard's System Scanner: finished at 2008-05-10 00:49:27 ------------

            Deckard's System Scanner v20071014.68
            Extra logfile - please post this as an attachment with your post.
            --------------------------------------------------------------------------------

            -- System Information ----------------------------------------------------------

            Microsoft Windows XP Professional (build 2600) SP 2.0
            Architecture: X86; Language: English

            CPU 0: Intel(R) Pentium(R) M processor 1500MHz
            Percentage of Memory in Use: 38%
            Physical Memory (total/avail): 1278.92 MiB / 792.63 MiB
            Pagefile Memory (total/avail): 1517.93 MiB / 1155.96 MiB
            Virtual Memory (total/avail): 2047.88 MiB / 1926.57 MiB

            C: is Fixed (NTFS) - 32.97 GiB total, 6.54 GiB free.
            D: is CDROM (No Media)

            \\.\PHYSICALDRIVE0 - HTS548040M9AT00 - 37.26 GiB - 2 partitions
            \PARTITION0 (bootable) - Installable File System - 32.97 GiB - C:
            \PARTITION1 - Unknown - 4.29 GiB



            -- Security Center -------------------------------------------------------------

            AUOptions is scheduled to auto-install.
            Windows Internal Firewall is enabled.

            AntiVirusDisableNotify is set.

            FW: Norton Internet Worm Protection v2005 (Symantec)
            AV: Norton AntiVirus 2005 v2005 (Symantec Corporation) Outdated

            [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

            [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
            "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
            "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
            "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
            "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


            -- Environment Variables -------------------------------------------------------

            ALLUSERSPROFILE=C:\Documents and Settings\All Users
            APPDATA=C:\Documents and Settings\CATANYAG\Application Data
            CLASSPATH=.;C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
            CommonProgramFiles=C:\Program Files\Common Files
            COMPUTERNAME=DENNIS
            ComSpec=C:\WINDOWS\system32\cmd.exe
            FP_NO_HOST_CHECK=NO
            HOMEDRIVE=C:
            HOMEPATH=\Documents and Settings\CATANYAG
            IBMSHARE=C:\IBMSHARE
            LOGONSERVER=\\DENNIS
            NUMBER_OF_PROCESSORS=1
            OS=Windows_NT
            Path=C:\PROGRAM FILES\THINKPAD\UTILITIES;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\WINDOWS\Downloaded Program Files;C:\IBMTOOLS\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\Pinnacle\Shared Files\Filter;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\QuickTime\QTSystem\
            PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.pyo;.pyc;.py;.pyw
            PROCESSOR_ARCHITECTURE=x86
            PROCESSOR_IDENTIFIER=x86 Family 6 Model 9 Stepping 5, GenuineIntel
            PROCESSOR_LEVEL=6
            PROCESSOR_REVISION=0905
            ProgramFiles=C:\Program Files
            PROMPT=$P$G
            PYTHONCASEOK=1
            PYTHONPATH=C:\IBMTOOLS\utils\support;C:\IBMTOOLS\utils\logger
            QTJAVA=C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
            RRU=C:\Program Files\IBM\IBM Rapid Restore Ultra\
            SESSIONNAME=Console
            SystemDrive=C:
            SystemRoot=C:\WINDOWS
            TCL_LIBRARY=C:\IBMTOOLS\Python22\tcl\tcl8.4
            TEMP=C:\DOCUME~1\CATANYAG\LOCALS~1\Temp
            TK_LIBRARY=C:\IBMTOOLS\Python22\tcl\tk8.4
            TMP=C:\DOCUME~1\CATANYAG\LOCALS~1\Temp
            USERDOMAIN=DENNIS
            USERNAME=CATANYAG
            USERPROFILE=C:\Documents and Settings\CATANYAG
            windir=C:\WINDOWS


            -- User Profiles ---------------------------------------------------------------

            CATANYAG (admin)
            UST TRAINING (admin)
            Office.DENNIS (admin)
            Administrator (admin)


            -- Add/Remove Programs ---------------------------------------------------------

            --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
            --> c:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
            --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\SETUP.EXE"
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\SETUP.EXE" -l0x9 ControlPanelAnyText
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\SETUP.EXE"
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\SETUP.EXE"
            --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll -l0x9 ControlPanelAnyText
            --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Absolute Poker --> C:\Program Files\_uninstallation_info\Absolute Poker\CasinoUninstall.exe
            AC3Filter (remove only) --> C:\Documents and Settings\CATANYAG\Desktop\AC3Filter\uninstall.exe
            Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
            Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Reader 7.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
            Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
            AIM 6 --> C:\Program Files\AIM6\uninst.exe
            Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
            Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
            ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
            ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,[emailprotected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
            ATI HYDRAVISION --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
            ccCommon --> MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
            Coupon Printer for Windows --> "C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
            Cucusoft DVD to iPod + iPod Video Converter Suite 5.28.5.12 --> "C:\Program Files\Cucusoft\ipod-converter\unins000.exe"
            DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
            DVD Decrypter (Remove Only) --> "C:\Documents and Settings\CATANYAG\Desktop\DVD Decrypter\uninstall.exe"
            DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
            Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
            HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
            HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            IBM 32-bit Runtime Environment for Java 2, v1.4.1 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6C72E14A-C1F3-45E5-8810-83CE3C19ED63} /l1033
            IBM Active Protection System --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72806716-7088-41B2-8FA6-717A2A164DAB}\SETUP.EXE" -l0x9 anything
            IBM DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
            IBM Integrated 56K Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014\HXFSETUP.EXE -U -IVEN_8086&DEV_24C6&SUBSYS_05591014
            IBM RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
            IBM Rescue and Recovery with Rapid Restore --> MsiExec.exe /X{11783F13-C3A9-44A8-929B-21A476F65272}
            IBM Themes --> MsiExec.exe /I{6CE96A14-61E2-48CC-837E-22710A953ADE}
            IBM ThinkPad Battery MaxiMiser and Power Management Features --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unbmm.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsbmm.dll"
            IBM ThinkPad Configuration --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNTPUW.ISU -c"C:\Program Files\ThinkPad\Utilities\Tpinswin.dll"
            IBM ThinkPad EasyEject Utility --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unezej.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsej.dll"
            IBM ThinkPad Keyboard Customizer Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2111B23F-7FDA-4A41-8309-E5A1663CA296}\SETUP.EXE" -l0x9 anything
            IBM ThinkPad Power Management Driver --> RunDll32.exe tpinspm.dll,Uninstall
            IBM ThinkPad Presentation Director --> C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNNPDR.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsnpd.dll"
            IBM ThinkPad UltraNav Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
            IBM ThinkPad UltraNav Wizard --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82512BC9-BD5D-4C50-BE4D-B98E7DF78687}\SETUP.EXE" UNINSTALL
            IBM TrackPoint Accessibility Features --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA664480-3844-11D5-8C25-444553540000}\SETUP.EXE"
            IBM Update Connector --> MsiExec.exe /X{8D815BF3-2399-459C-B121-49373FEFB9E8}
            Intel(R) PRO Network Adapters and Drivers --> Prounstl.exe
            Intel(R) PROSet/Wireless Software --> C:\WINDOWS\Installer\iProInst.exe
            Internet Worm Protection --> MsiExec.exe /I{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
            InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
            iPod Access for Windows v2.9.4 --> "C:\Program Files\iPod Access for Windows\unins000.exe"
            iPod for Windows 2005-10-12 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A} /l1033
            iPod Reset Utility --> MsiExec.exe /X{91A2689C-D4B1-43BB-A521-0E29B963FC56}
            iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
            J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
            Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
            LimeWire 4.14.8 --> "C:\Program Files\LimeWire\uninstall.exe"
            LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
            LiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
            Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            mCore --> MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
            mDriver --> MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
            Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
            Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            mMHouse --> MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
            mPfMgr --> MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
            mProSafe --> MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
            MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
            mWlsSafe --> MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
            Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
            Norton AntiVirus 2005 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
            Norton AntiVirus 2005 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{C6F5B6CF-609C-428E-876F-CA83176C021B}.exe /X
            Norton AntiVirus Help --> MsiExec.exe /I{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
            Norton AntiVirus Parent MSI --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
            Norton AntiVirus SCSSDist MSI --> MsiExec.exe /I{541230A3-1D3A-4879-B7E0-E71F90E35548}
            Norton AntiVirus SYMLT MSI --> MsiExec.exe /I{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8}
            Norton WMI Update --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352}
            Norton WMI Update --> MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
            Odyssey Client --> MsiExec.exe /X{99D42EC7-652B-4819-B3E6-6450C815E03F}
            palmOne --> MsiExec.exe /X{E434580A-2D4A-4433-A81E-4BCAE86AD148}
            PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\SETUP.EXE"
            PCFriendly --> C:\Program Files\PCFriendly\inuninst.exe
            Pinnacle Mobile Media Organizer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCC64390-4796-4BEC-87AB-87282CBAFF8C}\Setup.exe" -l0x9 UNINSTALL
            QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
            Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
            Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
            Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
            SPBBC --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
            Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
            Symantec --> MsiExec.exe /I{228F6876-A313-40A3-91C0-C3CBE6997D09}
            Symantec Script Blocking Installer --> MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
            SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
            ThinkPad FullScreen Magnifier --> RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall.NT 132 C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.inf
            ThinkPad Software Installer --> _tpiu000.exe /U
            TPP Storage Driver Installation --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E258A840-7E9A-443A-B156-67102C48BF17}\Setup.exe" NotFirstInstall
            USB 2.0 IrDA Bridge --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10F5D9BB-E2F2-4B18-A65D-928B73D22E6F}\setup.exe" -l0x9
            USB Storage Adapter (TPP) --> tppun.exe TPP725
            USB Storage Adapter V2 (TPP) --> tppun.exe TPP200
            USB Storage Adapter V3 (TPP) --> tppun.exe TPP300
            Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
            Wallpapers --> MsiExec.exe /I{F386C340-DF4B-4BBA-9503-420FB7EDB395}
            Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
            Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
            Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Wireless-G Notebook Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A2EDF5F-F3C6-4919-AE34-C08A71AD034A}\Setup.exe" -l0x9


            -- Application Event Log -------------------------------------------------------

            Event Record #/Type9341 / Warning
            Event Submitted/Written: 05/09/2008 00:16:05 AM
            Event ID/Source: 1524 / Userenv
            Event Description:
            Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

            Event Record #/Type9326 / Warning
            Event Submitted/Written: 05/08/2008 10:45:38 PM
            Event ID/Source: 1015 / MsiInstaller
            Event Description:
            Failed to connect to server. Error: 0x8007043C

            Event Record #/Type9325 / Warning
            Event Submitted/Written: 05/08/2008 10:45:38 PM
            Event ID/Source: 1004 / MsiInstaller
            Event Description:
            Detection of product '{90110409-6000-11D3-8CFE-0150048383C9}', feature 'OfficeUserData', component '{4A31E933-6F67-11D2-AAA2-00A0C90F57B0}' failed. The resource 'HKEY_CURRENT_USER\Software\ODBC\ODBC.INI\MS Access Database\' does not exist.

            Event Record #/Type9323 / Warning
            Event Submitted/Written: 05/08/2008 10:39:30 PM
            Event ID/Source: 1524 / Userenv
            Event Description:
            Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

            Event Record #/Type9307 / Warning
            Event Submitted/Written: 05/08/2008 10:30:48 PM
            Event ID/Source: 1524 / Userenv
            Event Description:
            Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



            -- Security Event Log ----------------------------------------------------------

            No Errors/Warnings found.


            -- System Event Log ------------------------------------------------------------

            Event Record #/Type112440 / Warning
            Event Submitted/Written: 05/10/2008 00:48:34 AM
            Event ID/Source: 3004 / WinDefend
            Event Description:
            %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow.

            For more information please see the following:
            %DENNIS275

            Scan ID: {3533E261-EA50-4BEA-AC48-037552BE9E79}

            User: DENNIS\CATANYAG

            Name: %DENNIS271

            ID: %DENNIS272

            Severity: 1.1.1593.05

            Category: 1.1.1593.06

            Path Found: %DENNIS276

            Alert Type: %DENNIS278

            Detection Type: 1.1.1593.02

            Event Record #/Type112439 / Warning
            Event Submitted/Written: 05/10/2008 00:48:34 AM
            Event ID/Source: 3004 / WinDefend
            Event Description:
            %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow.

            For more information please see the following:
            %DENNIS275

            Scan ID: {57941E0F-A630-4E96-A90B-88353EDE282D}

            User: DENNIS\CATANYAG

            Name: %DENNIS271

            ID: %DENNIS272

            Severity: 1.1.1593.05

            Category: 1.1.1593.06

            Path Found: %DENNIS276

            Alert Type: %DENNIS278

            Detection Type: 1.1.1593.02

            Event Record #/Type112438 / Warning
            Event Submitted/Written: 05/10/2008 00:48:34 AM
            Event ID/Source: 3004 / WinDefend
            Event Description:
            %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow.

            For more information please see the following:
            %DENNIS275

            Scan ID: {159A93A4-5612-4A73-9E97-BAABD4EA9841}

            User: DENNIS\CATANYAG

            Name: %DENNIS271

            ID: %DENNIS272

            Severity: 1.1.1593.05

            Category: 1.1.1593.06

            Path Found: %DENNIS276

            Alert Type: %DENNIS278

            Detection Type: 1.1.1593.02

            Event Record #/Type112437 / Warning
            Event Submitted/Written: 05/10/2008 00:48:31 AM
            Event ID/Source: 3004 / WinDefend
            Event Description:
            %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow.

            For more information please see the following:
            %DENNIS275

            Scan ID: {348AC47F-9B1B-4648-B5AB-15C5D248421E}

            User: DENNIS\CATANYAG

            Name: %DENNIS271

            ID: %DENNIS272

            Severity: 1.1.1593.05

            Category: 1.1.1593.06

            Path Found: %DENNIS276

            Alert Type: %DENNIS278

            Detection Type: 1.1.1593.02

            Event Record #/Type112436 / Warning
            Event Submitted/Written: 05/10/2008 00:48:31 AM
            Event ID/Source: 3004 / WinDefend
            Event Description:
            %DENNIS27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %DENNIS27 can't undo changes that you allow.

            For more information please see the following:
            %DENNIS275

            Scan ID: {DDC1C48A-EA8C-4D35-BFDE-28EB2024A503}

            User: DENNIS\CATANYAG

            Name: %DENNIS271

            ID: %DENNIS272

            Severity: 1.1.1593.05

            Category: 1.1.1593.06

            Path Found: %DENNIS276

            Alert Type: %DENNIS278

            Detection Type: 1.1.1593.02



            -- End of Deckard's System Scanner: finished at 2008-05-10 00:49:27 ------------

            The current version of Java is Java(TM) 6 Update 6 and you can get it HERE

            Go to add/remove programs and uninstall

            J2SE Runtime Environment 5.0 Update 3
            Java(TM) 6 Update 5
            Viewpoint Media Player

            ----------

            Try running StartUpLite to get rid of the un-necessary startups.

            ----------

            Is Norton up to date? Is is a paid version or has the subscription run out?

            Quote
            AV: Norton AntiVirus 2005 v2005 (Symantec Corporation) Outdated
            Okay, got rid of the 3 things from Add/Remove (strangely enough, the download of Java I got was from Java's website...and it was 6.5).

            Downloaded the new Java.

            Ran the startup cleaner.

            The Norton is EXTREMELY outdated and not paid for.OK we need to get you some current protection.

            First download these programs, don't install them yet.

            Antivurus: Pick only one. I will list multiple but if you want my personal preference it is Avast.
            Avast - http://www.filehippo.com/download_avast_antivirus/
            AVG - http://www.filehippo.com/download_avg_antivirus/
            AntiVir - http://www.filehippo.com/download_antivir/

            Firewall: Be sure to choose Advanced Mode when installing.
            http://www.filehippo.com/download_comodo/

            After they are downloaded don't connect to the internet until you have Norton uninstalled and the new protection installed.

            Download the Norton Removal Tool

            Go to add remove programs and uninstall anything with Norton, Live Update or Symantec in the name.

            Now run the Norton Removal Tool

            Install the new AV and Firewall then run a full scan with the new AV.

            Let me know how everything is now.
            3065.

            Solve : HijackThis log for a win32/vundo!generic problum?

            Answer»

            if someone could please help

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 9:10:14 PM, on 5/10/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\WLTRYSVC.EXE
            C:\WINDOWS\System32\bcmwltry.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
            C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Yahoo!\Antivirus\ISafe.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Viewpoint\Common\ViewpointService.exe
            C:\WINDOWS\system32\Tablet.exe
            C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\system32\WTablet\TabUserW.exe
            C:\WINDOWS\system32\Tablet.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\WINDOWS\system32\WLTRAY.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
            C:\WINDOWS\system32\igfxsrvc.exe
            C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
            C:\PROGRA~1\Yahoo!\YOP\yop.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
            C:\WINDOWS\stsystra.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
            C:\WINDOWS\mrofinu1535.exe
            C:\program files\steam\steam.exe
            C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
            C:\Program Files\Logitech\SetPoint\SetPoint.exe
            C:\Program Files\WINZIP\WZQKPICK.EXE
            C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
            C:\PROGRA~1\Yahoo!\browser\ycommon.exe
            C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\AIM\aim.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
            C:\Program Files\Svconr\Svconr.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\b155.exe
            C:\Program Files\JavaCore\JavaCore.exe
            C:\Program Files\InetGet2\sacatapo821058.exe
            C:\Program Files\Opera\Opera.exe
            C:\Documents and Settings\Jeff Hansen\My Documents\HiJackThis.exe
            C:\Program Files\Mozilla Firefox\firefox.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://enascor.com/search/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
            O2 - BHO: testCPV6 - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\Spcron\Spcron.dll
            O2 - BHO: (no name) - {2E1550C1-DB0B-4B2D-B338-CA5DCF368E13} - C:\WINDOWS\system32\pwlosnmw.dll (file missing)
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
            O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\ugmupocq.dll (file missing)
            O2 - BHO: (no name) - {E93121AD-7C67-417A-A6A5-87C60214AC80} - C:\WINDOWS\system32\pmnlm.dll (file missing)
            O2 - BHO: (no name) - {F7F6584C-864B-411D-A410-BB2DE0D33CA1} - C:\WINDOWS\system32\nnnmjgHy.dll
            O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
            O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
            O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
            O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
            O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1535.exe 61A847B5BBF7281337983D466188719AB689201 522886B092CBD44BD8689220221DD3257
            O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
            O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
            O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
            O4 - HKCU\..\Run: [JavaCore] C:\Program Files\\JavaCore\\JavaCore.exe
            O4 - HKCU\..\Run: [QdrPack15] "C:\Program Files\QdrPack\QdrPack15.exe"
            O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
            O4 - Startup: Microsoft Office Shortcut Bar.Lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
            O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
            O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures05.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
            O20 - Winlogon Notify: nnnmjgHy - C:\WINDOWS\SYSTEM32\nnnmjgHy.dll
            O20 - Winlogon Notify: pmnlm - C:\WINDOWS\system32\pmnlm.dll (file missing)
            O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
            O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
            O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
            O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
            O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
            O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
            O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

            --
            End of file - 9893 bytesWelcome to CH

            Please download Combofix by sUBs from one of the below links.
            (Try all three if necessary)

            Important! Combofix.exe MUST be saved to and ran from the Desktop.
            • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
            • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
              • Click this link to see a list of security programs that should be disabled and how to disable them.
              • If yours is not listed and you don't know how to disable it, please ask.
            • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
            • Double click combofix.exe & follow the prompts.
              • Choose Yes to accept the Disclaimers.[
              • When finished, it will produce a log for you.
              • Post that log in your next reply.
              Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
              • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
              • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
              ComboFix 08-05-09.1 - Jeff Hansen 2008-05-10 21:26:51.1 - NTFSx86
              Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT -4:00]
              Running from: C:\Documents and Settings\Jeff Hansen\Desktop\ComboFix.exe
              * Created a new restore point

              WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
              .

              ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              C:\Documents and Settings\Guest\err.log
              C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\#SharedObjects\JLWWAZY2\www.broadcaster.com
              C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
              C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
              C:\Documents and Settings\Jeff Hansen\err.log
              C:\Documents and Settings\Jeff Hansen\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
              C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\bestwiner.stt
              C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\CPV.stt
              C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor
              C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
              C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
              C:\Program Files\Common Files\{34F43~1
              C:\Program Files\Common Files\{34F43~1\Uninstall.exe
              C:\Program Files\Common Files\{34F43~2
              C:\Program Files\Common Files\{C4F43~1
              C:\Program Files\CPV
              C:\Program Files\inetget2
              C:\Program Files\inetget2\sacatapo821058.exe
              C:\Program Files\ISM
              C:\Program Files\ISM\ism.exe
              C:\Program Files\ISM\Uninstall.exe
              C:\Program Files\JavaCore
              C:\Program Files\JavaCore\JavaCore.exe
              C:\Program Files\JavaCore\UnInstall.exe
              C:\Program Files\QdrDrive
              C:\Program Files\QdrDrive\qdrloader.exe
              C:\Program Files\QdrPack
              C:\Program Files\QdrPack\QdrPack15.exe
              C:\Program Files\Temporary
              C:\WA6P
              C:\WINDOWS\b104.exe
              C:\WINDOWS\b148.exe
              C:\WINDOWS\b149.exe
              C:\WINDOWS\b152.exe
              C:\WINDOWS\b155.exe
              C:\WINDOWS\b156.exe
              C:\WINDOWS\b999.exe
              C:\WINDOWS\mrofinu1535.exe
              C:\WINDOWS\system32\components
              C:\WINDOWS\system32\dgjlm.ini2
              C:\WINDOWS\system32\dgjlm.tmp
              C:\WINDOWS\system32\iyspawlq.ini
              C:\WINDOWS\system32\mcrh.tmp
              C:\WINDOWS\system32\mevrkpsw.ini
              C:\WINDOWS\system32\mlnmp.bak1
              C:\WINDOWS\system32\mlnmp.bak2
              C:\WINDOWS\system32\mlnmp.ini
              C:\WINDOWS\system32\mlnmp.ini2
              C:\WINDOWS\system32\mlnmp.tmp
              C:\WINDOWS\system32\nnnmjgHy.dll

              .
              ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Legacy_COM+_MESSAGES


              ((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
              .

              2008-05-10 12:55 . 2008-05-10 12:55d--------C:\Program Files\Spcron
              2008-05-10 12:50 . 2008-05-10 12:50d--------C:\Program Files\Svconr
              2008-05-09 22:31 . 2008-05-09 22:32d--------C:\Documents and Settings\Jeff Hansen\.limewire
              2008-05-09 19:22 . 2008-05-09 19:22d--------C:\Documents and Settings\Jeff Hansen\Application Data\Lavasoft
              2008-05-09 12:40 . 2008-02-12 14:4548--a------C:\Documents and Settings\Jeff Hansen\readme.bat
              2008-05-09 10:45 . 2008-05-09 10:45d--------C:\Program Files\Common Files\Macromedia Shared

              .
              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2008-05-11 01:39---------d-----wC:\Program Files\Steam
              2008-05-11 01:38---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\WTablet
              2008-05-11 01:37---------d-----wC:\Documents and Settings\LocalService\Application Data\WTablet
              2008-05-08 21:33---------d-----wC:\Program Files\Common Files\Adobe
              2008-05-08 21:27---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\AdobeUM
              2008-03-26 21:40---------d-----wC:\Program Files\LimeWire
              2008-03-26 17:45---------d-----wC:\Program Files\Kate's Video Converter
              2008-02-10 03:2115----a-wC:\Documents and Settings\Jeff Hansen\StopWZC.bat
              2008-02-10 03:2016----a-wC:\Documents and Settings\Jeff Hansen\StartWZC.bat
              2008-01-09 21:20251----a-wC:\Program Files\wt3d.ini
              2007-03-23 14:39382----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1942.dat
              2007-03-23 14:3869,632----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4827.dat
              2007-03-23 14:38151----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb292.dat
              2007-03-23 14:380----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb2391.dat
              2006-11-30 03:4249----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb41.dat
              2006-11-29 15:466,144----a-wC:\Documents and Settings\Guest\Application Data\internaldb1362.dat
              2006-11-22 06:520----a-wC:\Program Files\Common Files\err.log
              2006-11-18 17:080----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb5436.dat
              2006-11-16 20:079,216----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb9040.dat
              2006-11-16 20:070----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1912.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4604.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb3902.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb153.dat
              2006-11-04 21:037,048----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin
              2007-12-06 23:1088--sh--rC:\WINDOWS\system32\41457874FA.sys
              2007-09-10 18:0756--sh--rC:\WINDOWS\system32\FA74784541.sys
              2007-12-06 23:106,580--sha-wC:\WINDOWS\system32\KGyGaAvL.sys
              .

              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* empty entries & legit default entries are not shown
              REGEDIT4

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}]
              C:\WINDOWS\system32\pwlosnmw.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}]
              2008-02-07 21:07217088--a------C:\Program Files\Messenger\kywokelyt821058.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}]
              C:\WINDOWS\system32\pmnlm.dll

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
              "Steam"="c:\program files\steam\steam.exe" [2008-04-01 19:03 1271032]
              "Svconr"="C:\Program Files\Svconr\Svconr.exe" [2008-05-10 12:50 57344]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 17:44 98304]
              "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41 77824]
              "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45 118784]
              "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08 1347584]
              "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 12:56 761947]
              "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
              "CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-03-23 14:31 230512]
              "CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-03-23 14:31 185456]
              "YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43 407032]
              "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 19:15 180269]
              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
              "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
              "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
              "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
              "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
              "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-16 02:37 57344]

              C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Startup\
              LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2005-03-09 15:57:14 81920]
              Microsoft Office Shortcut Bar.Lnk [2007-04-02 15:06:31 761]

              C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
              Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
              Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-25 09:30:07 784912]
              WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-26 23:45:57 106560]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
              "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
              "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
              c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
              C:\WINDOWS\system32\pmnlm.dll

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
              @=""

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
              "DisableMonitoring"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "C:\\Program Files\\America Online 9.0\\waol.exe"=
              "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
              "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
              "C:\\Program Files\\LimeWire\\LimeWire.exe"=
              "C:\\WINDOWS\\system32\\sessmgr.exe"=
              "C:\\Program Files\\Messenger\\msmsgs.exe"=
              "C:\\StubInstaller.exe"=
              "C:\\Program Files\\Opera\\Opera.exe"=
              "C:\\Program Files\\AIM\\aim.exe"=
              "C:\\Program Files\\iTunes\\iTunes.exe"=
              "C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
              "C:\\Program Files\\Steam\\SteamApps\\hippiegothie\\team fortress 2\\hl2.exe"=

              R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
              R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 17:18]
              R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 15:55]
              S3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [2006-08-08 13:25]

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
              \Shell\AutoRun\command - E:\setup.exe

              .
              Contents of the 'Scheduled Tasks' folder
              "2008-05-05 15:24:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
              - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
              "2008-05-11 01:37:22 C:\WINDOWS\Tasks\Winter Fun Wallpaper Changer.job"
              - C:\Documents and Settings\All Users\Start Menu\Programs\Winter Fun Pack 2004 for Windows XP\Winter Fun Wallpaper Changer.lnk
              .
              **************************************************************************

              catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-05-10 21:39:09
              Windows 5.1.2600 Service Pack 2 NTFS

              scanning hidden processes ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden files: 0

              **************************************************************************
              .
              ------------------------ Other Running Processes ------------------------
              .
              C:\WINDOWS\system32\WLTRYSVC.EXE
              C:\WINDOWS\system32\BCMWLTRY.EXE
              C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
              C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Yahoo!\Antivirus\iSafe.exe
              C:\WINDOWS\ehome\ehrecvr.exe
              C:\WINDOWS\ehome\ehSched.exe
              C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\WINDOWS\system32\Tablet.exe
              C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
              C:\WINDOWS\system32\WTablet\TabUserW.exe
              C:\WINDOWS\system32\Tablet.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\system32\igfxsrvc.exe
              C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
              C:\PROGRA~1\Yahoo!\browser\ycommon.exe
              C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
              .
              **************************************************************************
              .
              Completion time: 2008-05-10 21:45:36 - machine was rebooted
              ComboFix-quarantined-files.txt 2008-05-11 01:45:30

              Pre-Run: 10,848,620,544 bytes free
              Post-Run: 10,703,892,480 bytes free

              220--- E O F ---2008-04-11 07:09:05Delete these files/folders, as follows:

              1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
              It must be Notepad, not Wordpad.
              • Click Start , then Run
              • Type notepad.exe in the Run Box.
              2. Copy the TEXT in the below code box by highlighting all the text and pressing Ctrl+C

              Code: [Select]KillAll::

              Folder::
              C:\Program Files\Spcron
              C:\Program Files\Svconr

              REGISTRY::
              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}]
              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}]
              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}]
              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Svconr"=-
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
              3. Go to the Notepad window and click Edit > Paste
              4. Then click File > Save
              5. Name the file CFScript.txt - Save the file to your Desktop
              6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



              ComboFix will begin to execute, just follow the prompts.
              After reboot (in case it asks to reboot), it will produce a log for you.
              Post that log (Combofix.txt) in your next reply.

              Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze

              ----------

              Create An Uninstall List
              • Start HijackThis
              • Click on the Open the Misc Tools section
              • Click on the Open Uninstall Manager button.
              • Click on the Save list button and specify where you would like to save this file and click Save.
                • When you press Save button a notepad will open with the contents of that file.
              • Copy and paste that list in your reply.
              .
              ----------

              Next post add (you may need to use two posts to get everything in)
              New Combofix log
              Uninstall list


              Let me know how everything is now
              .ComboFix 08-05-09.1 - Jeff Hansen 2008-05-10 22:18:40.2 - NTFSx86
              Running from: C:\Documents and Settings\Jeff Hansen\Desktop\ComboFix.exe
              Command switches used :: C:\Documents and Settings\Jeff Hansen\Desktop\CFScript.txt
              * Created a new restore point

              WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
              .

              ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\bestwiner.stt
              C:\Program Files\Spcron
              C:\Program Files\Spcron\Spcron.dll
              C:\Program Files\Svconr
              C:\Program Files\Svconr\Svconr.exe

              .
              ((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
              .

              2008-05-09 22:31 . 2008-05-09 22:32d--------C:\Documents and Settings\Jeff Hansen\.limewire
              2008-05-09 19:22 . 2008-05-09 19:22d--------C:\Documents and Settings\Jeff Hansen\Application Data\Lavasoft
              2008-05-09 12:40 . 2008-02-12 14:4548--a------C:\Documents and Settings\Jeff Hansen\readme.bat
              2008-05-09 10:45 . 2008-05-09 10:45d--------C:\Program Files\Common Files\Macromedia Shared

              .
              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2008-05-11 02:26---------d-----wC:\Program Files\Steam
              2008-05-11 02:25---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\WTablet
              2008-05-11 02:24---------d-----wC:\Documents and Settings\LocalService\Application Data\WTablet
              2008-05-08 21:33---------d-----wC:\Program Files\Common Files\Adobe
              2008-05-08 21:27---------d-----wC:\Documents and Settings\Jeff Hansen\Application Data\AdobeUM
              2008-03-26 21:40---------d-----wC:\Program Files\LimeWire
              2008-03-26 17:45---------d-----wC:\Program Files\Kate's Video Converter
              2008-03-19 09:471,845,248----a-wC:\WINDOWS\system32\win32k.sys
              2008-03-19 09:471,845,248------wC:\WINDOWS\system32\dllcache\win32k.sys
              2008-03-10 13:4632,768----a-wC:\WINDOWS\system32\~GLH0003.TMP
              2008-02-20 06:51282,624----a-wC:\WINDOWS\system32\gdi32.dll
              2008-02-20 06:51282,624------wC:\WINDOWS\system32\dllcache\gdi32.dll
              2008-02-20 05:3245,568----a-wC:\WINDOWS\system32\dnsrslvr.dll
              2008-02-20 05:3245,568------wC:\WINDOWS\system32\dllcache\dnsrslvr.dll
              2008-02-20 05:32148,992------wC:\WINDOWS\system32\dllcache\dnsapi.dll
              2008-02-15 09:0718,432------wC:\WINDOWS\system32\dllcache\iedw.exe
              2008-02-10 03:2115----a-wC:\Documents and Settings\Jeff Hansen\StopWZC.bat
              2008-02-10 03:2016----a-wC:\Documents and Settings\Jeff Hansen\StartWZC.bat
              2008-01-09 21:20251----a-wC:\Program Files\wt3d.ini
              2007-03-23 14:39382----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1942.dat
              2007-03-23 14:3869,632----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4827.dat
              2007-03-23 14:38151----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb292.dat
              2007-03-23 14:380----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb2391.dat
              2006-11-30 03:4249----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb41.dat
              2006-11-29 15:466,144----a-wC:\Documents and Settings\Guest\Application Data\internaldb1362.dat
              2006-11-22 06:520----a-wC:\Program Files\Common Files\err.log
              2006-11-18 17:080----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb5436.dat
              2006-11-16 20:079,216----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb9040.dat
              2006-11-16 20:070----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb1912.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb4604.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb3902.dat
              2006-11-16 04:570----a-wC:\Documents and Settings\Jeff Hansen\Application Data\internaldb153.dat
              2006-11-04 21:037,048----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin
              2007-12-06 23:1088--sh--rC:\WINDOWS\system32\41457874FA.sys
              2007-09-10 18:0756--sh--rC:\WINDOWS\system32\FA74784541.sys
              2007-12-06 23:106,580--sha-wC:\WINDOWS\system32\KGyGaAvL.sys
              .

              ((((((((((((((((((((((((((((( [emailprotected]_21.45.14.05 )))))))))))))))))))))))))))))))))))))))))
              .
              - 2008-05-11 01:37:182,048--s-a-wC:\WINDOWS\bootstat.dat
              + 2008-05-11 02:24:272,048--s-a-wC:\WINDOWS\bootstat.dat
              .
              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* empty entries & legit default entries are not shown
              REGEDIT4

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}]
              C:\WINDOWS\system32\pwlosnmw.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}]
              2008-02-07 21:07217088--a------C:\Program Files\Messenger\kywokelyt821058.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}]
              C:\WINDOWS\system32\pmnlm.dll

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
              "Steam"="c:\program files\steam\steam.exe" [2008-04-01 19:03 1271032]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 17:44 98304]
              "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41 77824]
              "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45 118784]
              "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08 1347584]
              "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 12:56 761947]
              "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
              "CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-03-23 14:31 230512]
              "CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-03-23 14:31 185456]
              "YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43 407032]
              "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 19:15 180269]
              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
              "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
              "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
              "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
              "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
              "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-16 02:37 57344]

              C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Startup\
              LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2005-03-09 15:57:14 81920]
              Microsoft Office Shortcut Bar.Lnk [2007-04-02 15:06:31 761]

              C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
              Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
              Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-25 09:30:07 784912]
              WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-26 23:45:57 106560]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
              "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
              "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
              c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
              C:\WINDOWS\system32\pmnlm.dll

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
              @=""

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
              "DisableMonitoring"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "C:\\Program Files\\America Online 9.0\\waol.exe"=
              "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
              "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
              "C:\\Program Files\\LimeWire\\LimeWire.exe"=
              "C:\\WINDOWS\\system32\\sessmgr.exe"=
              "C:\\Program Files\\Messenger\\msmsgs.exe"=
              "C:\\StubInstaller.exe"=
              "C:\\Program Files\\Opera\\Opera.exe"=
              "C:\\Program Files\\AIM\\aim.exe"=
              "C:\\Program Files\\iTunes\\iTunes.exe"=
              "C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
              "C:\\Program Files\\Steam\\SteamApps\\hippiegothie\\team fortress 2\\hl2.exe"=

              R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
              R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 17:18]
              R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 15:55]
              S3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [2006-08-08 13:25]

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
              \Shell\AutoRun\command - E:\setup.exe

              .
              Contents of the 'Scheduled Tasks' folder
              "2008-05-05 15:24:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
              - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
              "2008-05-11 02:24:33 C:\WINDOWS\Tasks\Winter Fun Wallpaper Changer.job"
              - C:\Documents and Settings\All Users\Start Menu\Programs\Winter Fun Pack 2004 for Windows XP\Winter Fun Wallpaper Changer.lnk
              .
              **************************************************************************

              catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-05-10 22:26:55
              Windows 5.1.2600 Service Pack 2 NTFS

              scanning hidden processes ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden files: 0

              **************************************************************************
              .
              ------------------------ Other Running Processes ------------------------
              .
              C:\WINDOWS\system32\WLTRYSVC.EXE
              C:\WINDOWS\system32\BCMWLTRY.EXE
              C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
              C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Yahoo!\Antivirus\iSafe.exe
              C:\WINDOWS\ehome\ehrecvr.exe
              C:\WINDOWS\ehome\ehSched.exe
              C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\WINDOWS\system32\Tablet.exe
              C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\system32\WTablet\TabUserW.exe
              C:\WINDOWS\system32\Tablet.exe
              C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
              C:\WINDOWS\system32\igfxsrvc.exe
              C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
              C:\PROGRA~1\Yahoo!\browser\ycommon.exe
              C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
              .
              **************************************************************************
              .
              Completion time: 2008-05-10 22:35:20 - machine was rebooted
              ComboFix-quarantined-files.txt 2008-05-11 02:34:55
              ComboFix2.txt 2008-05-11 01:45:37

              Pre-Run: 10,695,467,008 bytes free
              Post-Run: 12,507,443,200 bytes free

              183--- E O F ---2008-04-11 07:09:05uninstall list


              Ad-Aware SE Personal
              Adobe Flash Player 9 ActiveX
              Adobe Flash Player Plugin
              Adobe Help Center 2.0
              Adobe Photoshop Elements 4.0
              Adobe Reader 7.1.0
              Adobe Shockwave Player
              AIM "You've Got Pictures" Picture Finder Plugin v9.5.1.8
              AOL Coach Version 1.0(Build:20040229.1 en)
              AOL Connectivity Services
              AOL Instant Messenger
              AOL Uninstaller (Choose which Products to Remove)
              Apple Mobile Device Support
              Apple Software Update
              AT&T Yahoo! Applications
              Audacity 1.2.5
              Broadcom Management Programs
              CDDRV_Installer
              Conexant HDA D110 MDC V.92 Modem
              Corel Painter Essentials 3
              CursorXP
              Dell Digital Jukebox Driver
              Dell Support 3.1
              Dell Wireless WLAN Card
              DellConnect
              Digital Content Portal
              Digital Line Detect
              DivX Codec
              DivX Content Uploader
              DivX Converter
              DivX Player
              DivX Web Player
              Documentation & Support Launcher
              EducateU
              ESPNMotion
              Games, Music, & Photos Launcher
              GemMaster Mystic
              Half-Life 2
              High Definition Audio Driver Package - KB835221
              HijackThis 2.0.2
              Hotfix for Windows Media Format 11 SDK (KB929399)
              Hotfix for Windows Media Player 10 (KB903157)
              Hotfix for Windows Media Player 11 (KB939683)
              Hotfix for Windows XP (KB888795)
              Hotfix for Windows XP (KB891593)
              Hotfix for Windows XP (KB895961)
              Hotfix for Windows XP (KB899337)
              Hotfix for Windows XP (KB899510)
              Hotfix for Windows XP (KB902841)
              Hotfix for Windows XP (KB926239)
              HyperCam 2
              Intel(R) Graphics Media Accelerator Driver
              Internal Network Card Power Management
              Internet Service Offers Launcher
              iPod for Windows 2006-03-23
              iTunes
              J2SE Runtime Environment 5.0 Update 1
              J2SE Runtime Environment 5.0 Update 3
              Java 2 Runtime Environment, SE v1.4.2_03
              Java(TM) SE Runtime Environment 6 Update 1
              KhalInstallWrapper
              Learn2 Player (Uninstall Only)
              LimeWire PRO 4.8.1
              Logitech SetPoint
              Macromedia Flash 5
              MCU
              Microsoft .NET Framework 1.0 Hotfix (KB887998)
              Microsoft .NET Framework 1.0 Hotfix (KB930494)
              Microsoft .NET Framework 1.1
              Microsoft .NET Framework 1.1
              Microsoft .NET Framework 1.1 Hotfix (KB928366)
              Microsoft .NET Framework 2.0 Service Pack 1
              Microsoft Compression Client Pack 1.0 for Windows XP
              Microsoft GIF Animator
              Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
              Microsoft Office 97, Professional Edition
              Microsoft Plus! Digital Media Edition Installer
              Microsoft Plus! Photo Story 2 LE
              Microsoft User-Mode Driver Framework Feature Pack 1.0
              Microsoft Visual C++ 2005 Redistributable
              Modem Helper
              Mozilla Firefox (2.0.0.14)
              MSXML 4.0 SP2 (KB927978)
              MSXML 4.0 SP2 (KB936181)
              MSXML 4.0 SP2 Parser and SDK
              NetWaiting
              NetZeroInstallers
              nik COLOR Efex Pro 2.0 IE
              Opera 9.24
              Otto
              Peggle Deluxe
              Peggle Extreme
              Picasa 2
              Portal
              PowerDVD 5.7
              QuickSet
              QuickTime
              RealPlayer
              RealWorld Cursor Editor
              Safety Alert 2006
              Safety Bar
              Saitek SST Programming Software
              Search Enhancer
              Security Update for Windows Media Player (KB911564)
              Security Update for Windows Media Player 10 (KB911565)
              Security Update for Windows Media Player 11 (KB936782)
              Security Update for Windows Media Player 6.4 (KB925398)
              Security Update for Windows XP (KB890046)
              Security Update for Windows XP (KB893756)
              Security Update for Windows XP (KB896428)
              Security Update for Windows XP (KB899587)
              Security Update for Windows XP (KB899589)
              Security Update for Windows XP (KB900725)
              Security Update for Windows XP (KB901017)
              Security Update for Windows XP (KB902400)
              Security Update for Windows XP (KB905414)
              Security Update for Windows XP (KB905749)
              Security Update for Windows XP (KB911562)
              Security Update for Windows XP (KB911567)
              Security Update for Windows XP (KB911927)
              Security Update for Windows XP (KB913580)
              Security Update for Windows XP (KB914388)
              Security Update for Windows XP (KB914389)
              Security Update for Windows XP (KB917344)
              Security Update for Windows XP (KB917422)
              Security Update for Windows XP (KB917953)
              Security Update for Windows XP (KB918118)
              Security Update for Windows XP (KB918439)
              Security Update for Windows XP (KB918899)
              Security Update for Windows XP (KB919007)
              Security Update for Windows XP (KB920213)
              Security Update for Windows XP (KB920214)
              Security Update for Windows XP (KB920670)
              Security Update for Windows XP (KB920683)
              Security Update for Windows XP (KB920685)
              Security Update for Windows XP (KB921398)
              Security Update for Windows XP (KB921503)
              Security Update for Windows XP (KB921883)
              Security Update for Windows XP (KB922616)
              Security Update for Windows XP (KB922760)
              Security Update for Windows XP (KB922819)
              Security Update for Windows XP (KB923191)
              Security Update for Windows XP (KB923414)
              Security Update for Windows XP (KB923694)
              Security Update for Windows XP (KB923980)
              Security Update for Windows XP (KB924191)
              Security Update for Windows XP (KB924270)
              Security Update for Windows XP (KB924496)
              Security Update for Windows XP (KB924667)
              Security Update for Windows XP (KB925454)
              Security Update for Windows XP (KB925486)
              Security Update for Windows XP (KB925902)
              Security Update for Windows XP (KB926255)
              Security Update for Windows XP (KB926436)
              Security Update for Windows XP (KB927779)
              Security Update for Windows XP (KB927802)
              Security Update for Windows XP (KB928090)
              Security Update for Windows XP (KB928255)
              Security Update for Windows XP (KB928843)
              Security Update for Windows XP (KB929123)
              Security Update for Windows XP (KB929969)
              Security Update for Windows XP (KB930178)
              Security Update for Windows XP (KB931261)
              Security Update for Windows XP (KB931768)
              Security Update for Windows XP (KB931784)
              Security Update for Windows XP (KB932168)
              Security Update for Windows XP (KB933566)
              Security Update for Windows XP (KB933729)
              Security Update for Windows XP (KB935839)
              Security Update for Windows XP (KB935840)
              Security Update for Windows XP (KB936021)
              Security Update for Windows XP (KB937143)
              Security Update for Windows XP (KB937894)
              Security Update for Windows XP (KB938127)
              Security Update for Windows XP (KB938829)
              Security Update for Windows XP (KB939653)
              Security Update for Windows XP (KB941202)
              Security Update for Windows XP (KB941568)
              Security Update for Windows XP (KB941569)
              Security Update for Windows XP (KB941644)
              Security Update for Windows XP (KB941693)
              Security Update for Windows XP (KB942615)
              Security Update for Windows XP (KB943055)
              Security Update for Windows XP (KB943460)
              Security Update for Windows XP (KB943485)
              Security Update for Windows XP (KB944338)
              Security Update for Windows XP (KB944533)
              Security Update for Windows XP (KB944653)
              Security Update for Windows XP (KB945553)
              Security Update for Windows XP (KB946026)
              Security Update for Windows XP (KB947864)
              Security Update for Windows XP (KB948590)
              Security Update for Windows XP (KB948881)
              SigmaTel Audio
              Sonic DLA
              Sonic Encoders
              Sonic RecordNow Audio
              Sonic RecordNow Copy
              Sonic RecordNow Data
              Sonic Update Manager
              Spybot - Search & Destroy 1.4
              Steam
              Synaptics Pointing Device Driver
              Tablet
              Team Fortress 2 Dedicated Server
              Update for Windows Media Player 10 (KB913800)
              Update for Windows XP (KB894391)
              Update for Windows XP (KB898461)
              Update for Windows XP (KB900485)
              Update for Windows XP (KB908531)
              Update for Windows XP (KB910437)
              Update for Windows XP (KB911280)
              Update for Windows XP (KB916595)
              Update for Windows XP (KB920872)
              Update for Windows XP (KB922582)
              Update for Windows XP (KB927891)
              Update for Windows XP (KB929338)
              Update for Windows XP (KB930916)
              Update for Windows XP (KB931836)
              Update for Windows XP (KB933360)
              Update for Windows XP (KB936357)
              Update for Windows XP (KB938828)
              Update for Windows XP (KB942763)
              Update for Windows XP (KB942840)
              Update for Windows XP (KB946627)
              Update Rollup 2 for Windows XP Media Center Edition 2005
              URGE
              Viewpoint Manager (Remove Only)
              Viewpoint Media Player
              Viewpoint Toolbar
              WebCyberCoach 3.2 Dell
              WhiteCap
              Windows Media Format 11 runtime
              Windows Media Format 11 runtime
              Windows Media Player 10
              Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
              Windows Media Player 11
              Windows Media Player 11
              Windows XP Hotfix - KB885836
              Windows XP Hotfix - KB886185
              Windows XP Hotfix - KB888302
              Windows XP Hotfix - KB890859
              Windows XP Hotfix - KB890927
              Windows XP Media Center Edition 2005 KB908246
              Windows XP Media Center Edition 2005 KB925766
              WinZip
              Xvid 1.1.2 final uninstall

              That didn't get everything I hoped it would and there was a new entry I have not seen before. We may need to run it again if the next set of instructions don't work.

              -----

              Your Java is out of date.
              Older versions of Java have VULNERABILITIES that malware can use to infect your system.
              Please follow these steps to remove older version(s) of Java components and update.

              Step 1 - Get the new version
              • Go to the Sun Java Download Page
              • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
              • Click the button and choose the options.
                • Platform Windows
                • Language English
                • Next place a check mark in the box to agree to the License Agreement.
              • "I agree to the Java SE Runtime Environment 6 License Agreement"
              • Click Continue
              • Click on the link to download Windows Offline Installation and save to your desktop.
              • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
              • Follow the prompts to complete the installation.
              Step 2 - Remove old version(s)
              • Close any programs you may have running - especially your web browser.
              • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
              • Uninstall:
              • J2SE Runtime Environment 5.0 Update 1
              • J2SE Runtime Environment 5.0 Update 3
              • Java 2 Runtime Environment, SE v1.4.2_03
              • Java(TM) SE Runtime Environment 6 Update 1
              • Do not remove Java 6 Update 6
                • Click the Remove or Change/Remove button.
                • Repeat as many times as necessary to remove each old Java version.
                • Restart your computer once all Java components are removed.
                Step 3 - Remove old folder(s)
                • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
                • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
                -----

                Go to add/remove programs and uninstall:
                Safety Alert 2006
                Safety Bar
                Search Enhancer
                Viewpoint Manager (Remove Only)
                Viewpoint Media Player
                Viewpoint Toolbar


                Please check add/remove programs to be sure these actually uninstalled. Let me know if they don't.

                ----------

                Download SDFix.exe and save it to your Desktop.

                Double click SDFix.exe and it will extract the files to %systemdrive%
                (Drive that contains the Windows Directory, typically C:\SDFix)

                Please then reboot your computer in Safe Mode by doing the following:

                • Restart your computer
                • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                • Instead of Windows loading as normal, the Advanced Options Menu should appear;
                • Select the first option, to run Windows in Safe Mode, then press Enter.
                • Choose your usual account.
                • Open the extracted SDFix folder and double click RunThis.bat to start the script.
                • Type Y to begin the cleanup process.
                • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
                • Press any Key and it will restart the PC.
                • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
                  (Report.txt will also be copied to Clipboard).
                • Finally add the contents of the Report.txt in your next post.
                ----------

                Now run a new Hijackthis scan and post that log as well.

                ----------

                Next post
                SDFix log
                New Hijackthis log


              3066.

              Solve : just a check?

              Answer»

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 13:44:50, on 12/05/2008
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
              Boot mode: Normal

              RUNNING PROCESSES:
              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\WLANExt.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Program Files\ONSPEED\onspeedcore.exe
              C:\Program Files\Google\Gmail Notifier\gnotify.exe
              C:\Windows\ehome\ehtray.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\system32\brsvc01a.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\brss01a.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Spyware Doctor\pctsAuxs.exe
              C:\Program Files\Spyware Doctor\pctsSvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Spyware Doctor\pctsTray.exe
              C:\Program Files\ONSPEED\onspeedgui.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Windows\System32\mobsync.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\3 Mobile\3 Mobile Broadband\3 Mobile Broadband.exe
              c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5405
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll
              O2 - BHO: Prefetch - {A66AA08A-9BF0-4e87-99E6-6972731D6B99} - C:\Program Files\ONSPEED\Prefetch.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
              O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
              O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
              O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
              O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\ONSPEED\gui_resource.dll/327
              O8 - Extra context menu item: Show Original Image - res://C:\Program Files\ONSPEED\gui_resource.dll/328
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
              O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2B635990-A110-48A4-BBA5-7CD9B5E59939}: NameServer = 172.31.76.69 172.31.140.69
              O17 - HKLM\System\CS1\Services\Tcpip\..\{2B635990-A110-48A4-BBA5-7CD9B5E59939}: NameServer = 172.31.76.69 172.31.140.69
              O20 - AppInit_DLLs: ,interceptor.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Windows\
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\Windows\system32\brsvc01a.exe
              O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Intel Corporation - (no file)
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
              O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

              --
              End of file - 8083 bytes
              Looks fine, just one thing.

              Your Java is out of date.
              Older versions of Java have vulnerabilities that malware can use to infect your system.
              Please follow these steps to remove older version(s) of Java components and update.

              Step 1 - Get the new version

              • Go to the Sun Java Download Page
              • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
              • Click the button and choose the options.
                • Platform Windows
                • Language English
                • Next place a check mark in the box to agree to the License Agreement.
              • "I agree to the Java SE Runtime Environment 6 License Agreement"
              • Click Continue
              • Click on the link to download Windows Offline Installation and save to your DESKTOP.
              • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
              • Follow the prompts to complete the installation.
              Step 2 - Remove old version(s)
              • Close any programs you may have running - especially your web browser.
              • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
              • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
              • Do not remove Java 6 Update 6
              • Click the Remove or Change/Remove button.
              • Repeat as many times as necessary to remove each old Java version.
              • Restart your computer once all Java components are removed.
              Step 3 - Remove old folder(s)
              • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
              • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
              Thank you for yor time and advice
              When i get to 6%of download it keeps failing any ideas?Try a different site.

              http://www.filehippo.com/download_java_runtime/thanks again found away.
              to dowload through browser and not there download manager.
              3067.

              Solve : Buffer Overrun?

              Answer»

              Open HJT, checkmark all O1 entries, click "Fix checked".
              When HJT is done, it'll rescan.
              Do you still see O1 entries now?Ok
              I did not restart between them. In fact I didn't restart at all. I hope I wasn't supposed to.

              [recovering space - attachment deleted by admin]BTW, it didn't rescan, I had to rescan. Does that make a difference?WOW! We got it! Oh, man!

              Your computer is clean!

              Very LAST cleaning step. You can do it by yourself. I need to go to bed.

              1. DOWNLOAD, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
              Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
              Run CCleaner.

              2. Turn off System RESTORE:

              - Windows XP:
              1. Click Start.
              2. Right-click the My Computer icon, and then click Properties.
              3. Click the System Restore tab.
              4. Check "Turn off System Restore".
              5. Click Apply.
              6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
              7. Click OK.
              - Windows Vista:
              1. Click Start.
              2. Right-click the Computer icon, and then click Properties.
              3. Click on System Protection under the Tasks column on the left side
              4. Click on Continue on the "User Account Control" window that POPS up
              5. Under the System Protection tab, find Available Disks
              6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
              7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
              8. Click OK

              3. Restart computer.

              4. Turn System Restore on.

              5. Let me know, how your computer is doing.
              Oh yea, the hard part's done so you take off and go to bed.

              Hey thank you very much. I too am going to bed, I'll finish this tomorrow.

              Just do that last step as a very first thing, so no other crap sets in.
              Good night

              3068.

              Solve : Spyware + some disabled processes?

              Answer»

              My computer is being hit with some REALLY annoying popups and my desktop background was changed to some ad for spyware removal. I tried to follow the instructions in the before you get started thread and I found that some of the apps listed are being blocked by the administrator, which is me but I didn't block them. Task MANAGER is also disabled.

              So here's what I've done so far:

              1. Nothing suspicious in add/remove programs

              2. CCleaner did it's thing

              3. Blocked from installing SAS

              4. Was ABLE to install and run Malwarebyte's (Log at end of post)

              5. Found I have java 6.4 but blocked from updating

              6. was able to run Hijackthis




              Could someone please tell me what I need to do to at LEAST get this mess fixed? Thanks

              [recovering space - attachment deleted by admin]Welcome to CH.

              Download SDFix.exe and save it to your Desktop.

              Double click SDFix.exe and it will extract the files to %systemdrive%
              (Drive that contains the Windows DIRECTORY, typically C:\SDFix)

              Please then reboot your computer in Safe Mode by doing the following:

              • Restart your computer
              • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
              • Instead of Windows loading as normal, the Advanced Options Menu should appear;
              • Select the first option, to run Windows in Safe Mode, then press Enter.
              • Choose your usual account.
              • Open the extracted SDFix folder and double click RunThis.bat to start the script.
              • Type Y to begin the cleanup process.
              • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
              • Press any Key and it will restart the PC.
              • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
              • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
                (Report.txt will also be copied to Clipboard).
              • Finally add the contents of the Report.txt in your next post along with a fresh Hijackthis log.
              ok

              [recovering space - attachment deleted by admin]Looks good so far. Still some work to do.

              Please download Combofix by sUBs from one of the below links.
              (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
              • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
              • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
                • Click this link to see a list of security programs that should be disabled and how to disable them.
                • If yours is not listed and you don't know how to disable it, please ask.
              • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
              • Double click combofix.exe & follow the prompts.
                • Choose Yes to accept the Disclaimers.[
                • When finished, it will produce a log for you.
                • Post that log in your next reply.
                Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
                • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
                • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
                .
                If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly. Still be sure to rename combofix as detailed above.

                Next post please add:
                Combofix log
                3069.

                Solve : Dangerous virus on your computer?

                Answer»

                The original error went away and I got a new one with yop.exe and "CAVFrm.dll not found". I repeated the AutoRuns scan and deleted yop.exe and now there are no more error messages.

                Considering that yop.exe was tied to the CA antivirus protection that missed the original VIRUSES and that I now have several better programs in place (thanks to you), I am OK DELETING yop.exe. In addition, it seems that YAHOO has changed from OFFERING CA AV to Norton since my original download.

                Thanks again for all of your help. Hard to believe this kind of help is FREE. You rock.

                No problem, glad it worked out!

                3070.

                Solve : MicroSoft Windows Malicious Software Removal tool?

                Answer»

                I just DL'd this up-date and shortly afterward I got a message stating that it had found and removed Trojan Downloader:Win32/Zlob. I can't understand how this could have got in considering all the protections I have in place. I have Avast, Windows firewall, Windows Defender, Threatfire, Spybot S&D and Spywareblaster and Ad-Aware. Could this be a case of false positives?Possible. Don't clean ANYTHING....

                Print these instructions out.

                1. Download SUPERAntiSpyware Free for Home Users:
                http://www.superantispyware.com/

                * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                * An icon will be created on your desktop. Double-click that icon to launch the program.
                * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                * Close SUPERAntiSpyware.

                Restart computer in Safe Mode.
                To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; SELECT Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                * Open SUPERAntiSpyware.
                * Under "Configuration and Preferences", click the Preferences button.
                * Click the Scanning Control tab.
                * Under Scanner Options make sure the following are checked (leave all others unchecked):
                o Close browsers before scanning.
                o SCAN for tracking cookies.
                o Terminate memory threats before quarantining.
                * Click the "Close" button to leave the control center screen.
                * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                * On the left, make sure you check C:\Fixed Drive.
                * On the right, under "Complete Scan", choose Perform Complete Scan.
                * Click "Next" to start the scan. Please be patient while it scans your computer.
                * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                * Make sure everything has a checkmark next to it and click "Next".
                * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                * If asked if you want to reboot, click "Yes".
                * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                o Click Preferences, then click the Statistics/Logs tab.
                o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                o Please copy and paste the Scan Log results in your next reply.
                * Click Close to exit the program.
                Post SUPERAntiSpyware log.

                RESTART COMPUTER!

                2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                * Double-click mbam-setup.exe and follow the prompts to install the program.
                * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                * If an update is found, it will download and install the latest version.
                * Once the program has loaded, select Perform full scan, then click Scan.
                * When the scan is complete, click OK, then Show Results to view the results.
                * Be sure that everything is checked, and click Remove Selected.
                * When completed, a log will open in Notepad.
                * Post the log back here.

                The log can also be found here:
                C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                RESTART COMPUTER!

                3. Download HijackThis:
                http://www.snapfiles.com/get/hijackthis.html
                Post HijackThis log.Too late. The aformentioned program already removed it but I'll run the other checks anyway. Be right back.Smart enough After an almost 3 hrs. scan I came up with no logs. When I re-opened the program, there were no logs showing. There were 16 items fixed. 14 were adware and tracking cookies. I'll continue on with the other scansFair enough Malwarebytes' Anti-Malware 1.12
                Database version: 755

                Scan type: Full Scan (C:\|E:\|F:\|G:\|)
                OBJECTS scanned: 113766
                Time elapsed: 31 minute(s), 47 second(s)

                Memory Processes Infected: 0
                Memory Modules Infected: 0
                Registry Keys Infected: 1
                Registry Values Infected: 0
                Registry Data Items Infected: 0
                Folders Infected: 0
                Files Infected: 6

                Memory Processes Infected:
                (No malicious items detected)

                Memory Modules Infected:
                (No malicious items detected)

                Registry Keys Infected:
                HKEY_CURRENT_USER\Software\Ares Gold (Adware.WhenUSave) -> Quarantined and deleted successfully.

                Registry Values Infected:
                (No malicious items detected)

                Registry Data Items Infected:
                (No malicious items detected)

                Folders Infected:
                (No malicious items detected)

                Files Infected:
                C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP601\A0040726.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP602\A0041031.exe (Rogue.VirusHeat) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP602\A0041032.Dll (Rogue.Multiple) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP603\A0041172.Dll (Rogue.Multiple) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{E86671B7-0B27-4F2F-B076-666F9A93935E}\RP603\A0041173.exe (Rogue.VirusHeat) -> Quarantined and deleted successfully.
                C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
                Keep going Here's the hijack log. It looks good to my inexperienced but learning eyes. I think the only ones I need to fix are # 20 and #23 Service: Ad-aware- no file

                [recovering space - attachment deleted by admin]Checkmark:
                - O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                - O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                - O23 - Service: Ad-Aware 2007 Service (aawservice) - Unknown owner - (no file)
                Click "Fix checked" button.

                Other, then that the log is clean.

                Don't forget to reset System Restore.
                Thanks, Broni. I suppose those bugs could have gotten in before I installed all the protection I now have. I guess it begs the question; is there such a thing as a clean computer?Some people come close, but there is no 100% protection.

                3071.

                Solve : Computer infected with Trojan.Win32.Blackbird (among others!) - logs attached?

                Answer»

                Heavens know what my husband clicked on to get this on his computer, but now he has the much-feared "Trojan.Win32.Blackbird" icon on his desktop, as well as what seems to be a bunch of other Trojans on his computer.

                I followed Step 1 through 6 listed in this forum to try and fix the problem (don't think it is fixed yet), and have posted the requested log files from SuperAntispyware, Malwarebytes and Hijackthis to this message.

                Any help would be appreciated. I've kicked my hubby's computer off the internet until this is resolved.

                Thanks!

                - katheryne


                [recovering space - attachment deleted by admin]Welcome to CH.

                Please download Combofix by sUBs from one of the below links.
                (Try all three if necessary)

                Important! Combofix.exe MUST be saved to and ran from the Desktop.
                • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
                • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
                  • Click this link to see a list of security programs that should be disabled and how to disable them.
                  • If yours is not listed and you don't know how to disable it, please ask.
                • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
                • Double click combofix.exe & follow the prompts.
                  • Choose Yes to accept the Disclaimers.[
                  • When finished, it will produce a log for you.
                  • Post that log in your next reply.
                  Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
                  • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
                  • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
                  If needed, see this Combofix tutorial with screenshots that will detail the downloading and running of combofix more thoroughly.

                  ----------

                  Next post add
                  Combofix log
                  Attached with this reply is the combofix log.

                  Also, now the computer is v e r y slow to start up... meaning the desktop comes up, but I can't really click on anything for a few minutes. The SuperAntiSpyware seems to be the culprit since its logo hangs on the computer... possibly not though. Causality vs correlation and all that. It could just be the complete FUBARedness (inventing a word here) of the computer.

                  Thank you, thank you, thank you, for your help.

                  - katheryne




                  [recovering space - attachment deleted by admin]After we get all of the malware gone lets see if things get back to normal.


                  Delete these files/folders, as follows:

                  1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
                  It must be Notepad, not Wordpad.
                  • Click Start , then Run
                  • Type notepad.exe in the Run Box.
                  2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

                  Code: [Select]KillAll::

                  Folder::
                  C:\Documents and Settings\All Users\Application DATA\wrefyhov

                  Registry::
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  "{BB324F49-82D8-4778-9E25-267724F65061}"=-
                  [HKEY_CLASSES_ROOT\clsid\{bb324f49-82d8-4778-9e25-267724f65061}]
                  [HKEY_CLASSES_ROOT\mkrndofl.1]
                  [HKEY_CLASSES_ROOT\TypeLib\{F0F2A7EE-1699-40E7-934F-03C3A3F8F42D}]
                  [HKEY_CLASSES_ROOT\mkrndofl]
                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
                  "mbJotgwLG7"=-
                  3. Go to the Notepad window and click Edit > Paste
                  4. Then click File > Save
                  5. Name the file CFScript.txt - Save the file to your Desktop
                  6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



                  ComboFix will begin to execute, just follow the prompts.
                  After reboot (in case it asks to reboot), it will produce a log for you.
                  Post that log (Combofix.txt) in your next reply.

                  Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze

                  ----------

                  Download and install CleanUp!.exe

                  Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
                  Set the program up as follows:
                  • Click Options...
                  • Move the arrow to Standard CleanUp!
                  • Uncheck the following: (if checked)
                    • Delete Newsgroup cache
                    • Delete Newsgroup Subscriptions
                  • Click OK
                  Click the CleanUp! button to start the program. Reboot/logoff when prompted.

                  Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!
                  If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility


                  ----------

                  Next post add
                  Combofix log


                  Let me know how everything is now.Hi there,
                  Attached is the most recent ComboFix log.
                  - katheryne


                  [recovering space - attachment deleted by admin]Looks much better as far as the malware is concerned. Now lets work on the performance issues.

                  I see indications of 3 antivirus software installed. Do you primarily use AVG?

                  Create An Uninstall List
                  • Start HijackThis
                  • Click on the Open the Misc Tools section
                  • Click on the Open Uninstall Manager button.
                  • Click on the Save list button and specify where you would like to save this file and click Save.
                    • When you press Save button a notepad will open with the contents of that file.
                  • Copy and paste that list in your reply.
                  .
                  Also let me know how things are now.

                  To be almost certain that youve nuked the Virus you should create a restore point first then back up your data and do a complete Reinsall of your whole Operating System by FIRSTLY Re formatting your whole hardrive...this is just so that you dont leave any backdoor connections open to this Trojan/Virus. This is a security must seeing that any data or passwords typed via the interent can still possibly be logged and sent to the hacker. Are you saying we don't know what we are doing?

                  Quote
                  If you receive advice from someone other than the approved Malware Removal Specialists, you do so at your own risk. We are not responsible if you take potentially inaccurate/harmful advice from someone who is not a designated helper.

                  Guidlines

                  Jackimo, while a clean install is always the only way to be 100% sure no infection is left, we use tools that analyze every file on a PC to determine if it is clean. Users can be confident in the advice we give. A reinstall isn't necessary in 99.99% of the infected PCs we see. Nor is it as practical as it sounds.
                  excuse me, but I also have fallen VICTIM to this same situation.

                  and though I have searched the forums and followed advice given to others on the blackbird thing, I don't think my laptop is completely clean and was wondering if you could help me?

                  I downloaded everything that katheryne was advised to use and can post the logs for any of them if you'd like me too.

                  right now though, my laptop cannot access the internet, and I know for a fact that it is my laptop and not the internet connection itself. also, I have recently downloaded AVG but cannot update it because of that. neither my laptop's wired nor wireless internet work and simply end up as limited or no connection.

                  I'd really appreciate the help and thank you in advanced.

                  also, I cannot access system restore at all.Please start a new topic and post the logs there.Hi again,

                  Here is the uninstall list from HijackThis. I'm really wondering if the problem with the EXTREMELY slow initial response time of the computer is SuperAntiSpyware. It seems like the program is trying to update. But when I click on "install new updates", it does not find any. When I exit the program, the computer seems to snap out of its lethargy.

                  Possibly a re-install of SuperAntiSpyware would work? Do I really need to run SuperAntiSpyware in the background anyway if I have AVG installed? (Would either of those programs, btw, have found this trojan and warned me?)

                  I'd be perfectly happy to run just one anti-virus program. Whatever you'd recommend would be fine with me.

                  - katheryne


                  Adobe Flash Player ActiveX
                  Adobe Reader 7.0.8
                  AOLIcon
                  Apple Mobile Device Support
                  Apple Software Update
                  AVG Free 8.0
                  Blue's 123 Time Activities
                  CCleaner (remove only)
                  CleanUp!
                  Conexant D850 56K V.9x DFVc Modem
                  Corel Photo Album 6
                  Dell CinePlayer
                  Dell Digital Jukebox Driver
                  Dell Driver Reset Tool
                  Dell Game Console
                  Dell Support 3.1
                  Digital Content Portal
                  Digital Line Detect
                  DivX Content Uploader
                  DivX Web Player
                  Documentation & Support Launcher
                  EarthLink setup files
                  EducateU
                  ELIcon
                  Games, Music, & Photos Launcher
                  Google Toolbar for Internet Explorer
                  HijackThis 2.0.2
                  Hotfix for Windows Internet Explorer 7 (KB947864)
                  Hotfix for Windows Media Format 11 SDK (KB929399)
                  Hotfix for Windows Media Format SDK (KB902344)
                  Hotfix for Windows Media Format SDK (KB910998)
                  Hotfix for Windows Media Player 11 (KB939683)
                  Hotfix for Windows XP (KB914440)
                  Hotfix for Windows XP (KB915865)
                  Hotfix for Windows XP (KB926239)
                  HP Care Pack Core
                  HP LaserJet P2015 Series 1.0
                  HP Update
                  Intel(R) Extreme Graphics 2 Driver
                  Intel(R) PRO Network Adapters and Drivers
                  Intel(R) PROSet for Wired Connections
                  iTunes
                  J2SE Runtime Environment 5.0 Update 6
                  Java DB 10.3.1.4
                  Java(TM) 6 Update 6
                  Java(TM) SE Development Kit 6 Update 6
                  LiveReg (Symantec Corporation)
                  LiveUpdate 2.6 (Symantec Corporation)
                  Malwarebytes' Anti-Malware
                  MCU
                  Microsoft .NET Framework 1.1
                  Microsoft .NET Framework 1.1
                  Microsoft .NET Framework 1.1 Hotfix (KB928366)
                  Microsoft Compression Client Pack 1.0 for Windows XP
                  Microsoft Internationalized Domain Names Mitigation APIs
                  Microsoft National Language Support Downlevel APIs
                  Microsoft Office Outlook 2003 with Business Contact Manager Update
                  Microsoft Office Professional Edition 2003
                  Microsoft Office Small Business Edition 2003
                  Microsoft Plus! Digital Media Edition Installer
                  Microsoft Plus! Photo Story 2 LE
                  Microsoft User-Mode Driver Framework Feature Pack 1.0
                  Microsoft Visual C++ 2005 Redistributable
                  Microsoft Works
                  Modem Helper
                  Mozilla Firefox (2.0.0.14)
                  MSXML 4.0 SP2 (KB927978)
                  MSXML 4.0 SP2 (KB936181)
                  My Sirius Studio
                  NetWaiting
                  NetZeroInstallers
                  Norton Ghost 10.0
                  PCFriendly
                  QuickTime
                  RealPlayer
                  Roxio DLA
                  Roxio RecordNow Audio
                  Roxio RecordNow Copy
                  Roxio RecordNow Data
                  Safari
                  SearchAssist
                  Security Update for Step By Step Interactive Training (KB898458)
                  Security Update for Step By Step Interactive Training (KB923723)
                  Security Update for Windows Internet Explorer 7 (KB928090)
                  Security Update for Windows Internet Explorer 7 (KB929969)
                  Security Update for Windows Internet Explorer 7 (KB931768)
                  Security Update for Windows Internet Explorer 7 (KB933566)
                  Security Update for Windows Internet Explorer 7 (KB937143)
                  Security Update for Windows Internet Explorer 7 (KB938127)
                  Security Update for Windows Internet Explorer 7 (KB939653)
                  Security Update for Windows Internet Explorer 7 (KB942615)
                  Security Update for Windows Internet Explorer 7 (KB944533)
                  Security Update for Windows Media Player 10 (KB917734)
                  Security Update for Windows Media Player 11 (KB936782)
                  Security Update for Windows Media Player 6.4 (KB925398)
                  Security Update for Windows XP (KB890046)
                  Security Update for Windows XP (KB893756)
                  Security Update for Windows XP (KB896428)
                  Security Update for Windows XP (KB899587)
                  Security Update for Windows XP (KB900725)
                  Security Update for Windows XP (KB901017)
                  Security Update for Windows XP (KB902400)
                  Security Update for Windows XP (KB905414)
                  Security Update for Windows XP (KB905749)
                  Security Update for Windows XP (KB911927)
                  Security Update for Windows XP (KB913580)
                  Security Update for Windows XP (KB914389)
                  Security Update for Windows XP (KB916281)
                  Security Update for Windows XP (KB917422)
                  Security Update for Windows XP (KB917953)
                  Security Update for Windows XP (KB918118)
                  Security Update for Windows XP (KB918899)
                  Security Update for Windows XP (KB919007)
                  Security Update for Windows XP (KB920213)
                  Security Update for Windows XP (KB920214)
                  Security Update for Windows XP (KB920670)
                  Security Update for Windows XP (KB920683)
                  Security Update for Windows XP (KB920685)
                  Security Update for Windows XP (KB921398)
                  Security Update for Windows XP (KB921503)
                  Security Update for Windows XP (KB922616)
                  Security Update for Windows XP (KB922819)
                  Security Update for Windows XP (KB923191)
                  Security Update for Windows XP (KB923414)
                  Security Update for Windows XP (KB923689)
                  Security Update for Windows XP (KB923694)
                  Security Update for Windows XP (KB923980)
                  Security Update for Windows XP (KB924191)
                  Security Update for Windows XP (KB924270)
                  Security Update for Windows XP (KB924496)
                  Security Update for Windows XP (KB924667)
                  Security Update for Windows XP (KB925486)
                  Security Update for Windows XP (KB925902)
                  Security Update for Windows XP (KB926255)
                  Security Update for Windows XP (KB926436)
                  Security Update for Windows XP (KB927779)
                  Security Update for Windows XP (KB927802)
                  Security Update for Windows XP (KB928255)
                  Security Update for Windows XP (KB928843)
                  Security Update for Windows XP (KB929123)
                  Security Update for Windows XP (KB930178)
                  Security Update for Windows XP (KB931261)
                  Security Update for Windows XP (KB931784)
                  Security Update for Windows XP (KB932168)
                  Security Update for Windows XP (KB933729)
                  Security Update for Windows XP (KB935839)
                  Security Update for Windows XP (KB935840)
                  Security Update for Windows XP (KB936021)
                  Security Update for Windows XP (KB938829)
                  Security Update for Windows XP (KB941202)
                  Security Update for Windows XP (KB941568)
                  Security Update for Windows XP (KB941569)
                  Security Update for Windows XP (KB941644)
                  Security Update for Windows XP (KB941693)
                  Security Update for Windows XP (KB943055)
                  Security Update for Windows XP (KB943460)
                  Security Update for Windows XP (KB943485)
                  Security Update for Windows XP (KB944653)
                  Security Update for Windows XP (KB945553)
                  Security Update for Windows XP (KB946026)
                  Security Update for Windows XP (KB948590)
                  Security Update for Windows XP (KB948881)
                  Sonic Activation Module
                  Sonic Update Manager
                  Spybot - Search & Destroy 1.4
                  SUPERAntiSpyware Free Edition
                  Update for Windows XP (KB894391)
                  Update for Windows XP (KB898461)
                  Update for Windows XP (KB900485)
                  Update for Windows XP (KB904942)
                  Update for Windows XP (KB910437)
                  Update for Windows XP (KB911280)
                  Update for Windows XP (KB916595)
                  Update for Windows XP (KB920872)
                  Update for Windows XP (KB922582)
                  Update for Windows XP (KB927891)
                  Update for Windows XP (KB929338)
                  Update for Windows XP (KB930916)
                  Update for Windows XP (KB931836)
                  Update for Windows XP (KB933360)
                  Update for Windows XP (KB936357)
                  Update for Windows XP (KB938828)
                  Update for Windows XP (KB942763)
                  URGE
                  URL Assistant
                  Viewpoint Media Player
                  WebCyberCoach 3.2 Dell
                  Windows Driver Package - SIRIUS (zsi_fw) SIRIUS (07/28/2006 1.00.0003)
                  Windows Driver Package - SIRIUS (zsi_zap) SIRIUS (07/28/2006 1.02.0006)
                  Windows Internet Explorer 7
                  Windows Media Format 11 runtime
                  Windows Media Format 11 runtime
                  Windows Media Player 10
                  Windows Media Player 11
                  Windows Media Player 11
                  Windows XP Hotfix - KB885836
                  Windows XP Hotfix - KB886185
                  Windows XP Hotfix - KB888302
                  Windows XP Hotfix - KB890859
                  WinRAR archiver
                  Yahoo! Music Jukebox
                  Yahoo! WidgetsUninstall Super... and the reinstall the new SUPERAntiSpyware 4.1.1040 Prerelease. It has some speed enhancements. You can turn off any monitoring with it. The free version doesn't have any real time protection anyway so it needs to be set to off.

                  Go to add/remove programs and uninstall:
                  J2SE Runtime Environment 5.0 Update 6
                  Java DB 10.3.1.4 <unless you use it.
                  Java(TM) SE Development Kit 6 Update 6
                  LiveReg (Symantec Corporation)
                  LiveUpdate 2.6 (Symantec Corporation)
                  SearchAssist
                  URL Assistant
                  Viewpoint Media Player


                  Now run CCleaner.

                  ----------

                  Use StartUpLite to get rid of any un-necessary startups. You can uninstall startuplite when it is finished if you choose, or keep it. Your choice.

                  ----------

                  Use the Secunia Software Inspector

                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  ----------

                  Suggestion:

                  Defrag the drive with a third party defrag program. This will give improved performance. Pick only one. I have used both of these and am now using IOBit because it has an automatic defrag feature.

                  Iobit SmartDefrag
                  Defraggler

                  ----------

                  Let me know how things are now.


                  I'll do what you recommend later tonight. In the meantime, I just got a "Resident Shield alert" saying:
                  Accessed file is infected.
                  Threat detected!
                  File name: C:\System Volume Information _restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP534\A0033727.dll
                  Threat name: Trojan horse Downloader.Zlob.SE
                  Detected on open

                  Is that from a Restore Point? I wouldn't mind deleting all my previous Restore Points. The data on this computer is all backed up.
                  Yes it is a restore point. We would clear the restore points in the final steps, but we can do it now in order to keep any warnings from coming up.

                  • Go to Start > All Programs > Accessories > System Tools > System Restore
                  • Select Create a restore point, and click Next.
                  • Next, go to Start > Run and type in cleanmgr
                  • Select the More options tab
                  • Next to System Restore click Clean up...
                  This will remove all restore points except the new one you just created.Hello again,

                  Uninstalling the version of SuperAntiSpyware, installing the new version, and then setting it to NOT run at startup fixed much of the delay when starting up the computer. It does take AVG a little bit to get its *censored* in gear, but my husband calls the wait "not a problem". I'm just thinking he wants his computer back after my kicking him off it for almost a week. But he's right, the little bit of EXTRA wait for the virus scan to start up isn't that bad.

                  Thanks again for all of your help. Hopefully this thread can help others who have experienced the same problem, or at least help point them to some of the best tools to use out there.

                  - katheryne


                  3072.

                  Solve : Uh Oh! Please help... Viruses?

                  Answer» COOL
                  HAPPY COMPUTING!
                  3073.

                  Solve : UNKNOWN VIRUS?

                  Answer» HI,
                  I HAVE RECEIVED A MESSAGE BY MY ANTIVIR:

                  Q-te
                  A VIRUS OR UNWANTED PROGRAM WAS FOUND.

                  C:\WINDOWS\Temp\tmp1D.tmp

                  Contains detection pattern of a probably damaged sample

                  CC/Agent.HM
                  Unq-te

                  My AVIRA antivir cannot neutralize it. Any help?

                  Thanks!
                  Please start here. Please read this before requesting malware removal helpQuote from: evg1024 on May 14, 2008, 01:22:39 PM
                  HI,
                  I HAVE RECEIVED A MESSAGE BY MY ANTIVIR:

                  Q-te
                  A VIRUS OR UNWANTED PROGRAM WAS FOUND.

                  C:\WINDOWS\Temp\tmp1D.tmp

                  Contains detection pattern of a probably damaged sample

                  CC/Agent.HM
                  Unq-te

                  My AVIRA antivir cannot neutralize it. Any help?

                  Thanks!

                  HI,
                  I HAVE PREFORMED AS SUGGESTED AND
                  SuperAntispyware log
                  Malwarebytes' log
                  Hijackthis log
                  ARE ENCLOSED.

                  THANKS VERY MUCH FOR THE VERY SOUND AND QUALITY ASSISTANCE! SHOULD I KEEP ALL DOWNLOADED PROGRAMS ON MY PC? AND HOW OFFTEN SHOULD I RUN IT?
                  THANKS AGAIN!
                  JEV

                  [recovering space - attachment deleted by admin]Quote from: evilfantasy on May 14, 2008, 06:34:00 PM
                  Please start here. Please read this before requesting malware removal help
                  The logs look fine, are you still having any problems?

                  Run the new programs EVERY other week or so just to ensure nothing has made it's way back into the computer.

                  Just a quick fix with hijackthis and then some cleanup steps.

                  Open Hijackthis and select Do a system scan only.

                  Place a check mark next to the following entries: (if there)

                  O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

                  Important: Close all windows except for Hijackthis and then click Fix checked.

                  Exit Hijackthis.

                  ----------

                  Please download ATF Cleaner by Atribune. ATF Cleaner

                  Make sure that all browser windows are closed.

                  Windows Vista USERS: ATF-Cleaner must be Run as an Administrator
                  • Under the Main tab, put a check next to Select All.
                    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
                  • If you use the Firefox browser:
                    Click on Firefox at the top and put a check next to Select All.
                    If you would like to keep your saved passwords, click No at the prompt.
                    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
                  • If you use the Opera browser:
                    Click on Opera at the top and put a check next to Select All.
                    If you would like to keep your saved passwords, click No at the prompt.
                    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
                  .
                  Important: Restart the computer before continuing.

                  ----------

                  This is a good time to clear your infected system restore points and establish a new clean restore point:
                  • Go to Start &GT; All Programs > Accessories > System Tools > System Restore
                  • Select Create a restore point, and click Next.
                  • Next, go to Start > Run and type in cleanmgr
                  • Select the More OPTIONS tab
                  • Next to System Restore click Clean up...
                  This will remove all restore points except the new one you just created.

                  Use the Secunia Software Inspector

                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .

                  Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

                  Let us know if anything else comes up.HI,
                  ALL IS WELL NOTED.
                  THANKS A LOT FOR ALL - HAVE A VERY BEAUTIFUL DAY!Good to know.

                  Safe surfing...

                  There was no need for this to be broken up into two different threads, so I went ahead and merged them. Glad to see all is well.
                  3074.

                  Solve : Web browser problems?

                  Answer»

                  When i try to USE opera it lets me connect to my speed dial tabs such as google and then from there when i search for something it shuts down. Same with other sites it lets you get to the HOME page then when i got to navigate around it freezes up.

                  This happens whether or not i have my firewall on or off.

                  On occasions it will work with my firewall off but most of the time i get the same problem

                  IE works fine but says it has to close DUE to an unknown problem. Searching for the problem returns nothing.

                  I have been getting a few ads saying i have unwanted viruses and illegal porn with are probably spyware/malware?

                  could this be related. I searched for them with my firewall (outpost pro) and it found 2 traces i removed them and those messages have stopped but i still have the web browser problems.

                  Any ideas?

                  Thanks.
                  If two different browsers are acting up on that machine it's possible this is a Windows issue...what version ? ?Quote

                  I have been getting a few ads saying i have unwanted viruses and illegal porn with are probably spyware/malware?
                  Most likely, your computer is infected...

                  Print these instructions out.

                  1. Download SUPERAntiSpyware Free for Home Users:
                  http://www.superantispyware.com/

                  * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                  * An icon will be created on your desktop. Double-click that icon to launch the program.
                  * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                  * Close SUPERAntiSpyware.

                  Restart computer in Safe MODE.
                  To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                  * Open SUPERAntiSpyware.
                  * Under "Configuration and Preferences", click the Preferences button.
                  * Click the Scanning Control tab.
                  * Under SCANNER Options make sure the following are checked (leave all others unchecked):
                  o Close browsers before scanning.
                  o Scan for tracking cookies.
                  o Terminate memory threats before quarantining.
                  * Click the "Close" button to leave the control center screen.
                  * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                  * On the left, make sure you check C:\Fixed Drive.
                  * On the right, under "Complete Scan", choose Perform Complete Scan.
                  * Click "Next" to start the scan. Please be patient while it scans your computer.
                  * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                  * Make sure everything has a checkmark next to it and click "Next".
                  * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                  * If asked if you want to reboot, click "Yes".
                  * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                  o Click Preferences, then click the Statistics/Logs tab.
                  o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                  o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                  o Please copy and paste the Scan Log results in your next reply.
                  * Click Close to exit the program.
                  Post SUPERAntiSpyware log.

                  RESTART COMPUTER!

                  2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                  * Double-click mbam-setup.exe and follow the prompts to install the program.
                  * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                  * If an update is found, it will download and install the latest version.
                  * Once the program has loaded, select Perform full scan, then click Scan.
                  * When the scan is complete, click OK, then Show Results to view the results.
                  * Be sure that everything is checked, and click Remove Selected.
                  * When completed, a log will open in Notepad.
                  * Post the log back here.

                  The log can also be found here:
                  C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                  Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                  RESTART COMPUTER!

                  3. Download HijackThis:
                  http://www.snapfiles.com/get/hijackthis.html
                  Post HijackThis log.at work atm.

                  i will do this 2moro night.

                  patio i am using vista(x86) 32 bit, sp1.

                  got a cod4 final 2nite. wish my team luck!Good luck Yep...Good Luck.
                  I thought cod was fish...
                  3075.

                  Solve : HJ log?

                  Answer»

                  Can someone please cheeck this for someone as there internet is down.


                  Scan saved at 7:56:30 AM, on 14/05/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWSLogfile of HijackThis v1.99.1
                  Scan saved at 7:56:30 AM, on 14/05/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRAM Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\WINDOWS\system32\cisvc.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Documents and Settings\Mr.Murray\Desktop\hijackthis_199\HijackTh is.exe
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: (no name) - {3D0EEAFE-E90D-4BB9-881E-3DF2369A1858} - C:\WINDOWS\system32\efcbcCrr.dll (file missing)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: {60b5e5a7-b125-78f9-1fd4-1df53882611f} - {f1162883-5fd1-4df1-9f87-521b7a5e5b06} - C:\WINDOWS\system32\owwuqpiw.dll
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [sunjavaupdatesched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [soundman] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [remotecontrol] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                  O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [MOTIVE smartbridge] C:\PROGRA~1\ALIANT\NETASS~1\SMARTB~1\MotiveSB.exe
                  O4 - HKLM\..\Run: [launchapp] Alaunch
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [hp software update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [agrsmmsg] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\Mr.Murray\Local Settings\Temporary Internet Files\Content.IE5\WLIRQ72W\install_sbd_en[1].exe
                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: WEB Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: Support - {6A1E322D-A3D1-453E-922D-347C663BEF84} - http://support.primus.ca (file missing) (HKCU)
                  O9 - Extra button: Setup - {88E53018-61C2-4E5B-A69C-257DD10F8208} - https://signup.primus.ca (file missing) (HKCU)
                  O9 - Extra button: Account - {A99F899A-3298-4DF0-ADC0-4E8458F31E38} - http://setup.primus.ca:8000/ (file missing) (HKCU)
                  O11 - Options group: [INTERNATIONAL] International*
                  O14 - IERESET.INF: START_PAGE_URL=http://www.primus.ca
                  O16 - DPF: {00330010-0000-0000-0000-000020160010} - http://207.234.185.217/ABoxInst_int25.exe
                  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                  O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
                  O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} - http://www.icannnews.com/app/ST/ActiveX.ocx
                  O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
                  O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} - http://downloads.shopathomeselect.com/wardmedia/grinstall_wm1001_sp2.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181491216296
                  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                  O16 - DPF: {8F4213B4-A970-4B3C-820D-343C693D5BF0} (SelfProvisioning.Wizard) - http://dsp03.eastlink.ca/SelfProvisioning.cab
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
                  O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O20 - Winlogon Notify: efcDUkLb - C:\WINDOWS\
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                  O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\WINDOWS\system32\cisvc.exe
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Documents and Settings\Mr.Murray\Desktop\hijackthis_199\HijackTh is.exe
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: (no name) - {3D0EEAFE-E90D-4BB9-881E-3DF2369A1858} - C:\WINDOWS\system32\efcbcCrr.dll (file missing)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: {60b5e5a7-b125-78f9-1fd4-1df53882611f} - {f1162883-5fd1-4df1-9f87-521b7a5e5b06} - C:\WINDOWS\system32\owwuqpiw.dll
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [sunjavaupdatesched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [soundman] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [remotecontrol] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                  O4 - HKLM\..\Run: [quicktime task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [motive smartbridge] C:\PROGRA~1\ALIANT\NETASS~1\SMARTB~1\MotiveSB.exe
                  O4 - HKLM\..\Run: [launchapp] Alaunch
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [hp software update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [agrsmmsg] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\Mr.Murray\Local Settings\Temporary Internet Files\Content.IE5\WLIRQ72W\install_sbd_en[1].exe
                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: Support - {6A1E322D-A3D1-453E-922D-347C663BEF84} - http://support.primus.ca (file missing) (HKCU)
                  O9 - Extra button: Setup - {88E53018-61C2-4E5B-A69C-257DD10F8208} - https://signup.primus.ca (file missing) (HKCU)
                  O9 - Extra button: Account - {A99F899A-3298-4DF0-ADC0-4E8458F31E38} - http://setup.primus.ca:8000/ (file missing) (HKCU)
                  O11 - Options group: [INTERNATIONAL] International*
                  O14 - IERESET.INF: START_PAGE_URL=http://www.primus.ca
                  O16 - DPF: {00330010-0000-0000-0000-000020160010} - http://207.234.185.217/ABoxInst_int25.exe
                  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                  O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
                  O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} - http://www.icannnews.com/app/ST/ActiveX.ocx
                  O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
                  O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} - http://downloads.shopathomeselect.com/wardmedia/grinstall_wm1001_sp2.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181491216296
                  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                  O16 - DPF: {8F4213B4-A970-4B3C-820D-343C693D5BF0} (SelfProvisioning.Wizard) - http://dsp03.eastlink.ca/SelfProvisioning.cab
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
                  O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O20 - Winlogon Notify: efcDUkLb - C:\WINDOWS\
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                  O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                  O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)Please go to this thread and read the instructions for posting the required logs.Sorry to bother you he just wanted a check.
                  Im sorry for taking up your time.I wouldn't ask you to go through the steps if it weren't necessary. The log is bad.

                  You need to uninstall one of the antivirus suites. Running TWO is never advised.

                  3076.

                  Solve : Boot Virus New Laptop (Xmas) please help!?

                  Answer»

                  Hi I got a new Compaq PRESARIO v6000 laptop at Xmas now someone I trusted sent me a “SOMETHING” over MSN/WLM. I now know this “virus” for want of a better WORD stopped my computer from booting (even getting to the Compaq screen before windows loads) I cured this virus by removing the laptop battery yay fixed but then it came back seeming randomly a few weeks later ad again today. I had full AVG trial installed and windows firewall along with WIN Defender at the time oh and I’m running on windows Vista home Pre and my hard drive is sectioned into my laptop recovery drive (D) and my main drive (C). So my question is how to I get rid of this forever? And what is it?
                  PS yes I reformatted it still came back!

                  Thankyou all!You reformatted hard drive, or you reinstalled Windows over the top?I used recovery partition to reinstall windows (hope my problem is fixable)Print these instructions out.

                  1. Download SUPERAntiSpyware Free for Home Users:
                  http://www.superantispyware.com/

                  * Double-click SUPERAntiSpyware.exe and use the default SETTINGS for installation.
                  * An icon will be created on your desktop. Double-click that icon to launch the program.
                  * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                  * Close SUPERAntiSpyware.

                  Restart computer in Safe Mode.
                  To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                  * Open SUPERAntiSpyware.
                  * Under "Configuration and Preferences", click the Preferences button.
                  * Click the Scanning Control tab.
                  * Under Scanner Options make sure the following are checked (leave all others unchecked):
                  o Close browsers before scanning.
                  o Scan for tracking cookies.
                  o Terminate memory threats before quarantining.
                  * Click the "Close" button to leave the control center screen.
                  * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                  * On the left, make sure you check C:\Fixed Drive.
                  * On the right, under "Complete Scan", choose Perform Complete Scan.
                  * Click "Next" to start the scan. Please be patient while it scans your computer.
                  * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                  * Make sure everything has a checkmark next to it and click "Next".
                  * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                  * If asked if you want to reboot, click "Yes".
                  * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                  o Click Preferences, then click the Statistics/Logs tab.
                  o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                  o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                  o Please copy and paste the Scan Log results in your next reply.
                  * Click Close to exit the program.
                  Post SUPERAntiSpyware log.

                  RESTART COMPUTER!

                  2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                  * Double-click mbam-setup.exe and follow the prompts to install the program.
                  * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                  * If an update is found, it will download and install the latest version.
                  * Once the program has loaded, select Perform full scan, then click Scan.
                  * When the scan is complete, click OK, then Show Results to view the results.
                  * Be sure that everything is checked, and click Remove Selected.
                  * When completed, a log will open in Notepad.
                  * Post the log back here.

                  The log can also be found here:
                  C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                  Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                  RESTART COMPUTER!

                  3. Download HijackThis:
                  http://www.snapfiles.com/get/hijackthis.html
                  Post HijackThis log.SUPERAntiSpyware Scan Log
                  http://www.superantispyware.com

                  Generated 05/16/2008 at 09:36 AM

                  Application Version : 4.0.1154

                  Core Rules Database Version : 3461
                  Trace Rules Database Version: 1452

                  Scan type : Complete Scan
                  Total Scan Time : 00:45:23

                  Memory items scanned : 218
                  Memory threats detected : 0
                  Registry items scanned : 6759
                  Registry threats detected : 0
                  File items scanned : 100053
                  File threats detected : 3

                  Adware.Tracking Cookie
                  C:\Users\Josh\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt
                  C:\Users\Josh\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
                  C:\Users\Josh\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt
                  Malwarebytes' Anti-Malware 1.12
                  Database version: 755

                  Scan type: Full Scan (C:\|D:\|)
                  Objects scanned: 139930
                  Time elapsed: 17 minute(s), 8 second(s)

                  Memory Processes Infected: 0
                  Memory Modules Infected: 0
                  Registry Keys Infected: 0
                  Registry Values Infected: 0
                  Registry Data Items Infected: 0
                  Folders Infected: 0
                  Files Infected: 0

                  Memory Processes Infected:
                  (No malicious items detected)

                  Memory Modules Infected:
                  (No malicious items detected)

                  Registry Keys Infected:
                  (No malicious items detected)

                  Registry Values Infected:
                  (No malicious items detected)

                  Registry Data Items Infected:
                  (No malicious items detected)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:15:28, on 16/05/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                  C:\WINDOWS\RtHDVCpl.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  C:\WINDOWS\System32\igfxpers.exe
                  C:\Program Files\AVG8\avgtray.exe
                  C:\Program Files\Lexmark 3400 Series\ezprint.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Windows\system32\wbem\unsecapp.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

                  http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

                  http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

                  http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

                  http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

                  http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

                  http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=PRESARIO&pf=laptop
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

                  Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -

                  C:\Program Files\AVG8\avgssie.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

                  Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

                  /Start
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG8\avgtray.exe
                  O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
                  O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
                  O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                  O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3

                  \LXCYtime.dll,[emailprotected]
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User

                  'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter

                  (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User

                  'NETWORK SERVICE')
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12

                  \EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

                  Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

                  C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1

                  \MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -

                  C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3

                  \Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -

                  http://www.systemrequirementslab.com/sysreqlab2.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG8

                  \avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8

                  \avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8

                  \avgwdsvc.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program

                  Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

                  Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
                  O23 - Service: lxcy_device - - C:\Windows\system32\lxcycoms.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0

                  \SharedCOM\RoxMediaDB9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing

                  Shared\stllssvr.exe

                  --
                  End of file - 6623 bytes



                  All 3 logs someone has said to me it might be somthing to do with the MBR or Bootsector?Can anyone help me please?Remember, we don't have 911 service. All volunteers, here. We need to work, eat, and sleep
                  You need to repost HJT log, but this time disable "word wrap" in Notepad, because the log is hard to read.

                  3077.

                  Solve : Help Please, Spyware/Adware issue.?

                  Answer»

                  Well, I believe it has to do with both adware and spyware.

                  It started last night, midnight my time. My entire desktop, once having an ironman background, suddenly had something different.

                  Instead of my original background it now has ads ATTACHED to it so there's no way to EXIT them out. Also, it won't let me change the background back to how it was. I even went to change it and it won't let me click on any of the offered wallpapers in the system.

                  I performed a scan and had found that I had quite a bit of spyware and such on my computer. I quarantined and removed them.

                  This was done in safe MODE. I went back to the normal mode ((Restarted the computer as I was advised by my program))

                  It's still there and I still am unable to change my wallpaper.

                  Does anyone have any suggestions on fixing this issue? It would be muchly appreciated.PLEASE start here. Please read this before requesting malware removal help

                  3078.

                  Solve : how to utilize AVG update '.bin' files??

                  Answer»

                  I subscribed to "[emailprotected]" to recieve update files via e-mail and they come in .bin form. I have not worked with these type of files before and don't know what section to download them to nor how to open them ect.
                  I realize that by getting automatic updates from AVG, my AVG protection software stays CURRENT, but I was interested in knowing some of the ongoing changes that are made to the updates. But I can't even get the files to open. How do I open the files and what do I do with them once I open them?
                  I am not real knowledgable about computers so this may be a stupid question. If so, at least I'll be less stupid for asking so thanks for any help!
                  Below is a .txt copy of the latest e-mail.

                  Date: Wed, 14 May 2008 18:04:17 GMT
                  Subject: [avg8-update] New AVG Anti-Virus 8 Update - AVI 269.23.16 / IAVI 1433

                  --- AVG Anti-Virus Update ---
                  (5/14/2008)

                  ********************************
                  ** AVG Anti-Virus 8 **
                  ********************************

                  --- information about Update ---

                  Update Summary:

                  - added new variants of Worm/Autoit
                  - added new variants of trojan Patched, Proxy, Downloader.Small


                  Update file for all Virus Database versions (size 6551189 bytes):
                  http://www.grisoft.com/softw/80/update/u7avi1309ww.bin

                  IAVI Update file for all Virus Database versions (size 23748580 bytes,
                  version 1433):
                  http://www.grisoft.com/softw/80/update/u7iavi1443f1.bin


                  All available Update files, including previous versions,
                  may be found at the following link:
                  http://www.grisoft.com/doc/update

                  --
                  AVG Technologies


                  To unsubscribe from the AVG8-UPDATE service, please follow the
                  instructions at http://www.grisoft.com/ww.avg-update-bulletin-form

                  Arte you using the free or paid version?

                  Quote

                  Important notice for AVG Free Users

                  The listed program updates should not be used for the AVG Anti-Virus Free EDITION. AVG Free users can perform the update directly from within the program, or download updates from AVG Free Advisor website.
                  Paid version. A paid version key code is required in order to be elgible for this AVG update service mail ist.
                  I hope I'm not violating any license agreement by posting the contents of the message on this open forum, if so I certainly did so out of ignorance and will be happy for the text to be deleted or modified. Try this.

                  Make sure your computer date and time are correct (AVG needs to know)

                  Launch the AVG Control Center, select the Update Manager button,
                  then press the "properties" button at the bottom of the window

                  UNcheck the option "do not ask for update source", and click "apply"

                  Click the Update button at the bottom of the window and find the folder
                  you put .bin file

                  Click OK and AVG will update (unless it's already up to date) I could not find a way to follow your directions in my AVG8 interface, so I went to my sisters computer, which is still running AVG 7.5 free version, and your directions work fine.
                  But:
                  You did give me enough information to figure out how it's done in my version of AVG 8 {version 8.0.93}.
                  --This is how I did it:

                  1- create a file in My Documents. {I named my file "AVG 8 Update .bin fles"}
                  2- download the file in the e-mail labled "Update file for all Virus Database versions" to the location created in "My Documents"
                  3- open AVG "User Interface". {"AVG Overview" screen is displayed}
                  4- click on "Tools" then select "Update from Directory" in the drop down menu. Then select the file location in the file selection box displayed on the screen {"My Documents/AVG 8 Update .bin files" in my case}.
                  5- The update progress screen will display then "Update Finished Sucessfully" {in my case a subtitle displayed "New Update Files Not Found" since I already have then latest file downloaded via "Automatic Updates" set to updae every 4 hours.

                  That being said, {" I already have then latest file downloaded via "Automatic Updates" set to updae every 4 hours."}, I see no advantage of this portion of the update service in my case. I was hoping the service would give more information about the latest threats such as possible sites that the threats can be contracted from, what e-mail message "subject ect." cantain threats, and possibly some tips for file names to enter in the "Do Not Alow" box in firewall advanced settings.
                  I guess I just miss-understood the purpose of the update service.
                  The webpage says,
                  "Subscribe or unsubscribe for a free email service, providing you with information concerning the availability of new updates, current virus outbreaks, and other important news concerning AVG products. On average, AVG Update Bulletin is sent twice a week. In case of virus outbreaks it is sent more frequently."

                  Where is the "other important news concerning AVG products"?

                  Thanks for your help evilfantasy !

                  Glad you worked it out.

                  Install SpywareBlaster and SITE Advisor if you don't already have them.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                  * Using SpywareBlaster to protect your computer from Spyware and Malware

                  To install Site Advisor, just download the Plug-in for Internet Explorer or the Plug-in for FireFox

                  Here are some links that will have some of the information you are looking for.
                  http://free.grisoft.com/ww.top-threats
                  http://www.ca.com/us/securityadvisor/pest/browse.aspx?cat=adware
                  http://www.bitdefender.com/syndicate/rtvr/main.html#

                  Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Thanks for the excellent links. I've had limited time to explore everything but I have installed SpywareBlaster and I have a question about it in a minute.

                  1ST I'll update you on what I have done.
                  Tony Kleins page suggested using Firefox browser due to better security features, faster ect. so I downloaded and installed it and have it set as my default and I locked down ActiveX in Internet Explorer per instructions. I installed Site Advisor for both IE and Firefox, installed Lavasoft's Ad-Aware and Spybot S&D. I already have Malwarebytes {paid version} and Secunia PSI installed as you suggested in a previous topic you helped me with.
                  Current scans with AVG8, Malwarebytes, Spybot and Ad-Aware all show my computer to be infection free.

                  So far a concern I see is in SpywareBlasters block list in the IE catagory. There are several items that do not have a check in the box and the names are in red letters. They are all listed as type = active x.
                  Some of the names are as follows:
                  MoneyTree (2)
                  VX2 Variant
                  Spyblast install control
                  Spyblast iinstall control (2)
                  SearchWWW
                  ClientMan Variant
                  Alexa Variant
                  CoolWebSearch Variant 00110011-4B0B-44D5-ect.
                  CoolWebSearch Variant 17DA0C9E-4AZ7----------
                  IEPlugin {8}
                  Rank.com Hijacker
                  CoolWebSearch / Gonnasearch Variant

                  There are more I can post if you need them.
                  My question is, should I check all these items and click on the box "Protect Against Checked Items" or are they active x controls that my software needs to function correctly?

                  BTW My computer passed all security test except it failed the test in the "javascript, cookies and third party cookie" sections of http://www.jasons-toolbox.com/BrowserSecurity/ which I linked to from Tony Klien's page.

                  Thanks again with your help so far. I imagine I might have some more questions after I learn more about all the cool tools you linked me too.

                  SpywareBlasters blocks bad activex objects.

                  To use it select Download latest protection updates.

                  Then choose Enable all protection.



                  [recovering space - attachment deleted by admin]That did it. SORRY, I missed clicking the 'Enable all protection' button. SpywareBlaster is now working fine and with paid version so it updates automatically.
                  Thanks again!!!No problem, glad you got it going!
                  3079.

                  Solve : How does everything look??

                  Answer»

                  Just wanted to make sure everything was running well on my girflirend's comp....... Please run through this quick? thank you!

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 8:03:15 PM, on 5/15/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\LEXBCES.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\LEXPPS.EXE
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\BCMSMMSG.exe
                  C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\internet explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.verizon.net/newsroom/portals/newsroom.portal
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                  O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [QUICKTIME Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
                  O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
                  O4 - Global STARTUP: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java CONSOLE - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\AIM95_c1\aim.exe
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
                  O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                  O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

                  --
                  End of file - 6483 bytes
                  Looks fine Thanks Broni!

                  3080.

                  Solve : computer problems post-Trojan.Win32.Blackbird and friends?

                  Answer»

                  I'm not sure what to do. Can you get an XP CD and try a repair install?I don't have an XP CD... I'm just gonna reformat my hardrive, thanks anyway thoughweird... well, I had SERVICE pack 2, and I DOWNLOADED service pack 3, now my internet works (and I haven't reformatted), but it's very testy. sometimes the IP address is invalid... sometimes there's a problem with the DNS, and now my AIM no LONGER functions properly...

                  I'm so confused! Try reinstalling anything that doesn't work right.

                  3081.

                  Solve : Is this registry a malware????

                  Answer» HI I have seen a LOT of forums saying that this directory O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe is malware of some sort....I don't know whether is it true or not..Can you guys help me???Btw my com running on windows vista.Anyway below is a log from hijackthis.



                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:19:23 AM, on 18/5/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\ntvdm.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                  C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
                  C:\Windows\WindowsMobile\wmdSync.exe
                  C:\Program Files\Grisoft\AVG7\avgcc.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
                  C:\Windows\System32\spool\drivers\w32x86\3\E_FATIBNP.EXE
                  C:\Program Files\Ares\Ares.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\System32\mobsync.exe
                  C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                  C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
                  C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
                  C:\Program Files\Grisoft\AVG7\avgw.exe
                  C:\Program Files\Grisoft\AVG7\avginet.exe
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Windows\system32\WerCon.exe
                  C:\Program Files\Windows Live Toolbar\msn_sl.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sg.yahoo.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sg.yahoo.com
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SingNet
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  F3 - REG:win.ini: run= C:\WINPENJR\WIN16\CUSTOM.EXE
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                  O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
                  O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                  O4 - HKCU\..\Run: [EPSON Stylus Photo R270 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBNP.EXE /FU "C:\Windows\TEMP\E_S40E6.tmp" /EF "HKCU"
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                  O4 - Global Startup: Bluetooth.lnk = ?
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: E&xport to Microsoft EXCEL - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                  O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O13 - Gopher Prefix:
                  O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                  --
                  End of file - 11740 bytesI don't think the file is malicious. You can run the tools in our removal thread to see if anything is turned up. Go to this thread and follow the instructions.

                  There are a few things that need to be addressed,

                  Open Hijackthis and select Do a system scan only.

                  Place a check mark next to the following entries: (if there)

                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

                  Important: Close all windows except for Hijackthis and then click Fix checked.

                  Exit Hijackthis.

                  ----------

                  Your Java is out of date.
                  Older versions of Java have vulnerabilities that malware can use to infect your system.
                  Please follow these steps to remove older version(s) of Java components and update.

                  Step 1 - Get the new version
                  • Go to the Sun Java Download Page
                  • On the Sun Java page scroll to the 5th download. Java Runtime Environment (JRE) 6 Update 6
                  • Click the button and choose the options.
                    • Platform Windows
                    • Language English
                    • Next place a check mark in the box to agree to the License Agreement.
                  • "I agree to the Java SE Runtime Environment 6 License Agreement"
                  • Click Continue
                  • Click on the link to download Windows Offline Installation and SAVE to your desktop.
                  • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
                  • Follow the prompts to complete the installation.
                  Step 2 - Remove old version(s)
                  • Close any programs you may have running - especially your web browser.
                  • Go to Start > Control Panel > Add/Remove programs and remove all older versions of Java.
                  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
                  • Do not remove Java 6 Update 6
                  • Click the Remove or Change/Remove button.
                  • Repeat as many times as necessary to remove each old Java version.
                  • Restart your computer once all Java components are removed.
                  Step 3 - Remove old folder(s)
                  • Double click My Computer on the desktop, Locate this folder: C:\Program Files\Java
                  • Open the Java folder and delete any subfolders except the jre1.6.0_06 folder which was just created by the newest Java installation.
                  3082.

                  Solve : "Task Manger" is not available for clicking, please help....?

                  Answer»

                  My computer contracted some nasty malware yesterday and I think I got rid of it all by following the steps in the "Please read this before requesting malware removal help". However, when I press ALT+CONTROL+DELETE the option to click the Task Manager button is not available. Can anyone help me to fix this? Thanks in advance!If you have posted no logs you haven't followed the instructions in the Please Read This section...Here are the logs that I have from Superantispyware, Malwarebytes and hijackthis.

                  [recovering space - attachment deleted by admin]*** Go Start>Control Panel>Add\Remove, and...
                  Uninstall any of the following programs associated with Viewpoint:
                  * Viewpoint Manager
                  * Viewpoint Media Player
                  * Viewpoint Toolbar

                  1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                  - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=%tb_id
                  - R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=%tb_id
                  - R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=%tb_id
                  - O2 - BHO: (no name) - {4A9FD117-0E8D-4B21-B75B-E21DFC9F0C09} - C:\WINDOWS\system32\iifccaBr.dll (file missing)
                  - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  - *O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  - O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://www.spywarelabs.com/1203030306/VBouncerOuter1203.EXE
                  - O18 - Protocol: relatedlinks - {CD8D1CAA-FE4A-45DF-A06C-028AAF1821DE} - C:\PROGRA~1\COMMON~1\BTLINK\btlink.dll (file missing)
                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  - O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

                  4. Click on Fix checked button.

                  5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                  7. Delete following files/folders (if present):

                  - Viewpoint folder from C:\Program Files

                  8. Restart in Normal Mode.

                  9. Post new HijackThis log.I followed all the steps outlined above. Here is the new hijackthis log.

                  [recovering space - attachment deleted by admin]Your computer is clean

                  1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. GET "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore POINTS will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the Tasks column on the left side
                  4. Click on Continue on the "User Account Control" WINDOW that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. Read So how did I get infected in the first place?: http://www.castlecops.com/postlite7736-.html

                  6. Let me know, how your computer is doing.

                  Thanks for all the help in getting my computer clean!!

                  For some reason though I still do not have the option to click on "Task Manager" when I press ALT+CTRL+DELETE. Any ideas as to why?Yeah, it happens when computer gets infected.
                  See here: http://www.raymond.cc/blog/archives/2007/06/28/restore-task-manager-regedit-and-folder-options-disabled-by-virus/ for solution.Broni-

                  Task Manager is functioning normaly now, thanks!

                  Thanks for all the help in getting my computer clean!! I really do appreciate it!You're very welcome

                  3083.

                  Solve : Which Virus Scanner???

                  Answer»

                  Okay I have a few virus scanners that I can install wonder which would work better? Bullguard,Norton,AVG,Avast I dont care much for avg since it comes with a firewall an you have to set all the features but I don't like Norton to much ehter cause you have to pay after a while. Avast!

                  AVG is declining in my opinion. Read this. It looks like AVG is refusing to allow other anti-malware apps to run (peacefully) along with the new 8.0 version since it has anti-malware built in to it.

                  Quote

                  An "ActiveX Compatibility" registry key is a result of the "Immunize" function included in some anti-spyware programs (e.g.: "Spybot search & destroy", "Spyware blaster",...)

                  The key contains the same registry entries as the actual threats, thus preventing them from working correctly. Some anti-spyware programs use this method to prevent launching of the malware. Unfortunately, these parts are still detected by AVG signatures and that is why AVG marks them as infected.

                  To assure protection provided by AVG against these threats, it is not possible to remove such signatures from AVG virus bases.
                  Because of this, "Immunize" function included in above mentioned softwares is NOT compatible with AVG products.


                  http://www.grisoft.com/ww.faq.num-1067

                  So AVG thinks that their database/definitions should be the only thing protecting a users computer from here on out. I think we all know that layered protection is the best method and you should never "put all your eggs in one BASKET" so to speak.

                  And a quote from chaslang at majorgeeks.com

                  Quote
                  You may want to read comments I had on this here: http://forums.majorgeeks.com/showthread.php?t=159452

                  I don't agree with Grisoft. I feel their software needs to be rewritten to properly look for the actual infection not the CLSID.

                  If this ISSUE does not get resolved, we may need to pull AVG from the recommed antivirus list since it will be quite annoying!!!
                  Okay cause I didnt have one for most of the time.I get the FEELING your computing habits are on the dangerous side of things.

                  Quote
                  Okay I have a few virus scanners that I can install

                  Hopefully these are licensed copies you have...Some what I pull a lot of crap off when I have the full defense up. Know there only trial programs for the most part.I see. Have a look at this.

                  Free BitDefender AntiVirus 2008 License Key for 6 MonthsI got bitdefender if theres any differce between the two.
                  3084.

                  Solve : Is any malicious software in my computer? Please help!?

                  Answer»

                  This is what I get running hijackthis
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 5:17:16 PM, on 5/15/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\IPSSVC.EXE
                  C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\PnkBstrA.exe
                  C:\WINDOWS\system32\PnkBstrB.exe
                  C:\WINDOWS\system32\svchost.exe
                  c:\program files\lenovo\system update\suservice.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
                  C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\WINDOWS\system32\ICO.EXE
                  C:\WINDOWS\system32\FSRremoS.EXE
                  C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                  C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
                  C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
                  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                  C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
                  C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
                  C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                  C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                  C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
                  C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
                  C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
                  C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNP.EXE
                  C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Pando Networks\Pando\pando.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Ares\Ares.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\WinRAR\WinRAR.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lenovo.com/welcome/thinkcentre
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/welcome/thinkcentre
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search BAR = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
                  O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: Pando Toolbar BHO - {E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (file missing)
                  O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
                  O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                  O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
                  O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
                  O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                  O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [OMNIPAGE] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                  O4 - HKLM\..\Run: [TXP] c:\program files\topthemesxp\txp.exe
                  O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
                  O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [ares lite] "C:\Program Files\Ares Lite\Ares.exe" -h
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                  O4 - HKCU\..\Run: [EPSON Stylus Photo R270 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNP.EXE /FU "C:\WINDOWS\TEMP\E_SCC.tmp" /EF "HKCU"
                  O4 - HKCU\..\Run: [Start WINGMAN Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
                  O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
                  O4 - HKCU\..\Run: [viwc] C:\WINDOWS\system32\viwc.exe
                  O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                  O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - HKCU\..\Run: [ActiveX Message Killer] C:\Program Files\ActiveXMessageKiller\ActiveXMessageKiller.exe
                  O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
                  O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
                  O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
                  O4 - Global Startup: BlueSoleil.lnk = ?
                  O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: &Search - ?p=ZNxmk789YYSG
                  O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                  O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/thinkcentre
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
                  O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
                  O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
                  O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
                  O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development GROUP - C:\Program Files\Ares\chatServer.exe
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                  O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                  O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
                  O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
                  O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
                  O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
                  O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
                  O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
                  O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  O24 - Desktop COMPONENT 0: (no name) - http://gfx2.hotmail.com/mail/w2/ltr/i_safe.gif

                  --
                  End of file - 14166 bytes

                  I don't know is my computer has any virus in it....Please help!There are some questionable entries in the log, go to this thread and read the instructions. Post all of the logs here when complete.

                  Once the logs are posted a malware specialist will be along to assist you in further removal instructions.

                  3085.

                  Solve : Dell laptop will not stay shut down?

                  Answer»

                  This is wrong log (before you applied fixes), you can see "No action taken" after each line.
                  Please, post the correct one.
                  Was HJT run AFTER Superantispyware, and Malwarebytes?Malwarebytes' Anti-Malware 1.14
                  Database version: 814

                  9:52:44 PM 6/1/2008
                  mbam-log-6-1-2008 (21-52-44).txt

                  Scan type: Full Scan (C:\|)
                  Objects scanned: 144522
                  Time elapsed: 49 minute(s), 32 second(s)

                  Memory Processes Infected: 0
                  Memory Modules Infected: 0
                  Registry Keys Infected: 126
                  Registry Values Infected: 3
                  Registry Data Items Infected: 0
                  Folders Infected: 16
                  Files Infected: 67

                  Memory Processes Infected:
                  (No malicious items detected)

                  Memory Modules Infected:
                  (No malicious items detected)

                  Registry Keys Infected:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\hbtinstie.hbinstobj (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\hbtinstie.hbinstobj.1 (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{8c875948-9c60-4381-9248-0df180542d53} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{38370864-346f-4afa-8c4b-4fbff518c0bb} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{4cf5a3c1-07a2-4336-9b54-6870452ebde1} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{175816a5-219e-4079-b2f9-53c501c409ba} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{1c1793e0-1034-4cac-837d-aa545f6961bf} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{5d16197a-1eaa-45af-b29a-69f1aa055e87} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{8a61a950-c325-4f44-ba64-273180ff3464} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{b53d4cd4-406d-43cc-8244-7893d72236dd} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{b671426c-5c1a-48ac-9652-bc9402b1c404} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{b9bb3219-f84c-4060-966b-4a1e73e24226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{f786cb18-3809-4e49-bc99-9a66da47db8b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{71efe583-62fe-4419-9918-ca3b683f7b36} (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\IEHlprObj.IEHlprObj (Worm.OnlineG) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.

                  Registry Values Infected:
                  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.Registry Data Items Infected:
                  (No malicious items detected)

                  Folders Infected:
                  C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Installr\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\Wallpaper (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\bin (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\Ready (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\temp (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\Upload (Adware.Comet) -> Quarantined and deleted successfully.

                  Files Infected:
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3RESTUB.DLL (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3SCHMON.EXE (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\RECYCLER\S-1-5-21-2011789891-3564645870-2311836058-500\Dc1\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Installr\2.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\001EEE84.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\001EFBE2.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\001F05A6.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\001F0DB5.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\001F165F.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\01C7604B (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\01C85912.swf (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001EEBB5.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001EFBA4.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F0568.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F0D76.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F1621.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F1DE1.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F26DA.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001F2AE1.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001FF093.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\001FF92E.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00200A74.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00201447.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00201A81.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00201F25.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00203174.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\002037EC.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\00399257.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\01C79054.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\01C7BA71.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\01C85F4C.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\01C9A941.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\f3wallpp.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\wrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001EFBA4.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F0568.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F0D76.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F1621.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F1DE1.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F26DA.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001F2AE1.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001FF093.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\001FF92E.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\00200A74.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\00201447.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\00201A81.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\00201F25.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\00203174.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images\101x135\002037EC.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\01D1465A.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\bin\SSSUninst.exe (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\SSSInst\temp\dmE9.tmp.exe (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\Wallpaper\Autumn Forest Path.jpg (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\Wallpaper\swpstart.exe (Adware.Comet) -> Quarantined and deleted successfully.
                  C:\Program Files\Screensavers.com\Wallpaper\Thanksgiving Crops.jpg (Adware.Comet) -> Quarantined and deleted successfully.

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 7:50:44 PM, on 6/5/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                  Boot mode: NORMAL

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
                  C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
                  C:\WINDOWS\system32\cisvc.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\WINDOWS\system32\FreezeScreenSaver.exe
                  C:\Program Files\Google\Common\Google UPDATER\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\inetsrv\inetinfo.exe
                  C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\system32\mqsvc.exe
                  C:\WINDOWS\system32\mqtgsvc.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                  C:\WINDOWS\system32\dla\tfswctrl.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Program Files\Digital Line Detect\DLG.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
                  C:\PROGRA~1\Webshots\webshots.scr
                  C:\WINDOWS\eHome\ehmsas.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\Magentic\bin\MgApp.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\WINDOWS\system32\cidaemon.exe
                  C:\WINDOWS\system32\cidaemon.exe
                  C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.47.48:80
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                  O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                  O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                  O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
                  O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
                  O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
                  O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
                  O4 - Global Startup: Digital Line Detect.lnk = ?
                  O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm103YYUS
                  O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                  O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                  O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SCRIPT Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
                  O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211772414487
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
                  O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
                  O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
                  O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

                  --
                  End of file - 11254 bytes

                  Very well. Let me check it out...1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                  - O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
                  - *O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  - *O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  - O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
                  - O4 - Global Startup: Digital Line Detect.lnk = ?
                  - *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  - O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm103YYUS
                  - O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  - O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  - O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe

                  4. Click on Fix checked button.

                  5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                  7. Delete following files/folders (if present):

                  - iWin Games folder from C:\Documents and Settings\All Users\Application Data
                  - FreezeScreenSaver.exe file from C:\WINDOWS\system32

                  8. Restart in Normal Mode.

                  9. Post new HijackThis log.Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 9:11:15 PM, on 6/5/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                  C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
                  C:\WINDOWS\system32\cisvc.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\inetsrv\inetinfo.exe
                  C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\system32\mqsvc.exe
                  C:\WINDOWS\system32\mqtgsvc.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                  C:\WINDOWS\system32\dla\tfswctrl.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  C:\PROGRA~1\Webshots\webshots.scr
                  C:\WINDOWS\eHome\ehmsas.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\PROGRA~1\Magentic\bin\MgApp.exe
                  C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.47.48:80
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                  O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                  O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
                  O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                  O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
                  O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
                  O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                  O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                  O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                  O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                  O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
                  O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211772414487
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
                  O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
                  O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

                  --
                  End of file - 9805 bytes



                  Your computer is clean

                  1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the Tasks column on the left side
                  4. Click on Continue on the "User Account Control" window that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't INTERFERE with your antivirus program

                  6. Read So how did I get infected in the first place?: http://www.castlecops.com/postlite7736-.html

                  7. Let me know, how your computer is doing.
                  The sign of a clean machine...

                  3086.

                  Solve : Need help. Question about the first aid recovery cd.?

                  Answer»

                  Thanks Broni. I really appreciate it!
                  Please tell me what else needs to be done.

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 9:04:38, on 2008/06/06
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\SYSTEM32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\SYSTEM32\Ati2evxx.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\rundll32.exe
                  C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                  C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                  C:\Program Files\Logitech\QuickCam\Quickcam.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\WINDOWS\system32\conime.exe
                  C:\Program Files\Verizon Online\Help Support\bin\mpbtn.exe
                  C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R3 - URLSearchHook: Yahoo! 、uィ罔C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: ATLAS Translation Bar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V11\ATLIECP.DLL
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
                  O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O3 - Toolbar: ATLAS Translation Bar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V11\ATLIECP.DLL
                  O3 - Toolbar: Yahoo! 、uィ罔C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
                  O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                  O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O4 - Global Startup: Verizon Online Help & Support.lnk = C:\Program Files\Verizon Online\Help Support\bin\matcli.exe
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Translate by ATLAS - C:\Program Files\ATLAS V11\Atlscript.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: ATLAS Translation - {B7707A72-4355-11D4-82BD-00000EBBEF8D} - C:\Program Files\ATLAS V11\Atlscript.html
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - ESC Trusted Zone: http://*.update.microsoft.com
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL (file missing)
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                  O23 - Service: Microsoft Office Groove Audit Service - Unknown owner - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (file missing)
                  O23 - Service: Microsoft Office Diagnostics Service (odserv) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (file missing)
                  O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

                  --
                  End of file - 8821 bytes
                  Good JOB

                  Your computer is clean

                  1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the TASKS column on the left side
                  4. Click on Continue on the "User Account Control" window that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against MALWARES. It won't interfere with your antivirus program

                  6. Read So how did I get infected in the first place?: http://www.castlecops.com/postlite7736-.html

                  7. Let me know, how your computer is doing.
                  Thank you so much Broni I can't thank you enough! I thought my computer was terminally ILL but you saved me!
                  Its like new again! This is the last Hijack file after I did what you said. I'll be more careful in the future

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 6:33:20, on 2008/06/06
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\SYSTEM32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\SYSTEM32\Ati2evxx.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\mozilla.org\Mozilla\mozilla.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R3 - URLSearchHook: Yahoo! 、uィ罔C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: ATLAS Translation Bar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V11\ATLIECP.DLL
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
                  O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O3 - Toolbar: ATLAS Translation Bar - {3C6301ED-0F78-4AF2-8150-D9C052361A8E} - C:\Program Files\ATLAS V11\ATLIECP.DLL
                  O3 - Toolbar: Yahoo! 、uィ罔C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Translate by ATLAS - C:\Program Files\ATLAS V11\Atlscript.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: ATLAS Translation - {B7707A72-4355-11D4-82BD-00000EBBEF8D} - C:\Program Files\ATLAS V11\Atlscript.html
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - ESC Trusted Zone: http://*.update.microsoft.com
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                  O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - (no file)
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                  O23 - Service: Microsoft Office Groove Audit Service - Unknown owner - C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (file missing)
                  O23 - Service: Microsoft Office Diagnostics Service (odserv) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (file missing)
                  O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

                  --
                  End of file - 6674 bytes
                  You're very welcome
                  Enjoy your "new" computer....

                  3087.

                  Solve : Something is blocking my games from starting up?

                  Answer»

                  this is when i RESTARTED my computer and took it off safe mode. I did everything you told me to



                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 1:20:13 AM, on 5/14/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  F:\WINDOWS\System32\smss.exe
                  F:\WINDOWS\system32\winlogon.exe
                  F:\WINDOWS\system32\services.exe
                  F:\WINDOWS\system32\lsass.exe
                  F:\WINDOWS\system32\svchost.exe
                  F:\WINDOWS\System32\svchost.exe
                  F:\WINDOWS\system32\spoolsv.exe
                  F:\Program Files\ESET\ESET NOD32 Antivirus\EKRN.exe
                  F:\WINDOWS\system32\PnkBstrA.exe
                  F:\WINDOWS\system32\PnkBstrB.exe
                  F:\Program Files\Webroot\Washer\WasherSvc.exe
                  F:\WINDOWS\Explorer.EXE
                  F:\WINDOWS\RTHDCPL.EXE
                  F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                  F:\Program Files\DNA\btdna.exe
                  F:\Program Files\Webroot\Washer\wwDisp.exe
                  F:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  F:\WINDOWS\system32\wuauclt.exe
                  F:\WINDOWS\system32\wuauclt.exe
                  E:\GF8\Win2KXP 162.18\setup.exe
                  E:\GF8\Win2KXP 162.18\setup.exe
                  F:\PROGRA~1\Mozilla Firefox\firefox.exe
                  F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                  F2 - REG:system.ini: UserInit=F:\WINDOWS\system32\Userinit.exe
                  O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
                  O2 - BHO: (no name) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                  O2 - BHO: (no name) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
                  O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - (no file)
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                  O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - F:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL (file missing)
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [egui] "F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "F:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
                  O4 - HKLM\..\Run: [StopSignSsSsMon] Rundll32.exe "F:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] F:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                  O4 - HKCU\..\Run: [swg] F:\WINDOWS\system32\regsvr32.exe
                  O4 - HKCU\..\Run: [BitTorrent DNA] "F:\Program Files\DNA\btdna.exe"
                  O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] F:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
                  O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "F:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [Window Washer] "F:\Program Files\Webroot\Washer\wwDisp.exe"
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  O4 - Global Startup: Adobe Reader Synchronizer.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                  O8 - Extra context menu item: Download All by FlashGet - F:\Program Files\FlashGet\jc_all.htm
                  O8 - Extra context menu item: Download using FlashGet - F:\Program Files\FlashGet\jc_link.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
                  O20 - Winlogon Notify: Fly - F:\WINDOWS\
                  O20 - Winlogon Notify: LOVE - F:\WINDOWS\
                  O23 - Service: McAfee Application Installer Cleanup (0005051207003295) (0005051207003295mcinstcleanup) - Unknown owner - F:\DOCUME~1\Zuratai\LOCALS~1\Temp\000505~1.EXE (file missing)
                  O23 - Service: Apache2.2 - Unknown owner - F:\Documents and Settings\Zuratai\Desktop\AC Web Ultimate Repack\Server\apache\bin\apache.exe (file missing)
                  O23 - Service: eAcceleration Notification Service (eac_notifysvc) - Unknown owner - F:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe (file missing)
                  O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - Unknown owner - F:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe (file missing)
                  O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - F:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                  O23 - Service: Eset Service (ekrn) - ESET - F:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                  O23 - Service: McAfee E-mail Proxy (Emproxy) - Unknown owner - F:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision CORPORATION - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: McAfee HackerWatch Service - Unknown owner - F:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe (file missing)
                  O23 - Service: McAfee Update Manager (mcmispupdmgr) - Unknown owner - F:\PROGRA~1\McAfee\MSC\mcupdmgr.exe (file missing)
                  O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (file missing)
                  O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - f:\program files\common files\mcafee\mna\mcnasvc.exe (file missing)
                  O23 - Service: McAfee Scanner (McODS) - Unknown owner - F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
                  O23 - Service: McAfee Protection Manager (mcpromgr) - Unknown owner - F:\PROGRA~1\McAfee\MSC\mcpromgr.exe (file missing)
                  O23 - Service: McAfee Redirector Service (McRedirector) - Unknown owner - f:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe (file missing)
                  O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
                  O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe
                  O23 - Service: PnkBstrB - Unknown owner - F:\WINDOWS\system32\PnkBstrB.exe
                  O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - F:\Program Files\Webroot\Washer\WasherSvc.exe

                  --
                  End of file - 9060 bytes

                  3088.

                  Solve : can't access certain websites?

                  Answer»

                  Quote from: DANKK on May 29, 2008, 11:11:36 PM

                  Quote from: Broni on May 29, 2008, 06:17:39 PM
                  I want you to run one more program (if it'll run)...

                  Download SDFix (http://downloads.andymanchesta.com/removaltools/sdfix.exe) and save it to your Desktop.

                  * Run the SDFix.exe by double clicking on it.
                  * Allow it to install into the DEFAULT location which is c:\SDFix
                  * Now please reboot your computer into Safe Mode:
                  # After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                  # Instead of Windows loading as normal, the Advanced Options Menu should appear;
                  # Select the first option, to run Windows in Safe Mode, then press Enter.
                  * When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
                  * Type Y to begin the cleanup process.
                  * It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
                  * Press any Key and it will restart the PC.
                  * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                  * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
                  * Attach the Report.txt file to your next message.

                  SDFix: Version 1.186
                  Run by DAN on Thu 05/29/2008 at 06:40 PM

                  Microsoft Windows XP [Version 5.1.2600]
                  RUNNING From: C:\SDFix

                  Checking Services :


                  Restoring Windows Registry Values
                  Restoring Windows Default Hosts File
                  Restoring Default Desktop Wallpaper

                  Rebooting


                  Checking Files :

                  Trojan Files Found:

                  C:\WINDOWS\system32\000060.exe - Deleted
                  C:\WINDOWS\system32\000090.exe - Deleted
                  C:\WINDOWS\astctl32.ocx - Deleted
                  C:\WINDOWS\default.htm - Deleted
                  C:\WINDOWS\hosts - Deleted
                  C:\WINDOWS\rundll32.vbe - Deleted
                  C:\WINDOWS\system32\drivers\hosts - Deleted
                  C:\WINDOWS\system32\hljwugsf.bin - Deleted
                  C:\WINDOWS\xxxvideo.hta - Deleted





                  Removing Temp Files

                  ADS Check :



                  Final Check :

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware

                  detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-05-29 21:48:00
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clb.dll]
                  "0"=hex:00,00,28,0a,01,00,05,00
                  "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clbcatex.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clbcatq.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

                  \Minimal\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

                  \Network\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clbdriv

                  er]
                  "start"=dword:00000001
                  "type"=dword:00000001
                  "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver

                  s\vmdesched.sys"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clb.dll]
                  "0"=hex:00,00,28,0a,01,00,05,00
                  "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clbcatex.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clbcatq.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Min

                  imal\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Net

                  work\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\clbdriver]
                  "start"=dword:00000001
                  "type"=dword:00000001
                  "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver

                  s\vmdesched.sys"

                  scanning hidden registry entries ...

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

                  NT\CurrentVersion\clbImageData]
                  "affid"="7"
                  "subid"="run04"
                  "control"=hex:1a,00,15,13,07,11,18,1f,14,0a,49,09,4b,1a,09,50

                  ,11,e5,f5
                  "prov"="10010"
                  "googleadserver"="pagead2.googlesyndication.com"
                  "flagged"=dword:00000001
                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\

                  Shell

                  Extensions\Approved\{443EA021-5049-9583-E2C5-EC68521FB889}]
                  "famgilbokocb"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c,

                  62,6b,00,02
                  "famgilbokopa"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c,

                  62,6b,00,02
                  "faaghhcjldie"=hex:61,61,00,00

                  scanning hidden files ...

                  C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll 498688 bytes

                  executable
                  C:\WINDOWS\system32\drivers\vmdesched.sys 6656 bytes

                  executable
                  C:\WINDOWS\system32\clb.dll 10752 bytes executable
                  C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable
                  C:\WINDOWS\system32\clbcatq.dll 498688 bytes executable
                  C:\WINDOWS\system32\cdosys.dll 31560 bytes executable
                  C:\WINDOWS\system32\clbinit.dll 1695 bytes
                  C:\WINDOWS\system32\dllcache\clb.dll 10752 bytes executable
                  C:\WINDOWS\system32\dllcache\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\system32\dllcache\clbcatq.dll 498688 bytes

                  executable
                  C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 501248 bytes

                  executable

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 1
                  hidden files: 13


                  Remaining Services :




                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda

                  ccess\parameters\firewallpolicy\standardprofile\authorizedapp

                  lications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg

                  r.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\Program Files\\AMERICA Online

                  9.0\\waol.exe"="C:\\Program Files\\America Online

                  9.0\\waol.exe:*:Enabled:America Online 9.0"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\AWHOST32.EXE:*:Disabled:pcAnywhe

                  re Host Service"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Disabled:pcAnywher

                  e Remote Service"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
                  "C:\\Program Files\\LIMEWIRE\\LimeWire.exe"="C:\\Program

                  Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                  "%windir%\\Network

                  Diagnostic\\xpnetdiag.exe"="%windir%\\Network

                  Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\APC\\PowerChute Business

                  Edition\\server\\pbeserver.exe"="C:\\Program

                  Files\\APC\\PowerChute Business

                  Edition\\server\\pbeserver.exe:*:Disabled:PowerChute Business

                  Edition Server"
                  "C:\\Program Files\\Common

                  Files\\AOL\\1170644168\\ee\\aolsoftware.exe"="C:\\Program

                  Files\\Common

                  Files\\AOL\\1170644168\\ee\\aolsoftware.exe:*:Enabled:AOL

                  Shared Components"
                  "C:\\Program Files\\Common

                  Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common

                  Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
                  "C:\\Program Files\\Google\\Google

                  Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google

                  Talk\\googletalk.exe:*:Enabled:Google Talk"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\WINAW32.EXE"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\WINAW32.EXE:*:Disabled:pcAnywher

                  e Main Program"
                  "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program

                  Files\\AIM6\\aim6.exe:*:Enabled:AIM"
                  "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program

                  Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                  "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program

                  Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour"
                  "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program

                  Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype"
                  "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program

                  Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda

                  ccess\parameters\firewallpolicy\domainprofile\authorizedappli

                  cations\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg

                  r.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\Program Files\\America Online

                  9.0\\waol.exe"="C:\\Program Files\\America Online

                  9.0\\waol.exe:*:Enabled:America Online 9.0"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
                  "%windir%\\Network

                  Diagnostic\\xpnetdiag.exe"="%windir%\\Network

                  Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                  Remaining Files :


                  File Backups: - C:\SDFix\backups\backups.zip

                  Files with Hidden Attributes :

                  Wed 1 Sep 2004 54,384 A..H. --- "C:\Program

                  Files\America Online 9.0\aolphx.exe"
                  Wed 1 Sep 2004 156,784 A..H. --- "C:\Program

                  Files\America Online 9.0\aoltray.exe"
                  Wed 1 Sep 2004 31,344 A..H. --- "C:\Program

                  Files\America Online 9.0\RBM.exe"
                  Tue 20 May 2008 377 A..H. --- "C:\Program

                  Files\InterActual\InterActual Player\iti705.tmp"
                  Tue 20 May 2008 114 A..H. --- "C:\Program

                  Files\InterActual\InterActual Player\itiAF.tmp"
                  Wed 19 Apr 2006 95,892 A..H. --- "C:\Program

                  Files\Walgreens\Walgreens PhotoShow 4\data\Walgreens

                  PhotoShow Express.exe"
                  Thu 8 May 2008 0 A..H. ---

                  "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8

                  c0d990dc65796\BIT5.tmp"
                  Wed 25 May 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
                  Wed 25 May 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
                  Fri 10 Jun 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
                  Fri 10 Jun 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"

                  Finished!




                  any further hope on this before I reformat the harddrrive?I had a similar problem, then I found his forum... try checking your "host" file... it worked for me


                  http://www.broadbandreports.com/forum/remark,10186774
                  I lost this thread, somehow. I think, I didn't get any email notification.
                  DANKK, if you're still there, please, update me on your computer status.Quote from: Broni on June 06, 2008, 03:24:12 PM
                  I lost this thread, somehow. I think, I didn't get any email notification.
                  DANKK, if you're still there, please, update me on your computer status.
                  I want you to run one more program (if it'll run)...

                  Download SDFix (http://downloads.andymanchesta.com/removaltools/sdfix.exe) and save it to your Desktop.

                  * Run the SDFix.exe by double clicking on it.
                  * Allow it to install into the default location which is c:\SDFix
                  * Now please reboot your computer into Safe Mode:
                  # After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                  # Instead of Windows loading as normal, the Advanced Options Menu should appear;
                  # Select the first option, to run Windows in Safe Mode, then press Enter.
                  * When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
                  * Type Y to begin the cleanup process.
                  * It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
                  * Press any Key and it will restart the PC.
                  * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                  * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
                  * Attach the Report.txt file to your next message.


                  SDFix: Version 1.186
                  Run by DAN on Thu 05/29/2008 at 06:40 PM

                  Microsoft Windows XP [Version 5.1.2600]
                  Running From: C:\SDFix

                  Checking Services :


                  Restoring Windows Registry Values
                  Restoring Windows Default Hosts File
                  Restoring Default Desktop Wallpaper

                  Rebooting


                  Checking Files :

                  Trojan Files Found:

                  C:\WINDOWS\system32\000060.exe - Deleted
                  C:\WINDOWS\system32\000090.exe - Deleted
                  C:\WINDOWS\astctl32.ocx - Deleted
                  C:\WINDOWS\default.htm - Deleted
                  C:\WINDOWS\hosts - Deleted
                  C:\WINDOWS\rundll32.vbe - Deleted
                  C:\WINDOWS\system32\drivers\hosts - Deleted
                  C:\WINDOWS\system32\hljwugsf.bin - Deleted
                  C:\WINDOWS\xxxvideo.hta - Deleted





                  Removing Temp Files

                  ADS Check :



                  Final Check :

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware

                  detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-05-29 21:48:00
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clb.dll]
                  "0"=hex:00,00,28,0a,01,00,05,00
                  "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clbcatex.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUIL

                  anguages\RCV2\clbcatq.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

                  \Minimal\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

                  \Network\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clbdriv

                  er]
                  "start"=dword:00000001
                  "type"=dword:00000001
                  "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver

                  s\vmdesched.sys"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clb.dll]
                  "0"=hex:00,00,28,0a,01,00,05,00
                  "1"=hex:b6,00,b6,eb,2f,6b,03,cb,5a,e8,c3,ac,b9,40,38,e1
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clbcatex.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:cf,24,2a,85,a4,d7,fe,3c,03,76,96,fe,18,b6,ec,d3
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILangu

                  ages\RCV2\clbcatq.dll]
                  "0"=hex:2a,00,3e,11,0c,00,d1,07
                  "1"=hex:6a,b7,9d,1d,7d,d8,1d,46,23,79,12,2a,da,6a,19,42
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Min

                  imal\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Net

                  work\vmdesched.sys]
                  @="driver"
                  [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\clbdriver]
                  "start"=dword:00000001
                  "type"=dword:00000001
                  "imagepath"=str(2):"\??\globalroot\systemroot\system32\driver

                  s\vmdesched.sys"

                  scanning hidden registry entries ...

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

                  NT\CurrentVersion\clbImageData]
                  "affid"="7"
                  "subid"="run04"
                  "control"=hex:1a,00,15,13,07,11,18,1f,14,0a,49,09,4b,1a,09,50

                  ,11,e5,f5
                  "prov"="10010"
                  "googleadserver"="pagead2.googlesyndication.com"
                  "flagged"=dword:00000001
                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\

                  Shell

                  Extensions\Approved\{443EA021-5049-9583-E2C5-EC68521FB889}]
                  "famgilbokocb"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c,

                  62,6b,00,02
                  "famgilbokopa"=hex:68,61,6f,62,6b,61,69,6d,68,61,64,62,6f,6c,

                  62,6b,00,02
                  "faaghhcjldie"=hex:61,61,00,00

                  scanning hidden files ...

                  C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll 498688 bytes

                  executable
                  C:\WINDOWS\system32\drivers\vmdesched.sys 6656 bytes

                  executable
                  C:\WINDOWS\system32\clb.dll 10752 bytes executable
                  C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable
                  C:\WINDOWS\system32\clbcatq.dll 498688 bytes executable
                  C:\WINDOWS\system32\cdosys.dll 31560 bytes executable
                  C:\WINDOWS\system32\clbinit.dll 1695 bytes
                  C:\WINDOWS\system32\dllcache\clb.dll 10752 bytes executable
                  C:\WINDOWS\system32\dllcache\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\system32\dllcache\clbcatq.dll 498688 bytes

                  executable
                  C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 110080 bytes

                  executable
                  C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 501248 bytes

                  executable

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 1
                  hidden files: 13


                  Remaining Services :




                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda

                  ccess\parameters\firewallpolicy\standardprofile\authorizedapp

                  lications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg

                  r.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\Program Files\\America Online

                  9.0\\waol.exe"="C:\\Program Files\\America Online

                  9.0\\waol.exe:*:Enabled:America Online 9.0"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\AWHOST32.EXE:*:Disabled:pcAnywhe

                  re Host Service"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Disabled:pcAnywher

                  e Remote Service"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
                  "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program

                  Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                  "%windir%\\Network

                  Diagnostic\\xpnetdiag.exe"="%windir%\\Network

                  Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\APC\\PowerChute Business

                  Edition\\server\\pbeserver.exe"="C:\\Program

                  Files\\APC\\PowerChute Business

                  Edition\\server\\pbeserver.exe:*:Disabled:PowerChute Business

                  Edition Server"
                  "C:\\Program Files\\Common

                  Files\\AOL\\1170644168\\ee\\aolsoftware.exe"="C:\\Program

                  Files\\Common

                  Files\\AOL\\1170644168\\ee\\aolsoftware.exe:*:Enabled:AOL

                  Shared Components"
                  "C:\\Program Files\\Common

                  Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common

                  Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
                  "C:\\Program Files\\Google\\Google

                  Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google

                  Talk\\googletalk.exe:*:Enabled:Google Talk"
                  "C:\\Program

                  Files\\Symantec\\pcAnywhere\\WINAW32.EXE"="C:\\Program

                  Files\\Symantec\\pcAnywhere\\WINAW32.EXE:*:Disabled:pcAnywher

                  e Main Program"
                  "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program

                  Files\\AIM6\\aim6.exe:*:Enabled:AIM"
                  "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program

                  Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                  "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program

                  Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour"
                  "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program

                  Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype"
                  "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program

                  Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda

                  ccess\parameters\firewallpolicy\domainprofile\authorizedappli

                  cations\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmg

                  r.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\Program Files\\America Online

                  9.0\\waol.exe"="C:\\Program Files\\America Online

                  9.0\\waol.exe:*:Enabled:America Online 9.0"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
                  "C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common

                  Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
                  "%windir%\\Network

                  Diagnostic\\xpnetdiag.exe"="%windir%\\Network

                  Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                  Remaining Files :


                  File Backups: - C:\SDFix\backups\backups.zip

                  Files with Hidden Attributes :

                  Wed 1 Sep 2004 54,384 A..H. --- "C:\Program

                  Files\America Online 9.0\aolphx.exe"
                  Wed 1 Sep 2004 156,784 A..H. --- "C:\Program

                  Files\America Online 9.0\aoltray.exe"
                  Wed 1 Sep 2004 31,344 A..H. --- "C:\Program

                  Files\America Online 9.0\RBM.exe"
                  Tue 20 May 2008 377 A..H. --- "C:\Program

                  Files\InterActual\InterActual Player\iti705.tmp"
                  Tue 20 May 2008 114 A..H. --- "C:\Program

                  Files\InterActual\InterActual Player\itiAF.tmp"
                  Wed 19 Apr 2006 95,892 A..H. --- "C:\Program

                  Files\Walgreens\Walgreens PhotoShow 4\data\Walgreens

                  PhotoShow Express.exe"
                  Thu 8 May 2008 0 A..H. ---

                  "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8

                  c0d990dc65796\BIT5.tmp"
                  Wed 25 May 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
                  Wed 25 May 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
                  Fri 10 Jun 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
                  Fri 10 Jun 2005 8 A..H. --- "C:\Documents and

                  Settings\All Users\Application

                  Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"

                  Finished!


                  How is your computer doing?Quote from: Broni on June 06, 2008, 11:18:22 PM
                  How is your computer doing?
                  [/quote

                  still the same. can't access some sites. some of them takes me to differnet sites.
                  See, if Malwarebytes will run now.
                  3089.

                  Solve : Wondering if desktop computer is infected ...?

                  Answer» ALRIGHT, I had a problem with the whole bugs screensaver, blue/yellow warning on this desktop, but a couple months ago, it stopped after I ran Malwarebyte's Anti-Malware.

                  I'm on a different computer [different than the laptop that evilfantasy helped me to fix] that I also believe is infected.

                  Before following the procedures in the malware removal post, our internet was just HORRIBLE on this computer. Meaning, it WOULD not receive a signal and also, when we tried to access our homepage, it always said page cannot be displayed. With any page, it mentioned the same error message.

                  However, after running the scans and restarting the computer, we picked up an EXCELLENT signal and our internet is just great. That's how I'm able to type out this message. =)

                  Anyway, here's all the logs that you requested. I just want to cure this computer from any other infections that aren't surfacing yet or that I can't see.

                  =)

                  Thanks for the help !!

                  [recovering space - attachment deleted by admin]Oh!

                  Forgot to mention the fact that the computer now has set restrictions on a lot of options on the computer, such as assessing the Control Panel, the remove/add programs, the desktop properties, etc. The TASK Manager used to be restricted, but I found some .reg file extension from a website designed to fix this problem, saved it on the computer desktop, and it fixed after reboot. The other registry key file edit things for the control panel, add remove programs, etc, would not work; even after reboot it did not work.

                  Another thing is SOMETIMES the desktop likes to freeze, and all the icons on the desktop would disappear, it the computer would be at a stand still. The only way to get out of this problem is just to turn the computer off by pressing the power button. The screen itself would not refresh, it just blanks out. I can see, you're using two antivirus programs: Avira, and McAfee. It looks like Avira is active, and McAfee used to be your antivirus.
                  Please EXPLAIN. One of them has to go.I'll get rid of Mcafee because I recently downloaded Avira to start the malware removal process. I didn't think we had an antivirus program that was active on that computer.

                  Thanks for that information. Quote
                  I didn't think we had an antivirus program that was active on that computer.
                  Not good.

                  Use this tool: http://majorgeeks.com/McAfee_Consumer_Product_Removal_Tool_d5420.html to remove McAfee.
                  When done, post new HJT log.
                  3090.

                  Solve : Re: Windows Security Center?

                  Answer»

                  Thanks Savior, I am having the same problems as Arwest had on May 1, 2008,
                  ""I have a HP Pavilion Computer running MICROSOFT XP. When I turned on my compute this morning a Windows Security Center box popped up telling me I was not protected with anitvirus and spyware, even though I have norton antivirus, webroot spyware and adaware, which are all run regularly. When I clicked on the Windows Security box to INSTALL, my Norton BLOCKED it and labeled it a virus. After running all my anitvirus and several spyware programs, I cannot get rid of this. It continues to pop up boxes telling me to click on the security button on my taskbar and download.""

                  The only difference is My computer is a Dell Optiplex 320.Can anyone help me .Moved to Computer Viruses and Spyware.

                  We ask that you read and follow all instructions in the pinned topic titled Please read this before requesting MALWARE removal help. Following the steps in the Guide will ALLOW for us to quickly help you with specific fixes for what may remain on your system.

                  When you have completed those steps post the logs in this thread.

                  3091.

                  Solve : Malware Protector 2008/Bug Screen and Background virus?

                  Answer»

                  Last night I was attacked by this when visiting a video game site and quickly exited. Im running xp with sp2 and Webroot Spy Sweeper with Antivirus. I removed the Malware Protector 2008 shortly after it installed using the Control panel. I think the spy sweeper blocked most of it but I think some traces still remain.

                  I followed the steps in the thread before posting and it seems the background and bug screensaver is gone but if someone could just take a quick look at the logs and tell me how bad the infestation was and if it was completely removed, it would be very much appreciated and thanks.




                  [recovering space - attachment DELETED by admin]Do you use Norton as your AV, and firewall? It's not clear from the log, if it's running in full.

                  Open HJT, checkmark all O18 entries, click "Fix checked", and post new log.I fixed the entries and re-scaned with Hijack. Webroot spysweeper also has antivirus protection and my firewall is the regular Windows one.

                  [recovering space - attachment deleted by admin]It's still not clear. What's the story with Norton?
                  Spysweeper is NOT a substitute for antivirus program.I used to have Norton installed but removed it when I got my new AV. The full name of my AV is "Webroot Spy Sweeper with Antivirus" if that was the thing that was confusing."Webroot Spy Sweeper with Antivirus"...fair enough, but I can see, the above product includes firewall, as well. Is it disabled, since you have Windows firewall up?
                  Run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039 to remove Norton's leftovers, answer my question about firewall, and post new HJT log.

                  I'm off to EURO 2008 soccer game, so I'll be out for couple of hours.Ok, Norton's been removed, Av firewall is disabled which is why I have Windows firewall and heres the new log.

                  Also should I re-scan in safe mode or is that unnessary?

                  Thanks for helping me out Broni

                  [recovering space - attachment deleted by admin]You're welcome
                  I'm not FAMILIAR with Webroot firewall, but Windows firewall is definitely the lowest quality firewall, so you may reconsider.

                  ...and no, HJT has to be run in Normal Mode.

                  1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no ACTUAL program will be removed):

                  - *O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
                  - *O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                  - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  - O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
                  - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  - O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
                  - *O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                  - *O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  - *O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware.exe"
                  - O4 - Startup: GameSpot Download Manager.lnk = D:\stuff\GameSpot\GameSpotDownloadManager_Win32.exe
                  - O4 - Global Startup: Remocon Driver.lnk = ?
                  - O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  - O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  - O16 - DPF: {00000000-7777-0704-0B53-2C8830E9FAEC} - http://gn.one2bill.de/soft/axload.cab
                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SASWINLO.dll

                  4. Click on Fix checked button.

                  5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                  7. Delete following files/folders (if present):

                  - sysrest32.exe, regscan.exe files from C:\WINDOWS\system32
                  - GameSpotDownloadManager_Win32.exe file from D:\stuff\GameSpot

                  8. Restart in Normal Mode.

                  9. Post new HijackThis log.Ok followed everything you said but the files in Safe mode weren't present and heres the new log:

                  [Saving space - attachment deleted by admin]Very good

                  Your computer is clean

                  1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. GET "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the Tasks column on the left side
                  4. Click on Continue on the "User Account Control" window that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. (OPTIONAL) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                  6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                  7. Let me know, how your computer is doing.
                  Thank you very much Broni It was a big help and it seems CCleaner is similar to the program Window Washer.You're very welcome
                  Is computer doing OK?Yes, computers ok.

                  After the computer got infected I didn't really notice any significant change in performance besides the the bug screen saver and background change.

                  Does that mean it wasnt that bad?If you could only see some other logs....
                  You had just light infection.

                  3092.

                  Solve : PC running slow after virus removal?

                  Answer»

                  AVG 8.0 still would not recognize my Win XP SP2.
                  SUPERAntiSpyware still crashes during installation.

                  Other than that, no problem.

                  Thanks.1. Download this diagnostics tool MGADiag.exe and save this to your Desktop.
                  2. Double-click on MGADiag.exe and click Continue
                  3. When the program has finished, click on Copy
                  4. Post the results in your next reply.MGADiag result attached.
                  Thanks.

                  [Saving space - attachment deleted by admin]This may be the problem with the installs.

                  Right now, your computer has a Volume Licensing edition of XP installed, and that installation was done with a now-blocked Volume Licensing Key (VLK). VLKs are blocked by Microsoft at the request of the original keyholder for such reasons as the key was lost, stolen, compromised, misused, or expired. Also, MS may have blocked the key if it notices a pattern of misuse or more installations of XP using that key than authorized.

                  As a rule, VL editions of XP should not be sold to individual consumers. Businesses, schools and gov'ts normally use VL editions for flexibility in installing many computers.

                  This may be why you are getting errors on trying to install some programs and you likely aren't able to install any MS updates either.

                  Look on the computer or in the MATERIALS that came with your computer to see if you have a Certificate of Authenticity (COA).

                  Look for:

                  1. What edition of Windows XP is it for, Home, Pro, Media Center, or some other edition or version of Windows?
                  2. Does it read "OEM Software" or "OEM Product" in black lettering?
                  3. Or, does it have the computer manufacturer's name in black lettering?

                  Not sure what to look for and more information Click here: http://www.microsoft.com/resources/howtotell/en/coa.mspx

                  If you have been sold this copy of XP as new then go here:
                  http://www.microsoft.com/resources/howtotell/reports/report.aspx?displaylang=en

                  You can call 1-866-PCSAFETY (1-866-727-2338). This phone number is for virus and other security-related support. It is available 24 hours a day for the U.S. and Canada. They will help you get your Windows validated.

                  Let me know if you need any more information and I will try to help. At this POINT there isn't MUCH I can do.


                  The Windows came together with the computer when I bought it from the shop.
                  Those information you want me to check is suppose to be on the stickers on the casing, if I'm not mistaken. Unfortunately, my PC is ALMOST 4 years old and I only have some "remaining" of the stickers left on the casing, and I can barely read the printing on it.
                  You said that "VL editions of XP should not be sold to individual consumers", so I'm wondering whether the shop has bought such VL and use it on the computers sold. While VL allows multiple use of the license, they may have misused the VL on PC sold rather than their own PC at work. Is that possible to happen and is that a fault? I can hardly go back and argue with the shop as it's been so many years and I don't think they will admit the fault.

                  Anyway, since it's the problem with the Windows license, and my computer seems to be running fine at the moment, I guess that should be it for now.

                  Thanks for all your support.
                  Thanks to Broni too.
                  The shop probably has a business license to install and sell Windows. The license may have run out and they didn't renew it. Maybe they now install Vista so thought the XP license didn't need to be renewed? Don't know for sure, just speculating. MS is good about working with people on renewing their Windows. It may take supernatural PATIENCE and a bit of your time but it would be best to ring them up and give it a try. You may even call the shop who sold it to you. They should know that their license had expired and they have left their customers hanging. They may even know of a better (quicker) way to take care of it. Or they were installing illegitimate copies, Then MS should be made aware of it.

                  If you have been sold this copy of XP as new then go here:
                  http://www.microsoft.com/resources/howtotell/reports/report.aspx?displaylang=en

                  In the event you are a victim of piracy, help is available from this site: http://www.microsoft.com/piracy/

                  3093.

                  Solve : I to have the bug screensaver herpies?

                  Answer»

                  Quote

                  Is bad computer still in Safe Mode?

                  Yes but just to make sure I wasn't crazy I put memory stick back in good computer the program fired right up.

                  I tried opening superantivirus on bad computer in both mode's.. same ERROR message every time

                  "THE DRIVE OR NETWORK CONNECTION THAT THE SHORTCUT "BOOTSAFE.INK' REFERSE TO IS UNAVAILABLE. MAKE SURE THAT THE DISK IS PROPERLY INSERTED OR THE NETWORK RESOURCE IS AVAILABLE, AND THEN TRY AGAIN.Quote
                  BOOTSAFE.LNK not .INK is part of Superantispyware....
                  Try Malwarebytes.Quote from: Broni on June 11, 2008, 10:42:23 PM
                  BOOTSAFE.LNK not .INK is part of Superantispyware....
                  Try Malwarebytes.

                  ya TYPO on the .ink do yo have alink to malwarebytes ?..
                  My instructions?O... sorry thanx
                  malwarebytes is not opening eather ?... Try HijackThis, then.Quote from: Broni on June 12, 2008, 07:57:30 PM
                  Try HijackThis, then.

                  I tried .... it would'nt open I get the same error message
                  I'm afraid, you're facing Windows reinstall.Transfer SDFix over and run it in Safe Mode. Post the log when complete.

                  Download SDFix.exe and save it to your Desktop.

                  Double click SDFix.exe and it will extract the files to %systemdrive%
                  (Drive that CONTAINS the Windows Directory, TYPICALLY C:\SDFix)

                  Now then reboot your computer in Safe Mode by doing the following:

                  • Restart your computer
                  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
                  • Select the first option, to run Windows in Safe Mode, then press Enter.
                  • Choose your usual account.
                  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
                  • Type Y to begin the cleanup process.
                  • It will remove any Trojan Services and Registry Entries that it FINDS then prompt you to press any key to Reboot.
                  • Press any Key and it will restart the PC.
                  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
                    (Report.txt will also be copied to Clipboard).
                  • Finally copy and paste the contents of the results file Report.txt in your next reply.
                  If SDFix won't run or you get errors, follow the link for instructions on running SDFix. How to use SDFix

                  Evil,

                  hey bro I just tried double clicking SDFix in safe mode and I get nothing but a hour glass for like 0.2 sec..

                  Broni

                  Could you point me out to the best wright up on installing windows ?..

                  Thanks in advance & for every body who worked with me.

                  XP clean install: http://www.michaelstevenstech.com/cleanxpinstall.htmlI've still got a few more things to try unless you would rather just reinstall.

                  Download Deckard's Association File Tool (DAFT) and save it to your desktop.
                  • Rename daft.exe to daft.com and double click on it to run.
                  • Read the disclaimer and click OK.
                  • Click on the Scan button.
                  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a checkmark (tick) in the boxes in question.
                  • Click the Fix button.
                  3094.

                  Solve : Win32.trojan?

                  Answer»

                  Is there a program that can get rid of Win32.trojan , Win32.backdoor , and many more.
                  I have had this problem for a while. Yes, i have tried to get rid of them by zonealarm, avast, macafee, avg, ect. But i want to know if there is a program that is specifically designed to get rid of only those. I am aware that they come back but I just aant something to get rid of them when I want to.

                  thx

                  Print these instructions out.

                  1. Download SUPERAntiSpyware FREE for Home Users:
                  http://www.superantispyware.com/

                  * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                  * An icon will be created on your desktop. Double-click that icon to launch the program.
                  * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                  * Close SUPERAntiSpyware.

                  PHYSICALLY DISCONNECT FROM THE INTERNET

                  Restart computer in Safe Mode.
                  To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll SEE "Safe Mode" in all four corners of your screen

                  * Open SUPERAntiSpyware.
                  * Under "Configuration and Preferences", click the Preferences button.
                  * Click the Scanning Control tab.
                  * Under Scanner Options make sure the following are checked (leave all others unchecked):
                  o Close browsers before scanning.
                  o SCAN for tracking cookies.
                  o Terminate memory threats before quarantining.
                  * Click the "Close" button to leave the control center screen.
                  * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                  * On the left, make sure you check C:\Fixed Drive.
                  * On the right, under "Complete Scan", choose Perform Complete Scan.
                  * Click "Next" to start the scan. Please be patient while it scans your computer.
                  * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                  * Make sure everything has a checkmark next to it and click "Next".
                  * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                  * If asked if you want to reboot, click "Yes".
                  * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                  o Click Preferences, then click the Statistics/Logs tab.
                  o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                  o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                  o Please COPY and paste the Scan Log results in your next reply.
                  * Click Close to exit the program.
                  Post SUPERAntiSpyware log.

                  RECONNECT TO THE INTERNET

                  RESTART COMPUTER!

                  2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                  * Double-click mbam-setup.exe and follow the prompts to install the program.
                  * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                  * If an update is found, it will download and install the latest version.
                  * Once the program has loaded, select Perform full scan, then click Scan.
                  * When the scan is complete, click OK, then Show Results to view the results.
                  * Be sure that everything is checked, and click Remove Selected.
                  * When completed, a log will open in Notepad.
                  * Post the log back here.

                  The log can also be found here:
                  C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                  Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                  RESTART COMPUTER!

                  3. Download HIJACKTHIS:
                  http://www.snapfiles.com/get/hijackthis.html
                  Post HijackThis log.

                  3095.

                  Solve : Cant open downloaded zips problems- Hijack log?

                  Answer»

                  Okay keep in mind that other people use this pc. But I cant open any zips that are downloaded an hope that something will say in it


                  Logfile of HijackThis v1.99.1
                  Scan saved at 4:17:37 AM, on 6/11/2008
                  Platform: Windows 2000 SP4 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\WINNT\System32\svchost.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\WINNT\system32\nvsvc32.exe
                  C:\WINNT\system32\HPZipm12.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\WINNT\System32\tcpsvcs.exe
                  C:\WINNT\System32\snmp.exe
                  C:\WINNT\system32\stisvc.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINNT\Explorer.EXE
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
                  C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                  C:\WINNT\system32\RUNDLL32.EXE
                  C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                  C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                  C:\Program Files\WordWeb\wweb32.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                  C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\WINNT\system32\wuauclt.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Documents and Settings\Brenda\Desktop\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bedford.net/
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O3 - Toolbar: @msdxmLC.dll,[emailprotected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
                  O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [AVAST!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
                  O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                  O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
                  O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1210897146075
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210944805605
                  O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{1283C04C-107F-4152-B77C-0FCC6C6E5895}: NameServer = 69.72.74.11 69.72.74.3
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{1283C04C-107F-4152-B77C-0FCC6C6E5895}: NameServer = 69.72.74.11 69.72.74.3
                  O23 - SERVICE: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                  O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe

                  What format of a zip file is it.

                  Here is a note of caution. Hard to open zip files are often related to torrents or warez. Once these hard to open files are finally opened you realize you have just unleashed some of the worst malware known to a PC. A new HDD and/or a CPU is often the only option. Some malware writers don't care to scam anyone, rather they get their kicks from destroying as many PC's as they can.rar an the other format that I cant think of it, but its happens to any an all. Anything I can remove in the HijackThe log was fine.

                  What program are you using to open them with?Winzip its an old versionTry one of these.

                  http://www.filehippo.com/download_izarc/

                  http://www.filehippo.com/download_7-zip/I like to use something I'm familiar with but I tried reinstalling it an it still happens.Do you get any error messages?The winzip wizard cant open this file, it doesnt appear to be a vaild archive, If you downloaded this file TRY again. But I tried download it again an so on an so but it keeps coming up. These are files I want an it happens to others as wellWill you send it to me in an email so I can check it out.

                  evilfantasy69 at yahoo.com

                  Post here when it is sent so I will know it's you.

                  This is my spam mail account so nobody else try to email me there. I will just DELETE it.What is it that you want??? It happens to any downloaded file of this kind I dont think it will help.winZIP can't open RAR files, at least not the old version your using. I had the same problem with Powerarchiver, except with PA, I could view the RAR, but not extract it. Try to extract it with the programs evilfantasy suggested, or winRAR. even if they are unfamiliar to you.I use wrar to do that I couldnt think of the other format.I downloaded them with a faster connection an they work. Not sure whats WRONG here.

                  3096.

                  Solve : It is me again lol?

                  Answer»

                  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -&GT; Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mywebsearchservice (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Registry Values Infected:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Registry Data ITEMS Infected:
                  (No malicious items detected)

                  Folders Infected:
                  C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Files Infected:
                  C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\Internet Explorer\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Windows\System32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  C:\Windows\System32\autorun.inf (Trojan.Agent) -> Quarantined and deleted successfully.
                  Very GOOD...HJT
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 11:59:45 PM, on 6/11/2008
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                  C:\Program Files\AVG\AVG8\avgtray.exe
                  C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                  C:\Program Files\AIM6\aim6.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Vongo\Tray.exe
                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                  C:\Program Files\AIM6\aolsoftware.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=PRESARIO&pf=laptop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=PRESARIO&pf=laptop
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                  O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                  O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                  O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                  O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Vongo Tray.lnk = ?
                  O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
                  O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O13 - Gopher Prefix:
                  O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.yorkphoto.com/YorkActivia.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                  --
                  End of FILE - 10159 bytes
                  The log is clean.
                  We'll eliminate some unnecessary startups.
                  Open HJT, and checkmark:
                  - O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  - O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  - O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  - O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
                  - O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  - O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
                  - O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  - O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  - O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                  - O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  - O4 - Global Startup: Vongo Tray.lnk = ?
                  Click "Fix checked" button.

                  Then....

                  1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. GET "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the Tasks column on the left side
                  4. Click on Continue on the "User Account Control" window that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                  6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                  7. Let me know, how your computer is doing.
                  Working wonderful...... thank you so much for the 100000000000000 time lolGive me few more zeros.....LOL

                  Good luck!hmmm.... does hijackthis not work on ALL accts. on the comp.? the guest acct still has things come on even tho we had stopped it on the admin acctAccount doesn't matter.
                  What things?

                  3097.

                  Solve : McAfee or Avast... THAT is a question?

                  Answer»

                  My ISP has the option of having McAfee Antivirus and Firewall being installed.

                  Generally, I steer away from McAfee, but, I will admit, it has gotten better.

                  I am wondering:
                  Protection abilities wise, would it be a better idea to go with Avast or McAfee? Either way, I would be getting it free.

                  What are the pros and cons of either?

                  I am really not sure where to go with that...
                  I dont know if McAfee is as fast with its resident scanner as Avast is... I that with older versions of McAfee, your system could really be slowed down, and that Avast wasnt nearly as bad.. I have no idea about the new one though. Personally, I'd stay away from McAfee.I haven't had any experience with McAfee in years and the only serious problems I have ever assisted in was it's removal, and those seem to be rare 'stubborn' uninstalls. But then there is a tool - McAfee Consumer Product Removal Tool - that takes care of that.

                  Personally I may give it a try since it's free. What's to loose besides gaining KNOWLEDGE?

                  You could always do a before and after with the McAffee Internet Connection Speedometer just for kicks.....Well, I think I will try it. I assume I dont need the MSN Explorer software installed to run it..

                  I can get the McAfee Firewall, and Webroot for MSN, but, I think I will stick to Defender, and Windows Firewall... (Yes, I realize some of you dont think Defender is a good program.. but, it does decently) Windows Defender actually popped up and alerted me to something yesterday (updating and activating the new version of malwarebytes real time protection) which was a shocker. Haven't had that happen in months! Maybe the last update did something?

                  As long as McAfee's firewall and AV will work OK without each other it sounds like a good plan.Quote from: evilfantasy on June 08, 2008, 10:25:22 PM

                  Windows Defender actually popped up and alerted me to something yesterday (updating and activating the new version of malwarebytes real time protection) which was a shocker. Haven't had that happen in months! Maybe the last update did something?

                  As long as McAfee's firewall and AV will work OK without each other it sounds like a good plan.
                  Now to wait for their site to no longer be under maintenance... and to cross my fingers hoping that it WONT end up charging extra due to some random POLICY changes that they made without TELLING anyone down the line way back...
                  3098.

                  Solve : Bug Screensaver Virus...Again?

                  Answer» HELLO. I saw in another THREAD about this virus to DL SuperAntiSpyware, Malwarebytes and HJT. Run them and POST the logs here.

                  I've downloaded the programs and am going to try running them now. Will be back shortly to post the logs. THANKS in advance!
                  3099.

                  Solve : Spyware? Please help me :(?

                  Answer»

                  Very good ....checking....*** You need to update your Java:
                  http://java.sun.com/javase/downloads/index.jsp
                  Java Runtime Environment (JRE) 6 Update 6
                  Uninstall all previous versions of Java through Add\Remove.

                  1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                  - F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wmsdkns.exe,
                  - O2 - BHO: gooochi browser optimizer - {2088e8f7-fefb-c842-4abd-e1e7b58f70ab} - C:\WINDOWS\system32\{3dc0d1fa-3623-ea3c-45d4-ebf60842ffde}.dll (file missing)
                  - O2 - BHO: (no name) - {3AB1D3A2-2273-4107-8BC9-F12B3FE93757} - C:\WINDOWS\system32\qoMFyVPh.dll (file missing)
                  - O2 - BHO: (no name) - {65152511-930D-4EB8-9055-CF66D1CAAA15} - C:\WINDOWS\system32\mlJBUKcy.dll (file missing)
                  - O2 - BHO: {740f18a8-c35d-6669-5d04-910197ec46b6} - {6b64ce79-1019-40d5-9666-d53c8a81f047} - C:\WINDOWS\system32\kmiwrwom.dll (file missing)
                  - O2 - BHO: (no name) - {79906AC8-B875-4A64-9EE0-55A2D5E8A18C} - C:\WINDOWS\system32\fccYPiih.dll (file missing)
                  - O2 - BHO: (no name) - {85EA3A83-9765-44EA-80EC-BA2EF1CA1E10} - C:\WINDOWS\system32\yayvTkHW.dll (file missing)
                  - O2 - BHO: (no name) - {C53A682C-2DFB-4332-9879-E4BFBF3D6CFC} - C:\WINDOWS\system32\vtUlLEVm.dll (file missing)
                  - *O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  - *O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
                  - *O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                  - O4 - HKCU\..\Run: [A00F39131FA1.exe] C:\DOCUME~1\Mimers\LOCALS~1\Temp\_A00F39131FA1.exe
                  - O4 - HKCU\..\Run: [A00FD7484.exe] C:\DOCUME~1\Mimers\LOCALS~1\Temp\_A00FD7484.exe
                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  - *O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
                  - *O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
                  - O4 - Startup: csrss.lnk = ?
                  - O4 - Startup: PowerReg Scheduler.exe
                  - O4 - Global Startup: Digital Line Detect.lnk = ?
                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  - O20 - Winlogon Notify: ddcabcd - ddcabcd.dll (file missing)
                  - O20 - Winlogon Notify: ddccb - C:\WINDOWS\
                  - O20 - Winlogon Notify: qoMCusTj - qoMCusTj.dll (file missing)

                  4. Click on Fix checked button.

                  5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                  6. Open Windows Explorer. Go Tools&GT;Folder Options>View TAB, put a checkmark next to Show hidden files, and folders.

                  7. Delete following files/folders (if present):

                  - wmsdkns.exe file from C:\WINDOWS\system32

                  8. Restart in Normal Mode.

                  9. Post new HijackThis log.Ok, I wasnt able to get on the computer yesterday, sorry! I am printing out the next set of directions now....think we are close to being fixed?I'll have to see your fresh HJT log.Alright....Hopefully I did everything right this time. However, I could not find the wmsdkns file.

                  here is the new hjt

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 9:08:32 PM, on 6/8/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                  C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
                  C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\WINDOWS\stsystra.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061101
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = FILE://C:/WINDOWS/HOMEPAGE.HTML
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061101
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O2 - BHO: PopupBlockerBHO.CPopupBlockerBHO - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\Program Files\SmartPopupBlocker\PopupBlockerBHO.dll
                  O2 - BHO: AVG SECURITY Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
                  O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
                  O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
                  O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
                  O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                  O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
                  O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1163217834437
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
                  O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
                  O16 - DPF: {82B56B47-90DC-4F58-9A7D-D27BA46D3C0F} (MyPhotoAlbum Easy Upload Tool Combo Control) - http://cheryl919.myphotoalbum.com/ImageUploader4.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
                  O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
                  O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
                  O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/cnma/default/cinematycoon.cab
                  O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                  O20 - Winlogon Notify: !SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
                  O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

                  --
                  End of file - 8333 bytes
                  Very good

                  Your computer is clean

                  1. Download, and INSTALL CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                  Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                  Run CCleaner.

                  2. Turn off System Restore:

                  - Windows XP:
                  1. Click Start.
                  2. Right-click the My Computer icon, and then click Properties.
                  3. Click the System Restore tab.
                  4. Check "Turn off System Restore".
                  5. Click Apply.
                  6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                  7. Click OK.
                  - Windows Vista:
                  1. Click Start.
                  2. Right-click the Computer icon, and then click Properties.
                  3. Click on System Protection under the Tasks column on the left side
                  4. Click on Continue on the "User Account Control" window that pops up
                  5. Under the System Protection tab, find Available Disks
                  6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                  7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                  8. Click OK

                  3. Restart computer.

                  4. Turn System Restore on.

                  5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't INTERFERE with your antivirus program

                  6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                  7. Let me know, how your computer is doing.
                  OMG you are seriously not even kidding a GENIOUS! MY HERO!! lol I cant even type how thankful I am for your time and helping me out! You have no idea how thankful I truly am!

                  BRONI IS AMAZING!!!!



                  You just made me smile
                  That's all I need.
                  Happy computing!

                  3100.

                  Solve : I am infected with ntos.exe trojan keylogger - please help.?

                  Answer»

                  I run Win XP SP2 and all software is legal.

                  I use Zonealarm Security Suite for firewall and antivirus. However, as I have pointed out to my 'friends' at the Zonealarm forum, it would appear that Zonealarm is completely inadequate for providing protection or removal of this sort of virus.

                  I have followed all the steps kindly set out in the sticky and I hereby humbly attach my logs below for your perusal.

                  I can confirm that I have never received or responded to any spoof emails over the last 12 months.

                  I would be hugely grateful for any support that can be provided. My computer appears to
                  be seriously infected by this malicious virus.

                  PS: Your 'attach' function has not been working for me this morning, so I attach my logs here:
                  CCleaner-ScanLog
                  Ccleaner-RegistryLog
                  SuperAntiSpywareLog
                  MBAMLog
                  TrojanRemoverLog
                  HijackThisLogOpen Hijackthis and select Do a system scan only.

                  Place a check mark next to the following entries: (if there)

                  F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


                  Important: Close all windows except for Hijackthis and then click Fix checked.

                  Exit Hijackthis.

                  ----------

                  Run the F-Secure online scan for Viruses, Spyware and RootKits:

                  This scanner works with Internet Explorer only

                  • Go to the F-Secure Online Virus Scanner
                  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
                  • Allow the Active X control to be installed on your computer, then click the Accept button
                  • Click Full System Scan and allow the components to download and the scan to complete.
                  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
                  • When cleaning has finished, click Show report (this will open an Internet Explorer window CONTAINING the report)
                  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
                  If Automatic cleaning with Submit samples HANGS, click Cancel, then New Scan
                  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
                  • Click Automatic cleaning
                  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
                  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post along with a fresh HijackThis log.
                  Note:
                  • This scan will only work with Internet Explorer
                  • You must have administrator rights to run this scan
                  • This scan can take several hours, so please be patient
                  [/I]

                  Hello EvilFantasy

                  Thank you for your advice. I have removed the two specified items use HJT (renamed Sniper) and I have run the F-Secure online scan and attached the log to this post.

                  I look forward to hearing what you think.

                  PS: Your 'attach' function is still not working for me today (it causes my IE6 to consistently crash each time). I know you asked me to paste it, but if it's ok with you, I would prefer to host the file at the location below:

                  FSecureOnlineScannerLogHow is everything now?Hi EvilFantasy

                  Thank you for your continued help with this.

                  I am amazed and delighted to say that the ominous ntos.exe entry in the usernit section of my registry has now disappeared. In addition, I have performed scans with SuperAntiSpyware and Malwarebytes Anti-Malware and both have found nothing!

                  Does this mean that my computer is ok again now?

                  Does this mean that you're a genius? Looks good!!!

                  Final steps.

                  Set a New Restore Point to prevent possible reinfection from an OLD one
                  Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                  • Go to Start > Programs > Accessories > System Tools and click System Restore
                  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                  • Next go to Start > Run and type Cleanmgr
                  • Click OK
                  • Click the More Options Tab.
                  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                  .
                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  Here are some GREAT FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  To prevent unknown applications from being installed on your computer install WinPatrol 2008
                  Using Winpatrol to protect your computer from malicious software

                  Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                  Using SpywareBlaster to protect your computer from Spyware and Malware

                  Check out Keeping Yourself Safe On The Web for tips and free tools to keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hello EvilFantasy

                  Thank you so much for all your help. I have scanned everything again just to be certain and it appears that my computer is definitely healed!

                  You're a life-saver!

                  Kind regards

                  PippsNo problem.

                  Safe surfing...