Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3951.

Solve : Norton or McAfee.......?

Answer»

I have two free sercurity Cd's. One is McAfee Internet Sercurity SUITE 2008 w/ Site Advisor, the other, Norton Internet Sercurity 2008. I need to install one of these, if you had a choice, which do you think is the better one. I know many people don't either one, but I know a little more on how to work these two in case something should happen. I know nothing about that free AVG or if they even have a help support line.
Thanks.............what is your computer specs? Free AVG...no support PHONE but an excellent Free Forum.

I have enough space on my computer to hold either one. My new DELL computer came with a 90 day free trial of Norton. My 90 days are almost up, so I was wondering if it was just easier renewing my Norton seeing I already have it installed. I wasn't sure if McAfee was better.You do NOT want to run more than one Anti-Virus program on one machine...
Since you are set on these two select one of them and stick with it.

You will be sacrificing performance for a bloated protection package but at least you were offered choices.I didn't want to run both Norton and McAfee on my computer, just one. I have Norton installed now that came with my computer for 90 days. My 90 days are almost up. I either need to renew my Norton, or let it expire, and then install McAfee. I didn't know which security is better, Norton or McAfee.Believe me, leave BOTH of them alone. They will slow your computer down, and possibly cause all kind of other problems.Here are the reasons why I don't like Norton:

  • Norton loads so many graphics and DLLs into memory, which slows your computer down.
  • If you GET a virus, worm, trojan whatever it is, you must be logged on as an admin to remove the virus. If the admin is not there, you are on a limited account and there is a password on the admin account that you don't know about, you're screwed -- big TIME.
  • Live Update is a pain in the a##. You have to choose updates, and most of the time, you cannot install them for some reason.
  • I've read a lot of posts about Norton causing problems with the internet connection.
  • You have to pay a lot of money every year to use this product.
  • Virus scan takes too long.

I agree with patio, AVG Free Edition is a great AV product.i agree with broni, because before, i am running with 2 AV... and thats really slows down my computer. that's why i reformat my computer. 1 AV is enough in your system. try AVG free edition.If i had that choice i will leave both Norton and Macfee and go for AVG free adition its better...Quote
i am running with 2 AV
It's always very bad idea....My friends Lap Top came with a 90 day free install of Norton...now he has had a @#$%load of problems & needed help to remove some trojans & viruses. He is now very happy with AVG Free.I had Norton three years ago and I thought all files were removed and gone and now out of the blue I'm having a problem with my emails because Norton is lurking somewhere on my computer and I haven't figured out a way to get rid of it. I have tried everything. I highly recommend AVG.Quote from: pepper on February 06, 2008, 07:15:15 PM
I had Norton three years ago and I thought all files were removed and gone and now out of the blue I'm having a problem with my emails because Norton is lurking somewhere on my computer and I haven't figured out a way to get rid of it. I have tried everything. I highly recommend AVG.

From Our Archives
3952.

Solve : Analyse hijack log and combofix?

Answer»

I will go ahead and post this.


Time to cleanup and secure the work you have done

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
  • The above procedure will:
  • Delete the following:
  • ComboFix and its associated files and folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • SET a new, clean Restore Point.
Next
.
Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop.

1. Double click OTMoveIt2.exe to launch it.
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other DEFENSIVE PROGRAMS alerts you, allow it access.
4. Click YES at the next prompt (list DOWNLOADED, Do you want to begin cleanup process?)
  • When finished exit out of OTMoveIt2
.
Learn more about how to PROTECT yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?
3953.

Solve : Trying to scan with ESET NOD32 to obtain log..problem?

Answer»

Hi,

I have to tell you upfront that I am not very computer savvy But, I take direction quite well and boy do I need help!!!!!!!!!!!



I have been trying to get all my scans done to create the logs necessary to post for help with an invasion of malware (?) and worm win 32netsky(?) Not sure exactly of the culprits. I intended to start a thread about this issue but, I can't seem to get my ducks in a ROW

I am not able to get ESET NOD32 to scan. I am running Windows XP and have upgraded my explorer to 7.0. I have Bitdefender for antivirus. Spy Sweeper and Superantispyware. I have my Superantispyware log ready and Hijackthis. Java is updated.

When I go to the site to use the scan (Link provided in the "read this first" thread)......I hit the start button after I agree to the terms then I am taken to a page that I fully expected to be where it would require me to download active x. It takes me there but never offers me the option to download active x or to start the scan. I even waited for a bit to see if things were just running slow. Nada!!!!!! Tried it several times.

Yes...I am infected with something (which has many friends) I have little control over my computer so it could be this not allowing the download also.

Could it be my security settings? Bitdefender? Will you be able to help me if I can't get this to scan?




my hijackthis log if it will help:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:49 PM, on 1/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Safe mode



Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: SXG Advisor - {2A694270-A5B8-49D5-980B-26A31981285A} - C:\WINDOWS\dopfwrlkdn.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The egodktf - {639A02E7-1E2F-4870-83E8-75FDA08620D6} - C:\WINDOWS\egodktf.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\DEFAULT Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [eBayToolbar] "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
O4 - HKLM\..\Run: [FilmLoop] "C:\Program Files\FilmLoop Player\FilmLoop.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bxsnvqt - {528597EE-13BE-4BB2-AE8D-CF2B9A4494F8} - C:\WINDOWS\bxsnvqt.dll
O21 - SSODL: aslpmqk - {15790138-2910-4790-93A0-A3FA9BFFE89A} - C:\WINDOWS\aslpmqk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 9146 bytes



Any ideas of how I can get this scan to run? TIA!!!!!


Attach your Superantispyware log, then re-run HijackThis, but this time in Normal Mode, not Safe Mode. Post its log, as well.Sorry for the delayed response. I have been trying to get my superantispyware to scan in normal mode. What ever has a hold of my computer keeps the scan from completing or by bogging down my system to the point it freezes up. I have been scanning now for 6 hours in normal mode. But......my superantispyware is stuck scanning "backup files" over and over again.

I have totally lost control of my computer. My desktop keeps turning blood red....I have trojans popping up everywhere. I keep getting redirected to other sites to download products. I had a similar issue with my husband's computer a few years ago....but, with help was able to fix it.........This time is different. As many as 6 screens at a time pop up. Now my computer is slow I feel it is on the verge of crashing. I have really been trying .....I just want to cry.... Thanks for trying to help......OK.
First of all, Superantispyware should be run in Safe Mode. Try that. Post its log.
If it still won't let you, we'll work on your HJT log created in Safe Mode.
If Superantispyware in Safe Mode is successful, try to run HJT in Normal Mode, and post its log.
If Superantispyware in Safe Mode won't be able to finish, again, we'll look at your HJT log from Safe Mode.
Thank you I will try that. It will most likely be tonight (late) before I post as I have to go to work. But, I will let the scan run now in safe mode and hopefuly post itCool.Here is my superantivirus log run in safe mode:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/29/2008 at 04:55 PM

Application Version : 3.9.1008

Core Rules Database Version : 3390
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 03:57:00

Memory items scanned : 165
Memory threats detected : 0
Registry items scanned : 6181
Registry threats detected : 0
File items scanned : 262796
File threats detected : 1

Trojan.Unclassified/FKN
C:\WINDOWS\FKNXWQF.EXE
Here is my hijackthis log run in normal mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:52 AM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: SXG Advisor - {2A694270-A5B8-49D5-980B-26A31981285A} - C:\WINDOWS\dopfwrlkdn.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [2wSysTray] "C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [eBayToolbar] "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
O4 - HKLM\..\Run: [FilmLoop] "C:\Program Files\FilmLoop Player\FilmLoop.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
same Hijackthis log continued:

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bxsnvqt - {528597EE-13BE-4BB2-AE8D-CF2B9A4494F8} - C:\WINDOWS\bxsnvqt.dll (file missing)
O21 - SSODL: aslpmqk - {15790138-2910-4790-93A0-A3FA9BFFE89A} - C:\WINDOWS\aslpmqk.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 10360 bytes
I will check back again tomorrow and see what my next step is. Thanks for your patience Go Start>Control Panel>Add\Remove, and...
Uninstall any of the following programs associated with Viewpoint:
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar

1. Print this post out, since you won't have an access to it, at some point.

2. CLOSE all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable UNNECESSARY startups; in those cases (marked with *), no actuall program will be removed):

- O2 - BHO: SXG Advisor - {2A694270-A5B8-49D5-980B-26A31981285A} - C:\WINDOWS\dopfwrlkdn.dll (file missing)
- O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
- *O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
- *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
- *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
- *O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
- O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFW BInitialSetup1.0.0.15.cab
- O21 - SSODL: bxsnvqt - {528597EE-13BE-4BB2-AE8D-CF2B9A4494F8} - C:\WINDOWS\bxsnvqt.dll (file missing)
- O21 - SSODL: aslpmqk - {15790138-2910-4790-93A0-A3FA9BFFE89A} - C:\WINDOWS\aslpmqk.dll (file missing)
- O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

4. Click on "Fix checked" button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

7. Delete following files/folders (if present):

- dopfwrlkdn.dll, bxsnvqt.dll, aslpmqk.dll files from C:\WINDOWS
- Viewpoint folder from C:\Program Files

8. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

9. Restart in Normal Mode.

10. Turn System Restore on.

11. Post new HijackThis log.Here is my new hijackthis log:::


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:08:26 AM, on 2/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FilmLoop Player\FilmLoop.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqnrs08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [2wSysTray] "C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [eBayToolbar] "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
O4 - HKLM\..\Run: [FilmLoop] "C:\Program Files\FilmLoop Player\FilmLoop.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
same hijackthis log continued:

O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 9781 bytes
Very nice. The log is clean

We need to remove couple of startups, and we're done with HJT.
Open HJT, checkmark these:
- O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
- O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
- O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
Click "Fix checked".
Close HJT.

Last steps:
1. Download, and INSTALL CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
2. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

3. Download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
It won't interfere with your antivirus, nor firewall.

Report how your computer is doing.

3954.

Solve : Just need to check something?

Answer»

I was trying to find something that would record keystrokes on my computer and i downloaded this thing called keyprowlerhttp://www.download.com/KeyProwler-Pro-Keylogger/3000-2132_4-10767600.html
and it didnt even work and now it won't uninstall at all so i need to know if there is something i can get to really check through my computer for spyware cause i think i got a bad program and now i don't wanna do like any online banking till i check it all out so thanks.System Restore?yeah that's a great idea thanks lol i should have thought of thatIf that fails, try this. (unless you already have)

Note: You may have to re-download the installer.

How To Uninstall:

To Increase Stealth, KeyProwler is designed so that it cannot be uninstalled VIA Windows Add/Remove Programs, the only way KeyProwler can be removed is by using the same installer that is used to install KeyProwler.

To Uninstall KeyProwler:

1. Run KeyProwler Installer that you downloaded. Just as if you were going to reinstall the program.

2. Click "Next" At the Welcome Screen

3. The user is presented with 3 Options, choose "Remove" and click "Next"

4. KeyProwler is now removed from the system. evilfantasy has it! That is the intended method of removal.

robrowboski: When you set it up, how did you tell it to log keystrokes? I installed it and set it up to send the log to my gmail account. WORKED like it's supposed to for me. Whoa! Crappyness! After the uninstall components of the keylogger were still running on start-up. It increased my load time from 30 seconds to about 5 minutes! My network CONNECTION started dropping out, too. I did a system restore and all is well.

I was lulled into believing it was a safe download because it CAME from Download.com. I am displeased. That's some crappy software. What lead you to believe download.com doesn't have baggage ? ?

I haven't trusted that site in over 4 years.You may post your HJT log for us to see, if nothing is lurking there.I guess I just haven't been burned by Download.com before. Luck, I suppose. I've learned my lesson and Windows restore saved my bacon. The rule of thumb: if your computer knowledge is limited, always ask around before installing anything new.

3955.

Solve : My computer restartes itself?

Answer»

when i start my computer it loads up then acts LIKE you have pressed the reset button could you please help me i need it for workWelcome to the CH forums.

You are probably SUFFERING from a hardware failure which causes a BSOD (Blue Screen Of DEATH possibly a Stop 8e) which you don't see because you have your System Properties set to automatically restart on a system failure.

You should check your RAM using Memtest86 (from memtest86.com) and your hard drive using the manufacturers diagnostics program.

Good luckWhen I had XP, I had the MS Blaster Worm which automatically restarted my computer after a while, but a restart message should appear with a load bar.Quote

When I had XP
What Windows is it now?It was before I got a new laptop, but I have Vista now.
3956.

Solve : http://gaigoibaucat.xlphp.net virus??

Answer»

is there any kind of virus like this one??? there's a text oftenly appears on my powerpoint. HELP!!!We can't tell unless you read post #1 and #2 HERE and attach the logs.i also have the same problem.
i am using windows xp and avg free edition and it has the LATEST updates.
the avg cannot detect the problem.
the virus or whatsoever... causes my yahoo messenger to send links to all in my address list. i cannot use regedit, task MANAGER, ipconfig and folder options. so far that is the problems that i encounter. i dont have the sp1 as you say but i want to know what you think about it before i download and install any. please do help... i found out that the virus is somewhat came from a thailander... im just not SURE...
please helprosemichelle
You NEED to start your own topic

3957.

Solve : Symantec email problem....help!!!?

Answer»

I have a computer tech coming tomorrow morning around 9 am. I let you know what he says. I'll pray...Me too!!! Well he checked everything in the SYSTEM and couldn't FIND any symantec or norton. He copied and pasted the message that I'm getting into google and a bunch of things came up. Apparently I'm not the only one having this problem and there doesn't seem to be an ANSWER yet.


http://aumha.net/viewtopic.php?t=30518&sid=de0bce794175cdc6b515752baf6c653c

He did say that everything looks really good and that my system is very happy!

Quote from: PEPPER on February 08, 2008, 04:30:35 PM

Apparently I'm not the only one having this problem and there doesn't seem to be an answer yet.

Actually the link had a pretty good answer. The Ahuma forums are well respected. It isn't anything to do with your computer, it is coming from a server that the email passes through. So, we're back to one of my very first suspicions:
Quote
This message may be just included with the email of the person, who is SENDING back the message, or even ISP
- post #32....
Oh, well....at least computer is doing fineI'm not going to worry about it anymore. When I start to get that message I'll just copy and paste into a new email and tell the other person to do the same thing. It's just an annoyance. Thanks for trying to help.
3958.

Solve : this computer make the internet slow when it turn on.?

Answer»

i also have tried taking out the HDD and make it as a slave in my own COMPUTER (windows xp) then run full SCAN of avira but no resultGo HERE and install then run the Dr. Web CureIt and post that log.well, after the full scan, it didn't find anything in that "main computer" by i did try scanning the other computer ( PC 06 & PC 03 ) and found something. However, i still sure this main computer affecting the rest when it turn on.PC 06 Dr. Web CureIt Log

tsad.dll;C:\WINDOWS;Adware.TSAdvert;;
mirc.exe;C:\mIRC;Program.mIRC.601;;
mirc32.exe;C:\mIRC\backup;Program.mIRC.590;;
scoop.exe;C:\Scoop2000;Program.mIRC.570;;
MS-DOS Mode for Games.pif;D:\;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\CYBER\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\CYBER;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\CYBER;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\CYBER\FIFA\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\CYBER\FIFA;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\CYBER\FIFA;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\CYBER\awang papar file\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\CYBER\awang papar file;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\CYBER\awang papar file;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\CYBER\aku\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\CYBER\aku;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\CYBER\aku;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\DRIVER\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\DRIVER;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\DRIVER;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\DRIVER\LAN\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\DRIVER\LAN;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\DRIVER\LAN;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\DRIVER\4IN1NA\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\DRIVER\4IN1NA;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\DRIVER\4IN1NA;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\DRIVER\USB\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\DRIVER\USB;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\DRIVER\USB;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\Tmp\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\Tmp;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\Tmp;BackDoor.Oblivion.1;Deleted.;
FOLDER.HTT\VbScript.3;D:\Raiden II\FOLDER.HTT;VBS.Moks;;
FOLDER.HTT;D:\Raiden II;Archive contains infected objects;Moved.;
MS-DOS Mode for Games.pif;D:\Raiden II;BackDoor.Oblivion.1;Deleted.;
PC 03 Dr. Web CureIt Log



tsad.dll;C:\WINDOWS;Adware.TSAdvert;Deleted.;
mirc.exe;C:\mirc;Program.mIRC.602;Deleted.;
mirc32.exe;C:\mirc\backup;Program.mIRC.591;Deleted.;
scoop.exe;C:\Scoop2000;Program.mIRC.570;Deleted.;
mirc32.exe;D:\mirc\backup;Program.mIRC.591;Deleted.;
This "Main Computer" acting as a server, sorry forgot to wrote that.Looks like you need to run all of the steps in the removal guide.I got 1 pc here with windows xp, everytime i ran "web cure it" it shutdown somewhere around 3% completed
Same with running Avira anti virus, but this computer works fine except while scanning.
I can't hook it as a slave because the screw for the HDD to tight!Try this.

TrendMicro Sysclean

Create a new folder on the desktop by Right-Clicking an empty area of the desktop and SELECT New > Folder. Name it Sysclean.

1. Download Sysclean by Trendmicro and save it to the new folder on your Desktop.
2. Download the latest Pattern Files from Trendmicro and save it to the same folder as the Sysclean. Pattern file is in Zip format such as lptxxx.zip (Windows)
3. Extract the contents of the lptxxx.zip in the folder where Sysclean in located.

  • It will only work if these are in the same folder.
4. Reboot computer in SafeMode

a) During BootUp process Press F8 continuously until selection appears
b) Use Arrow Up+Down to select SafeMode on the selections menu.
c) Hit Enter to proceed.

5. If it requires you to login please use the login name with administrative rights. Without this privilege, Sysclean will not delete/clean infected files located on SYSTEM folder.
6. Open the Sysclean folder on on your Desktop and Double-click Sysclean to run and do a full system scan. This may take time. Reboot when finished, repeat as desired to make sure that all threats are removed.
well, it still shutting down
I'm going to turn this computer on for a while to make sure that it is not caused by overheating...After that i post the resultfor a few days all of the computer acting fine, i mean the internet connection, and guess what, the ISP told us that they having problem ( They didn't mention earlier!) because of cables underseas thing...
Probably related to this.....
http://news.yahoo.com/s/ap/20080208/ap_on_hi_te/mideast_internet_outage

I think this thread solve already.Thanks for letting us know.
3959.

Solve : Need help... Yahoo Messenger Virus??

Answer»

i also have the same problem.
i am using windows xp and avg free edition and it has the LATEST updates.
the avg cannot detect the problem.
the virus or whatsoever... causes my yahoo messenger to send links to all in my address list. i cannot use regedit, task manager, ipconfig and folder OPTIONS. so FAR that is the problems that i encounter. i dont have the sp1 as you say but i want to know what you think about it before i download and install any. please do help... i found out that the virus is somewhat came from a thailander... im just not sure...
please help
i also dont understand this one: C:\windows\hinhem.src

-ZylstraStart with this thread.

Then post the logs here so we can see what is going on.The link has been removed to prevent accidental clicking.
A report of the website can be found here:
http://www.siteadvisor.com/sites/gaigoibaucat.xlphp.net
Also, as you can see in the address above and on the report, you could visit the site if you really WANTED to.

3960.

Solve : how to enable the registry editor?

Answer»

Please help again...
After infected by the so-called gaigoibaucat virus....
It disabled my registry editor and my TASK manager. So far my Yahoo Messenger is safe from sending files that CONTAINS gaigoibaucat virus...
I want to KNOW how to enable my registry editor and task manager again. Please help.You don't APPEAR to have FOLLOWED the directions given by evilfantasy in your last thread.
Quote from: evilfantasy on February 07, 2008, 08:54:42 AM

Start with this thread.

Then post the logs here so we can see what is going on.
How are we supposed to help you if you don't follow the given advice?
3961.

Solve : Bl4cK P3g4sUs virus help!?

Answer»

I need help on this worm. It creates 240 kb files inside folders that when you try to open them, will freeze the computer. Won't allow system restore and can't start in safe mode. It disables antivirus softwares, or any other softwares. Missing RUN in start menu. And when you try to look at my computer properties, it is suddenly registerd to Bl4cK P3g4sUs. I'll attach some pics to better explain what i mean.

Although recently I gained control of the computer and was able to succesfully open a few programs, I STILL wasn't TOTALLY clean. Tried to scan, but can't find anything with norton, kaspersky or nod 32. Dr. web found something though but it only moved it. PLEASE Help!

[file cleanup - saving space - attachment deleted by admin]Go through the steps LISTED here.
Please read this before requesting help.

3962.

Solve : Adware Problems!?

Answer»

I have 3 Adware bugs on my computer that I cannot get ride of even with Spyware Doctor. Spyware Doctor finds Them, Removes them But when I open Internet Explorer they reappear. The list of Adware Bugs go's as follows( Adware.Leorvbar), (Adware.Admedia ),( Adware.Agent.BN), Please help. Running windows xp. 1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/
Note: This Scanner is for Internet Explorer Only
1. You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
2. If it wants to install an ActiveX component allow it
3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
4. Once ActiveX CONTROL is installed click on the "Start" button to initialize the scanner
5. After initialization is complete, make sure, that "Remove found threats", and "Scan unwanted applications" are checkmarked.
6. Click the "Scan" button
7. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
Post ESET's log.

2. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

Print these instructions out.

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current DATED log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.Thanks for the help, But I am getting a (Error update failed )on the Eset online scanner any ideas?Run TrendMicro free on-line scan, HouseCallHey Broni, Hijack this Info-Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:35 AM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: emotrlq - {71043D18-3FC1-46BD-B1AF-2342E18DBAE3} - C:\WINDOWS\emotrlq.dll (file missing)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://setup.bellsouth.net/wizlet/PWReset/static/controls/WebflowActiveXInstaller_4-2-1.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182202701703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bdmnopx - {78AF4938-E2FE-4FA5-A525-7453F921B6AC} - C:\WINDOWS\bdmnopx.dll
O21 - SSODL: admggxp - {574A97C0-0CFE-4AB1-AD7E-4ACF49F4BF81} - C:\WINDOWS\admggxp.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 7431 bytes
Me again Superantispyware log-SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/09/2008 at 00:12 AM

Application Version : 3.9.1008

Core Rules Database Version : 3399
Trace Rules Database Version: 1391

Scan type : Complete Scan
Total Scan Time : 00:20:21

Memory items scanned : 174
Memory threats detected : 0
Registry items scanned : 4433
Registry threats detected : 13
File items scanned : 22118
File threats detected : 13

Adware.SXGAdvisor
HKLM\Software\Classes\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\InprocServer32
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\InprocServer32#ThreadingModel
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\ProgID
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\Programmable
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\TypeLib
HKCR\CLSID\{FD66D953-73D5-4A4B-8D97-A3E505C24121}\VersionIndependentProgID
C:\WINDOWS\DMDQDRXGLR.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD66D953-73D5-4A4B-8D97-A3E505C24121}

Adware.Tracking Cookie
C:\Documents and Settings\Tony T\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][2].txt
C:\Documents and Settings\Tony T\Cookies\[emailprotected][1].txt

Trojan.Net-MU/Gen
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName

Trojan.Unclassified/EGO
C:\RECYCLER\S-1-5-21-1123561945-1647877149-1606980848-1004\DC15.DLL
Broni, Thank you so much dude!You're welcome

1. Print this post out, since you won't have an ACCESS to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- O3 - Toolbar: emotrlq - {71043D18-3FC1-46BD-B1AF-2342E18DBAE3} - C:\WINDOWS\emotrlq.dll (file missing)
- *O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
(disable these by - right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' - OK your way out)
- O21 - SSODL: bdmnopx - {78AF4938-E2FE-4FA5-A525-7453F921B6AC} - C:\WINDOWS\bdmnopx.dll
- O21 - SSODL: admggxp - {574A97C0-0CFE-4AB1-AD7E-4ACF49F4BF81} - C:\WINDOWS\admggxp.dll

4. Click on "Fix checked" button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

7. Delete following files/folders (if present):

- emotrlq.dll, bdmnopx.dll, admggxp.dll files from C:\WINDOWS\

8. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

9. Restart in Normal Mode.

10. Turn System Restore on.

11. Post new HijackThis log.Well, I think I did that right. New post- Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:13:22 AM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://setup.bellsouth.net/wizlet/PWReset/static/controls/WebflowActiveXInstaller_4-2-1.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182202701703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bdmnopx - {787B02F5-0015-46EB-8574-18EB793FEDCF} - C:\WINDOWS\bdmnopx.dll
O21 - SSODL: admggxp - {F6625C6B-47AA-466F-8243-242D2728E77D} - C:\WINDOWS\admggxp.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 7276 bytes
Thanks again, I think we got It!!!!!Not quiet, yet.

Go Start>Run, type in:
regedit
Click OK.
Registry Editor will open.
Go File>Export, and save your registry to safe location.
Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
In right pane (look under Data column), you'll see two entries:
- {787B02F5-0015-46EB-8574-18EB793FEDCF}
- {F6625C6B-47AA-466F-8243-242D2728E77D}
In each case, right click on the entry, and click Delete.
Disregard Windows warnings.

Restart to Safe Mode.
Using Windows Explorer, delete admggxp.dll, bdmnopx.dll files from C:\WINDOWS\

Restart in Normal Mode, and check, if the above files are gone.

Post new HJT log.
Wow, You blow my mind with your computer skills! Hijack this log-Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:09 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://setup.bellsouth.net/wizlet/PWReset/static/controls/WebflowActiveXInstaller_4-2-1.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182202701703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bdmnopx - {60D9C175-975A-49C5-B5CB-26F7FFB750F6} - C:\WINDOWS\bdmnopx.dll (file missing)
O21 - SSODL: admggxp - {0F263273-8013-4D96-820C-40F08456EEF3} - C:\WINDOWS\admggxp.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 7280 bytes
This is better...
Open HJT again, checkmark these two:
- O21 - SSODL: bdmnopx - {60D9C175-975A-49C5-B5CB-26F7FFB750F6} - C:\WINDOWS\bdmnopx.dll (file missing)
- O21 - SSODL: admggxp - {0F263273-8013-4D96-820C-40F08456EEF3} - C:\WINDOWS\admggxp.dll (file missing)
Click "Fix checked".
Close HJT.
Turn System Restore off.
Restart computer.
Turn System Restore on.
Post new HJT log.
Alrighty than! Hijack this log-Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:25:36 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://setup.bellsouth.net/wizlet/PWReset/static/controls/WebflowActiveXInstaller_4-2-1.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182202701703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 7072 bytes
Cool All nice, and clean.
One more housekeeping move...
Open HJT, and checkmark:
- O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Click "Fix checked". You don't need it as a startup. Actual program won't be removed.

Now...
Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

How is your computer doing?Did what you said, I ALREADY have CC Cleaner but will run It. You Are so awsome dude! Thank you. Also I em dropping Internet Explorer, And using opera for browsing. Internet Explorer gets hacked to much! I'm glad, thing worked out

You may...
Download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
It won't interfere with your antivirus, nor firewall.

3963.

Solve : need help recovering from trojan?

Answer»

i recently encountered a Trojan, I'm confident that the original file (and the ones it brought in) are gone, i used AVG scanning in safe mode to FIND and heal everything and it seems it did. the problem is that somewhere during this something took away my administrative properties. along with this the only audio i can get are the microsoft sounds, anything playing out of winamp or anything else will not play. winamp will even tell me that the driver is missing.

if i could get any information about restoring myself as an admin or about the sound issues it would be appreciated Try going to device manager and reinstalling the drivers.

You may also want to go here and SCROLL down to the Hijackthis instructions and post a log so we can check it to be sure the malware is actually gone.i cant go to device manager and i cant even do the first step in your intructions, i don't have administrative powers and i need help on how to remedy thisYou are going to have to get logged on as an administrator.

*sigh* how?Parents? Whos computer is it?NO ONE IS AN ADMINISTRATORHow is that possible? Someone had to make the limited account. Is this a public computer?well in guessing it was from the virus, and no its not a public computer. there are 4 accounts on the computer, when we first set everything up we were all admins but now no oneSorry, I just re-read your first post. I wasn't clear that all accounts have been restricted. If you see me not understanding something then tell me in more detail what is going on!

Log off. On the welcome screen press and hold Ctrl+Alt (both at the same time) Then press the Delete button twice. This will bring up log on options. For the user name type administrator. Do not type in a password! You should be able to log in that way. Post a Hijackthis log.

If it does ask for a password then type administrator for that as well.cant, it says that the system cannot log me on because the user name or password is incorrect, i tried it with and without the administrator as a password

whats the likely hood that I'm just going to have to reformat?Last ditch effort......

http://home.eunet.no/pnordahl/ntpasswd/Hmm, this may be a bit above my level, i think i may just end up dumping everything and starting freshSometimes that is the best choice. Without knowing exactly what is on the computer I am going to include this speech on backdoor trojans. It has some information you may want to follow through with to do with personal information (identity theft)

Again this MIGHT not apply but it never hurts to be on the safe side.



Backdoor Trojans, IRCBots
and rootkits are very dangerous because they provide a means of accessing a computer system that bypasses security mechanisms and steal SENSITIVE information like passwords, personal and financial data which they send back to the hacker. Remote attackers USE Backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge.

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

Your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because the Backdoor Trojan has been removed the computer is now secure. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS.

When should I re-format? How should I reinstall?.
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

3964.

Solve : Should i have this many??

Answer»

i have 6 "svchost.exe" RUNNING in my PROCESSES and TWO "rundll32.exe"It's normal.ok THANKS

3965.

Solve : computer for mobile maintenence?

Answer»

what r the tips 4 GOOD workig COMPUTER in mobile PHONE MAINTENANCE softwareDo you mean portable security?

3966.

Solve : Windows XP and gditst?

Answer»

Hello

I have Windows XP and I keep getting this gditst installing itself inprogram files and sometimes of the desktop.
I delete it and it keeps coming back.


Any Idea's?i'd get ahold of A-Squared free or Spybot SnD and scan your computer. And are you using a virus protection like Avast or AVG?

From what I see you might have a virus or some kind of trojan or other infection since that file should not come back if you are certain it is not any of those windows system files that recreates itself upon reboot for PROPER computer running.

It looks like a malware...

1. Run one of two free on-line scanners:
*** ESET Online Scanner at: http://www.eset.com/onlinescan/
Note: This Scanner is for Internet Explorer Only
1. You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
2. If it wants to install an ActiveX component allow it
3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
5. After initialization is complete, make sure, that "Remove found threats", and "Scan unwanted applications" are checkmarked.
6. Click the "Scan" button
7. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
Post ESET's log.

*** TrendMicro free on-line scan, HouseCall
It works with Firefox, and Internet Explorer

Click on http://prerelease.trendmicro-europe.com/hc66/launch/img/btn-launch_housecall.gif
It'll ask you to download small housecall66.exe to your computer.
Double click on the above file to BEGIN scanning process.

HouseCall pop-up window will open.
Accept the agreement.
In next window, select Complete Scan, and click on Start Scanning button.

Relax, it'll take a while.

Upon completion HouseCall will displat results under Results tab.
Write down list of INFECTIONS, and post it back here.
Click CLEAN now button.
Close application.


2. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

Print these instructions out.

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner OPTIONS make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
* Click Close to exit the program.
Post SUPERAntiSpyware log.

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.

3967.

Solve : total soln 4 formating a computer??

Answer»

slow n restarting COMPUTER due to virus... iwant to format it but dont know n dont want to loose my files data....i myself want to make it NORMAL after formatingThis can't be done...
You can HOWEVER ATTEMPT a Repair install that may improve things.
We'll need more DETAILS though.

3968.

Solve : Help!! How to stop all the Popups, Adwares and Trojans??!!!?

Answer»

I don't know why OTmoveIt is doing that with your computer. Hopefully everything is OK now.

Thanks Dairyman.I don't know either Evil. I'll be looking to you guys for ADVICE on the best pc to get later on

Quote from: dairyman on January 17, 2008, 04:02:20 AM

Quote from: green tea on January 17, 2008, 12:37:18 AM
but the clock is still in that weird format. It's 23:34 right now

Click on START, click on Control Panel, click on REGIONAL and Language Options and click on the "Regional Options" tab. Click Customize. Click on the Time tab, click on the Time format drop-down box and choose h:mm:ss tt. Make sure the AM symbol is set to AM and PM set to PM. Click Apply and click OK. Click OK on the Regional and Language Options dialog.

Good luck

Sweet!! It works, thank you!

I love this place. I learn something new about the computer everytime ^__^

Glad it worked, I had never seen that either.

Safe surfing...............Hey guys..

Does using ATF Cleaner a lot effect the memory?? For the past 2-3 weeks, I've been having trouble loading Yahoo.com. Usually that loads instantly since I have cable. But now, the SCREEN just stays blank and takes FOREVER. At first, I was hoping it was just Yahoo doing a maintenance check or something, but then it loads just fine at work. And most of the other websites I go to loads ok.

And recently, I would open IE and go to a website, but then the browser closes, and a popup will appear with the following message: "The instruction @ "0x7e1t9afc" referenced memory at "0x01fa6ec8" memory could not be "red" Click ok to terminate program"

I'm not sure what's going on, so I thought I'd ask here first It shouldn't effect the memory although it does clean the Prefetch which isn't advised to do on a regular basis. You can uncheck the Prefetch option before running ATF Cleaner.

CCleaner is a safer alternative for a daily cleaner. It has a setting to clean Old Prefetch Data but must be enabled under Advanced Options.

Quote
Cleaning the Prefetch folder in Windows XP/Vista is a MYTH and will reduce performance. The Prefetch folder is self cleaning at 128 entries by Windows. When the 128 limit is reached Windows will keep the 32 most used prefetch files. Cleaning the folder before this will cripple Windows load and all application load times.
Full Article


Haven't heard of Prefetch before this.. I should have asked about the effects of using some of these programs before using them every now and then.

So it looks like I have to let Yahoo load twice before it goes back to normal. I guess it makes sense since one of the comments on that article said the load time could go up 100% *doh*It is also a good idea to restart the computer immediately after doing a thorough cleaning, with either ATF or CCleaner.I have a Dell and run windows XP. In the tasktray a red X keeps popping up announcing that my computer is infected and wants me to buy a certain antispyware. How do I get this annoyance out of my tasktrayDon19wil49 you will need to read this post and start a new thread with the information.
3969.

Solve : Buffer Overflows?

Answer»

I apologize if this is the incorrect forum. I have all my movies and movie segments stored in a folder on my D drive. Every time I access the folder, I get a Buffer Overflow WARNING. These warning used to be limited to that movie folder but now the warnings come when I play certain movie cds on my F drive. How do I get rid of these warnings?

About my computer: I have a HP Pavillion laptop, model dv9627cl, 2GB Memory, 200GB hard Drive, Windows Vista Home Premium 32-bit, McAfee Viruscan Plus 3user version 8.

I get three different buffer overflow warnings:

1. "A buffer overflow was detected and blocked on your computer"
Process: C;\Windows\system32\DllHost.exe
Process description: Com Surrogate

2. "A buffer overflow was detected and blocked on your computer"
Process: C:\Windows\explorer.exe
Process description: Windows Explorer

3. "A buffer overflow-----"
Process: C:\Windows\Explorer.EXE
Process description: Windows Explorer

Warning #1 only appears when I access the movie folder on D drive but doesn't affect my PLAYING of the movies there.

Warnings #2 and 3 usually appear when I try and play certain movies I have on cds and when the warning appears, I can't play the cd. The F drive freezes up and I have to close it.

I went through all the steps requested by "evilfantasy" although step #5--the online virus scan-- would not work, even in IE and with Admin. rights. I could never get the "run as administrator" button to come up. I also could only retrieve two of the logs to save. When the DrWeb CureIt scan was done, the "save report list" button would not highlight and would not allow me to click on it.

Here are the two logs I was able to save:



[file cleanup - saving space - attachment deleted by admin]We're not dealing with malwares here. The log is clean.
When did your problem start? How old is your computer? Did it come with Vista, or was it an upgrade?Also, what program do you use to play movies? Does it happen with movies only?Thanks for the fast reply and quick check on the logs, Broni! My computer is almost four months old and came with Vista. The problem started towards the end of December. At first, the warnings came erratically and soon got to the point where they come each time I open my movies folder after the first boot up in the morning and any re-boot after that. I use Media Player Classic from the K-lite codec pack and VLC media player. I rarely use Windows Media Player. Right now, I only get the overflow warnings when I open my videos folder or when I try and watch certain cds with movies on them.

When the buffer overflow warning comes up and mentions the Process, is that where the overflow is originating from? Should I try deleting the process files mentioned in each warning?

Also, for the first 60 days I had this computer, I was using a free trial of Norton Security and ANTIVIRUS and never got any warnings pertaining to buffer overflows. The same goes for when I had my old Sony comp with Trend Micro Security Suite. McAfee is the first antivirus and security program that has brought up this problem. OK.
I did some reading, and it looks like this particular message is strictly connected to McAfee only. I don't know, if they are GOING to issue some patch to correct this problem, but you're not alone.
Quote

Should I try deleting the process files mentioned in each warning?
No, you can't. Those files are crucial Windows files, and it's not Windows fault, but McAfee being too protective.
What is buffer overflow?
A simple definition of buffer overflow is writing data outside designated memory blocks when the memory block is full. Most antivirus programs use pattern files to detect the buffer overflows. So, if antivirus code is overprotective, or flawed, it'll flag legit programs as virus activity, and block them.
Since they're blocked = you can't play your DVDs.
Why you can actually play movies from your HD, after the error, but not from DVD drive is beyond my knowledge.
I don't like McAfee, but I assume, you paid your subscription, so you're stuck.
In my opinion, you have two options.
I'm not familiar with new McAfee versions, so you'll have to dig through its options...
1. You may turn buffer overflow protection off (it may have some sub-options), which isn't the best thing to do.
2. McAfee must have some way to exclude some processes from being flagged.
I wish, I could have had more help for you.Thanks again, Broni, for the quick reply and additional info on the overflows. I kind of suspected the warnings may have been unique to McAfee since I never had them with other AV programs I used. I'm getting McAfee for free for one year through Scottrade Online Brokerage and have contacted the McAfee help forums to no avail. If I have to switch back to Norton or Trend Micro, it won't be the end of the world. I guess you get what you pay for, eh? Again, your help was much appreciated and if I find out anything new, I'll post it here for all. Broni, I also checked and found I have buffer overflow protection enabled within McAfee, which is why I get the warnings, but I'm reluctant to disable the feature because of the seriousness of problems that the overflows may cause (when the alerts appear, they always mention how serious overflows can be). Again, as I find out more from McAfee, I'll inform the forum.If you have it for free, I'd uninstall it right away. Stay away from Norton, and TrendMicro. You're gonna have similar problems.
Go for free AVG, or Avast.
3970.

Solve : I can only assume this is a virus??

Answer»

I'd LIKE to try that Eg0Death, but when I go into My Computer, the only "Properties" I can find is in the menu under FILE, and it is grayed out.

You really deserve an award for all this help.The beeps on IM's are from whatever IM Client you are using...look under Options/Tools for "play sound" etc.
If it happens on DLoads this is either your browser settings or a DLoad Manager you use...again check the above options.Eg0Death, I figured out how to do all the things you suggested. Thank you, not let's see if it all worked!Okay, so I did everything but the second suggestion, II. Delete the Minidump Files and the Sysdata.xml File. I went to do it and couldn't find anything like that in there, so I didn't delete anything. But I did everything else, and I still get the MEMORY DUMP thing. D:I'm still getting quite frequent blue death screens. Tell us what STOP codes and file names (if any) those blue screens are giving you.

3971.

Solve : trojan i ant get healed?

Answer»

Can you tell by the log what starts when the computer is switched on because i know i don't use a lot of the stuff on the desktop but don't know what is what & don't want to switch something off which is important.

so far the compuer has not crashed on freezed on me i have had it running now 7hrs with up to 5 windows open so THANK YOU FOR THAT SO MUCH as soon as i can i will make a donation to you hope i can send it by western union do not have credit card

Go to add/remove programs and uninstall AdVantage

----------

Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O4 - HKCU\..\Run: [AdVantage] "C:\Program Files\AdVantage\AdVantage.exe"
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing)


Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Download OTMoveIt2 by OldTimer.

  • Save it to your desktop.
  • Double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code: [Select]C:\Program Files\AdVantage\AdVantage.exe
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box ENTER *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the CONTENTS of that document back here in your next post.

----------

Post the OTMoveIt log and let me know how things are now.OTMoveIt2 v1.0.20 log created on 02292008_204146

this is all i got i tried it twice but the same thing came up Go to C:\Program Files\AdVantage\AdVantage.exe

Delete this file and folder AdVantage.exe and AdVantagehave not got that folder on the computer
    Time to do some cleanup and secure the work you have done.
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.

The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it)

    1. Double click OTMoveIt2.exe to launch it.
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
    • When finished exit out of OTMoveIt2
    .
    Here are some great tools to help you keep from getting infected again.

    Spybot Search & Destroy - A safe and effective spyware scanner.
    * Official Spybot Tutorial
    * Spybot FAQ

    AVG Anti-Spyware Free Edition - Very reliable with a HIGH detection rate.
    * AVG Anti-Spyware User Manual

    SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * SpywareBlaster Tutorial

    Comodo BOClean - Stops trojans and many more malicious attacks.

    Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
    * Click here for a list of free firewalls.
    * Why would I consider a third party firewall?

    UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
    * Help with Windows updates

    Learn more about how to protect yourself while on the internet READ this article by Tony Klien: So how did I get infected in the first place?

    Let us know if anything else comes up.
    3972.

    Solve : Hi !?

    Answer»

    Hello Everyone !

    I am new to the forums. After viewing other online help forums I am very impressed with this forum! It seems to be the best !
    I am having major computer problems ! My computer is loaded with viruses !
    Here are my symptons :
    1. Programs take forever to come up , if they even come up !
    2. Avg will not run , actually I ran it earlier and it STOPPED in the middle of the test and would not start back up !
    3.I keep receiving these windows saying " Your computer is making un-authorized system downloads or some type of garbage like that , download this sypware remover . ( I have run ADWARE and spyware remover already)
    4. I keep getting these pop ups on the bottem of the toolbar that say "Windows antivirus , windows has detected spware INFECTION"

    How in the world do I fix this !?!?!?!? Thanks so much , Wayne
    btw ..I did a search and could not really find anything to fit the descriptions of the problems I am having .Welcome to CH.

    Please see this thread to begin the removal process. Post all of the logs when complete.Quote from: evilfantasy on February 10, 2008, 12:32:03 PM

    Welcome to CH.

    Please see this thread to begin the removal process. Post all of the logs when complete.
    Thanks so much for your help Evil ! I failed to mention in my post that I cannot use the computer , because of the freezing up so I can't start with the first steps. That would have helped huh ?!? I am on my FATHER's laptop, so I can't download any type of antivirus to the computer. I had antivirus on the computer but it either expired or was TAKEN off by the viruses , I don't know if that is possible or not !?!? I hope my computer is not beyond repair Can you start it in safe mode?

    If so download ClamWin to a flash drive and transfer it to the computer to run a virus scan. See if anything is found and remove it. Then see if you can log on in normal mode to run the rest of the scans.

    Quote from: evilfantasy on February 10, 2008, 01:02:19 PM
    Can you start it in safe mode?

    If so download ClamWin to a flash drive and transfer it to the computer to run a virus scan. See if anything is found and remove it. Then see if you can log on in normal mode to run the rest of the scans.


    umm , what is safe mode ? ebarrassed ! Shows how computer literate I am ! This is safe mode.
    Basically, you tap F8 while the computer is starting, a menu will appear and you select safe mode.Quote from: needinghelppp on February 10, 2008, 01:16:29 PM
    Quote from: evilfantasy on February 10, 2008, 01:02:19 PM
    Can you start it in safe mode?

    If so download ClamWin to a flash drive and transfer it to the computer to run a virus scan. See if anything is found and remove it. Then see if you can log on in normal mode to run the rest of the scans.


    umm , what is safe mode ? ebarrassed ! Shows how computer literate I am !

    Ok , I can enter in safemode. However , I do not have a flashdrive , am I out of luck ? I hate to go buy one of these things , then these procedures not work , and I have to put it in the shop , so then I spent even more money than I needed to.Quote from: Deerpark on February 10, 2008, 01:49:57 PM
    This is safe mode.
    Basically, you tap F8 while the computer is starting, a menu will appear and you select safe mode.
    Thanks !
    3973.

    Solve : can not coplete a syware scan?

    Answer»

    i run a a spyware scan and when it get to a FILE CALLED c:\WINDOWS\system32\aux.dyr it freezes. what is this file and how can i fix it? also when i put a disk in my cd drive it wont open automatically like it use to how can i fix that?What scan do you try to run? Windows version?and what spyware PROGRAM are you using?im am trying to run SUPERANTISPYWARE free edition. aux.dyr << Are you sure that is right?

    Have you tried running it in safe mode?

    3974.

    Solve : CMIII running in the background?

    Answer»

    Hi, when I start Windows XP and I check the task manager I see 3 instances of CMIII running in the background and its USING up 100% of the cpu. I need to CLOSE all of them from the task manager or else everything SLOWS down. Is this a trojan and how do I get rid of it?Start here post the logs when finished.

    3975.

    Solve : SOMEONE PLEAAASEEEE HEELPP?!!?!?!?

    Answer»

    when i try to CHECK my messages or send a message on myspace i GET taken to this link...
    it was fine yesterday.. COULD it be a virus that norton is not FINDING???

    http://gateway.2wire.net/xslt?PAGE=HURL00Start here post the logs when FINISHED.

    3976.

    Solve : Hijackthis.com help- Computer keeps freezing up- please help?

    Answer»

    ok so i just rebooted the computer and this message comes up,

    windows cannot find 'C:\WINDOWS\system32\sstqo.exe' make sure you typed the name correctly and then try again.

    then its followed by

    Cannot load or run 'C:\WINDOWS\system32\sstqo.exe' SPECIFIED in registry. make sure the file exists in your computer or remove the reference to it in the registry.I have to apologize...I missed one entry...
    Open HJT, and checkmark:
    - F3 - REG:win.ini: load=C:\WINDOWS\system32\sstqo.exe
    Click "Fix checked".

    RESTART in Safe Mode.
    Using Windows Explorer, delete sstqo.exe (if exist) from C:\WINDOWS\system32

    Turn SYSTEM Restore off.

    Restart in Normal Mode.
    Turn System Restore on.

    Post new HJT log.

    3977.

    Solve : An interesting tidbit of info about AVG?

    Answer»

    I DOUBT this would affect the average user, but for those of you that solve problems for others it just might someday be SOMETHING to know.
    Maybe it is common knowledge already..... I don't know.


    Check out:
    http://forums.mozillazine.org/viewtopic.php?t=631529

    Presently there are 11 posts.

    The last one says:
    "Apparently, the POP server in AVG only allows 10 connections. I would check with their SUPPORT forums for a SOLUTION."

    The prior posts explain how they arrived there.


    3978.

    Solve : Has anyone heard of Output.cab??

    Answer»

    I found this on my DESKTOP tonight and I don't know what it is or where it came from. I went to Add/Remove and I can't find it there. I'm sure I did something stupid again but I even GOOGLED it and couldn't find anything. Does anyone have any ideas on this one?How big is it?
    Usually a .CAB file is a package that contains other files. The fact that it is named output.cab leads me to believe you might have accidentally created it. If it's a 0 BYTE file you can delete it. If it's a largeish file you may want to find out what's in it first.I couldn't find anything in my Add/Remove programs so I right clicked it and deleted it. Do you think there's something else I should do?We cleaned your computer pretty recently, right?
    You should be OK.
    In the future, as The Emperor said, it's better to ask a question here, before deleting.
    Now, it's gone, so be it.Oh my word that was THE Emperor??? I remember what happened now. When I was having that PROBLEM with the Symantec message (previous post) in my Incredimail emails I emailed Incredimail and they asked me to download Output.cab which I did and I received an email from them tonight saying they are working on it. I'll keep you posted. So it wasn't a bad thing Emporer!!!!

    3979.

    Solve : PC Tools Threat Fire (Free) update problem.?

    Answer»

    Yes. I am the owner and only user.

    Should I uninstall and reinstall again?

    I mentioned once in an earlier thread..
    c:\docume~1\Owner\Locals~1\Temp\TFUD.exe show up in everytime I USE CCleaner\REGISTRY.

    It just so happens to be one of the .exe file processes I've been asked to find and allow. If that makes any sense. Try to uninstall, clear temp files, and install again.You could try. Only this time use Revo to uninstall it with to ensure that everything is removed and you get a clean install.

    Download Revo Uninstaller

    Go in to Revo, right click what you want to uninstall (threatfire), choose advanced mode.
    This will launch the programs built in uninstaller and go through that process.
    Once complete, in Revo click next and it will scan the registry for leftovers.
    Choose Select all and click Delete then click Next and it will scan for any files/folders left behind.
    If any are found choose Select all > Delete.[/quote]

    A fresh downloading would mean you have the latest version so there should be no need to update. But if the problem is still there then try visiting the ThreatFire forum and asking there. They have some great helpers over there and I am sure they would like to know of this problem so they can look in to it.

    PC Tools/Threatfire Community ForumOK. TAlk to you all in a day or so.

    For now, Thanks for everything.

    TUpdate Info you. It's working now and here is why...

    Besides the 4 processes you suggested I find in the program files and 'allow' them; I was instructed to find a fifth process to allow. It is a second TFUD.exe in...
    C:\Documents & Settings\Owner\Local Settings\Temp\TFUD.exe

    There are no updates available as of yet but at least this time I wasn't told to check my internet connection.

    Thanks guy's

    T
    I saw your thread in ThreatFire forum. Strangely enough, I use Comodo, as well, and I didn't have to go through all these steps...hmmmThe update has been released.

    http://www.pctools.com/forum/showthread.php?p=179334#post179334Yes. Everything in that department is working just fine now. I think it was Comodo 'Learning' that poped up and told me today about the advancement I received . I checked it and I was up to date. Good advice and a job well done. But I wasn't able to link into the Revo Uninstaller as suggested. IE7 couldn't complete the task. Spilt milk I don't know?

    I have another problem, it has to do with specific email addresses that I want to write too (trusted addresses/friends); the email I send are rejected and I'm informed by the postmaster my mail was undeliverable. I have to RESORT to using offline services like hotmail. It's a problem and not incidental.

    I live in a 1 1/2 horse town, I've contacted my ISP (VALP.NET) for support HA Ha. It's always the other guy's fault. I must be sending a bad signal. My email editor is MS Office '03.

    I need direction to solve a problem that seemingly should be simple but for me is not. I'm being told by the Post Master I have SPAM HEADER, CMDSPACE & WEIGHT warnings that I am exceeding.

    I have used the "greater" forum before asking questions like this in the other categories but never get a response.

    You're the DUDES that have the answers; unless one is a chick.

    Would you like to work the issue? Should I start a new thread?

    Quote

    But I wasn't able to link into the Revo Uninstaller as suggested.

    Link fixed.

    http://www.majorgeeks.com/Revo_Uninstaller_d5706.htmlQuote
    I have another problem
    You may want to start a new topic.
    3980.

    Solve : New and need help?

    Answer»

    First off HI!! i am new to the site and need some help. Well a while ago i got a virus or trojan horse dont remember for sure, anyways i got most of it all cleared up but there is one thing that i can not get back and thats my desktop background. It will not let me do patterns just solid colors. its hard to explain but i can choose solid colors and nothing else, cant USE my PICTURES or anything and its drivin me crazy haha. Any help would be really really really appreciated!!!!! Thanks in advance!!!Also when i shut the computer down the screen with the background i want on there comes up its kinda like my desktop has two layers, the solid color one on top and the one i want on bottom, also when i start the computer back up i get two boxes that come up. one looks like this
    c:\program files\fuhudwno\xibankro.dll
    and the other one this
    c:\WINDOWS\system32\btpkdnym.dllWelcome to the CH forums.

    I think your system is still infected - one of the Mods may move your post to the Computer Viruses and Spyware forum.

    Meantime can you give us some indication of your hardware/software setup so that we know what kind of beast we're trying to diagnose especially your Operating System, Anti-Virus and Firewall names.

    Please READ this..

    K the computer i have is here http://www.amazon.com/Pavilion-Center-a1310n-Desktop-Processor/dp/B000E1VZ7M
    and for a anti virus i have AVG free and i just have the windows firewallThankyou. Strongly recommend that you install a third-party firewall such as Zone Alarm or Comodo - both free. The built-in XP firewall only checks incoming intrusions so if you are infected and the malware wants to report home via the INTERNET there's nothing to alert you.

    Start a cleanup here..

    Good luck.

    Moving this post to Computer Viruses and Spyware to help it be resolved faster

    OP is MIA, though...I tried doin everything you said and i still have the same stuff goin on anything else i can try?Quote

    anything else i can try?

    Posting the logs as requested in the instructions. We can't help without the logs.
    3981.

    Solve : what is a good/free spyware program??

    Answer»

    Thanks,
    I probably will retry the spybot s&d and maybe the other ones too. I'm just a little gunshy RIGHT now because of my recent ordeal!

    Also, I still don't know why the Trend Micro Housecall WOULD not run. I use FireFox. Would it be better to run it in IE?
    Or more to the POINT, If I feel McAfee has MISSED something, and I want to run ANOTHER virus scan, are there other/better options than "housecall"? If I download another antivirus program i.e. AVG, it conflicts with McAfee and funny things happen.
    JImGo in to add/remove programs and uninstall the Housecall entry and then try it again. If it doesn't work after that then try it in IE.OK

    3982.

    Solve : MS Office & Norton AntiVirus definition issue.?

    Answer»

    Hello everyone, I have an issue with Norton LiveUpdate associated with MS OFFICE.
    The Norton LiveUpdate Utility activates EVERYTIME SOMEONE opens an office file.

    The utility SUGGESTS that the virus definitions are out of date and liveupdate needs to obtain new definitions. LiveUpdate runs and says that the latest definitions are up to date.

    Every computer in our office running Norton is experiencing the same issue.
    Has ANYONE heard or experienced this issue before?

    Your help will be appreciated.

    Thanks in advance.One more reason to dislike Norton...
    Anyway, try to disable Norton AntiVirus Office plug-in: http://support.microsoft.com/kb/329820Thank you for the reply and it looks as if this has solved our issue.

    3983.

    Solve : major help needed fast have had no luck elsewhere and need my computer 4 school!?

    Answer»

    im not enitrly sure of what it is yet ive tryed about 8 to 10 different instructions on how to GET rid of that icon in the tray with a red dot with a white X accross. i keep getting the balloon every 1 to 2 min saying your computer is infected! windows has detected spyware infrection! ... blah blah recomendes blah blah you know how its installs fake anti spyware and crap but yes majority of instructions calles for avg anti virus and hijackthis to install and run well when i try this i install like the instructions say and the instructions say start the avg and run the scan and then later use the hijackthis .SEE this is where the problem is everytime i try to start the program i CANT it just trys to load then nothing niether avg or hijackthis will load ? any way to get them to work or to get rid of this crap? (also i have unstalled and reinstalled both programs quiet a few times and same result and have tryed starting them in safe mode and still same problem) i also have a FAKE windows UPDATE icon and help and support center icon on my desktop and i dont want to CLICK it because i can see it has a shortcut to the internet then some website ALSO i have a balloon with a red dot and white X saying "a critical error could occur ***STOP: 0x000007B (0xF20184, 0x00000, 0xCC0034)**** Inaccessible handler or device. Click balloon to fis the problem" , obvously a fake random code to scare me but how to i get rid of the balloon and the fake windows icon (i have tried deleting the icons and new ones *magicaly* appear on my desktop LOL ok well im running XP on a DELL and i have used the smitfraud.exe program a good 12 times and followed online instructions about the same problem but still havent been fixed i have tried to download hijackthis and avg and go figure they wont START!!!! i have trend-micro anti spyware and ad-aware and they find the problem i think but never deletes it even thou it says it does. We at least need a Hijackthis log to start with. How did you get smitfraud fix to run but not the other programs? idk i just dowload smitfraud to my desktop when into safe mode and clicked it it worked but avg and hijackthis every time i install them and then try and run them they dont work?Go to this post and work as many as the steps as you can. Boot into safe mode to run Dr Web and SuperAntispyware. Then run the Online scan from normal boot mode.

    Like I said, we will need to get some logs to see what is going on.

    3984.

    Solve : Please spare a moment to help me out if you can??

    Answer»

    Okay..
    I got a NEW laptop last week and I'm over the moon, but despite all my research before hand i cant help but think I've already screwed it up >.>

    This morning i TURNED it on and started about my normal business only to have it suddenly freeze on me. I turned it off and on again and had a look at that nifty gadget vista has which checks CPU/RAM usage and saw that it was working incredibly hard considering what little i was doing, heck I opened mozilla and it SHOT up to 100%.
    Uh-oh. so I decide the best thing to do would be to run a virus scan but the results I got weren't what i was expecting and i could really do with being told what to do here :


    (a screen shot SEEMED the best way to ask for help, hope I'm not breaking any rules here)

    Additional info you may need to know:
    ~I'm running vista home premium
    ~on an Acer aspire 5920 with 2GHz processing power, 2GB ram and 120 GB HDD
    ~However that 120GB came split into two drives
    ~and under someone else's advice i moved my documents to drive D. (but i doubt that's important)

    I asked if you could spare a moment not a morning so i'm sorry if i just RAMBLED away there..Try to uninstall/reinstall AVG.
    If you have Windows Defender running, turn it off during the above process.You may want to run chkdsk /r on both of those partitions....

    3985.

    Solve : Need help toRemove amvo.exe from my PC?

    Answer»

    Please help.........Please see this POST to begin the MALWARE REMOVAL process.

    3986.

    Solve : Help don't know what to do?

    Answer»

    I think I have a VIRUS or something

    My computer just stopped working at full capacity
    **my cd drive doesn't read cd's
    **any memory drive/flashdisk is atumatically asked to be formatted even though I have used it on my computer before
    **Any antivirus/spyware has benn disabled Avg, Spybot, CCleaner, Hijackthis
    **When I try to open the programs mention above, the computer immediatly closes them
    **I can't reinstall the programs
    **my wireless card has been disabled

    Does anyone have a solutionCan you boot into safemode?If you can boot to Safe Mode, try to run HijackThis from there.nope doesn't let me reboot in safe mode I tried it by doing.... run..msconfig and at startup pressing f8
    when I choose safe mode it starts booting up and then upruptly restarts stating an error messege

    we appologize for the inconvinience but windows did not start succesfully a RECENT hardware or software CHANGE might have caused this

    I tried selecting to boot up with last known good configuration and it just boots up like normal

    ***While in msconfig I saw system resote would that help in any way???
    ***would it be safe to take all my pics and info and burn it onto a cd and just restore settings or have a tech erase the harddrive and reinstall everything again??You can try System Restore. You don't have to worry about your pictures, and data. System Restore won't touch them.dont have that option anymore i am in a ENDLESS loop of restartsit gets up to the windows logo and a blue SCREEN flashes really quickly then it restarts.
    If you have your windows XP cd or your manufacturers recovery CD boot from that CD, choose to Install windows, press F8, then choose Repair windows. That will replace all of your system files without damaging your data. You should then be able to boot back into windows and continue cleaning your system.

    3987.

    Solve : stubbern trojan?

    Answer»

    Im having trouble ridding my computer of a trojan. It causes IE to crash occaisionally, has caused trouble with warcraft and causes my comp to run slow.

    Here are the logs of the scans you reccamended I do:

    any advice would be helpful, thanksSUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 02/12/2008 at 04:05 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3400
    Trace Rules Database Version: 1392

    Scan type : Complete Scan
    Total Scan Time : 00:35:35

    Memory items scanned : 357
    Memory threats detected : 2
    Registry items scanned : 3379
    Registry threats detected : 50
    File items scanned : 29938
    File threats detected : 28

    Adware.AboutBlankChanger
    C:\WINDOWS\TEMP\IEOBJ.DLL
    C:\WINDOWS\TEMP\IEOBJ.DLL
    HKLM\Software\Classes\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\InprocServer32
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\InprocServer32#ThreadingModel
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\ProgID
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\Programmable
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\TypeLib
    HKCR\CLSID\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}\VersionIndependentProgID
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{489C5DDD-AB4C-48EC-B397-505BABF9B4BD}

    Adware.E404 Helper/Variant
    C:\PROGRAM FILES\HELPER\1202682892.DLL
    C:\PROGRAM FILES\HELPER\1202682892.DLL
    C:\PROGRAM FILES\HELPER\1202682810.DLL
    C:\PROGRAM FILES\HELPER\1202682811.DLL
    C:\PROGRAM FILES\HELPER\1202682847.DLL
    C:\PROGRAM FILES\HELPER\1202682851.DLL

    Unclassified.Unknown Origin
    HKLM\Software\Classes\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\InprocServer32
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\InprocServer32#ThreadingModel
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\ProgID
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\Programmable
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\TypeLib
    HKCR\CLSID\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}\VersionIndependentProgID
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}

    Rootkit.RunTime3/FutureGen
    HKLM\System\ControlSet001\Services\Bjr75
    C:\WINDOWS\SYSTEM32\DRIVERS\BJR75.SYS
    HKLM\System\ControlSet003\Services\Bjr75
    HKLM\System\CurrentControlSet\Services\Bjr75
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP292\A0036570.SYS

    Trojan.DNSChanger-Codec
    HKCR\CLSID\E404.e404mgr
    HKCR\CLSID\E404.e404mgr#UserId
    HKCR\ChristmasPorn
    HKCR\ChristmasPorn\CLSID
    HKU\.DEFAULT\Software\ChristmasPorn
    HKU\S-1-5-18\Software\ChristmasPorn
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChristmasPorn
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChristmasPorn#UninstallString
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChristmasPorn#InstallLocation
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChristmasPorn#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ChristmasPorn#DisplayIcon
    C:\Program Files\ChristmasPorn\Uninstall.exe
    C:\Program Files\ChristmasPorn
    C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\G3F9VRPQ\TURBOCODEC1315[1].EXE
    C:\WINDOWS\TEMP\TURBOCODEC4531.EXE

    Adware.E404 Helper/Hij
    HKCR\E404.e404mgr
    HKCR\E404.e404mgr\CLSID
    HKCR\E404.e404mgr\CurVer
    HKCR\E404.e404mgr.1
    HKCR\E404.e404mgr.1\CLSID
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0\win32
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\FLAGS
    HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\HELPDIR
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid32
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib
    HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib#Version

    Rootkit.Unclassified/KR_Done
    C:\WINDOWS\system32\kr_done1

    Adware.Tracking Cookie
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\LocalService\Cookies\[emailprotected][2].txt
    C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][2].txt
    C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][2].txt
    C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][1].txt
    C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][2].txt
    C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][1].txt

    Trojan.Unknown Origin
    C:\DOCUMENTS AND SETTINGS\SAM\LOCAL SETTINGS\TEMP\XLOADER10296.EXE~

    Trojan.Unclassifed/K-Series
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP292\A0033488.EXE
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP292\A0035534.EXE
    C:\WINDOWS\TEMP\KDEZC.REN
    C:\WINDOWS\TEMP\KDGEN.REN

    Trojan.LoadAdv-Gen
    C:\WINDOWS\PREFETCH\LOADADV535.EXE-0DA65DC9.PF

    Adware.E404 Helper/Variant-A
    C:\XKUJGMD.EXE
    C:\WINDOWS\Prefetch\XKUJGMD.EXE-07347033.pf
    csrcli32.dll;c:\windows\system32;Trojan.PWS.GoldSpy;Deleted.;
    gtdownlr_134.ocx;c:\windows\system32;Adware.Gdown;;
    logcrypt.dll;c:\windows\system32;Trojan.DownLoader.46414;Deleted.;
    msdfmap.dll;c:\windows\system32;Trojan.PWS.GoldSpy;Deleted.;
    msftp.dll;C:\Documents and Settings\LocalService;Trojan.DownLoader.44897;Deleted.;
    msftp.dll;C:\Documents and Settings\Sam;Trojan.DownLoader.44897;Deleted.;
    1202549854.exe;C:\Documents and Settings\Sam\Local Settings\Temp;Trojan.Click.16987;Deleted.;
    A0036630.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Adware.Nopage;;
    A0036631.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Adware.Nopage;;
    A0036632.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Adware.Nopage;;
    A0036633.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Adware.Nopage;;
    A0036634.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Adware.Nopage;;
    A0037634.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.46414;Deleted.;
    A0037641.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    A0037642.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    A0037650.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    A0038640.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    A0038648.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.PWS.GoldSpy;Deleted.;
    A0038649.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.46414;Deleted.;
    A0038650.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.PWS.GoldSpy;Deleted.;
    A0038651.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    A0038652.dll;C:\System Volume Information\_restore{3D3CE40B-77A8-434D-B2A6-65D3C6785DA8}\RP293;Trojan.DownLoader.44897;Deleted.;
    gtdownlr_134.ocx;C:\WINDOWS\system32;Adware.Gdown;;
    msftp.dll;C:\WINDOWS\system32;Trojan.DownLoader.44897;Deleted.;
    202.exe;C:\WINDOWS\Temp;Trojan.Packed.147;Deleted.;
    4531.exe;C:\WINDOWS\Temp;Trojan.DownLoader.44983;Deleted.;
    Copy of pinch2-99-orig.exe;C:\WINDOWS\Temp;Trojan.PWS.LDPinch.1941;Deleted.;
    # version=4
    # OnlineScanner.ocx=1.0.0.635
    # OnlineScannerDLLA.dll=1, 0, 0, 79
    # OnlineScannerDLLW.dll=1, 0, 0, 78
    # OnlineScannerUninstaller.exe=1, 0, 0, 49
    # vers_standard_module=2870 (20080212)
    # vers_arch_module=1.063 (20080117)
    # vers_adv_heur_module=1.064 (20070717)
    # EOSSerial=3f62cc0fb59be3478aa7aea25fbd058f
    # end=finished
    # remove_checked=true
    # unwanted_checked=true
    # utc_time=2008-02-12 10:55:18
    # local_time=2008-02-12 05:55:18 (-0500, Eastern Standard Time)
    # country="United States"
    # osver=5.1.2600 NT Service Pack 2
    # scanned=87477
    # found=11
    # scan_time=686
    C:\Documents and Settings\LocalService\msftp.dllWin32/TrojanDownloader.Agent.NVF trojan (unable to clean - deleted)00000000000000000000000000000000
    C:\Documents and Settings\Sam\msftp.dllWin32/TrojanDownloader.Agent.NVF trojan (unable to clean - deleted)00000000000000000000000000000000
    C:\Documents and Settings\Sam\Local Settings\Temp\xdihwvxa.exe~Win32/TrojanDownloader.FakeAlert.G trojan (unable to clean - deleted)00000000000000000000000000000000
    C:\WINDOWS\system32\msftp.dllWin32/TrojanDownloader.Agent.NVF trojan (unable to clean - deleted)00000000000000000000000000000000
    C:\WINDOWS\Temp\52FE.tmpmultiple infiltrations (deleted)00000000000000000000000000000000
    C:\WINDOWS\Temp\52FE.tmp »NSIS »4531.exeprobably a variant of Win32/TrojanDownloader.Banload.BJY trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a PART of the deleted object)00000000000000000000000000000000
    C:\WINDOWS\Temp\52FE.tmp »NSIS »dropper1005.exeWin32/Adware.SpyKillerPro application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000
    C:\WINDOWS\Temp\srsvc.exeWin32/Adware.SpyKillerPro application (deleted)00000000000000000000000000000000
    C:\WINDOWS\Temp\srsvc.exe »NSIS »SpyKillerPro.exeWin32/Adware.SpyKillerPro application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000
    C:\WINDOWS\Temp\srsvc.exe »NSIS »SpyKillerProUpdate.exeWin32/Adware.SpyKillerPro application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000
    C:\WINDOWS\Temp\srsvc.exe »NSIS »helper.sysWin32/Adware.SpyKillerPro application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:30:23 PM, on 2/12/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\drivers\spool.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\spool.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    G:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe
    C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe
    C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thottbot.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [avast!] G:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Attractive Clock] G:\Program Files\Attractive Clock\Attractive Clock.exe
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Windows Console] wkssvc.exe
    O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
    O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spool.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] G:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe
    O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spool.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spool.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1184605009656
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184606985140
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1A10A1F2-DF85-4176-BFE4-AC0AED0A9830}: NameServer = 85.255.115.83,85.255.112.205
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4DB29E7A-E423-4A1C-A035-55A083D20E9B}: NameServer = 85.255.115.83,85.255.112.205
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8E8410DB-0FA6-4944-9771-4791FAE9D2A4}: NameServer = 85.255.115.83,85.255.112.205
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.83 85.255.112.205
    O17 - HKLM\System\CS1\Services\Tcpip\..\{1A10A1F2-DF85-4176-BFE4-AC0AED0A9830}: NameServer = 85.255.115.83,85.255.112.205
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.83 85.255.112.205
    O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll
    O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Windows INSTALLER Class - {24E31EA9-FCE2-404F-BD80-20543565D946} - C:\WINDOWS\TEMP\~~install.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spool.exe
    O23 - Service: Windows Image Acquisition (WIA) stisvcSchedule (stisvcSchedule) - Unknown owner - C:\WINDOWS\system32\advapi32v.exe

    --
    End of file - 7925 bytes
    Download SDFix.exe and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following:

    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard).
    • Finally add the contents of the Report.txt in your next post.
    .

    Please download Combofix by sUBs from one of the below links.
    (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
    • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
    • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
      • Click this link to see a list of security programs that should be disabled and how to disable them.
      • If yours is not listed and you don't know how to disable it, please ask.
    • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
    • Double click combofix.exe & follow the prompts.

        • From the keyboard select 1 and press Enter[/COLOR]
        • When finished, it will produce a log for you.
        • Post that log in your next reply.
        Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
        • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
        • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
        .
        ----------

        Next post please add
        SDFix log
        Combofix log

      I tried several times to get combofix to work, but couldnt get it to load.

      here is the SDFix log, however...

      SDFix: Version 1.141

      Run by Sam on Tue 02/12/2008 at 08:28 PM

      Microsoft Windows XP [Version 5.1.2600]

      Running From: C:\SDFix\SDFix

      Safe Mode:
      Checking Services:

      Name:
      4fdw
      runtime

      Path:
      \??\C:\WINDOWS\system32\4fdw.dll
      \??\C:\WINDOWS\System32\drivers\runtime.sys

      4fdw - Deleted
      runtime - Deleted


      Patched user32.dll detected!

      Note: SDFix Does Not Repair This File!

      "C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll" 577024 03/02/2005 01:09 PM
      "C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll" 577024 03/02/2005 01:19 PM
      "C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll" 578048 03/08/2007 10:48 AM
      "C:\WINDOWS\$NtServicePackUninstall$\user32.dll" 561152 03/02/2005 01:20 PM
      "C:\WINDOWS\$NtUninstallKB890859$\user32.dll" 577024 08/04/2004 02:56 AM
      "C:\WINDOWS\$NtUninstallKB890859_0$\user32.dll" 560128 03/31/2003 07:00 AM
      "C:\WINDOWS\$NtUninstallKB925902$\user32.dll" 577024 03/02/2005 01:09 PM
      "C:\WINDOWS\ServicePackFiles\i386\user32.dll" 577024 08/04/2004 02:56 AM
      "C:\WINDOWS\system32\user32.dll" 577536 03/08/2007 10:36 AM
      "C:\WINDOWS\system32\dllcache\user32.dll" 577536 03/08/2007 10:36 AM

      Download the below update to restore original files:

      http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx


      Restoring Windows Registry Values
      Restoring Windows Default Hosts File
      Restoring Default Schedule Service Path

      Rebooting...


      Normal Mode:
      Checking Files:

      Trojan Files Found:

      C:\WINDOWS\system32\4fdw.dll - Deleted
      C:\WINDOWS\system32\drivers\spool.exe - Deleted



      Folder C:\Program Files\Helper - Removed


      Removing Temp Files...

      ADS CHECK:



      Final Check:

      catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-02-12 20:38:20
      Windows 5.1.2600 Service Pack 2 NTFS

      detected NTDLL code modification:
      ZwEnumerateKey, ZwEnumerateValueKey, ZwQueryDirectoryFile, ZwQuerySystemInformation

      scanning hidden processes ...

      C:\WINDOWS\system32\.9c3322f5\9c3322f5.exe [492] 0x89076788

      scanning hidden services & system hive ...

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\9c3322f5]
      @="Service"
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\9c3322f5]
      @="Service"
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_9C3322F5]
      "NextInstance"=dword:00000001
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\9c3322f5]
      "Type"=dword:00000110
      "Start"=dword:00000002
      "ErrorControl"=dword:00000000
      "ImagePath"=str(2):"C:\WINDOWS\system32\.9c3322f5\9c3322f5.exe"
      "DisplayName"="Microsoft DDE+ server"
      "ObjectName"="LocalSystem"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\9c3322f5]
      @="Service"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\9c3322f5]
      @="Service"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_9C3322F5]
      "NextInstance"=dword:00000001
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\9c3322f5]
      "Type"=dword:00000110
      "Start"=dword:00000002
      "ErrorControl"=dword:00000000
      "ImagePath"=str(2):"C:\WINDOWS\system32\.9c3322f5\9c3322f5.exe"
      "DisplayName"="Microsoft DDE+ server"
      "ObjectName"="LocalSystem"

      scanning hidden registry entries ...

      scanning hidden files ...

      C:\WINDOWS\system32\.9c3322f5
      C:\WINDOWS\system32\.9c3322f5\9c3322f5.Aff.config 224 bytes
      C:\WINDOWS\system32\.9c3322f5\9c3322f5.core.dll 162816 bytes executable
      C:\WINDOWS\system32\.9c3322f5\9c3322f5.exe 51712 bytes executable
      C:\WINDOWS\system32\.9c3322f5\9c3322f5.GR.config 190 bytes
      C:\WINDOWS\system32\.9c3322f5\9c3322f5.ServerPlugin.config 45 bytes

      scan completed successfully
      hidden processes: 1
      hidden services: 1
      hidden files: 6


      Remaining Services:
      ------------------



      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "G:\\Program Files\\iTunes\\iTunes.exe"="G:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

      Remaining Files:
      ---------------

      File Backups: - C:\SDFix\SDFix\backups\backups.zip

      Files with Hidden Attributes:

      Sat 9 Feb 2008 784,896 A.SHR --- "C:\WINDOWS\wkssvc.exe~"
      Sun 10 Feb 2008 38,400 ..SHR --- "C:\WINDOWS\system32\advapi32v.exe"
      Sun 10 Feb 2008 41,427 ..SH. --- "C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe"
      Sun 10 Feb 2008 38,761 ..SH. --- "C:\Documents and Settings\Sam\Local Settings\Application Data\cftmon.exe"

      Finished!


      First:

      Go to www.windowsupdate.microsoft.com and get all critical updates.

      ----------

      Second:

      Download and install AVG Anti-Spyware Free to your desktop.

      * Once you have downloaded AVG Anti-Spyware Free , locate the icon on the desktop and double-click it to launch the set up program.
      * Once the setup is complete you will need run AVG and update the definition files
      * On the main screen select the icon Update then select the Update now link.
      * Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
      * Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
      * Once in the Settings screen click on Recommended actions and then select Quarantine <-- Dont forget this
      * Under Reports
      * Select Automatically generate report after every scan
      * Un-Select Only if threats were found
      * Under "What to scan"? "Select Scan every file".
      * Close AVG Anti-Spyware Free <-- Do not run the scan yet.

      Copy and paste the rest of the AVG instructions into notepad and save them to the Desktop or print them out so you can read them from safe mode.

      Boot your computer into Safe mode

      * Go to Start > Shut Off your Computer > Restart
      * As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
      * This will bring up a menu.
      * Use the Up and Down Arrow Keys to scroll up to Safemode
      * Then press the Enter on your Keyboard


      * Launch AVG Anti-Spyware Free by double-clicking the icon on your desktop.
      * Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan
      * AVG will now begin the scanning process, be patient this may take a little time.
      * Once the scan is complete do the following:
      * If you have any infections you will prompted, then select Apply all actions <--be sure qaurantine is selected
      * Next select the Reports icon at the top.
      * Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
      * Make sure to remember where you saved that file, this is important (usually the desktop)
      * Close AVG Anti-Spyware Free

      IMPORTANT:[/b] Do not open any other windows or programs while AVG is scanning, it may INTERFERE with the scanning process:

      * Add the AVG scan report in the next post.

      ----------

      Third:

      Please run the F-Secure Online Scanner

      Note: This Scanner works with Internet Explorer Only!
      • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
      • Allow the Active X control to be installed on your computer, then click the Accept button
      • Click Full System Scan and allow the components to download and the scan to complete.
      • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
      • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
      • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
        • If Automatic cleaning with Submit samples hangs, click
      Cancel, then New Scan[/list]
      • When the cleaning option is presented, Uncheck Submit samples to F-Secure
      • Click Automatic cleaning
      • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
      • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post.
      If needed go to Start > Run > type Notepad.exe then press OK.
      Paste the log into Notepad and save it to the desktop so it can easily be posted later.

      This scan can take quite some time, so please be patient

      Be sure to restart the computer.
      .
      ----------

      Fourth:

      After all of the above is complete and the computer restarted, run a NEW Hijackthis scan and post the log.

      ----------

      Next post add
      AVG scan log
      F-Secure scan log
      New Hijackthis log

      ok, did all those....heres the logs:
      AVG Anti-Spyware - Scan Report
      ---------------------------------------------------------

      + Created at:2:16:47 PM 2/13/2008

      + Scan result:



      C:\ftxybq.exe -> Backdoor.Agobot.app : CLEANED with backup (quarantined).
      C:\pngdmrl.exe -> Backdoor.Agobot.app : Cleaned with backup (quarantined).
      C:\WINDOWS\system32\advapi32v.exe -> Backdoor.IRCBot.bga : Cleaned with backup (quarantined).
      C:\d.exe -> Backdoor.IRCBot.bga : Cleaned with backup (quarantined).
      C:\WINDOWS\system32\drivers\ip6fw.sys -> Rootkit.Agent.pr : Cleaned with backup (quarantined).
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Abcsearch : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Adrevolver : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Adrevolver : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Advertising : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Burstnet : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Clickbank : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Doubleclick : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Euroclick : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Fastclick : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\WINDOWS\system32\config\systemprofile\Cookies\[emailprotected][1].txt -> TrackingCookie.Intelli-direct : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Overture : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Realmedia : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][1].txt -> TrackingCookie.Revsci : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Webtrends : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
      C:\Documents and Settings\Sam\Cookies\[emailprotected][2].txt -> TrackingCookie.Zedo : Cleaned.


      ::Report end

      canning Report
      Wednesday, February 13, 2008 15:37:19 - 16:43:26
      Computer name: HOUSE1
      Scanning type: Scan system for viruses, rootkits, spyware
      Target: C:\ G:\


      --------------------------------------------------------------------------------

      Result: 22 malware found
      Adware.Agent (spyware)
      System (Disinfected)
      Backdoor.Win32.Agent.eks (virus)
      C:\DOCUMENTS AND SETTINGS\SAM\LOCAL SETTINGS\TEMP\KJJ.EXE (Renamed & Submitted)
      C:\DOCUMENTS AND SETTINGS\SAM\LOCAL SETTINGS\APPLICATION DATA\CFTMON.EXE (Renamed & Submitted)
      C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\CFTMON.EXE (Renamed & Submitted)
      SpyKillerPro (spyware)
      System (Disinfected)
      Stealth_application (hidden item)
      C:\WINDOWS\SYSTEM32\.9C3322F5\9C3322F5.EXE (Submitted)
      Stealth_file (hidden item)
      C:\WINDOWS\SYSTEM32\.9C3322F5\9C3322F5.CORE.DLL
      Tracking Cookie (spyware)
      System (Disinfected)
      System
      System
      System
      System
      System
      System
      System
      System
      System
      Trojan-Downloader.Win32.Diehard.ef (virus)
      C:\WINDOWS\TEMP\LOAD.EXE (Renamed & Submitted)
      Trojan-Downloader.Win32.Small.hwc (virus)
      C:\WINDOWS\SYSTEM32\MSFTP.DLL (Renamed & Submitted)
      C:\DOCUMENTS AND SETTINGS\SAM\MSFTP.DLL (Renamed & Submitted)
      C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\MSFTP.DLL (Renamed & Submitted)
      Trojan.Win32.DNSChanger.apn (virus)
      C:\WINDOWS\SYSTEM32\KDKGG.EXE (Renamed & Submitted)

      --------------------------------------------------------------------------------

      Statistics
      Scanned:
      Files: 22986
      System: 3400
      Not scanned: 3
      Actions:
      Disinfected: 3
      Renamed: 8
      Deleted: 0
      None: 11
      Submitted: 9 Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 4:48:47 PM, on 2/13/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      G:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      G:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      G:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\svchost.exe
      G:\Program Files\Alwil Software\Avast4\setup\avast.setup
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thottbot.com/
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [avast!] G:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Attractive Clock] G:\Program Files\Attractive Clock\Attractive Clock.exe
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [updateMgr] G:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1184605009656
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184606985140
      O18 - Filter hijack: text/html - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll
      O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urikon.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: Windows Image Acquisition (WIA) stisvcSchedule (stisvcSchedule) - Unknown owner - C:\WINDOWS\system32\advapi32v.exe (file missing)
      O23 - Service: Automatic Updates wuauservdmadmin (wuauservdmadmin) - Unknown owner - C:\WINDOWS\system32\1_exceptionv.exe

      --
      End of file - 6195 bytes
      If combofix is still on the desktop download a new copy and try to run it again.

      Please download Combofix by sUBs from one of the below links.
      (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
      • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
      • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
        • Click this link to see a list of security programs that should be disabled and how to disable them.
        • If yours is not listed and you don't know how to disable it, please ask.
      • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
      • Double click combofix.exe & follow the prompts.

          • From the keyboard select 1 and press Enter[/COLOR]
          • When finished, it will produce a log for you.
          • Post that log in your next reply.
          Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
          • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
          • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
          ----------

          Next post
          Combofix log

        3988.

        Solve : trojan horse in captivity?

        Answer»

        ... for me too,.. thanks BroniDisable TeaTimer, as it'll interfere with the cleaning process:
        Right click Spybot's TeaTimer System Tray Icon.
        Click Exit Spybot-S&D Resident.
        TeaTimer closes.


        1. Print this post out, since you won't have an access to it, at some point.

        2. Close all windows, except for HijackThis.

        3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

        - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        - *O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
        - *O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        - *O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
        - *O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
        - O4 - HKLM\..\Run: [EarthLink Installer] " /C
        - *O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        - O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\4.bin\MWSBAR.DLL,S
        - *O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
        - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        - O4 - HKCU\..\RunOnce: [SpybotDeletingB6312] command /c del "C:\Documents and Settings\Richard\Local Settings\Temp\laf1.exe_old"
        - O4 - HKCU\..\RunOnce: [SpybotDeletingD8742] cmd /c del "C:\Documents and Settings\Richard\Local Settings\Temp\laf1.exe_old"
        - O4 - HKCU\..\RunOnce: [SpybotDeletingB3511] command /c del "C:\Program Files\Online Add-on\ictun.exe"
        - O4 - HKCU\..\RunOnce: [SpybotDeletingD1541] cmd /c del "C:\Program Files\Online Add-on\ictun.exe"
        - O4 - HKCU\..\RunOnce: [SpybotDeletingB8255] command /c del "C:\Program Files\Online Add-on\ictmdl.dll_old"
        - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        - *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        - O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRfox000
        - O20 - WINLOGON Notify: ACNotify - ACNotify.dll (file missing)

        4. Click on "Fix checked" button.

        5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

        6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

        7. Delete following files/folders (if present):

        - MyWebSearch folder from C:\Program Files

        8. Turn off System Restore:

        - Windows XP:
        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore".
        5. Click Apply.
        6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        - Windows Vista:
        1. Click Start.
        2. Right-click the Computer icon, and then click Properties.
        3. Click on System Protection under the Tasks column on the left side
        4. Click on Continue on the "User Account Control" window that pops up
        5. Under the System Protection tab, find Available Disks
        6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
        7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
        8. Click OK

        9. Restart in Normal Mode.

        10. Turn System Restore on.

        11. Post new HijackThis log.hey Broni,.. well,.. when i opened up hijackthis to "fix" the selected files,.. i couldn't find all the files you wanted me to fix. there were 6 files i couldn't find ,... 5 were " -04 - HKCU\..\runonce: [spybotdeletingB6312, D8742, B3511, D1541, and B8255,] ,.. and one was -08 - extra context menu item & search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRfox000,.. i checked and fixed all the others,.. but i'm GUESSING these "missing " files need to be fixed too,. so here's a new HJT log

        [file cleanup - saving space - attachment deleted by admin]It looks much better...
        Open HJT one more timr, and checkmark:
        - O8 - Extra context menu item: &Search - ?p=ZRfox000
        Click "Fix checked".
        Restart computer, and post new HJT log.hi Broni,... here's the newest hjt log

        [file cleanup - saving space - attachment deleted by admin]The log is clean.

        Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "SLIM" version.
        Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

        How is your computer doing?Hi Broni,.. the computer seems to be doing much better ,.. thanks very much to you. I do still have a question or two. Since i've deleted my Norton Anti-virus, what protection do i have now? Is the AVG a good anti-virus/malware protection?... and is my Windows firewall sufficient?
        Thanks again for all your help,.. it's GREATLY appreciated Good...
        AVG is very good AV program. As for malware real time protection, you may WANT to download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
        It won't interfere with your antivirus, nor firewall.

        Windows firewall has pretty poor ratings, so I recommend, you download free Comodo firewall: http://www.personalfirewall.comodo.com/, turn off Windows Firewall, and install Comodo.

        3989.

        Solve : IE Freezes or closes and lags bad!!?

        Answer»

        Hello!!!

        My Girlfriends Computer is having a problem with IE & windows explorer freezing on her or encountering problems and needs to close... also computer has been lagging bad.
        Have done defrag, scandisk, and disk cleanup. Did an a-squared scan which didn't find anything!! Also did an avg scan which found Trojans. Thinking maybe she has a mess of infections? I Have gone through your guidelines and have logs you recommended.. I'm not quite sure what to do within my lacking knowledge of viruses and Trojans.
        Any help would be greatly appreciated!
        Thank you in Advance!!

        O/S - Microsoft Windows XP Professional
        Version 2002, SP2
        Intel Pentium III processor , 930MHz
        System Manufacturer - D815EA
        System Model - EA81510A
        512 MB of Ram
        80 GB hardrive

        Following are logs!

        [file cleanup - saving space - attachment deleted by admin]Go to add/remove programs and look for Windows Messenger. If found please uninstall it.

        Note: This is different from MSN Messenger.

        ----------

        Click Start > Run and type in: services.msc
        Click OK
        In the Services window find: Boonty Games - BOONTY
        Select/highlight and right click the entry, and choose: Properties
        On the General tab, under Service Status click the Stop button
        Beside: Startup Type, in the drop menu, select: Disabled
        Click Apply, then OK

        Now, go to Start > Run, and copy/paste the following into the Open box:

        sc delete Boonty Games - BOONTY

        Click: OK

        ----------

        Open Hijackthis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://www.gamehouse.com/games/gamehouse/ghplayer.cab
        O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://www.gamehouse.com/games/DreamChronicles.cab
        O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - http://www.gamehouse.com/games/SpinTopGamesLauncher.cab
        O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVC Download Control) - http://www.gamehouse.com/games/dvcode/DVCControl.cab
        O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-us.cab
        O16 - DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} (DGTx.uc1) - http://69.57.132.82/DGTx.CAB
        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe


        Important: Close all windows except for Hijackthis and then click Fix checked.

        Exit Hijackthis.

        Restart the computer.

        ----------

        Please download Combofix by sUBs from one of the below links.
        (Try all three if necessary)

        Important! Combofix.exe MUST be saved to and ran from the Desktop.
        • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
        • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
          • Click this link to see a list of security programs that should be disabled and how to disable them.
          • If yours is not listed and you don't know how to disable it, please ask.
        • Warning: Combofix disconnects your computer from the internet. The CONNECTION is automatically restored before Combofix completes its run.
        • Double click combofix.exe & follow the prompts.

            • From the keyboard select 1 and press Enter[/COLOR]
            • When finished, it will produce a log for you.
            • Post that log in your next reply.
            Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
            • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
            • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
            ----------

            Next post please add
            Combofix log
            NEW Hijackthis log
          Thanks!!!... for the Quick response evilfantasy!!

          OK.. I didn't find windows messenger in the add/remove programs.. I did however remove it from the windows components.

          Also in the service status on Boonty games.. you said to click the stop button, It was already stopped. dunno if makes a difference but figured I should tell you.

          OK I did all you asked and I am sending the logs. will be waiting if something else needs to be done...once again thanks so much for the help!!

          [file cleanup - saving space - attachment deleted by admin]
            Everything looks fine on the malware front.

            We will want to do some cleanup at this point.

            LET's clear out the programs we've been using to clean up your computer, they are not suitable for
            general malware removal and could cause damage if launched accidentally.

            • Click START then RUN
            • Now type Combofix /u in the runbox
            • Make sure there's a space between Combofix and /u
            • Then hit Enter.

          The above procedure will:
          • Delete:
            • ComboFix and its ASSOCIATED files and folders.
            • VundoFix backups, if present
            • The C:\Deckard folder, if present
            • The C:_OtMoveIt folder, if present
            • Reset the clock settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .

            This is a good time to clear your infected system restore points and establish a new clean restore point:
            • Go to Start > All Programs > Accessories > System Tools > System Restore
            • Select Create a restore point, and click Next.
            • Next, go to Start > Run and type in cleanmgr
            • Select the More options tab
            • Next to System Restore click Clean up...
            This will remove all restore points except the new one you just created.

            Here are some great tools to help you keep from getting infected again.

            Spybot Search & Destroy - A safe and effective spyware scanner.
            * Official Spybot Tutorial
            * Spybot FAQ

            AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
            * AVG Anti-Spyware User Manual

            SpywareBlaster - SECURE your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * SpywareBlaster Tutorial

            Comodo BOClean - Stops trojans and many more malicious attacks.

            Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
            * Click here for a list of free firewalls.
            * Why would I consider a third party firewall?

            UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
            * Help with Windows updates

            Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

            Let us know how things are now.Hey There.. evilfantasy!!!

            Thanks so Much for the help!!! Did the clean up you said and cleaned out the restore points. The Computer is running like I had done a reformat on it..lol... Girlfriend was stressing about it big time! ... She is so happy now that it is running smooth again.. and she wants to say thank you too! Really appreciate the time you put in to help us less knowledgeable folks!! Think I will take you up on some of the advice of adding a few more tools like the comodo firewall.
            I Have the a-squared scanner and avg antivirus on here. Was wondering about the superantispyware and if I should leave it on here too!! Also should I keep the Dr. Web cureit?
            You have a Great Day and Again Thank You!! Definately leave the SuperAntispyware and Dr. Web. They are free and make a great ADDITION to the arsenal. I will alternate scanning weekly (or so) AVG, Super and Dr Web are among the best and most reliable. Be careful with aSquared. It is powerful and has been known to pick up legit items and flag them as malicious.

            Glad everything worked out. Regular maintenance with CCleaner and a spyware scan now and then will do wonders.

            Safe surfing...........
            3990.

            Solve : Can Not Reboot In Safe Mode?

            Answer»

            Among other problems (mentioned in previous post) I can not reboot in safemode. So I can not download and anti virus , spyware or HJT software. Can the safe MODE prob be handled FIRST?
            WinXP Home
            Dell Dimension 4550
            Pen 4
            1gb Ram
            60gb HD
            2.5ghz
            How are you accessing safemode ? ?
            Tap F8 repeatedly when booting before you see the windows splash screen...
            If this stiil does not work INSERT your Windows XP CD and got to Start/Run and type in sfc /scannow and hit Enter...let it run and re-boot.Why is not booting into safe mode stopping you from downloading? There are many ways to get to safe mode but if it is the malware that is blocking it then DO NOT FORCE SAFE MODE Instead continue on with any malware removal the best you can and post any logs you can get.

            Many Dell computers (mine included) the keyboard is the last thing to load so safe mode is impossible with the F8 method.

            If this is the case then use the tools below. If safe mode is "broken" then use SafeBootKeyRepair.

            Download & run this tool SafeBootKeyRepair-CF.

            It will only take a short moment for it to finish running. A log will be produced at C:\SafeBoot_Repair.txt. Please post that in your next reply.

            Do you have SUPERAntiSpyware installed? If so go to C:\Program Files\SUPERAntiSpyware and right click BootSafe.exe and send it to the desktop as a shortcut. Use it to boot into safe mode.

            If not then download the STAND alone version here

            3991.

            Solve : WinNT/Bagel.gen and Win32/Bagel.gen!C ARE THESE NEW??

            Answer»

            Three days I have been working on this.

            I cannot get rid of this. My anti virus quit working. I downloaded a new one and I get the MESSAGE that it "is not a vaid Win32 application". I have done the same with various spyware programs to the same result. I just download HJT but when it installed and I clicked on the desktop icon, I get "this is not a valid Win32 application"

            THe one adaward program that did work as far as scaning my machine reported the trojan and worm in the title above but with no way to remove with out buying the program. But is I do that an then install I will get "is not a Win32 application"

            I am about ready to just dump the Hard drive for a new one.

            DELL Diminsion 4450
            2.5ghz
            1GB Ram
            60GB H
            Intel Pen 4

            Please help.
            __________________
            William R. Bogart
            Edit | Quote | Quick Reply

            wrbogart
            View Public Profile
            Send a private message to wrbogart
            Send EMAIL to wrbogart
            Visit wrbogart's homepage!
            Find all posts by wrbogart
            Add wrbogart to Your Buddy List

            Computer Specifications [edit]
            Dell Computer Corporation Dimension 4550
            Windows XP Home Edition Service Pack 2 (build 2600)
            2.53 GIGAHERTZ Intel Pentium 4
            8 kilobyte primary memory cache
            512 kilobyte secondary memory cache
            NVIDIA GeForce4 MX 420 [Display adapter]
            768 Megabytes Installed Memory
            Sony DRU-810A DVD/CD RW Drive
            LITEON DVD-ROM LTD163 [CD-ROM drive]
            3.5" format removeable media [Floppy drive]

            #2 1 Minute Ago
            wrbogart

            Member Posts: 70
            Join Date: Mar 1999
            Experience: Intermediate

            PS

            Will not start in Safe Mode and cannot do a system restore
            either
            __________________
            William R. Bogart

            Do you have Windows XP CD?Yes, Have Win XP CD but CD rom and DVD rom will not read either.Those drives won't read ANY CD?

            3992.

            Solve : Multiple Personalitys!?

            Answer»

            My computer Lags, The mouse will not scroll, cannot exit websites esp google, And When I run Superantisyeware I keep getting tracking cookies!. And now nothing will OPEN like Hijack this Icons on desktop! Ok got this to work, Logfile of Trend MICRO HijackThis v2.0.2
            Scan saved at 9:52:17 AM, on 2/15/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
            C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
            C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\ThreatFire\TFTray.exe
            C:\PROGRA~1\SPYWAR~1\swdoctor.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Dell Support Center\bin\sprtcmd.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
            C:\Program Files\Network Associates\VirusScan\Mcshield.exe
            C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
            C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
            C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
            C:\WINDOWS\system32\PnkBstrA.exe
            C:\Program Files\Spyware Doctor\sdhelp.exe
            C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
            C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
            C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
            C:\Program Files\ThreatFire\TFService.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bellsouth.net/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
            O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
            O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
            O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
            O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\CUSTOM\dsca.exe"
            O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
            O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
            O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
            O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} - https://setup.bellsouth.net/wizlet/PWReset/static/controls/WebflowActiveXInstaller_4-2-1.cab
            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
            O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182202701703
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
            O23 - Service: MCAFEE Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
            O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
            O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
            O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
            O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
            O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

            --
            End of file - 7476 bytes
            I don't think it is malware. Try a good cleaning.

            Download and install CleanUp!.exe

            Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
            Set the program up as follows:

            • Click Options...
            • Make sure the arrow is set to Standard CleanUp!
            • Uncheck the following: (if checked)
              • Delete Newsgroup cache
              • Delete Newsgroup Subscriptions
            • Click OK
            Click the CleanUp! button to start the program. Reboot/logoff when prompted.

            Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility

            ----------

            Then use a third party defrag program to defrag the drive.

            http://filehippo.com/download_jkdefrag/I downloaded Cleanup.exe, But When I try to uncheck Newsgroups The arrow auto adjusts to custom setup? Also I have been using CC Cleaner, Is That close to the same thing?The instructions on Cleanup are slightly outdated so as long as the check boxes are correct everything will be fine. Sorry I need to update them.

            Cleanup will remove more then CCleaner. It is for a thorough cleaning where CCleaner is better for daily use.Alrighty Than! OW YEA, that worked really well. You guys are awsome, Thanks!Glad it worked.

            Safe surfing..............
            3993.

            Solve : dns spoofing?

            Answer»

            is there any body run dnsspoof from dsniff program or dnsa program. i try to run these program to implement DNS SPOOFING but no RESULT appear to me. any body can help me please Be more specific on what you're trying to ACCOMPLISH. With the information you've give, there's no way anyone can help you.

            3994.

            Solve : Does anyone know what this error message means??

            Answer»

            This started a few days ago and I have no idea what it means.

            Rundll

            Error loading C:/ProgramFiles\CommonFiles\ParetolLogis\UUS2\UUS.dll

            The specified module could not be found.

            This HAPPENS when I'm just playing a game that is in my system not ONLINE. Do you have XofySpy?

            If so uninstall it.Looked in add/remove and that wasn't there but I'm doing a search for it just incase.Search Paretologic alsoQuote from: evilfantasy on February 15, 2008, 06:11:02 PM

            Search Paretologic also


            Nothing for Paretologic either.Sorry I ran it again it's finding something. I had it as two words so I tried it as one word. It found two things so far. What do I do then.....delete them?It found two files. ParetoLogicDataRecover.msi and ParetoLogicRegistration.job

            I see you are off line now so I'm just GOING to go ahead and delete these files..msi is or was the installer for it or another PART of it.

            .job I'm not sure of. might have been the SCHEDULER?



            3995.

            Solve : Patch Tuesday - Microsoft releases six critical patches?

            Answer»

            2-13-08

            Quote

            This month's "Patch Tuesday" did not include a patch that had been promised in Microsoft's advance notification for February 2008. Microsoft could not be reached for comment at the time of writing to say why the patch had not been included.

            Source
            The windows Vista SP1 patch that is rolling out via Automatic UPDATES today causes a SIGNIFICANT portion of the machines to ENTER a reboot loop during the update requiring a reinstall. No fix has been mentioned by MSFT yet.
            More info can be found here:
            http://forums.microsoft.com/TechNet/showpost.aspx?postid=2848906&siteid=17Quote
            SP1 RC

            Different update but still good info.

            The Patch Tuesday release is just regular updates and not to do with the Beta version of SP1.This isn't the Beta SP1.
            We're getting reports that the Vista SP1 is actually being pushed out via Automatic Update as of today.
            Just thought I would warn folk if they are looking to go grab the regular patches to watch out for the Vista SP1 trying to install itself as an automatic update.Well that wasn't quite what they had previously stated. It was supposed to be MID March. Maybe they should have waited as planned.

            http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9063021Aha. Did some more checking around. Our users are morons.
            Some of them went and got the Vista update, then claimed it happened automagically.
            This compounded with the Slashdot story containing erroneous information led me to believe that the SP1 had been pushed out early. That is not the case. Please disregard all of my posts on this thread and go on about your business.It's a confusing trilogy trying to keep up with the release. I made a premature post last week myself.

            Still good info for what it has done to some of the PCs. I wonder how well the actual release will go.Quote
            We're getting reports that the Vista SP1 is actually being pushed out via Automatic Update as of today.
            Public release is planned for March....They RELEASED it to TechNet and MSDN subscribers on Valentines day.

            Quote
            Microsoft Corp. kept its promise and released Windows Vista Service Pack 1 yesterday to subscribers of its for-pay TechNet and Microsoft Developer Network (MSDN) services, the company said.
            I know that. I had a impression that TheEmperor post was referring to general public.
            3996.

            Solve : avg antivirus need local mirror?

            Answer»

            Hello everyone. I live in Serbia( thats in europe, sorry not sure if you know) I want to download AVG. I have a very slow dial up connection and was wondering if anyone knew of a site that had a mirror site I could download closer to HOME ( i can only FIND U.S and Austrailia)ok I just tried downloading it, 1 hour 30 into it the connect broke. I got to START over. is there any option?What site are you trying to download from?major geeks. I tried the file hippo site and its SLOWER. I got 2.6 kpbs around there. the most i get to dowmload is around 4.5Maybe you should ask a friend with broadband to download it for you...If FileHippo is slow then you may be out of luck.
            Have you tried the UK AVG site?

            http://www.avg.co.uk/doc/products-comparison-home-and-office/uk/crp/2?utm_source=Adwords&utm_medium=PPC
            no, but I will! thanks

            3997.

            Solve : please help me i m have trouble with computer?

            Answer»

            i have just reformatted my hard drivers for clean system .. Days later I'm finding popups ASKING me to scan and download programs to help me clean my system i know there is trouble some were but cant find so I'm looking for your help i have done all the log files and sending them in this post again thank you for looking and helping

            css4[1];C:\Documents and Settings\Hillary\Local Settings\Temporary Internet Files\Content.IE5\0DKIM07Z;Trojan.Virtumod.274;DELETED.;
            ptch[1];C:\Documents and Settings\Hillary\Local Settings\Temporary Internet Files\Content.IE5\HW5XQWLB;Trojan.Virtumod.269;Deleted.;
            ptch[2];C:\Documents and Settings\Hillary\Local Settings\Temporary Internet Files\Content.IE5\HW5XQWLB;Trojan.Virtumod.269;Deleted.;
            css4[1];C:\Documents and Settings\Susie\Local Settings\Temporary Internet Files\Content.IE5\0DKIM07Z;Trojan.Virtumod.274;Deleted.;
            ptch[1];C:\Documents and Settings\Susie\Local Settings\Temporary Internet Files\Content.IE5\B262KEVR;Trojan.Virtumod.269;Deleted.;
            css4[1];C:\Documents and Settings\Tera\Local Settings\Temporary Internet Files\Content.IE5\0DKIM07Z;Trojan.Virtumod.274;Deleted.;
            tk58[1].exe;C:\Documents and Settings\Tera\Local Settings\Temporary Internet Files\Content.IE5\HW5XQWLB;Trojan.StartPage.19993;Deleted.;
            A0000678.exe;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP11;Trojan.DownLoader.24715;Deleted.;
            A0002239.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP24;Trojan.Virtumod.240;Deleted.;
            A0003239.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP28;Trojan.Virtumod.240;Deleted.;
            A0003241.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP28;Trojan.Virtumod.272;Deleted.;
            A0003343.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP31;Trojan.Virtumod.274;Deleted.;
            A0004541.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP37;Trojan.Virtumod.274;Deleted.;
            A0004773.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004774.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004775.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004778.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004779.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004780.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004781.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004783.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004784.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004786.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004787.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004788.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004789.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            A0004790.dll;C:\System Volume Information\_restore{9AD0FAB8-E351-444F-9153-EBCF5E418524}\RP38;Trojan.Virtumod.269;Deleted.;
            rjwopojh.dll;C:\WINDOWS\system32;Trojan.Virtumod.260;Deleted.;
            nGpxx182328.exe;C:\WINDOWS\system32\nGpxx18;Trojan.DownLoader.24715;Deleted.;





            [file cleanup - saving space - attachment deleted by admin]Download Vundofix.exe to your desktop.

            • Double-click VundoFix.exe to run it.
            • Put a check next to Run VundoFix as a task.
            • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
            • When VundoFix re-opens, click the Scan for Vundo button.
            • Once it's done scanning, click the Remove Vundo button.
            • You will receive a prompt asking if you want to remove the files, click YES
            • Once you click yes, your desktop will go blank as it starts removing Vundo.
            • When completed, it will prompt that it will shutdown your computer, click OK.
            • Turn your computer back on.
            • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
            Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

            Please let Vundo finish, sometimes it can take multiple passes

            ----------

            Download SDFix.exe and save it to your Desktop.

            Double click SDFix.exe and it will extract the files to %systemdrive%
            (Drive that contains the Windows DIRECTORY, typically C:\SDFix)

            Please then reboot your computer in Safe Mode by doing the following:

            • Restart your computer
            • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
            • Instead of Windows loading as normal, the Advanced OPTIONS Menu should appear;
            • Select the first option, to run Windows in Safe Mode, then press Enter.
            • Choose your usual account.
            • Open the extracted SDFix folder and double click RunThis.bat to start the script.
            • Type Y to begin the cleanup process.
            • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
            • Press any Key and it will restart the PC.
            • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
            • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
              (Report.txt will also be copied to Clipboard).
            • Finally add the contents of the Report.txt in your next post.
            .
            ----------

            Run a new Hijackthis scan and post the log also.

            ----------

            Next post please add
            Vundofix log
            SDFix log
            Hijackthis log
            here are the logs you asked for
            again thanks so very much on helping out
            i cant tell you what this means to me thanks again

            [file cleanup - saving space - attachment deleted by admin]Download OTMoveIt2 by OldTimer.
            • Save it to your desktop.
            • Double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
            • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

              Code: [Select]C:\WINDOWS\system32\bpepdgko.dll
            • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
            • Click the red Moveit! button.
            • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
            • Close OTMoveIt2
            Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

            ----------

            Next post
            OTMoveIt logOTMoveIt log


            File/Folder C:\WINDOWS\system32\bpepdgko.dll not found.

            OTMoveIt2 v1.0.20 log created on 02262008_034434


            is this dll file important when i start windows it say run file error and i click OK then all seem fineNo it is part of the problem.


            This scanner works with Internet Explorer only
            Go to the BitDefender Online Scanner
            Click I Agree to the license and then install the ActiveX control.
            Please DO NOT change the Scanning Options.
            That will make your logs huge and we don't need to see clean files.

            Select Start Scan to begin.
            This scan can take a while so please be patient and let it complete.


            Once Bitdefender completes the scan:
            Click-on the Detected Problems tab.
            Then select Click here to export the scan report



            When the window comes up to save the report, change the Save as type: box to:
            Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save



            This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it.
            (take notice of where you save it so you can find it later)

            This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

            If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us

            Post the bdscan.txt in the next post.

            ----------

            Next post
            BitDefender log
            NEW Hijackthis log
            here are the file logs you ask for hope i did this right



            [file cleanup - saving space - attachment deleted by admin]Open Hijackthis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            O4 - HKLM\..\Run: [BMef98775c] Rundll32.exe "C:\WINDOWS\system32\bpepdgko.dll",s

            Important: Close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis.

            ----------

            Go to My Computer and locate then delete this file.

            C:\WINDOWS\system32\bpepdgko.dll

            ----------

            Restert the computer and let me know how things are now.the dll file is gone and when i restarted the error did not show up

            is there any thing i can do from this happing to me again ?

            or is there still more things to do here I will leave some links to programs to use to help keep the computer safe near the bottom of this post. There are some final steps to do now.

            Let's clear out the programs we've been using to clean up your computer, they are not suitable for
            general malware removal and could cause damage if launched accidentally.

            Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

            1. Double click OTMoveIt2.exe to launch it.
            2. Click on the CleanUp! button.
            3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
            4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
            5. Once complete exit out of OTMoveIt2

            This is a good time to clear your infected system restore points and establish a new clean restore point:
            • Go to Start > All Programs > Accessories > System Tools > System Restore
            • Select Create a restore point, and click Next.
            • Next, go to Start > Run and type in cleanmgr
            • Select the More options tab
            • Next to System Restore click Clean up...
            This will remove all restore points except the new one you just created.

            Here are some great tools to help you keep from getting infected again.

            Spybot Search & Destroy - A safe and effective spyware scanner.
            * Official Spybot Tutorial
            * Spybot FAQ

            AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
            * AVG Anti-Spyware User Manual

            SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * SpywareBlaster Tutorial

            Comodo BOClean - Stops trojans and many more malicious attacks.

            Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
            * Click here for a list of free firewalls.
            * Why would I consider a third party firewall?

            UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
            * Help with Windows updates

            Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I GET infected in the first place?

            Let us know if anything else comes up.
            3998.

            Solve : Why some email addressee's are refused delivery??

            Answer»

            No no, Thunderbird is just a mail client. You enter your server information in it and it goes out and picks up the mail. Just LIKE outlook express does. You don't require Firefox.By now you should know I'm a newbie but old enough to ask way to many questions before I just react. I hope you don't mind.

            I will read more about what TBird is. It should be harmless to download and see what it does once I understand what it is. I'll let you know, thanks, T.

            Well I sent mail using Tbird and my mail to the same addresses was RETURNED.

            So if I understand more now... Using a new email client (TBird) eliminates my PC as the source is that right?

            Why does using my hotmail account not fail as well?Quote from: tpolcha on February 16, 2008, 04:23:11 AM

            Why does using my hotmail account not fail as well?
            Because Hotmail is an online service with its own mail servers. So any mail you send through Hotmail isn't handled by your ISP's spam filter.So??

            Is is Declude that screens and labels my mail after it leaves my ISP and then it is refused somewhere when it is routed or refused by the ISP of the person I'm trying to send mail to???

            In one case, it is a yahoo address that I can't get trhough too but the ISP is Comcast.... So I need to contact Comcast for the resolution?

            Declude won't tell me why my mail fails their tests. They just refer me to the definitions; saying NOTHING specific about my transmition that is catching Decludes attention.

            They also just say that they are not responsible for 'bouncing' the mail. They haven't been helpful at all.

            ?So? The rest of the folks in my address book that I correspond with "Don't" have declude??? Maybe Baracuda? You only have this problem when sending mail from one specific email address right? And the problem PERSIST regardless of what client you use to send mail?

            So to me this suggest either your email provider is using a outbound spam filter from Declude or the email provider is doing something to your emails that makes them fail an inbound spam filter.

            In the first post you showed a log from an email you had sent to comcast.net, hotmail.com and yahoo.com email addresses. Did none of the intended recipients receive the email or was it only for some of them it bounced?Yes. My mail is refused when I use my ISP domain 'mail.valp.net'. It is refused when using MS Outlook Express, MS Office Outlook and now TBird but not when I use hotmail.

            In that example (first post) I sent mail to 5 addresses.

            The return notice identifies (first line) which of the 5 intended addresses
            were refused. The other 4 received delivery. So delivery only failed for one of the Yahoo addresses?Yes in that example, One yahoo account was refused.

            That is what is driving me so crazy.

            And as I made mention before I think, it will be aloud (in my estimate) say 1 to 5% of the attemtped tries. In 100 emails I might successfully get thru 5 times and 95 are refused.

            Quote from: tpolcha on February 16, 2008, 06:00:47 AM
            And as I made mention before I think, it will be aloud (in my estimate) say 1 to 5% of the attemtped tries. In 100 emails I might successfully get thru 5 times and 95 are refused.
            Is this NUMBER for all the emails you send or just for emails to this one person?OK. In the example post. The mail recipient that was refused is my 'X'.

            She uses yahoo as her client and she subscribes to Comcast I think as her ISP.

            Clarification: If my x was the lone addressee in 100 times in one week that I needed to correspond by email, I would expect to have at least 95 of my attempted sent mailings to be refused.

            It must be a filter at her end then. Either installed on her computer or at Yahoo. OK! I have some direction again to go in now. Thanks.

            I will task yahoo with some questions and return here to C/H with the next set of answers.

            C/H has proven to 'this beginner', they have their act together time and time again.

            From what I can find Declude is what Yahoo uses for an incoming spam filter. So the issue looks to be on the receiving end. You could try to contact Yahoo customer service and see what it takes to make sure your email gets through.
            3999.

            Solve : Its a virus..?

            Answer» THANKS man.

            I have an admin account that i think can do that also but i dont want to change ANYTHING i might get in trouble.

            Thanks alot man this computer should be ok now. I'll just RESTART now and i'll let you know about the status.

            Thanks alotNo probllem, glad we got it sorted out.

            Safe surfing...........Looks EVERYTHING is ok but its only background picture is not displaying COMPLETELY its only half way.

            ThanksNo now its showing
            4000.

            Solve : Computer running slow... HJT log posted?

            Answer»

            HI my uncle's computer is RUNNING slow i've tried running Norton virus scan, Spybot search & destroy, defragging the computer and Scan disk error checking. but it still seems to run slow. i was wondering if someone could look at this log and tell me what i need to do to speed things up. thanks ALOT!



            [file CLEANUP - saving space - attachment deleted by admin]Disable TeaTimer, as it'll interfere with the cleaning process:
            Right click Spybot's TeaTimer System Tray Icon.
            Click Exit Spybot-S&D Resident.
            TeaTimer closes.


            Open HJT, and checkmark following entries:
            - O2 - BHO: (no name) - {0E3208EE-A797-4095-95B8-783373A94A27} - C:\WINDOWS\system32\pmkjk.dll (file missing)
            - O4 - Global Startup: Dell Network Assistant.lnk = ?
            - O4 - Global Startup: Digital Line Detect.lnk = ?
            Click "Fix checked". Restart computer.

            You have a lot of startups (O4). Some of them can be disabled.

            What Java version is reported here: http://www.java.com/en/download/installed.jsp

            Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

            What are your computer specs?Your Java version is Version 5.0 Update 6. Please click the button below to get the recommended Java for your computer.

            Dell Inspiron 1501
            Mobile AMD Sempron(tm)
            Processor 3500+
            1.58 GHz, 448 MB of Ram
            52.1 GB hard drive 10GB being used 42.1GB Free

            Sorry it took me so long to reply.
            Which start ups can i disable?
            Quote

            Which start ups can i disable?
            Please, give me new HJT log, downloaded from here: http://www.snapfiles.com/get/hijackthis.html. Your version is outdated.

            You need to update your Java:
            http://java.sun.com/javase/downloads/index.jsp
            #4 - Java Runtime Environment (JRE) 6 Update 4
            Uninstall all previous versions of Java through Add\Remove.

            Did you run CCleaner?

            One of your problems is amount of RAM. I'd add a stick of 512MB, and you'll see the difference.updated java
            ran ccleaner also
            got updated HJT
            i'll ask my uncle to get some more RAM. any recommendations?
            new HJT log added
            thanks for the help

            [file cleanup - saving space - attachment deleted by admin]Quote
            i'll ask my uncle to get some more RAM. any recommendations?
            Go to www.crucial.com, enter your computer brand, and model - it'll tell you.

            Disable TeaTimer, as it'll interfere with the cleaning process:
            Right click Spybot's TeaTimer System Tray Icon.
            Click Exit Spybot-S&D Resident.
            TeaTimer closes.

            Open HJT, checkmark following startups (no actual program will be removed; they'll be prevented from starting with Windows):
            - O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
            - O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
            - O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
            - O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
            - O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            - O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            - O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            - O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            - O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            - O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            - O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            (if you use ASIAN characters in MS Office, leave the above 4 entries in green alone)
            - O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
            - O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            - O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            Click "Fix checked". Restart computer.thanks running a bit faster on start up
            thanks for the website i didn't think 2 Gigs of ram was that cheap.
            he does use some of the asian fonts so i didn't get rid of those 4 lines
            new HJT log posted.

            [file cleanup - saving space - attachment deleted by admin]It looks better...
            All, you need to do is to get more RAM. That should do it.Thanks alot for the help. i'm wondering how do u learn what all those values mean in HJT log and wether or not it's safe to remove? is there like some magic glossary list i could look at and remove them myself without having to bug u guys? As with any learning, it takes time. If you like to play with computer, and have some spare time, you can always sign up here: http://www.malwareremoval.com/forum/viewtopic.php?t=233
            It's free.
            For now, you better "bug" us, then make your computer unstable.