Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

4201.

Solve : A-Squared anti-dialer??

Answer»

Advice please.
Is it worth installing A-Squared ANTI-dialer? Or does the other security I have cover this? (IKBA!) Thanks.
Link to program below:

http://www.snapfiles.com/reviews/anti-dialer/a2antidialer.html

I have:-
Win XP Pro
Firefox
Winpatrol
AVG anti virus
AVG ant SPYWARE
RemoveIt
Spyware Blaster
Advanced Windows Care
Online Armor firewall
Super Anti Spyware free edition
AdAware SE personal
CCleaner If you are on a DIAL up connection then it is worth installing.I use broadband except when it goes down, twice this year so far, then use dial up.You could always just use it when needed.Thanks. I will DOWNLOAD it and keep it handy.

4202.

Solve : adware virus, need help?

Answer»

here is the latest log.

[recovering space - attachment deleted by admin]Go Start>Run, type in:
services.msc
Click OK.
Services window will open.
Find Windows File Depictor and Rotator service.
Right click on it, click Stop.
Right click again, click Properties, and under Startup type set it to Disable
Exit services window.

Go Start>Run, type in:
regedit
Click OK.
Registry Editor will open.

Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter
Click on + sign next to Filter
You'll see sub-folders. One of them will be:
text/html
Right click on it, click Delete. Agree.

Open HJT. Click on Config, then Misc Tools, and then press the Delete an NT service.. button. When it opens enter Windows File Depictor and Rotator and press OK.

Restart computer. Post new HJT log.hjt file.

[recovering space - attachment deleted by admin]Very nice. All clean...

Download, and install CCLEANER: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

Let me know, afterwards, how your computer is doing.thanks all set...one remaining issue. the background is still all white. it seems to be a left over from the red logo (adware advertising) that started this whole thing? any ideas?Did you TRY to change your background?yes i tried to change it, and it the changed background is there (underneath). I can see the correct background when i boot up, but then the whole background goes white. Download wphijack: http://files.iamnotageek.com/14/wphijack.zip
1. Unzip and save the file to your desktop.
2. Double-click wphijack.exe to run the program.
3. A window will appear reading "Wallpaper look like this?"
4. Click the Continue button.
5. Click Check for Hijack
6. Select all "REPAIR" buttons even though it may not say "Found!" This will fix a wallpaper hijack everytime if all repair buttons are pressed.did it. repaired all. nothing changed..Try XP Web\Wallpaper Defaults: http://www.kellys-korner-xp.com/xp_tweaks.htm (#339)that file is just a zip file with the original pdf's of the standard wallpaper. I unzipped that file for you. It lists all default Windows XP wallpapers:
Ascent.jpg
Autumn.jpg
Azul.jpg
Bliss.bmp
Crystal.jpg
Follow.jpg
Friend.jpg
Home.jpg
Moon flower.jpg
Peace.jpg
Power.jpg
Purple flower.jpg
Radiance.jpg
Red moon desert.jpg
Ripple.jpg
Stonehenge.jpg
Thumbs.db
Tulips.jpg
Vortec space.jpg
Wind.jpg
Windows XP.jpg

Open Windows Explorer, navigate to:
C:\WINDOWS\Web\Wallpaper
and compare your list with the above list.
Delete any unknown file.
Let me know, if you found any.
Restart computer.checked all files, they are all the same, rebooted, nothing. i did a ful scan with antispy and it found 45 adware cookies etc. i fixed them, but still assume that they will come back.Don't worry about tracking cookies. They'll be coming back. Nothing dangerous. You just need to clean them out, once in a while.
Now...
CREATE new profile, and see, if same problem exist. If not, MOVE your settings, and data from old profile to the new one, and delete old one.
Manual here: http://support.microsoft.com/kb/811151

4203.

Solve : Still having problems?

Answer»

I followed all orders regarding the Trojan but when I checked the FOUR items in HJT and ran the program again, the files were still there

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:42:28 PM, on 4/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\LAVASOFT\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Belkin\Belkin 54Mbps Wireless Utility\TOOL\OpenXpAuto.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Starfield\Desktop Notifier\wben.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Mozilla Firefox 3 Beta 4\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Intuit\QuickBooks Point of Sale 5.0\qbpos.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: (no name) - {4D0C329C-6250-4B45-A2BD-F7E8F7E40B3C} - c:\windows\system32\cdosysh.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54636635-BEA2-458F-925F-686E051AD2AC} - C:\WINDOWS\system32\ciadminj.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [QuickTime TASK] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [XpOpenAuto] "C:\Program Files\Belkin\Belkin 54Mbps Wireless Utility\TOOL\OpenXpAuto.exe" 979899a48a75987f6b9d86a9aa798c73837198a e83a6a498b878837b768a788c84
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [wben] "C:\Program Files\Starfield\Desktop Notifier\wben.exe"
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE9E888B-C60A-447A-B688-40B39CDE74EF}: NameServer = 205.171.3.65,205.171.3.64
O18 - Protocol: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\WINDOWS\system32\QBPOSProtocol.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hlhbwhtn - C:\WINDOWS\SYSTEM32\cdosysh.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 8777 bytes
Download SDFix.exe and SAVE it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally add the contents of the Report.txt in your next post.
Thanks again. BTW a winlogin.exe error occured immediately after the icons appeared ont he desktop following the finishing of the SDfix. here is the report

SDFix: Version 1.165

Run by Compaq_Owner on Tue 04/01/2008 at 04:13 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\COMPAQ~1\Desktop\SDfix\SDFix

Checking Services :

Name:
rwspczqn

Path:
system32\drivers\bdggybis.dat

rwspczqn - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting

Service rwspczqn - Deleted after Reboot

Checking Files :

Trojan Files Found:

C:\WINDOWS\SYSTEM32\CIADMINJ.DLL - Deleted


Could Not Remove C:\WINDOWS\system32\drivers\bdggybis.dat



Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-01 16:35:58
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes ...

THXPlease download Combofix by sUBs from one of the below links.
(Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
  • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
  • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
    • Click this link to see a list of security programs that should be disabled and how to disable them.
    • If yours is not listed and you don't know how to disable it, please ask.
  • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
  • Double click combofix.exe & follow the prompts.
    • Choose Yes to accept the Disclaimers.[
    • When finished, it will produce a log for you.
    • Post that log in your next reply.
    Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
    • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
    • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
    I disabled my A.V., Firewall and multiple spy programs. When computer rebooted they automatically reset back to normal mode. My avira picked up on combofix but I allowed it so it finished. Thanks again. I attached the log because it was to large to post.

    [recovering space - attachment deleted by admin]Download and install CleanUp!.exe

    Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
    Set the program up as follows:
    • Click Options...
    • Move the arrow to Standard CleanUp!
    • Uncheck the following: (if checked)
      • Delete Newsgroup cache
      • Delete Newsgroup Subscriptions
    • Click OK
    Click the CleanUp! button to start the program. Reboot/logoff when prompted.

    Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!
    If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility


    ----------

    Now post a new Hijackthis log.

    Let me know how things are now.C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\ps2.exe
    C:\Program Files\Belkin\Belkin 54Mbps Wireless Utility\TOOL\OpenXpAuto.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Starfield\Desktop Notifier\wben.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [XpOpenAuto] "C:\Program Files\Belkin\Belkin 54Mbps Wireless Utility\TOOL\OpenXpAuto.exe" 979899a48a75987f6b9d86a9aa798c73837198a e83a6a498b878837b768a788c84
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [wben] "C:\Program Files\Starfield\Desktop Notifier\wben.exe"
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FE9E888B-C60A-447A-B688-40B39CDE74EF}: NameServer = 205.171.3.65,205.171.3.64
    O18 - Protocol: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\WINDOWS\system32\QBPOSProtocol.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 7636 bytes


    IS IT GONE?!?! I don't see it in HJT but your the expert not me. thanksThat seems to have gotten it :0

    Let's clear out the programs we've been using to clean up your computer, they are not suitable for
    general malware removal and could cause damage if launched accidentally and will help secure the work you have done.
    .
    • Click START then RUN
    • Now type Combofix /u in the runbox
    • Make sure there's a space between Combofix and /u
    • Then hit Enter.
    .
    .
    The above procedure will:
    • Delete:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present
      • Reset the clock settings.
      • Hide file extensions, if required.
      • Hide System/Hidden files, if required.
      • Set a new, clean Restore Point.
      .
      Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop. (unless you already have it installed)

      1. Double click OTMoveIt2.exe to LAUNCH it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      5. Once complete exit out of OTMoveIt2

      Set a New Restore Point to prevent possible reinfection from an old one
      Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
      • Go to Start > Programs > Accessories > System Tools and click System Restore
      • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
      • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
      • Next go to Start > Run and type Cleanmgr
      • Click OK
      • Click the More Options Tab.
      • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
      .
      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      Here are some great tools to help you keep from getting infected again.

      To prevent unknown applications from being installed on your computer install WinPatrol 2007

      Another thing I would suggest installing SiteAdvisor. SiteAdvisor rates sites on business practices and spam.

      Spybot Search & Destroy - A safe and effective spyware scanner.
      * Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

      AVG Anti-Spyware Free Edition - Very reliable with a high detection rate.
      * AVG Anti-Spyware User Manual

      SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware

      Comodo BOClean - Stops trojans and many more malicious attacks.

      Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
      * Click here for a list of free firewalls.
      * Why would I consider a third party firewall?
      * Understanding and Using Firewalls

      UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com[/b]]http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
      * Help with Windows updates

      Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

      Let us know if anything else comes up.
      4204.

      Solve : Virus / trojan identified?

      Answer»

      I am using Avg free edition and I just got done scanning with it. When the progrmam finished scanning it identified these Trojans/ viruses

      Virus identified JAVA/ByteVerify,C:\Documents and Settings\HP_Owner.YOUR-03667082DE\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-5feef416,3/15/2008 7:56,4ef9724c-5feef416,14.34 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp32583953.exe,3/15/2008 9:12,tmp32583953.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp32589078.exe,3/15/2008 9:12,tmp32589078.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp36498765.exe,3/15/2008 9:12,tmp36498765.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp36503812.exe,3/15/2008 9:12,tmp36503812.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp41098156.exe,3/15/2008 9:12,tmp41098156.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp41103953.exe,3/15/2008 9:12,tmp41103953.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp72718.exe,3/15/2008 9:12,tmp72718.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp78687.exe,3/15/2008 9:12,tmp78687.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp94718.exe,3/15/2008 9:12,tmp94718.exe,16.26 KB
      Trojan horse Dropper.Generic.WIF,C:\Program Files\tmp99937.exe,3/15/2008 9:12,tmp99937.exe,16.26 KB
      Trojan horse Downloader.Zlob.ABD,C:\WINDOWS\dgtxrdfmng(2).dll,3/15/2008 9:12,dgtxrdfmng(2).dll,248 KB
      Trojan horse Downloader.Zlob.AAQ,C:\WINDOWS\drnpfdxrqv.dll,3/15/2008 9:12,drnpfdxrqv.dll,244 KB


      What should I do to these files? And are they harmfully.There are Java exploits that can be USED to infect a PC. Clear the Java cache and it should take care of this particular problem.

      Clearing Java Cache

      Go to Start > Control Panel and double-click the Java Icon. - Looks like a coffee CUP

      • On the General tab, under Temporary Internet Files, click the Settings button.
      • Next, click on the Delete Files button
      • There are two options in the window to clear the cache - Leave BOTH Checked
        • Applications
        • [/B]
        • Applets Trace and Log Files
      • Click OK on Delete Temporary Files Window
      Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
      • Click OK to leave the Temporary Files Window
      • Click OK to leave the Java Control Panel.
      .

      Be SURE to check for updates while you are in the Java control panel as well.
      4205.

      Solve : fun.exe dc.exe sviq.exe?

      Answer»

      Friends i m fed up of this viruses fun.exe dc.exe sviq.exe EVEN if i
      remove it from the task manager it comes BACK even if i go in SAFE mode
      and delete their respective folder in c: drive and delete from task
      manager they are againshown in task manager can i remove this viruses.
      ( if possible PROVIDE the solution without using antivirus )

      Also i have problems with regsvr.exe,wscript.exe,winhelp.exe
      Download and rename HijackThis (HJT)

      • Double-click on HJTInstall.
      • Click on the Install button.
      • It will automatically place HJT in C:\PROGRAM Files\TrendMicro\HijackThis\HijackThis.exe.
      • Upon install, HijackThis should open for you.
        • Close HijackThis and rename it.
        • Go to C:\Program Files\Trend Micro\HijackThis.exe
        • Right click on HijackThis.exe and select Rename.
        • Type in sniper.exe and press Enter.
        • Right-click on sniper.exe and select Send To > Desktop (create shortcut)
      • From the desktop open Hijackthis.
      • If using Windows Vista, Right-click and Run As Administrator.
      • Click on the Do a system scan and save a log file button
      • Hijackthis will scan and then a log will open in notepad.
      • Copy and then paste the entire contents of the log in your post.
        • Do not have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
      Although we have renamed Hijackthis to sniper, we will still refer to it as Hijackthis or HJT.

      4206.

      Solve : Something is leeching my bandwidth?

      Answer»

      I hope this is the right place for this. If it is not, I apologize. For no particular reason I became curious as to how much bandwidth I use with my broadband so I downloaded a freeware bandwidth meter. One curious thing I found was that something was constantly using my bandwidth at a rate of about 70k a minute, even when i'm idle. Someone suggested that I create a log with hijackthis and post it here, so here it is. I appreciate any help anyone could give me.


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:30:02 PM, on 4/2/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SYSTEM32\USRmlnkA.exe
      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
      C:\Program Files\PTBSync\PTBSync.exe
      C:\WINDOWS\SYSTEM32\USRshutA.exe
      C:\WINDOWS\SYSTEM32\USRmlnkA.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
      C:\Program Files\CursorXP\CursorXP.exe
      C:\Program Files\VCOM\PowerDesk\pddlghlp.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\ANALOG Devices\SoundMAX\SMAgent.exe
      C:\Program Files\Spyware Terminator\sp_rsser.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\Program Files\VMware\VMware Server\vmware-authd.exe
      C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
      C:\WINDOWS\system32\vmnat.exe
      C:\WINDOWS\system32\vmnetdhcp.exe
      C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Notepad++\notepad++.exe
      C:\Program Files\Pidgin\pidgin.exe
      C:\wamp\wampmanager.exe
      c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
      c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe
      C:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\VCOM\PowerDesk\PDExplo.exe
      C:\Documents and Settings\doug taylor\My Documents\zips\HiJackThis.exe

      R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [PTBSync] C:\Program Files\PTBSync\PTBSync.exe /Start
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
      O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Startup: Dialog Helper.lnk = C:\Program Files\VCOM\PowerDesk\pddlghlp.exe
      O4 - Startup: Port Monster.LNK = C:\Program Files\Zing Software\Port Monster\pm.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision EUROPE Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
      O23 - Service: Atomic Clock Synchronization (PTBSync) - ElmueSoft - C:\Program Files\PTBSync\PTBSync.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
      O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
      O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
      O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
      O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
      O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
      O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

      --
      End of file - 8020 bytes

      It's not malware. Can't you see what process it is in task manager?

      Download this http://www.anvir.com/taskmanagerfree/

      It will help you track down what is doing what.

      Screenshots http://www.anvir.com/screenshots.htm

      4207.

      Solve : Increasingly slow computer?

      Answer»

      The Avenger couldn't get them, you will NEED to go in and manually delete the files below.


      C : \ P r o G r a m F i l E s \ m I R C \ m i r c . e x e

      C : \ P r o g r a m F i l e s \ O N l i n e S e r v i c e s \ V o n a g e \ X t r a s \ r e g x t r a 1 2 1 . x 3 2

      C : \ P r o g r a m F i l e s \ O n l i n e S e r v i c e s \ P e o p l e P C \ I S P 5 9 0 0 \ B r a n d i n g \ p p a l 3 p p c . e x e

      Let me know how things are now.



      4208.

      Solve : Silly DI DVO Trojan?

      Answer»

      For some reason I can't remove this from my computer USING CA anti spyware nor anti virus. I need some very detailed help as to how to remove. I saw the part ONE prerequisite, but GOT lost as to whether I need to DOWNLOAD the three programs or not. THANK you. AldejaisStart Here...

      4209.

      Solve : AP# Downloader?

      Answer»

      In Windows EXPLORER, go Tools>Folder Options>View, and...
      - check "SHOW hidden files and FOLDERS"
      - un-check "Hide protected operating system files" (this one, you should put back on, later)thanks for the help, it appears to have worked.Good
      Did you delete all those files? Norton not complaining anymore?Yep. I CAME , I saw, I deleted some AP downloaders. Veni Vidi Vici.....good
      Happy COMPUTING

      4210.

      Solve : Google Horror?

      Answer»

      I'm doing a little research on something. But I have one problem.

      Let's say I go to google and type in "locomotion". Done reading that, so I type something else in the search box such as "switch rail", but even though I typed in "switch rail", it will show results for "locomotion". I have to refresh the page twice to show results for "switch rail".

      I'm using Windows XP Home Edition SP2 with Firefox/2.0.0.13.

      Anyone got ideas on how to fix ??

      Thank you.

      ## EDIT ##

      It ONLY happens on Google for some reason.

      #######*censored*....

      I found a process called "Au_.exe" in the Task Manager, so I searched for it, it's more BLOODY spyware!

      Grrrrrrrrrrr........... I wish I could trace the IP ADDRESS of the ***hole who put this spyware on my computer and fry his god *censored* hard drive.



      I'll be back tomorrow to get help from a malware REMOVAL specialist. Right now, I'm updating my protection apps.

      See ya' tomorrow.man that sucks....I would have to agree that is a bummer.Great news...


      It wasn't SpyFalcon. I did more searching an apparently, it's used by Nullsoft to install applications. But to be sure, I did the SUPERAntispyware scan, and it found nothing.

      Google is FUNCTIONING properly now. I guess the best way to get rid of a problem is to press the "Post" button.

      4211.

      Solve : ntoskrnl.exe Keeps Changing!?

      Answer»

      I am scanning with AVG and every scan it shows that ntoskrnl.exe KEEPS changing. I Googled the file and it seems to be an important start-up file (apparently). AVG is telling me to monitor this file, but my old anti VIRUS(ZONE Alarm) didn't find anything wrong. This just an AVG problem or is it serious?It may be corrupt or has been exploited by virus. Try doing these steps in post 2.

      Once complete a member of the malware team will be ALONG to help you with the logs.

      4212.

      Solve : Super Anti Spyware gave me blue screen of death.?

      Answer»

      Hi, I really hope someone can help me. I did something really stupid and downloaded an infected file from Limewire that gave me a bunch of junk. I removed Limewire but continued to get popups for programs like Frostwire that aren't even (to my knowledge) installed on my machine. I'd heard good things about Super Anti Spyware, so I installed it and ran a scan. It found several trojans and something called vundo. Once the scan finished, it asked me to restart. So far, so good...until I got a blue screen of death at start up. So I put Windows into safe mode and now I'm at a loss as to what to do. Is my only option reinstalling Windows at this point? And if so, how do I back up my data without backing up the viruses too? I'm also not sure if I have all the drivers I'd need. I don't feel comfortable doing it myself either so I will take it in for repair, but first I WANTED to see if anyone has any other suggestions. I'm running XP with McAfee, if that helps...could McAfee possibly have conflicted with something? I tried to disable it but I couldn't figure out how. Please help!Superantispyware shouldn't have removed anything that would cause a blue screen. If needed open Superantispyware (SAS) and select manage quarantine, select the log of items removed and click Restore.

      Can you get into normal mode? If so post a Hijackthis log so we can see what is GOING on. If needed run Hijackthis in safe mode.I'm not sure where the "manage quarantine" option is, but I do have the log file of what it fixed/removed, if that helps you.

      [recovering space - attachment deleted by admin]Download SDFix.exe and save it to your Desktop.

      Double click SDFix.exe and it will extract the files to %systemdrive%
      (Drive that contains the Windows Directory, typically C:\SDFix)

      Please then reboot your computer in Safe Mode by doing the following:

      • Restart your computer
      • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
      • Instead of Windows loading as normal, the Advanced Options Menu should appear;
      • Select the first option, to run Windows in Safe Mode, then press Enter.
      • Choose your usual account.
      • Open the extracted SDFix FOLDER and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC RESTARTS the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
        (Report.txt will also be copied to Clipboard).
      • Finally add the contents of the Report.txt in your next post.
      Hi, sorry for not getting back to you sooner. All right, I used SDFix and when it was finished, it didn't say "finished" or give me a file called "report", but there was one called "catchme", so I'm including that. It says there were no files found...is that good?

      [recovering space - attachment deleted by admin]Wait, sorry, here is the Report file. It was in the program folder though, not on the desktop - I don't know if that makes a difference? This is what it says:


      SDFix: Version 1.177
      Run by Owner on 29/04/2008 at 09:12 PM

      Microsoft Windows XP [Version 5.1.2600]
      Running From: C:\SDFix

      Checking Services :


      Restoring Windows Registry Values
      Restoring Windows Default Hosts File
      Please download Combofix by sUBs from one of the below links.
      (Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.
      • Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting Combofix.
      • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
        • Click this link to see a list of security programs that should be disabled and how to disable them.
        • If yours is not listed and you don't know how to disable it, please ask.
      • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
      • Double click combofix.exe & follow the prompts.
        • Choose Yes to accept the Disclaimers.[
        • When finished, it will produce a log for you.
        • Post that log in your next reply.
        Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
        • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
        • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
        Do I need to be in Safe Mode to do this, or can it be run from normal Windows?Normal mode.
        4213.

        Solve : HijackThis log - IE7 - XP?

        Answer»

        My web pages are always being redirected. Could somebody please take a look at the log file to see what I need to do?
        I ran Ad-Aware in Safe Mode, but that did not solve the problem. Thanks for your help.

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\SERVICES.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        C:\WINDOWS\System32\alg.exe
        C:\Program Files\SiteAdvisor\6253\SAService.exe
        C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        C:\Program Files\Microsoft IntelliPoint\IPoint.exe
        C:\WINDOWS\System32\wbem\wmiprvse.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
        O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        O4 - HKLM\..\RunServices: [BelkinAPM] C:\Program Files\Belkin AUTOMATIC Power Management Software\BelkinAPM.exe
        O4 - HKCU\..\Run: [McAfee Instant Update Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
        O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
        O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O11 - Options group: [INTERNATIONAL] International*
        O15 - Trusted Zone: http://*.mcafee.com
        O15 - Trusted Zone: http://download.windowsupdate.com
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/08948e0e8bd2aa5a5a14/netzip/RdxIE601.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178638478592
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178661988280
        O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{90270AC7-DCB6-4BEF-B655-5D8425BA1540}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{A0DDACB4-A177-4B9E-B6DB-1219156AD5AA}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{DDA99607-5AF0-4660-A1E5-0BD205BAB14A}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: BelkinAPM - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        O23 - Service: BelkinAPMmanager - ZeroG Software - C:\PROGRA~1\BELKIN~1\BE8806~1.EXE
        O23 - Service: BelkinAPMmonitor - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        O23 - Service: BelkinAPMRMI - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exeRepost HJT, including its header, this time.Ok, sorry. Hopefully by header you mean what I am posting here. Please let me know if I have not posted the correct info. Thanks again.

        Logfile of HijackThis v1.99.1
        Scan saved at 9:19:50 AM, on 3/13/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\SiteAdvisor\6253\SAService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        C:\WINDOWS\System32\alg.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\WINDOWS\system32\PnkBstrA.exe
        C:\Program Files\Real\RealPlayer\realplay.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
        C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        C:\WINDOWS\System32\wbem\wmiprvse.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
        O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        O4 - HKLM\..\RunServices: [BelkinAPM] C:\Program Files\Belkin Automatic Power Management Software\BelkinAPM.exe
        O4 - HKCU\..\Run: [McAfee Instant Update Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
        O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
        O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
        O11 - Options group: [INTERNATIONAL] International*
        O15 - Trusted Zone: http://*.mcafee.com
        O15 - Trusted Zone: http://download.windowsupdate.com
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/08948e0e8bd2aa5a5a14/netzip/RdxIE601.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178638478592
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178661988280
        O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{90270AC7-DCB6-4BEF-B655-5D8425BA1540}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{A0DDACB4-A177-4B9E-B6DB-1219156AD5AA}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{DDA99607-5AF0-4660-A1E5-0BD205BAB14A}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: BelkinAPM - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        O23 - Service: BelkinAPMmanager - ZeroG Software - C:\PROGRA~1\BELKIN~1\BE8806~1.EXE
        O23 - Service: BelkinAPMmonitor - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        O23 - Service: BelkinAPMRMI - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
        O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe


        Thanks,
        disbandedThis is outdated HJT version, but I checked it out anyway, and you'll have to perform couple more steps.
        With next HJT log, please download current version from the link provided at the bottom of my post.

        Is UkrTeleGroup your ISP?

        Print these instructions out.

        1. Download SUPERAntiSpyware Free for Home Users:
        http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

        Restart computer in Safe Mode.
        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and PREFERENCES", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
        o Close browsers before scanning.
        o Scan for tracking cookies.
        o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
        o Click Preferences, then click the Statistics/Logs tab.
        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
        o Please copy and paste the Scan Log results in your next REPLY.
        * Click Close to exit the program.
        Post SUPERAntiSpyware log.

        RESTART COMPUTER!

        2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

        The log can also be found here:
        C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
        Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

        RESTART COMPUTER!

        3. Download HijackThis:
        http://www.snapfiles.com/get/hijackthis.html
        Post HijackThis log.

        Ok, it has been a while, but I was finally able to run the suggested programs. Here is the mbam log

        Malwarebytes' Anti-Malware 1.11
        Database version: 679

        Scan type: Full Scan (C:\|)
        Objects scanned: 148985
        Time elapsed: 1 hour(s), 7 minute(s), 10 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 2
        Registry Values Infected: 0
        Registry Data Items Infected: 1
        Folders Infected: 0
        Files Infected: 12

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_CURRENT_USER\Software\Security Tools (Trojan.Zlob) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger) -> Data: kdjng.exe -> Delete on reboot.

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\WINDOWS\system32\kdjng.exe (Rootkit.DNSChanger) -> Delete on reboot.
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\H1BRH205\wpad[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Tony Davis\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Tony Davis\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065221.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065222.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065223.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065224.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065225.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065226.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP350\A0065227.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{9831E5C3-EA42-485C-AA43-7A0E8B2D9D2C}\RP355\A0066221.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.And here is my Hijackthis log. Any help would be greatly appreciated.

        Again, the problem is that my search engine gets redirected every time to some otehr site that I did not want to go to.

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 8:01:23 PM, on 4/24/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\PnkBstrA.exe
        C:\Program Files\SiteAdvisor\6253\SAService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O1 - Hosts: 221.135.111.121 Download.McAfee.com
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
        O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\RunServices: [BelkinAPM] C:\Program Files\Belkin Automatic Power Management Software\BelkinAPM.exe
        O4 - HKCU\..\Run: [McAfee Instant Update Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
        O4 - S-1-5-18 Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (User 'SYSTEM')
        O4 - .DEFAULT Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (User 'Default user')
        O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
        O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: http://*.mcafee.com
        O15 - Trusted Zone: http://download.windowsupdate.com
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/08948e0e8bd2aa5a5a14/netzip/RdxIE601.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178638478592
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178661988280
        O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {AA299E98-6FB5-409F-99D3-D30D749F4864} (kasRmtHlp Class) - http://misskas01.missionitservices.com/inc/kaxRemote.dll
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{90270AC7-DCB6-4BEF-B655-5D8425BA1540}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{A0DDACB4-A177-4B9E-B6DB-1219156AD5AA}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\..\{DDA99607-5AF0-4660-A1E5-0BD205BAB14A}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O17 - HKLM\System\CS1\Services\Tcpip\..\{0769696F-D7C0-43D3-AC08-64CFCD64BDA3}: NameServer = 85.255.116.124,85.255.112.131
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: BelkinAPM - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        O23 - Service: BelkinAPMmanager - ZeroG Software - C:\PROGRA~1\BELKIN~1\BE8806~1.EXE
        O23 - Service: BelkinAPMmonitor - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        O23 - Service: BelkinAPMRMI - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
        O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exeWow! MiA for over a month?.....LOLSuperantispyware log is missing.
        If you forgot to post it, do it now.
        If you didn't run SAS, run it now, and then re-run fresh HJT log.I ran the SAS in safe mode, but there was no log given after it was complete, and I can't find one. I will try to run it again and see what that gets me.If you ran it, according to instructions, you don't have to re-run it. I'll check your HJT log.*** You need to update your Java:
        http://java.sun.com/javase/downloads/index.jsp
        Java Runtime Environment (JRE) 6 Update 6
        Uninstall all previous versions of Java through Add\Remove.

        1. Print this post out, since you won't have an access to it, at some point.

        2. Close all windows, except for HijackThis.

        3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

        - O1 - Hosts: 221.135.111.121 Download.McAfee.com
        - O1 - Hosts: 221.135.111.121 Download.McAfee.com
        - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        - if UkrTeleGroup is NOT your ISP, checkmark all seven O17 entries
        - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

        4. Click on Fix checked button.

        5. Restart computer.

        9. Post new HijackThis log.Ok, here is the latest Hijackthis log.

        I did go to my internet browser and it appears that everything is fixed.
        So I really appreciate your help on this. You have been really great.


        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 9:33:00 PM, on 4/24/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        C:\Program Files\Belkin Automatic Power Management Software\jre\bin\javaw.exe
        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\PnkBstrA.exe
        C:\Program Files\SiteAdvisor\6253\SAService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
        O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
        O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
        O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\RunServices: [BelkinAPM] C:\Program Files\Belkin Automatic Power Management Software\BelkinAPM.exe
        O4 - HKCU\..\Run: [McAfee Instant Update Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
        O4 - S-1-5-18 Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (User 'SYSTEM')
        O4 - .DEFAULT Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (User 'Default user')
        O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: http://*.mcafee.com
        O15 - Trusted Zone: http://download.windowsupdate.com
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/08948e0e8bd2aa5a5a14/netzip/RdxIE601.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178638478592
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178661988280
        O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
        O16 - DPF: {AA299E98-6FB5-409F-99D3-D30D749F4864} (kasRmtHlp Class) - http://misskas01.missionitservices.com/inc/kaxRemote.dll
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: BelkinAPM - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~1.EXE
        O23 - Service: BelkinAPMmanager - ZeroG Software - C:\PROGRA~1\BELKIN~1\BE8806~1.EXE
        O23 - Service: BelkinAPMmonitor - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~4.EXE
        O23 - Service: BelkinAPMRMI - ZeroG Software - C:\PROGRA~1\BELKIN~1\BELKIN~3.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
        O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe

        --
        End of file - 8592 bytesVery good

        HJT log is clean.

        1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
        Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
        Run CCleaner.

        2. Turn off System Restore:

        - Windows XP:
        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore".
        5. Click Apply.
        6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        - Windows Vista:
        1. Click Start.
        2. Right-click the Computer icon, and then click Properties.
        3. Click on System Protection under the Tasks column on the left side
        4. Click on Continue on the "User Account Control" window that pops up
        5. Under the System Protection tab, find Available Disks
        6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
        7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
        8. Click OK

        3. Restart computer.

        4. Turn System Restore on.

        5. Download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
        It won't interfere with your antivirus, nor firewall.

        6. Let me know, how your computer is doing.

        4214.

        Solve : This message on another board re "Virtual Memory" Anyone??

        Answer»

        "The first half of this evening, after I'd installed the current year's edition of my anti-virus program, this laptop was stickier and slower than MOLASSES at the NORTH Pole. I finally disconnected from the Net, then reconnected, and up popped a box from Windows saying it had detected "low virtual memory" and it was UPGRADING it and making it all better, whatever, yes, I'm BACK to my usual somewhat pokey maneuverings among the Windows I keep open."??Quote from: Broni on March 31, 2008, 08:24:27 PM

        ??
        Why would a Virtual Memory advisory COME up?
        Just once, by the way.
        4215.

        Solve : Norton 2008-Computer slow?

        Answer»
        After upgrading RAM, the Pc is WORKING fine. I am unistalling Norton from my laptop and downloading AVG with other PROTECTIONS.

        Thank you again.
        airGood DECISION
        4216.

        Solve : Prevent/Remove virus?

        Answer»

        Friends what are the ways/precaution to remove viruses (if possible WITHOUT using
        antivirus) and avoid viruses to enter into system via pendrive.Why are you against using antivirus?



        They just make the system slowQuote from: LUCKY Rathod on April 03, 2008, 03:13:23 AM

        They just make the system slow

        And without them infected Try Avast Home Free I think you will be surprised at it. I use it on my old win98 that has never had an upgrade in almost 10 years and it doesn't slow it down.

        Quote from: evilfantasy on March 12, 2008, 08:53:49 AM
        Another way to look at it is this. If you think you are the safest INTERNET user in the world so decide you can do without running an antivirus but still somehow do pick up a nasty virus/trojan. You won't know about it until it is too late. In the time it takes you to figure it out (which could be a matter of minutes) the virus/trojan could be stealing your personal info and sending all of your contacts in your address book SPAM or worse LINKS infected with a virus or trojan. They could then forward it on, and on, and on.... So you could be infecting thousands of people simply by thinking you're safe enough to not get infected. Pretty much like a condom no?

        So do everyone a favor (me included) use an AV and Firewall.
        Quote
        via pendrive.

        You mean portable antiviruses?

        http://portableapps.com/apps/utilities/clamwin_portable
        4217.

        Solve : Burning CD problem?

        Answer»

        I have in the past burned several dozen using Roxio and a different computer and CDR
        disks. They play fine on my CD player.

        I've tried now using Windows Media player and CDRW CD's. They burn fine and play on my computers, but my CD player doesn't recognize that there's a CD?

        I tried burning on Window's media player then copying the CD on Nero, but they still won't play on my CD player. Get message, "No Disk"

        Wazzzup? based on my EXPERIENCE, they would be several reason for this.
        maybe your cd player only read "audio" and not "mp3" files, so better try to burn it as a cd audio.
        The cd player also might be having problem with its lens or something have you try wath movie with it or else just to make sure its good?QUOTE from: kuszmania9999 on April 03, 2008, 07:23:05 AM

        based on my experience, they would be several reason for this.
        maybe your cd player only read "audio" and not "mp3" files, so better try to burn it as a cd audio.
        The cd player also might be having problem with its lens or something have you try wath movie with it or else just to make sure its good?

        I did burn it as an Audio file so far as I know. Does Media player only burn mp3 do you know?
        I copied it also on Nero as an audio cd. still wouldn't recognize it. And yes, my CD player won't recognize mp3 disks.Quote from: kuszmania9999 on April 03, 2008, 07:23:05 AM
        based on my experience, they would be several reason for this.
        maybe your cd player only read "audio" and not "mp3" files, so better try to burn it as a cd audio.
        The cd player also might be having problem with its lens or something have you try wath movie with it or else just to make sure its good?
        Resolved. I USED a CDR instead of a CDRW and it worked fine. Who knew?Quote
        I've tried now using Windows Media player and CDRW CD's.
        Most standalone DVD players won't play CDRWs.Quote from: Broni on April 03, 2008, 06:06:27 PM
        Quote
        I've tried now using Windows Media player and CDRW CD's.
        Most standalone DVD players won't play CDRWs.
        I didn't know that. Thx.

        You're welcome.
        You may double check your DVD player manual.
        My DVD player will read CDRWs, but only, if they're closed, which doesn't make SENSE to me. I'd like to be ABLE to add stuff as I go, but it doesn't work that way on my player.
        4218.

        Solve : Can't access the interent - think I have a virus!!?

        Answer»

        I have windows vista and a wireless internet connection. I have virus protection, F-Secure. I am not computer literate at all and am having trouble, I think it is a virus!

        When I try to access the internet the page displayed "lack of connection" like it would when the modem is off, however the strenght says "Excellent"

        Obviously, I firstly assumed it was the connection, but my all my housemates worked fine.

        Soon after, one of my housemates had the same problem. When my friend came round her laptop would get on the interent either.

        One of my housemates has a mac and he can get online fine.



        I went on F-secure virus protection to scan my computer for viruses. When I CLICK 'scan my computer' absolutely nothing happens.

        Because I can't get on the interent I can't scan my computer with whats avabile online.


        I do not know what to do. I am considering backing up everything I have and resetting everything on my computer.


        Is there anything I can do???Laptop, or desktop? Windows version?
        Did you try to connect your computer straight to the modem?I have a laptop. Don't know what version. Just that its vista. Not with my laptop at the moment so can't check for you. It's only 9 months old if that helps.


        Yes, when I thought it was a problem with the modem I went to a friends house to finish some work off but I had the same problem there. So she suggested to connect straight to the modem but it remianed the same.

        Four laptops have been affective now, however my friend who's laptop wouldn't work, works at her house. and doesn't have a problem anymore.Quote
        So she suggested to connect straight to the modem but it remianed the same.

        Was it at her place, or yours?no it just works at her house. It started immediatly when she tried at HOME. However my laptop doesn't work at her house, or at mine.So, now all laptops, except for one Mac, don't work at your place, right?yes thats right.

        The reson I suspect it may be a virus is because the laptops failed at different times during the day. If if was a problem with the modem this wouldn't be the case would it. plus the connection says excellent yet it also says it is the "limited conncection"

        Also I have problems scanning my computer for viruses, could this be due to the fact the computer isn't connected at theinternet. thats what the technition at uni said. Because i've hear that viruses can do that sometimes.Possible.
        Go to your friend house (that one with connection), and ask her to burn couple of programs for you...
        Links, and manuals below:

        Print these instructions out.

        1. Download SUPERAntiSpyware Free for Home Users:
        http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

        Restart computer in Safe Mode.
        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
        o Close browsers before scanning.
        o Scan for tracking cookies.
        o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * BACK on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you WANT to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
        o Click Preferences, then click the Statistics/Logs tab.
        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
        o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
        Post SUPERAntiSpyware log.

        RESTART COMPUTER!

        2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

        The log can also be found here:
        C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
        Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

        RESTART COMPUTER!

        3. Download HijackThis:
        http://www.snapfiles.com/get/hijackthis.html
        Post HijackThis log.

        4219.

        Solve : New help to remove this file?

        Answer»

        Hi,

        I had 2 days ago notice that every time I run INTERNET Explorer 7, I noticed a short message appear on the 1ST LINE of IE tool bar, " Virus is now ATTACKING your system from MAnz_Shidah".
        I scaned with antivirus/anto-spyware and could not fine any affected files.

        The only 2 log files I found on HijackThis were:

        a) HKLM\..\run:[manz_shidah_virus]wscript.exe
        C:\windows\system\manz_shidah.js
        b) HKCU\software\microsoft\internet explorer\main, Windows title = Virus is Attacking your system

        I also noticed there were a Jscript file = Manz_shidah and HTML document = Attach your system appeared on all harddisk partitions which were not be able to delete.

        Please help, thanks




        Please start HERE

        Once you have the LOGS a malware specialist will be along to ASSIST you.

        4220.

        Solve : Computer Becoming Unusable?

        Answer»

        So basically my computer has issues.
        haha no but seriously im sure theres viruses.
        I'm pretty sure it has that one kind of virus where it takes like a keyword from what your doing or w/e and pop-ups come up about it.
        But yeah lots of pop-ups and its just gotten so slow.

        blahh...

        Compaq Presario
        Windows XP
        IE
        umm.. yeah what else?do you have anti virus software?
        try to scan your computer for virus Print these instructions out.

        1. Download SUPERAntiSpyware Free for Home Users:
        http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

        Restart computer in SAFE Mode.
        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
        o Close browsers before scanning.
        o Scan for tracking cookies.
        o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure EVERYTHING has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you WANT to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
        o Click Preferences, then click the Statistics/Logs tab.
        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        o If there are several logs, click the current dated log and press View log. A text file will open in your default text EDITOR.
        o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
        Post SUPERAntiSpyware log.

        RESTART COMPUTER!

        2. Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

        The log can also be found here:
        C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
        Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

        RESTART COMPUTER!

        3. Download HijackThis:
        http://www.snapfiles.com/get/hijackthis.html
        Post HijackThis log.here's this.
        i had to attach it because it was too big.
        the other one is coming.

        [recovering space - attachment deleted by admin]Here is the Malwarebytes log and the HijackThis log.
        Im sorry it's taken awhile, like I said the computer is slow.
        And i'm a student.
        So again sorry for the wait.

        [recovering space - attachment deleted by admin]Surely, you collected amazing number of bad stuff....
        HJT, you ran is an outdated 1.99.1 version. Please, download HJT through MY link.yeahh...
        & ok sorry here ya go.

        [recovering space - attachment deleted by admin]*** Go Start>Control Panel>Add\Remove, and...
        - Uninstall any of the following programs associated with Viewpoint:
        * Viewpoint Manager
        * Viewpoint Media Player
        * Viewpoint Toolbar
        - Uninstall PopUp Killer. Activate pop-up stopper provided by your browser.
        - Uninstall useless Logitech Desktop Messenger

        *** You need to update your Java:
        http://java.sun.com/javase/downloads/index.jsp
        #4 - Java Runtime Environment (JRE) 6 Update 5
        Uninstall all previous versions of Java through Add\Remove.

        1. Print this post out, since you won't have an access to it, at some point.

        2. Close all windows, except for HijackThis.

        3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

        - ALL O1 entries
        - O2 - BHO: {146694d1-2331-3e2b-28b4-3e0ffa341fa3} - {3af143af-f0e3-4b82-b2e3-13321d496641} - C:\WINDOWS\system32\wadhtdtl.dll
        - O2 - BHO: (no name) - {F0D76DD3-BE73-4A26-8852-C54D959FC6E9} - C:\WINDOWS\system32\pmnli.dll (file missing)
        - *O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
        - *O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
        - *O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        - *O4 - HKLM\..\Run: [PopUpKiller] C:\Program Files\PopUp Killer\popupkiller.EXE
        - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        - O4 - HKLM\..\Run: [46c90ce9] rundll32.exe "C:\WINDOWS\system32\novgqqaw.dll",b
        - O4 - HKLM\..\Run: [BM45fa3f75] Rundll32.exe "C:\WINDOWS\system32\cgfufpww.dll",s
        - *O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        - *O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
        - *O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
        - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        - O4 - Global Startup: Exif Launcher.lnk = ?
        - *O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        - O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Diana Bean\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
        - O20 - Winlogon Notify: efcawwt - efcawwt.dll (file missing)
        - O20 - Winlogon Notify: pmnli - C:\WINDOWS\system32\pmnli.dll (file missing)
        - O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
        - O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\rtekejegib.html
        - O24 - Desktop Component 1: (no name) - C:\Program Files\Internet Explorer\rtekejegib.html

        4. Click on "Fix checked" button.

        5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

        6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

        7. Delete following files/folders (if present):

        - pmnli.dll, cgfufpww.dll, novgqqaw.dll, pmnli.dll files from C:\WINDOWS\system32

        8. Turn off System Restore:

        - Windows XP:
        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore".
        5. Click Apply.
        6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        - Windows Vista:
        1. Click Start.
        2. Right-click the Computer icon, and then click Properties.
        3. Click on System Protection under the Tasks column on the left side
        4. Click on Continue on the "User Account Control" window that pops up
        5. Under the System Protection tab, find Available Disks
        6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
        7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
        8. Click OK

        9. Restart in Normal Mode.

        10. Turn System Restore on.

        11. Post new HijackThis log.log



        vvvvv

        [recovering space - attachment deleted by admin]It looks much better....

        1. Print this post out, since you won't have an access to it, at some point.

        2. Close all windows, except for HijackThis.

        3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

        - O4 - HKLM\..\Run: [BM45fa3f75] Rundll32.exe "C:\WINDOWS\system32\cgfufpww.dll",s
        - O4 - HKLM\..\Run: [46c90ce9] rundll32.exe "C:\WINDOWS\system32\novgqqaw.dll",b

        4. Click on "Fix checked" button.

        5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

        6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

        7. Delete following files/folders (if present):

        - novgqqaw.dll, cgfufpww.dll files from C:\WINDOWS\system32

        8. Turn off System Restore:

        - Windows XP:
        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore".
        5. Click Apply.
        6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        - Windows Vista:
        1. Click Start.
        2. Right-click the Computer icon, and then click Properties.
        3. Click on System Protection under the Tasks column on the left side
        4. Click on Continue on the "User Account Control" window that pops up
        5. Under the System Protection tab, find Available Disks
        6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
        7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
        8. Click OK

        9. Restart in Normal Mode.

        10. Turn System Restore on.

        11. Post new HijackThis log.

        4221.

        Solve : Help with trojan! No Internet Records?

        Answer»

        On my computer I run Kaspersky and I get this problem:

        detected: Trojan program Trojan-Downloader.Win32.Hmir.almFile: c:\windows\system32\drivers\daml9.sys

        Kaspersky has deleted the file a couple of times but it comes back, seemingly when MS Outlook runs.

        Attached is the HijackThis record.

        [recovering space - attachment deleted by admin]I don't SEE any MALWARE in the log, you will need to go to this thread and work the steps in post 2 then post the logs back here.Why did you run Combofix?

        That isn't part of the instructions.I thought it MIGHT be helpful, I had run it before the original postOH and another symptom when I start looking for daml9.sys in the register the computer restarts.It didn't hurt anything and may be needed. Only it is the spanish version so a little hard to read in some perts.

        Quote

        when I start looking for daml9.sys

        What is daml9.sys?

        Not to be rude, it is good that you are trying to fix this but please stick to my instructions. Doing things outside of them will just confuse me and make this much harder in the long run.

        I need the Hijackthis log.Sorry for the confusion. I thought I'd give you all the logs I have..

        Just to refresh what my problem is:

        On my computer I run Kaspersky and I get this problem:

        detected: Trojan program Trojan-Downloader.Win32.Hmir.alm File: c:\windows\system32\drivers\daml9.sys

        Kaspersky has deleted the file a couple of times but it comes back, when I try to open it in notepad, copy, paste, or anything it tells me that the file is being used. The hijackthis log is on the first post.

        Also, whenever I start looking for it on the registry the computer reboots, or when I set it to be deleted with Kaspersky it reboots without notice.

        I've been pretty successful with other malware until now. I've also looked for this trojan-downloader strand with only hits in an asian language.I need a new Hijackthis log from after RUNNING the other tools.Is Kaspersky updated? Do you have two antivirus installed?

        daml9.sys is a driver. C:\WINDOWS\system32\DRIVERS\daml9.sys

        Do you have an XP CD?

        If so, place it in your CD ROM drive and follow the instructions below:
        • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
          • Let this run undisturbed until the window with the blue progress bar goes away
        SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

        If you want to see what was replaced, right-click My Computer and click on Manage.
        In the new window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System.

        Thanks.. this is a work computer and I'll run that tomorrow, thanks alot!You gotta help me here.

        Quote from: evilfantasy on April 07, 2008, 03:45:19 PM
        What is daml9.sys?

        Quote from: evilfantasy on April 07, 2008, 04:08:10 PM
        Is Kaspersky updated? Do you have two antivirus installed?

        daml9.sys appeared out of nowhere, it's stuck onto the /windows/system32/drivers/ folder. I've looked it up online and have found nothing on it. All I know it's linked to this trojan downloader hmir.alm which in turn i've only seen on asian sites.

        I've been trying to see what it is linked to in the registry but as SOON as I get close to finding it the computer crashes.

        I've uninstalled AVG and any other anti-virus and kaspersky is up to date.OK, lets try this.

        Scan Suspicious File(s)

        Please visit one of the following:
        (Multiple sites are given in case one is not working)
        (If more than one file needs scanned they must be done separately and logs posted for each one)
        Copy the file path in the code box below.
        Code: [Select]C:\WINDOWS\system32\DRIVERS\daml9.sys
        • At the upload site, click once inside the window next to Browse.
        • Press Ctrl+V on the keyboard (both at the same time) to paste the file path in the window.
        • Next click Send File/Submit/Upload (depending on the site)
          • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
        • This will perform a scan across multiple different virus scanning engines.
        • Please wait for all of the scanning engines to complete.
        • Copy and then Paste the results in the next reply.
        Interesting news my friend, I get an error message when I try to upload the file for scanning.

        I haven't had a chance to run sfc.exe, does it matter if I have windows sp1?
        Quote from: lefloresg80 on April 08, 2008, 02:14:25 PM


        I haven't had a chance to run sfc.exe, does it matter if I have windows sp1?


        Possibly, there have been loads of service packs released since SP1.

        Why don't you have SP2?
        4222.

        Solve : Is AVG still free??

        Answer»

        I visited the Grisoft website and clicked on the Home Security PAGE, clicked on AVG Anti-virus and FOUND these two options:

        1 year Subscription USD 34.99
        2 years Subscription USD 51.99



        So, my main question: Is AVG still free?

        Right now I have AVG 7.5 installed on my computer and it still works, but when I visited the site I was shocked.Quote from: dairyman on MARCH 12, 2008, 11:24:44 PM

        I visited the Grisoft website

        It would be better to include the EXACT url.

        Quote
        and clicked on the Home Security page, clicked on AVG Anti-virus and found these two options:

        1 year Subscription USD 34.99
        2 years Subscription USD 51.99



        So, my main question: Is AVG still free?

        Right now I have AVG 7.5 installed on my computer and it still works, but when I visited the site I was shocked.

        Bookmark this one for your future use:
        http://free.grisoft.com

        There is a "Download" button there that will take you to:
        http://free.grisoft.com/doc/download-free-anti-virus/us/frt/0
        Hi WillyW,

        THANK you for the reply.

        The URL of the page was http://grisoft.com.

        I've bookmarked the free download link.
        4223.

        Solve : Broni having a few minor problems. What do I do??

        Answer»

        I have 119GB free space whatever that MEANS!Right click on "My Computer", click Properties.Quote

        I have 119GB free space whatever that means!
        This is about your hard drive.994 MHZ 448 MB OF RAM That looks fine. Get Firefox: http://www.mozilla.com/en-US/firefox/Broni it looks LIKE this problem had nothing to do with my computer. I went on the website tonight and this was posted.

        PLEASE READ : We are very sorry for the recent lag problems. Most issues have been fixed and we will upload a NEW version soon. Thank you for your patience - Admin.


        Sorry Broni to have TAKEN up so much of your time.Not a problem
        4224.

        Solve : Viruses disabled programs, need help!?

        Answer»

        I have a very badly infected computer, i could close out of the bad ones in task manager before, but they disabled it! i NEED help on fixing this, I'm running safe mode on admin user and I STILL CANT open them

        they also disabled display,control panel, and time modificationPlease read this before REQUESTING help.

        4225.

        Solve : Zlob.downloader.vcd?

        Answer»

        I running XP Home Ed. Ver. 2002, Sp2. I have Norton ANTIVIRUS 2008, also, Adaware 2007, SpyBot and CCleaner.
        I Can't GET rid of Zlob. I run SpyBot and it takes CARE of it. But once I restart my computer it comes right back. If I GO to HKEY_LOCAL_MACHINE\Software\Microsoft\Videoplugin and delete VideoPlugin it will do the same thing as running SpyBot. But, again, once I restart my computer it comes right back. How do I get rid of it?
        Go through the steps here and post the requested logs.

        4226.

        Solve : I have high-speed internet. When is it safe to turn off Anti-virus??

        Answer»

        Since my connection is always OPEN, even though my browser is not, when can I turn off my anti-virus to do scans etc? Will I have to disconnect the cable from my modem first?That would be the recommended way to do it...an unprotected machine doesn't take long to be infected.
        Do you have a firewall installed ?
        You could also just turn the modem off...Quote from: patio on March 10, 2008, 09:16:59 AM

        That would be the recommended way to do it...an unprotected machine doesn't take long to be infected.
        Do you have a firewall installed ?
        You could also just turn the modem off...

        I have a firewall--and my modem has no switch, just a power cord.I don't GET it... why do you want to turn off your anti-virus?Quote from: Deerpark on March 10, 2008, 10:03:03 AM
        I don't get it... why do you want to turn off your anti-virus?

        There's an open source program called Ultradefrag http://ultradefrag.sourceforge.net/ that says the AV must be turned off prior to running the program. You can run it at boot up, apparently before the AV LOADS, or you can run it manually. I was going to run it manually just to test it and see if it works any BETTER than the standard Windows XP defrag, but I need to upgrade netframe or WHATEVER it is.Disconnect modem from power source.It says to deactivate the AV for better performance, not that it won't work. I use Ultra Defrag with AV on with no problems.

        .Net Framework Downloads

        Quote from: evilfantasy on March 10, 2008, 06:01:38 PM
        It says to deactivate the AV for better performance, not that it won't work. I use Ultra Defrag with AV on with no problems.

        .Net Framework Downloads



        Thanks, that's good to know Evil. Are you pleased with the program itself?I started using it a few weeks back, switched from JK Defrag, and have only used it a few times and think I will keep it for a while. I haven't had a chance to completely explore it yet but like what I see so far. The different options are very useful.
        4227.

        Solve : Downloading Dr Web Cure It! Can you help??

        Answer»
        When I try to DOWNLOAD Dr Web Cure It! by following the links as proposed on the "read these instructions first" page, I simply open up a blank page when I click the "download" button.

        Anybody know why this might be happening? I have no IDEA what a mirror site is and I thought that the problem might be linked to my ACCESS to the ftp site from which the download occurs.

        If anybody can help I'd be very grateful as I'm currently following the instructions and I'd really like to be able to finish them off so I can get my computer fixed!!

        MANY thanks,

        JDE123It looks like download web page is having problem.
        You can get it from here: http://www.download.com/Dr-Web-CureIt/3000-2239_4-10605754.html
        4228.

        Solve : this are my log files, somebody help me what to do after this??

        Answer»

        I get an error message everytime i turn on my computer. the first thing appears at my desktop is,

        SSCVIHOST.exe
        windows cannot find 'SSCVIHOST .exe'. make sure you typed the name correctly, and then try again.To search for a file, click start button, and then click search.

        please, anyone.. im begging you, please help remove this error message? here is the scan logged at my computer.

        [saving space - attachment deleted by admin]1. Print this post out, since you won't have an access to it, at some point.

        2. Close all windows, except for HijackThis.

        3. Put a checkmark next to the following HijackThis entries:

        - F2 - REG:system.ini: Shell=Explorer.exe SSCVIHOST.exe

        - O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


        4. Click on "Fix It" button.

        5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

        6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

        7. Delete following files/folders (if present):

        Nothing to delete

        8. Turn off System Restore:

        - Windows XP:
        1. Click Start.
        2. Right-click the My Computer icon, and then click Properties.
        3. Click the System Restore tab.
        4. Check "Turn off System Restore".
        5. Click Apply.
        6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
        7. Click OK.
        - Windows Vista:
        1. Click Start.
        2. Right-click the Computer icon, and then click Properties.
        3. Click on System Protection under the Tasks column on the left side
        4. Click on Continue on the "User Account Control" window that pops up
        5. Under the System Protection tab, find Available Disks
        6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
        7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
        8. Click OK

        9. Restart in Normal Mode.

        10. Turn System Restore on.

        11. Run HijackThis again, and post back its log back here.I follwed all your instructions except for nos. 6 and 7 where i skipped because there is no folder options appearing on my tools menu on my windows explorer and everytime i try to access to the folder options a message "restrictions" appear. so what i did right now is post this logfile.

        [saving space - attachment deleted by admin]Your HJT log is clean, now.
        Are you still getting that error message?

        Quote

        I follwed all your instructions except for nos. 6 and 7 where i skipped because there is no folder options appearing on my tools menu on my windows explorer and everytime i try to access to the folder options a message "restrictions" appear
        In this case, it actually didn't matter, but I'm curious...Are you the owner/Adminstrator of this computer in question?thank you very much for your help... i really appreciate it, you did great!!! You're very welcome
        I assume, no more errors?well, as of this time, i haven't received any errors on my desktop.. thanks for your help... I'm glad, it helped
        Stop by anytime.hey its me again.. i've encountered another problem in my computer. please, help me remove the blank window on my desktop. it appears everytime my windows starts. the blank window is "cetihpz://errors/blank.htm"If you have HP printer, uninstall it, reboot, and reinstall printer's software.hi.. again, i encounter another problem with my computer. RUNDLL "error loading c:\WINDOWS\system32\tlilvaym.dll" "access is denied" I get this error message everytime my windows xp service pack 2 starts. please, help again solve this problem.. thanks... It looks like you're infected again.
        Post HJT log, please. i think so.. but im very optimistic with your help again, i can solve this problem. what do you mean post hjt log? is it the one that i posted in the forum? the post that you have instructed me to do?Print these instructions out.

        1. Download SUPERAntiSpyware Free for Home Users:
        http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and USE the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

        Restart computer in Safe Mode.
        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
        o Close browsers before scanning.
        o Scan for tracking cookies.
        o TERMINATE memory threats before QUARANTINING.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan SUMMARY box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
        o Click Preferences, then click the Statistics/Logs tab.
        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
        o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
        o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
        Post SUPERAntiSpyware log.

        RESTART COMPUTER!

        2. Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

        The log can also be found here:
        C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
        Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

        RESTART COMPUTER!

        3. Download HijackThis:
        http://www.snapfiles.com/get/hijackthis.html
        Post HijackThis log.
        4229.

        Solve : everything on my desktop disappears?

        Answer»

        //////////////////////////////////////////
        Avenger Pre-Processor log
        //////////////////////////////////////////

        Platform: Windows XP (build 2600, Service Pack 2)
        SAT Mar 08 18:28:02 2008

        18:27:35: Error: Invalid syntax in command:
        "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4862C7B6-5906-5FA9-511A-5F00B7CC8DC8}"
        Skipping line. (Registry value deletion mode)
        18:27:43: Error: Invalid syntax in command:
        "HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9485F885-9C7C-4EF8-83F6-FE154E3873E9}"
        Skipping line. (Registry value deletion mode)
        18:27:44: Error: Invalid syntax in command:
        "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\mljigdbbxu"
        Skipping line. (Registry value deletion mode)
        18:27:46: Error: Invalid syntax in command:
        "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\pmkhghijgd"
        Skipping line. (Registry value deletion mode)
        18:27:48: Error: Invalid syntax in command:
        "HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa"
        Skipping line. (Registry value deletion mode)


        //////////////////////////////////////////


        Logfile of The Avenger Version 2.0, (c) by Swandog46
        http://swandog46.geekstogo.com

        Platform: Windows XP

        *******************

        workin on the restDownload OTMoveIt2 by OldTimer.

        • Save it to your desktop.
        • Double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
        • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
        Code: [Select]C:\WINDOWS\ssqnmmnm
        C:\WINDOWS\system32\ssqnmmnm
        C:\WINDOWS\system32\vbzip10.dll
        C:\WINDOWS\system32\ddayxwtu.dll
        C:\WINDOWS\jkhfedab.dll
        C:\Documents and Settings\Owner\Application Data\awtqqpmn.dll
        HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4862C7B6-5906-5FA9-511A-5F00B7CC8DC8}
        HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9485F885-9C7C-4EF8-83F6-FE154E3873E9}
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mljigdbbxu
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pmkhghijgd
        HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
        • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window.
          IMPORTANT -- Paste only into the bottom input panel (under the Yellow bar), The top panel will not help you.
          Right-click and choose Paste.
        • Click the red Moveit! button.
        Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

        Close OTMoveIt2

        Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start>All Programs>Accessories>Notepad), click File>Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present. Copy and then paste the contents of that document in your next post.Ok after I did the Avenger log, and made all the files visible, when I went into SAFE mode and into windows\system32 to go and delete j?ava.exe I couldn't find it. All I had was java.exe, javacpl.cpl, javaw.exe, and javaws.exeGo to C:\_OTMoveIt\MovedFiles and post the moved files log please.

        Also post a fresh Hijackthis log.SORRY I'd hate to be a complete pain in the *censored* but can you fix that new link, sorry manFixed. You would THINK I should learn by now [Custom Input]
        < C:\WINDOWS\ssqnmmnm >
        C:\WINDOWS\ssqnmmnm moved successfully.
        < C:\WINDOWS\system32\ssqnmmnm >
        C:\WINDOWS\system32\ssqnmmnm moved successfully.
        < C:\WINDOWS\system32\vbzip10.dll >
        File/Folder C:\WINDOWS\system32\vbzip10.dll not found.
        < C:\WINDOWS\system32\ddayxwtu.dll >
        File/Folder C:\WINDOWS\system32\ddayxwtu.dll not found.
        < C:\WINDOWS\jkhfedab.dll >
        File/Folder C:\WINDOWS\jkhfedab.dll not found.
        < C:\Documents and Settings\Owner\Application Data\awtqqpmn.dll >
        File/Folder C:\Documents and Settings\Owner\Application Data\awtqqpmn.dll not found.
        < HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4862C7B6-5906-5FA9-511A-5F00B7CC8DC8} >
        Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4862C7B6-5906-5FA9-511A-5F00B7CC8DC8}\\ not found.
        < HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9485F885-9C7C-4EF8-83F6-FE154E3873E9} >
        Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9485F885-9C7C-4EF8-83F6-FE154E3873E9}\\ not found.
        < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mljigdbbxu >
        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mljigdbbxu\\ not found.
        < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pmkhghijgd >
        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pmkhghijgd\\ not found.
        < HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa >
        Registry key HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\ deleted successfully.

        OTMoveIt2 v1.0.20 log created on 03102008_160105ok now, I restarted my computer and everything starts up, gets to the desk top and a window comes up saying Isass.exe -system error, objective name not found. when I HIT ok it just restarts and the same thing happensCan you log on in safe mode?

        Do you have an XP CD to boot from and do a repair install?
        4230.

        Solve : DrWebb CureIt?

        Answer»

        trying to DOWNLOAD DrWebb CureIt, And page will not load. I am following directions as to what I NEED to do before POSTING problem, anyone else have this problem? or is it PART of my problem?
        well I guess the site was down downloading now

        4231.

        Solve : I Have a virus?

        Answer»

        While I am heaping praises, my computer is still having trouble opening web pages in a timely manner. Sometimes it fails completely. I guess the chase is still on.Keep everything but Omniquad total security.

        Do you have an XP CD?

        If so, place it in your CD ROM drive and follow the instructions below:

        • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
          • Let this run undisturbed until the window with the blue progress bar goes away
        SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

        If you want to see what was replaced, right-click My Computer and click on Manage.
        In the new window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System.


        The rain finally stopped today. First night we were getting large golfball size hail and then HEAVY rain for what SEEMED like 48 hours. Could be another flood riddled season in the midwest. Hope not.....Hmmm, the last time I was asked to place my XP cd in my drive, I accidentally reinstalled it and lost valuable personal files. Let's hope it doesn't happen again, it's a long drive to OK. That method won't delete anything. Just don't restart the computer with the CD in the drive and you won't chance loosing anything.Mission accomplished but computer still sluggish. Some sites had to be refreshed to get them to load. I defraged today as well.Let's try a few things with dial a fix.

        First

        Please download Dial-a-Fix by djlizard, SAVE it to the desktop then extract it to it's own folder.
        • Open the folder and run Dial-a-fix.exe
        • 2 windows will open. Close the one in the background labled Restrictive Policies
        • On the main window, CHECK the box in section 4, labled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
        • Check all boxes in Section 5, labled Registration Center.
        • Click Go
        • OK any error messages if received, but write them down and post them here.
        • Restart the computer when done
        .

        Next

        Open Dial-a-fix and click the hammer icon. Select Flush DNS and click Go
        When complete, select Repair Permissions and click Go
        When complete, select Repair/reinstall IE and click Go

        If at any time you are prompted for the XP cd, insert it
        Make note of any error messages and post them here
        Reboot when complete and let me know if there's any changeOK, but first I'm going to do some checks that dial-a-fix recommends first.Just concluded Dial a fix and had no problems. Computer is still slightly sluggish and some pages still have to be refreshed. Even on my own website, things like chat room boxes and stat counters are way slow to load. Any other suggestions?Just for grins, click on my website and scroll the whole page and time how long it takes. The last thing to load is the search engine boxes at the very bottom of the page. If your computer takes very long for it to load then I won't gripe but I know that in the past, mine use to load it in about 5 seconds.Pretty much instantly.

        Do you think it is the browser or your connection?

        It's possible, Insight has recently changed over to Comcast. As far as browsers, I've been using the same all a long. I installed Foxfire and tried it but it didn't do justice to some of the graphics on my site.

        I really appreciate your help and even recommended the site on my site, thanks again.Could be the connection. You could try re-installing IE7.

        • Uninstall the version of IE you have installed now, to do so follow these steps:
          • Click Start
          • Click Control Panel
          • Double click Add or Remove Programs
          • Scroll down until you find Internet Explore
          • Then click Change/Remove, and follow the prompts.
          • Note: If you are unable to see IE7 in Add or Remove Programs follow these steps:
          • Click Start
          • Click Run
          • Type or copy and paste, into the text box:
          • %windir%\ie7\spuninst\spuninst.exe
          • Then Press Enter
          • Restart your computer.
            • Install the fresh version of Internet Explorer 7.
          [/list]I downloaded, uninstalled and reinstalled IE7. I can't tell any difference so far. What is your opinion on the IE7 add ons that they offer?Which add-ons, and from where?They are the addons that you can choose after installing IE7. They come with it, one of them is ispell. BTW, my computer is getting a bit perkier.
          4232.

          Solve : Homepage Hijacked!?

          Answer»

          I have had my Homepage hijacked by what I believe to be a virus. My new homepage is automatically redirected to http://turbo-search101.com/. I think I acquired this through trying to download an Internet download booster (shakes head in shame). It is on my work PC (running XPSP2, and using Firefox as my default browser). My OS is Korean and I am on the school network. That's about it.
          [b]ANY[/b] help would be greatly appreciated as I am tired of this feeling of violation.
          Thanks

          [recovering space - attachment deleted by admin]Please download Combofix by sUBs from one of the below links.
          (Try all three if necessary)

          Important! Combofix.exe MUST be saved to and ran from the Desktop.
          • Close any open Web browsers. (Firefox, Internet Explorer, etc) before STARTING Combofix.
          • Important! Temporarily disable your antivirus, script blocking and any antispyware real time protection before performing a scan.
            • Click this link to see a list of SECURITY programs that should be disabled and how to disable them.
            • If yours is not listed and you don't know how to disable it, please ask.
          • Warning: Combofix disconnects your computer from the internet. The connection is automatically restored before Combofix completes its run.
          • Double click combofix.exe & follow the prompts.

              • From the keyboard select 1 and press Enter[/COLOR]
              • When finished, it will produce a log for you.
              • Post that log in your next reply.
              Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
              • If Combofix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your computer.
              • Important: Remember to re-enable your antivirus and antispyware before reconnecting to the Internet.
              .
              ----------

              Nexy post add
              Combofix log
              NEW Hijackthis log
            A simpler way would go to Internet Properties and change it BACK to what you want for your home page. I freaked out the first couple of times it happened to me. Sometimes when you visit a webpage, it asks you if you want it to be your homepage. I always click "no" or if there is no negative option, I just leave "yes" unchecked. Fortunately, this doesn't happen very often, and you won't have to change it back all the time. You can type in "about:blank" (without quotations) if you dont want a homepage. I usually have Google or Yahoo for my homepage.Quote
            A simpler way would go to Internet Properties and change it back to what you want for your home page.
            No.if you have a system restore point, then you can just use system restore and go backwards to the most recent point in time, just before you downloaded your software that supposedly hijacked your homepage.

            Once you do that, DON"T make the same mistake :-)

            That's the fastest way that I know to be sure that your problem is fixed without having to wade through firefox/internet properties or using other software to fix. And besides, you might already have infected your computer with a spyware.Guys please, if you want to be on the malware helpers list PM CBMatt for details.

            Adding comments after a fix has already been given just adds confusion to the thread.

            Thanks.Well, it is now pretty MUCH out of my hands. My boss brought in somebody who took my PC. It is to be reformatted and XP (English) installed. This was planned, but does it take care of the problem? I was using Firefox and had Foxmarks installed. Should I be WORRIED about contamination of my home PC since it hijacked my browser (incidentally it had no effect on IE)? I have printed off a copy of your previous instructions, made the correct adjustments (at home and will at work), and plan to run through the steps periodically as part of maintenance. Thanks for your time and attention. The format will take care of any problems. Foxmarks will save your bookmarks but you will need to reinstall all of your add-ons including foxmarks.

            If you use a flash drive between the two computers then it is wise to run spyware/virus scans on every computer the flash drive was used on. Flash drives can "cross contaminate" computers.

            Cool. Will do. Thanks again for the help.No problem, safe surfing.........
            4233.

            Solve : trojan downloader zlob?

            Answer»

            How to remove trojan downloader.zlob?Go through the steps here and post the requested logs. One of our experts will then be able to help you.i have spybot installed in my computer. will it cause conflit with other anti-spyware u have suggested. i am using windows xp with SP2. had problem in downloading Java. i think java has problem with windows. ur SUGGESTION please.hijackthis log file

            [recovering space - attachment deleted by admin]i ran all the programs u have suggested & hope the trojan has been removed. giving the file by drweb.

            00189375.FIL;C:\$VAULT$.AVG;Win32.HLLW.Autoruner;Deleted.;
            00230625.FIL;C:\$VAULT$.AVG;BackDoor.Generic.694;Deleted.;
            00375250.FIL;C:\$VAULT$.AVG;Adware.NewDotNet;;
            01255734.FIL;C:\$VAULT$.AVG;Adware.NewDotNet;;
            02316250.FIL;C:\$VAULT$.AVG;BackDoor.PcClient;Deleted.;
            miditest.htm;C:\Program Files\Anvil Studio\html;Modification of BAT.Mtr.1429;Moved.;
            fdcatch.dll;C:\Program Files\FreshDevices\FreshDownload;Trojan.DownLoader.50173;Deleted.;
            A0158693.exe;C:\System Volume Information\_restore{0882E8A3-F5B1-409D-8DD6-BA4A252AC8E9}\RP333;Program.ProxyOSS;;
            A0158713.dll;C:\System Volume Information\_restore{0882E8A3-F5B1-409D-8DD6-BA4A252AC8E9}\RP333;Trojan.DownLoader.50173;Deleted.;
            You need to post ALL three logs.

            Spybot is fine.Super antispyware log file.

            [recovering space - attachment deleted by admin]Other logs, please.spybot log file is here, but dont know how to save log file of AVG

            [recovering space - attachment deleted by admin]You didn't read instructions carefully enough.
            I need these three logs:
            SuperAntispyware log
            Dr. Web CureIt log
            Hijackthis log
            I got Super log. You need to run Dr. Web, and HJT as the last one.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 05:45:29, on 04-04-2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\SYSTEM32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\WINDOWS\system32\CTsvcCDA.exe
            C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\HPZipm12.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\MsPMSPSv.exe
            C:\WINDOWS\system32\fxssvc.exe
            C:\WINDOWS\SYSTEM32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
            C:\WINDOWS\VM_STI.EXE
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
            O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - (no file)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
            O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC SUITE 6\LaunchApplication.exe -startup
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKLM\..\Policies\Explorer\Run: [status] present
            O4 - HKLM\..\Policies\Explorer\Run: [winlogon] C:\heap41a\svchost.exe C:\heap41a\std.txt
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
            O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
            O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\system32\wweb32.dll/lookup.html
            O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
            O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
            O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O16 - DPF: {10E0E75E-6701-4134-9D95-C0942ED1F1C8} (Snapfish Outlook Import ActiveX Control) - http://www4.snapfish.co.in/SnapfishOutlookImport.cab
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.co.in/SnapfishActivia.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203595233859
            O17 - HKLM\System\CCS\Services\Tcpip\..\{B48675D5-C70E-4296-A662-188070601C1B}: NameServer = 202.56.224.153,202.56.230.6
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O22 - SharedTaskScheduler: inoperable - {1b40d2ad-d237-4544-b1e1-0bf75bf8fcc0} - (no file)
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

            --
            End of file - 8199 bytes
            DRweb file

            modem_common.js;C:\Program Files\Airtel\NetXpert Agent\agentcommon\inc;Probably SCRIPT.Virus;;
            sma_common.js;C:\Program Files\Airtel\NetXpert Agent\agentui\snapins\preferences;Probably SCRIPT.Virus;;
            sprtsync.dll;C:\Program Files\Airtel\NetXpert Agent\bin;Probably DLOADER.Trojan;;
            Quote

            DRweb file

            modem_common.js;C:\Program Files\Airtel\NetXpert Agent\agentcommon\inc;Probably SCRIPT.Virus;;
            sma_common.js;C:\Program Files\Airtel\NetXpert Agent\agentui\snapins\preferences;Probably SCRIPT.Virus;;
            sprtsync.dll;C:\Program Files\Airtel\NetXpert Agent\bin;Probably DLOADER.Trojan;;

            I don't want to sound like a pain in the back, but what is the problem with posting a WHOLE log?
            Was HJT run AFTER two other programs?sorry for troubling u. but drweb logfile is in excel format which cannot be attached here in additional OPTION of reply section..so i selected the content & pasted it here. after running which two progra should i run HJT?

            Quote
            drweb logfile is in excel format
            It doesn't sound right, but in any case, please, post new HJT log.
            4234.

            Solve : Security advice requested?

            Answer»

            I've just downloaded the LATEST version of ZoneAlarm Free Edition, which I've had for some time, and seen the info on their "Security SUITE", which is not free. I got to wondering if an all embracing system like that is better than the disparate programs I have at the moment.

            These are: AVG free ANTISPYWARE 7.5, AVG free AntiVirus 7.5.519, CCleaner, Internet Window Washer, LAVASOFT AdAware, and ZoneAlarm.

            The Window Washer seems to duplicate CCleaner, and I'm not sure what AdAware does.

            All these are updated regularly and I have had no problems - should I stick with what I've got?

            I use Firefox as my main browser, and have Windows XP SP2You're perfectly fine.doesnt alot of different antivirus programs and firewalls screw up your computer?Quote from: ms_dos_sux on April 05, 2008, 11:51:11 AM

            doesnt alot of different antivirus programs and firewalls screw up your computer?

            ONE AV program is the rule of thumb...
            Then layered protection with an ad program, a spyware program, a trojan program, a keylogger/rootkit program...topped off with a firewall and you should be good to GO...ONE firewall, as well.
            4235.

            Solve : Music slows down my computer and almost makes it freeze.?

            Answer»

            I have a toshiba satellite purchased roughly a year ago (more info available upon request.) Basically its still a competent computer that should have a lot of problems with speed. The problem is that when I play music, or video it slows down my computer and nearly freezes it. This happens INSTANTLY upon playing, the music also HEAVILY skips. It doesn't matter where the music is playing from, whether it is myspace, vlc, itunes, etc etc. Same result. Ive also experienced general slow down in computer performance. Ive RAN virus scan, spyware scan, defrag, registry clean. You name it. If any addition info is required please ask. Thank you!How much Random Access Memory (RAM) does your computer have?

            How many icons reside in the system tray? (The area on the right side of the taskbar, next to the clock?

            By asking these questions, I am trying to ascertain / figure out how much RAM you're using of what's available.

            There are also other ways to get this information.

            Thanks!I have 1gb of ram

            and these programs are in my system tray:
            Wordweb (dictionary)
            zone alarm
            soulseek
            avg
            rainlender (calender)
            cd/dvd acoustic silencer
            volume

            thanks again.Okay -- a gig of RAM -- good on you!

            With the stuff in your system tray, that doesn't scream of RAM overload to me...

            (I have FRIENDS who run a boatload of stuff in their system trays, and then wonder why the computer slows down.)Download HijackThis:
            http://www.snapfiles.com/get/hijackthis.html
            and post its log.
            I'd like to see what's running there.Broni is right -- we need to see what processes are running, as well as applications.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 4:19:12 PM, on 3/8/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            C:\WINDOWS\system32\DVDRAMSV.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Google\Update\1.0.103.3\GoogleUpdate.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
            c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
            C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
            C:\WINDOWS\system32\TDispVol.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
            C:\WINDOWS\system32\dla\DLACTRLW.exe
            C:\Program Files\Synaptics\SynTP\Toshiba.exe
            C:\toshiba\ivp\ism\pinger.exe
            C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Zune\ZuneLauncher.exe
            C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\Rainlendar2\Rainlendar2.exe
            C:\WINDOWS\system32\RAMASST.exe
            C:\Program Files\WordWeb\wweb32.exe
            C:\Program Files\RocketDock\RocketDock.exe
            c:\WINDOWS\system32\ZuneBusEnum.exe
            C:\Program Files\Soulseek\slsk.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
            O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.2.14.0\gears.dll
            O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
            O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
            O4 - HKLM\..\Run: [tdispVol] TDispVol.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
            O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
            O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
            O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
            O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
            O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
            O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
            O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
            O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.2.14.0\gears.dll
            O9 - Extra 'Tools' menuitem: &Google Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.2.14.0\gears.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
            O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
            O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
            O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            O23 - Service: Google Update Service (gupdate1c8614fdde71ee2) (gupdate1c8614fdde71ee2) - Google Inc. - C:\Program Files\Google\Update\1.0.103.3\GoogleUpdate.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            O23 - Service: Stuffit Archive Name Service - Smith Micro Software, Inc. - C:\Program Files\Smith Micro\StuffIt11\ArcNameService.exe
            O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
            O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

            --
            End of file - 9425 bytes
            I can't see anything special...

            Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

            4236.

            Solve : Suspected Virus...?

            Answer»

            HI, my computer has recently started to have problems with a few of my programs that connect to the net, the first being steam and i have tried everything with that from following trouble shooting on their website to completely removing it and reinstalling. The other software is ggarena which is sort of like a vpn program.

            ive run adaware, spybot and avg free and avg only found one generic trojan which i removed. i have included a hijack this log to see if anything is a miss there, but im all out of ideas apart from a complete reinstall which i would obviously PREFER to avoid.

            any other ideas for what i can try here? ive completely reinstalled both programs only to have the same issue and i have friends with legit windows etc same as me who all keep everything updated and are not having this problem.

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\INTERN~2\mum.exe
            C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
            C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Grisoft\AVG7\avgwb.dat
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
            \?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: Skype add-on (MASTERMIND) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
            O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
            O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
            O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
            O4 - HKCU\..\Run: [Steam] "H:\Steam\Steam.exe" -silent
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188903244875
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188903227500
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
            O23 - Service: NVIDIA Display DRIVER Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            We need the top part of the Hijackthis log. oh, sorry mate must of missed it when i copy and pasted it. ill POST it up later today. cheers.Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 9:51:40 PM, on 3/04/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\INTERN~2\mum.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
            H:\Steam\Steam.exe
            C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
            C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Garena\Garena.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
            O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
            O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
            O4 - HKCU\..\Run: [Steam] "H:\Steam\Steam.exe" -silent
            O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188903244875
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188903227500
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

            --
            End of file - 8514 bytes
            I don't see any malware, just one entry to fix. Are there any problems you can tell?


            Open Hijackthis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            Important: Close all windows except for Hijackthis and then click Fix checked.

            Exit Hijackthis.other than the two issues mentioned above i dont seem to have any other problems. but i have tried everything including uninstalling and reinstalling and they still dont work. ill do what you said with hijack this tonight. but im at a loss to to what could be causing it.

            almost at the point where a reinstall would be quicker than all the stuffing around....Whatever it is I don't think it is malware. Could your FIREWALL be blocking the programs?nah im not running a firewall other than the one through my router and that has never been an issue before. these programs work sometimes but more often dont. so i dont think they are being blocked. im going to try and delete steam and reinstall ggarena in case they are not liking each other or something stupid.

            such a pain though as they used to work fine together..

            4237.

            Solve : AdAware SE discontinued?

            Answer»

            As of January this year AdAwareSE is being discontinued.

            The program is however still Free and can be downloaded Here

            The rumors about now having to pay for it are untrue.

            Update as SOON as possible as i believe updates ended yesterday for SE.

            Temporary sticky.They released two updates this week. I wonder what this MEANS?

            http://www.majorgeeks.com/download726.htmlI believe they still want people using the older version to be protected...automatic updates for it ended the 2nd week of January.I down loaded the new free version yesterdayI've been informed that the new version is bundled with the Ask toolbar....

            THEREFORE i'm going to leave this a sticky for awhile longer.

            StoryThe Ask Toolbar is becoming a trend with a lot of products. Spy Sweeper is bundling it also. Not cool in my eyes.

            There was another Ad-Aware SE reference file released today if anyone is still using it.That's what i've been doing...
            The updates are being listed regularly at majorgeeks, Scott's Newsletter Forums and The Elder Geek to name a few...Quote from: patio on February 04, 2008, 10:33:12 AM

            I've been informed that the new version is bundled with the Ask toolbar....

            Therefore i'm going to leave this a sticky for awhile longer.

            Story
            No Ask tool bar on my new download.

            BTW I use Firefox browser and like it.When I downloaded the new free version, there was a check box option for the Ask toolbar. I unchecked it and got no Ask toolbar. I also have no problems getting the latest updates.Good to hear they are GIVING you a choice to not install it.
            Thanx for the info. Do you know of any good freeware replacements for AdAware? Spybot isn't all that good. WEBROOT Spy Sweeper is very good, but it is on a subscription basis and is good for one year. Last time I used it, it was about $30/year. It may have gone up since then.SuperAntispyware - http://filehippo.com/download_superantispyware/

            AVG Antispyware - http://filehippo.com/download_avg_antispyware/

            Both free and top notch

            Also if you don't have it already use SpywareBlaster - http://filehippo.com/download_spywareblaster/As this issue has been discussed and most here are aware of it i'm un-stickying it to clear up the Sticky section of the V & S Forums...

            4238.

            Solve : help friends comp has foto.zip?

            Answer»

            how do you remove it

            i have his hijack this log right here
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:00:16 AM, on 3/8/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\LTMSG.exe
            C:\Program Files\Microsoft IntelliType Pro\type32.exe
            C:\Program Files\Microsoft IntelliPoint\point32.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
            C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
            C:\Program Files\PowerISO\PWRISOVM.EXE
            C:\WINDOWS\system32\winstruct32.exe
            C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows LIVE\Messenger\MsnMsgr.Exe
            C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\explorer.exe
            C:\WINDOWS\system32\ntvdm.exe
            C:\WINDOWS\system32\CMMON32.EXE
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Grisoft\AVG Free\avgwb.dat
            C:\Program Files\Windows Media Player\wmplayer.exe
            C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by LocalNet
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\LocalNet Express 2.0\prpl_IePopupBlocker.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
            O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
            O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
            O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\LocalNet Express 2.0\trayctl.exe" /STARTUPLAUNCH
            O4 - HKLM\..\Run: [Pad39A-HtEHL] D:\Pad39A.exe
            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
            O4 - HKLM\..\Run: [Windows Instruction Services] winstruct32.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
            O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
            O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
            O4 - Global Startup: officejet 6100.lnk = ?
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://start.localnet.com/
            O17 - HKLM\System\CCS\Services\Tcpip\..\{81FFAF9E-4094-45DD-A5AC-396E4C097CD9}: NameServer = 64.136.173.8 64.136.164.66
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
            O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
            O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

            --
            End of file - 7503 bytesThis needs to be moved to the malware forum if a mod sees it.


            Scan Suspicious File(s)

            Please visit one of the following:
            (Multiple sites are given in case one is not working)
            (If more than one file needs scanned they must be done separately and logs posted for each one)

            Copy the file path in the code BOX below.
            Code: [Select]C:\WINDOWS\system32\winstruct32.exe
            • At the upload site, click once inside the window next to Browse.
            • Press Ctrl+V on the keyboard (both at the same time) to paste the file path in the window.
            • Next click Send File/Submit/Upload (DEPENDING on the site)
              • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
            • This will perform a scan across multiple different virus scanning engines.
            • Please wait for all of the scanning engines to complete.
            • Copy and then Paste the RESULTS in the next reply.
            ty my friend i never seen before

            did not know that these site's exist

            sorry for problem was so vauge

            on msn it sends randomly a file called foto.zip which i know know is a trojan and possibly i got it from a friendYes you have some QUESTIONABLE entries in the Hijackthis log, if you could scan the file and let me know the results then we will better know which direction to go.came back with a 17% of possibly being infected with a virus and one of the scanners said it had a trojan downloader which is my problem
            OK, you will need to look at this post

            Hijackthis only shows some forms of malware and this one is going to take the use of more tools.
            4239.

            Solve : mal/zlobJS-A?

            Answer»

            Quote

            I could not find where to delete spyware cleaner or vxs.exe
            That's fine.
            Post new HJT log, please.Here is the new one.

            thank you.Almost there. We need to remove one more thing.
            Go Start>Run, type in:
            services.msc
            Click OK.

            Services window will open. Find:
            Print Spooler SERVICE
            If it's listed as Started, right click on it, and click Stop
            Right click again, click Properties, and under Startup type select Disabled from drop-down menu.

            Restart computer. Post new HJT log.Here is the new one.All good...

            HJT log is clean.

            1. Turn off System Restore:

            - Windows XP:
            1. Click Start.
            2. Right-click the My Computer icon, and then click Properties.
            3. Click the System Restore tab.
            4. Check "Turn off System Restore".
            5. Click Apply.
            6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
            7. Click OK.
            - Windows Vista:
            1. Click Start.
            2. Right-click the Computer icon, and then click Properties.
            3. Click on System Protection under the TASKS column on the left side
            4. Click on Continue on the "User Account Control" window that pops up
            5. Under the System Protection tab, find Available Disks
            6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
            7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
            8. Click OK

            2. Restart computer.

            3. Turn System Restore on. Create new Restore Point.

            4. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

            6. Download, and install free ThreatFire: http://www.threatfire.com/, which will give you real-time protection against malwares.
            It won't interfere with your antivirus, nor firewall.

            7. Let me know, how your computer is doing.
            I did the last two things you mentioned. I downloaded CCleaner and ran it.

            And I've downloaded the threatfire.


            Someone whatever those problems were I had, they aren't completely gone though.

            One of the things that would happen is when I would have a browser open, for no reason at all an add would POP open on a full browser. Many of them saying, windows has detected a problem, do you want to run a scan. Now, I know better than to click on any of them, and just closed them.

            So today, when I have a browser open, same thing happens, but INSTEAD of their being an advertisement, blank browsers keep opening up. Just like before but without the advertisements. ( so far)

            Is there anything else I can do?

            thanks,

            Is IE your default browser? Do you have pop-up stopper enabled?okay, I ran threatfire, rebooted, and I think everything is good now. I havent seen anymore of those browsers just automatically open.

            Whewwwwwww.

            Thanks for helping a helpless girl out. I appreciate the time and effort you gave me.

            Very good. Keep me updated, if anything shows up
            4240.

            Solve : i got a wierd virus?

            Answer»

            ok guys, i downloaded this VIDEO(Card trick, im not perverted) and when i opened it, it said it could not be initialized, it terminated, and turned my backround wierd. now i can't use my taskmanager because it got disabled(by the virus) and spysweeper can't find anything. i run a windows xp sp2. please helpStart HERE. Once completed one of the malware specialists will be along to help you.ok guys, i followed the instructions but i put the logs as attatchments, please help to tell me if it is serious or not

            [recovering space - attachment deleted by admin]You have Viewpoint installed.

            Viewpoint Media Player/Manager/Toolbar is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". See Viewpoint to Plunge Into Adware

            It is SUGGESTED to remove the program now.
            Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

            • Viewpoint
            • Viewpoint Manager
            • Viewpoint Media Player
            • Viewpoint Toolbar
            • Viewpoint Experience Technology
            If you have trouble removing Viewpoint, I suggest that you use ViewpointKiller

            Once you have downloaded ViewpointKiller, unzip it to a convenient location such as your desktop.
            Run ViewpointKiller, and SELECT File > Do All Killings
            Follow the prompts, selecting Yes or No, depending on which selection you are most comfortable with.

            ----------

            Please download Malwarebytes' Anti-Malware (MBAM) to your desktop from either of these two links.
            • Double-click mbam-setup.exe and follow the prompts to install the program.
            • At the end, be sure a checkmark is placed next to
              • Update Malwarebytes' Anti-Malware
              • Launch Malwarebytes' Anti-Malware
              • Click Finish.
              • If an update is FOUND, it will download and install the latest version.
              • Once the program has loaded, select PERFORM full scan, then click Scan.
              • When the scan is complete, click OK, then Show Results to view the results.
              • Be sure that everything is checked, and click Remove Selected.
              • When completed, a log will open in Notepad.
              • Please copy and paste the log into your next reply
              Note: If you accidentally close the log it can be retrieved at any time from the Malwarebytes' Anti-Malware main screen.
              • Launch Malwarebytes' Anti-Malware.
              • Click the Logs tab.
              • Double-click log-mm.dd.yyyy [xxxxxx].txt
              .
              ----------

              Now run a new Hijackthis scan and post that log along with the MBAM log.

              Also let me know how things are now.

              4241.

              Solve : CPU at 100%?

              Answer»

              Hello,

              Here's a real n00b question. I looked at other posts about the CPU peaking and staying at 100%, but they didn't seem to completely answer my question.

              Is it normal for iexplore.exe to use 80-95% of the CPU? I've been having serious lag problems, and when poking around, I finally looked at the Task Manager, and saw that the CPU in general seems to run between 95 and 100%, making my internet veeeery slow. I looked at the processes tab, and it seems that iexplore.exe takes up most of that.

              Also, I have two iexplore.exe running. Is that normal as well? (I've checked the spelling to make sure they aren't malware, and all seems ok.)

              There are several other programs running, but take up only 1 or 2%, with the occasional program taking up 8% or so for a moment. It seems that iexplore.exe is simply taking up too much.

              Anything I can do?

              Thanks. Oh and to add,

              I have AVG Free Edition, updated daily. I recently added WindowsCare by IoBit to take care of spyware. Both say that I don't have any virus or spyware (and WindowsCare takes care of any sneaky spyware that may have climbed aboard, every time I run it, which is every day.)

              The computer is a laptop, Compaq 2500, and I use an EXTERNAL modem.

              thnx Quote

              Is it normal for iexplore.exe to use 80-95% of the CPU?
              I have two iexplore.exe running. Is that normal as well?
              No, to both questions.

              Print these instructions out.

              1. Run one of two free on-line scanners:
              *** ESET Online Scanner at: http://www.eset.com/onlinescan/
              Note: This scanner is for Internet Explorer only
              1. You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. CLICK on it.
              2. If it wants to install an ActiveX component allow it
              3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
              4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
              5. After initialization is complete, make sure, that "Remove found threats", and "Scan unwanted applications" are checkmarked.
              6. Click the "Scan" button
              7. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
              Post ESET's log.

              *** TrendMicro online scanner, HouseCall
              Note: This scanner works with Firefox, and Internet Explorer

              Click on
              It'll ask you to download small housecall66.exe to your computer.
              Double click on the above file to begin scanning process.

              HouseCall pop-up window will open.
              Accept the agreement.
              In next window, select Complete Scan, and click on Start Scanning button.

              Relax, it'll take a while...

              Upon completion HouseCall will display results under Results tab.
              Click Clean now button.
              Close application.

              Find TrendMicro log, housecall0.log. Its location:
              Windows XP: C:\Documents and Settings\username\Application Data\HouseCall 6.6\log
              Vista: C:\Users\username\AppData\Roaming\HouseCall 6.6\log


              2. Download SUPERAntiSpyware Free for Home Users:
              http://www.superantispyware.com/

              * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
              * An icon will be created on your desktop. Double-click that icon to launch the program.
              * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
              * Close SUPERAntiSpyware.

              Restart computer in Safe Mode.
              To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

              * Open SUPERAntiSpyware.
              * Under "Configuration and Preferences", click the Preferences button.
              * Click the Scanning Control tab.
              * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
              * Click the "Close" button to leave the control center screen.
              * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
              * On the left, make sure you check C:\Fixed Drive.
              * On the right, under "Complete Scan", choose Perform Complete Scan.
              * Click "Next" to start the scan. Please be patient while it scans your computer.
              * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
              * Make sure everything has a checkmark next to it and click "Next".
              * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
              * If asked if you want to reboot, click "Yes".
              * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
              * Click Close to exit the program.
              Post SUPERAntiSpyware log.

              3. Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

              * Double-click mbam-setup.exe and follow the prompts to install the program.
              * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
              * If an update is found, it will download and install the latest version.
              * Once the program has loaded, select Perform full scan, then click Scan.
              * When the scan is complete, click OK, then Show Results to view the results.
              * Be sure that everything is checked, and click Remove Selected.
              * When completed, a log will open in Notepad.
              * Post the log back here.

              Be sure to restart the computer.

              The log can also be found here:
              C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
              Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

              4. Download HijackThis:
              http://www.snapfiles.com/get/hijackthis.html
              Post HijackThis log.Wow! Thanks Broni.

              But first, should I delete the WindowClean antispyware first? And what about AVG? Is it safe to leave there, or is it better to get rid of it? I'm thinking program conflicts.

              Thanks so much for such detailed help. When you post your logs, I'll have a better look what programs you need, and which ones are not necessary.OK, thanks. I'll get started right now! Ok...well, here's part one of the results:

              ESET Online Scanner:

              # version=4
              # OnlineScanner.ocx=1.0.0.635
              # OnlineScannerDLLA.dll=1, 0, 0, 79
              # OnlineScannerDLLW.dll=1, 0, 0, 78
              # OnlineScannerUninstaller.exe=1, 0, 0, 49
              # vers_standard_module=2898 (20080223)
              # vers_arch_module=1.064 (20080214)
              # vers_adv_heur_module=1.064 (20070717)
              # EOSSerial=a1535db02377e64fa3da5a237a57db80
              # end=finished
              # remove_checked=true
              # unwanted_checked=true
              # utc_time=2008-02-24 11:22:58
              # local_time=2008-02-25 12:22:58 (+0100, ora solare Europa occidentale)
              # country="Italy"
              # osver=5.1.2600 NT Service Pack 2
              # scanned=247854
              # found=1
              # scan_time=10978
              C:\Programmi\MSN Messenger\msimg32.dllWin32/Toolbar.MyWebSearch application (unable to clean - deleted)00000000000000000000000000000000



              SuperAntiSpyware:

              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 02/25/2008 at 02:48 AM

              Application Version : 3.9.1008

              Core Rules Database Version : 3408
              Trace Rules Database Version: 1400

              Scan type : Complete Scan
              Total Scan Time : 01:54:24

              Memory items scanned : 182
              Memory threats detected : 0
              Registry items scanned : 5866
              Registry threats detected : 0
              File items scanned : 38557
              File threats detected : 1

              Adware.Tracking Cookie
              C:\Documents and Settings\user\Cookies\[emailprotected][2].txt


              Malwarebytes’ Anti-Malware:

              Malwarebytes' Anti-Malware 1.05
              Database version: 402

              Scan type: Full Scan (C:\|)
              Objects scanned: 61372
              Time elapsed: 42 minute(s), 57 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 11
              Registry Values Infected: 0
              Registry Data Items Infected: 0
              Folders Infected: 0
              Files Infected: 0

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

              Registry Values Infected:
              (No malicious items detected)

              Registry Data Items Infected:
              (No malicious items detected)

              Folders Infected:
              (No malicious items detected)

              Files Infected:
              (No malicious items detected)











              and here's part two:

              HijackThis:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 4.01.41, on 25/02/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
              C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\Explorer.EXE
              C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
              C:\Program Files\Hamlet\Adsl\dslstat.exe
              C:\Program Files\Hamlet\Adsl\dslagent.exe
              C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Programmi\HP\Digital Imaging\bin\hpqSTE08.exe
              C:\Programmi\Internet Explorer\iexplore.exe
              C:\Programmi\File comuni\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alltheweb.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmi\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
              O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Hamlet\Adsl\dslstat.exe icon
              O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Hamlet\Adsl\dslagent.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
              O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: &Search - ?p=ZSYYYYYYYYIT
              O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
              O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186956585460
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB33077-5045-48DC-8C59-70C51A9B45E4}: NameServer = 192.168.0.1
              O17 - HKLM\System\CCS\Services\Tcpip\..\{CA31DB1B-3817-48DA-BC08-757DE9E7BEB2}: NameServer = 212.216.112.112 212.216.172.62
              O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

              --
              End of file - 7180 bytes

              1. Print this post out, since you won't have an access to it, at some point.

              2. Close all windows, except for HijackThis.

              3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

              - R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              - O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
              - *O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
              - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
              - O8 - Extra context menu item: &Search - ?p=ZSYYYYYYYYIT


              4. Click on "Fix checked" button.

              5. Turn off System Restore:

              - Windows XP:
              1. Click Start.
              2. Right-click the My Computer icon, and then click Properties.
              3. Click the System Restore tab.
              4. Check "Turn off System Restore".
              5. Click Apply.
              6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
              7. Click OK.
              - Windows Vista:
              1. Click Start.
              2. Right-click the Computer icon, and then click Properties.
              3. Click on System Protection under the TASKS column on the left side
              4. Click on Continue on the "User Account Control" window that pops up
              5. Under the System Protection tab, find Available Disks
              6. Uncheck the box for any drive you WISH to disable system restore on (in most cases, drive "C:")
              7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
              8. Click OK

              6. Restart in Normal Mode.

              7. Turn System Restore on.

              8. Post new HijackThis log.

              Ok, after all this...I think I may have made a small error.

              I did as you said, and steps one thru four went just fine. Then, at step five (turning off System Restore), I blindly followed your instructions without really looking at what it was I was doing.

              After clicking on Properties, I unchecked the box that said "Turn off System Restore," as it was already checked when I opened the System Restore tab. It seems that System Restore was already off.

              I'm afraid I didn't read well enough. The version of Windows XP that I'm working on, is in Italian...and I'm afraid I just didn't pay close enough attention, I was thinking in English.

              At any rate, I thought something was amiss when no box opened asking my permission about deleting existing restore points after I had clicked Apply. I waited a few moments and then just went ahead and clicked OK.

              I restarted the computer, and when I went back in to "turn on" System Restore, I did in fact, turn it OFF. It was when the window opened that asked about the deleting of restore points, that I realized my mistake.

              SO, I clicked OK again, restarted the computer again, then went in and actually DID turn on System Restore, and now here we are.

              Here's what the Hijack log gives me in this moment:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 6.27.09, on 25/02/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
              C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
              C:\Program Files\Hamlet\Adsl\dslstat.exe
              C:\Program Files\Hamlet\Adsl\dslagent.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alltheweb.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Programmi\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
              O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Hamlet\Adsl\dslstat.exe icon
              O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Hamlet\Adsl\dslagent.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmi\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
              O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIZIO LOCALE')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
              O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186956585460
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{BEB33077-5045-48DC-8C59-70C51A9B45E4}: NameServer = 192.168.0.1
              O20 - Winlogon Notify: !SASWinLogon - C:\Programmi\SUPERAntiSpyware\SASWINLO.dll
              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

              --
              End of file - 6482 bytes
              You did well with that System Restore "thingy".

              Your HJT log is clean.

              Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
              Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

              When you're done, let me know how your computer is doing.

              It won't let me download the Slim version from your link. I can go as far as the Open File window, then it closes itself, as well as the webpage. I've tried three times now. grr...

              I noticed that it said that "These Builds are for system admins and advanced users." They obviously have NOT noticed that I have recently been advanced from newbie to rookie.

              One other thing I noticed, when wandering for the first time into the dark realm of the "Safe Mode," upon signing in, there was not only my little logon icon, but one above it for "Administrator." I thought that was me! Is this what's keeping me from being able to download CCleaner Slim? (Sounds like a well-bathed cowboy...)

              Sorry...haven't slept for a couple of days...I think I'm getting slappy.

              In all seriousness however, I just checked the Task Manager, and the CPU is bouncing around between 4 and 26% !!!!!!

              Thank you so so so much for your help. You are angel of wisdom and kindness. Quote
              These Builds are for system admins and advanced users
              Don't worry about it. The only difference between two version is, that Slim version comes without Yahoo toolbar (in normal version, you can opt out during installation).
              Try to download from here: http://www.majorgeeks.com/download4191.html

              Quote
              there was not only my little logon icon, but one above it for "Administrator." I thought that was me!
              I can't comment on this. I don't know what account were created on your computer.

              Quote
              the CPU is bouncing around between 4 and 26%
              This is much better. Can you look, which process is the main "taker"? Ciao

              Well, I've tried several times to download CCleaner but the same thing keeps happening. I'll click download, it will start, but when the window opens to install, it shuts down that window and explorer. I see the word Pirisoft, or something along those lines...and that's the end of it. I even tried using CCleaners website. Something's blocking it?

              As for who is the real Admin of my computer, I don't know what to tell you either. I bought it used, and there have been a couple of probs because of that too. For instance, when I tried to update Explorer to 7, I found out that my ID number doesn't match the number registered or some such thing. In their eyes I have a pirated copy of Windows. Quite a bother from time to time.

              As far as the "main taker" on Task Manager, looking at it in this moment, the Idle Cycle is taking up 92-97, taskmanager 3, iexplore.exe 1, explorer.exe 1, WLLoginProxy 1, svchost 2....it keeps changing, but that's what I see the most, more or less.

              However, if I visit a site like Kongregate, and play a game...iexplore goes to 90-100 and everything GETS really slow again...but perhaps that's just par for the course with a game. Unfortunately that means I will never finish Protector, which is leaving me a bit sad.

              That's it for now. Everything else seems to be fine tho. Quote
              the Idle Cycle is taking up 92-97
              This is perfectly normal. Idle process just shows un-used percentage of CPU.

              Quote
              when I tried to update Explorer to 7, I found out that my ID number doesn't match the number
              Did you try to do it from Administrator account?

              As for CCleaner, PM me with your email address, and I'll send you installation file.
              4242.

              Solve : AVG Drifting Towards The Dark Side??

              Answer»

              The new install procedure has an option checked by default that will install the Yahoo! toolbar. AVG is adamantly defending it as a highly valued feature that is useful by millions of users. You make up your own mind but any toolbar set to install by default isn't kosher with me, especially by an antivirus. The Yahoo! toolbar isn't malicious so don't take it that way, it's just that it can be hard enough to keep toolbars off of a computer to begin with. You shouldn't have to wonder if your antivirus may be installing one also.

              This thread is an example of the length AVG is willing to go in defending their decision. There were some very valid points POSTED by TeMerc that got deleted but a few of them are still there. (at the time of this posting) Well, the toolbar doesn't concern nearly as MUCH as the other comments there, the comments about version 8.0 causing major performance issues for some users. And, I don't believe the toolbar is the cause of that.

              I really don't begrudge them bundling Yahoo! toolbar as long as they give the user the option to un-select it during installation. CCleaner has done this for a long time. I imagine software developers get some financial benefit from Yahoo! by allowing their toolbar to be bundled with the software and that's OK with me. After all, we get the benefit of great freeware, like these two programs. I really don't have a problem with them adding the toolbar as an option. I do think you should have to opt-in instead of out as a first choice.

              CCleaner also has a slim version that doesn't include the toolbar at all. It is a result of the complaints they added it to the install. http://www.ccleaner.com/download/builds

              What bothers me most is I advise many users to install AVG. Now I feel I need to include additional advice to look out for the option and uncheck it to avoid the unnecessary baggage.Code: [Select]I do think you should have to opt-in instead of out as a first choice.
              Yes, I'd rather see that.

              Regarding CCleaner's Slim option, I've been aware of that for quite a long time and use it, but I think many users are not aware of it; they don't make it conspicuous. So, whenever I suggest CCleaner that someone, who would be a new user, download CCleaner, I still mention the Slim option and how to get it.It looks like Yahoo has been spending big money, lately. I've seen that stupid thing, as opt-in, or opt-out, on number of installs.
              It's really sad, that some good tools like AVG, or CCleaner, try to force/sneak it in on you.OK, I'm going to dig on this a little more. Check out a response left by someone from AVG in a blog complaining about the toolbar.
              Quote

              the majority of threats are now coming from the WEB, so it seems logical to start incorporating the threat protection into the browser
              As opposed to the threats coming from exactly where?

              People testing the install are also reporting that it in fact does install by default. Period!!! That is with or without the option checked. At this time it is only in the new 8.0 version but rumored to be included with an update in the free version later in the year. They have also pulled their free ROOTKIT scanner now that it is included in the new 8.0 version.

              Source and more information. It seems like just about every program you download from the internet wants to add their toolbar and most of them have some useful features. But when you stack one toolbar over another, pretty soon it TAKES up a lot of real estate on your screen. I wouldn't mind so much if there was a program that would consolidate the toolbars and you could just use the features you want. Anyone know of something like this?In Firefox, you can right click on the header, and you can quickly hide/un-hide toolbars.Quote from: spock on March 05, 2008, 09:01:28 PM
              It seems like just about every program you download from the internet wants to add their toolbar

              Yep, just did a test on the new Java download. The one from Sun Java is fine, but the one from www.java.com includes the Google toolbar. Sheesh, free ain't actually free any mare the toolbars seems to be like a must include pack advertisement. Ask toolbar, google toolbar, yahoo toolbar ... somewhere you have one of those being/going to be installed by default unless you stop it.I've just gotten to where I automatically check for those tool bar add-ins and any others before I download anything. I figure I can't gripe too much since the software is free. I'd rather uncheck a box than pay for the software.
              4243.

              Solve : Could you check this for me please??

              Answer»

              Would like to make it short. My pc got infected earlier and the machine seems to run fine now after some scans and repair processes. However, I still feel that my pc is still running slower than it used to. Could you please help and have a look at the hijackthis log to see if it's really clean? Thanks in advance.

              Logfile of HijackThis v1.99.1
              Scan saved at 21:09:09, on 05/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\system32\bgsvcgen.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\System32\igfxtray.exe
              C:\WINDOWS\System32\hkcmd.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\WINDOWS\AGRSMMSG.exe
              C:\Program Files\Apoint2K\Apoint.exe
              C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
              C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
              C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\BitComet\BitComet.exe
              C:\Program Files\MSN Messenger\MsnMsgr.Exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\WINDOWS\system32\conime.exe
              C:\Program Files\Sony Handheld\HOTSYNC.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Hijackthis\Maggie.exe

              O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
              O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
              O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)


              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
              O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
              O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
              O16 - DPF: {5DA0DDE7-A80D-4B4C-8DDF-74A80DE7B833} (talk2hk Control) - http://www.talk2hk.com/webtalk/talk2hk.cab
              O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184367778324
              O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {DAF94F73-2AA6-44D8-A562-A28831820D34} (Pixum EasyUploadX Control) - http://www.pixum.de/int/EasyUpload/ImgUploader.cab
              O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes/SonyISUpload.cab?v=1,0,0,38
              O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5243/mcfscan.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{67EDCCE0-192E-4A79-921F-3D7D19DDBEEE}: NameServer = 192.168.178.1
              O17 - HKLM\System\CCS\Services\Tcpip\..\{CE093A90-0C8E-4282-A2BE-13AC6A91B4E2}: NameServer = 213.191.74.11 213.191.92.82
              O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
              O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
              O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeSome of the 04 entries are optional. They are unnecessary to be running at startup and removing them with Hijackthis will help with performance.

              First we need to disable Tea Timer so it doesn't block any fixes. You can turn it back on when we are done.

              Disable Spybot's TeaTimer

              While TeaTimer is an excellent tool for the prevention of SPYWARE, it can sometimes prevent our tools from fixing certain things.
              Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your logs are clean.

              First:

              • Right click Spybot in the System Tray (looks like a calendar with a padlock SYMBOL)
              • Choose Exit Spybot S&D Resident
              Second:
              • Open Spybot S&D
              • Click Mode, check Advanced Mode
              • Go To Left Panel, Click Tools, then also in left panel, click Resident
              • If your firewall raises a question, say OK
              • Uncheck the box labeled Resident Tea-Timer and OK any prompts.
              • Use File, Exit to terminate Spybot
              • Reboot your machine for the changes to take effect.
              .
              ----------

              Open Hijackthis and select Do a system scan only.

              Place a check mark next to the following entries: (if there)

              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
              O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)


              Important: Close all windows except for Hijackthis and then click Fix checked.

              Exit Hijackthis.

              ----------

              Download and install CleanUp!.exe

              Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
              Set the program up as follows:
              • Click Options...
              • Move the arrow to Standard CleanUp!
              • Uncheck the following: (if checked)
                • Delete Newsgroup cache
                • Delete Newsgroup Subscriptions
              • Click OK
              Click the CleanUp! button to start the program. Reboot/logoff when prompted.

              Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!
              If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility


              ----------

              Let me know how things are now.thanks and seems it runs better. btw, you think the teatimer is a good enough guard? Thanks.Tea Timer can be a pain as well as a resource hog. I personally refuse to use it.


              This is a good time to clear your infected system RESTORE points and establish a new clean restore point:
              • Go to Start > All Programs > Accessories > System Tools > System Restore
              • Select Create a restore point, and click Next.
              • Next, go to Start > Run and type in cleanmgr
              • Select the More options tab
              • Next to System Restore click Clean up...
              This will remove all restore points except the new one you just created.

              Here are some great tools to help you keep from getting infected again.

              Spybot Search & Destroy - A safe and effective spyware scanner.
              * Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

              AVG Anti-Spyware Free Edition - Very reliable with a high DETECTION rate.
              * AVG Anti-Spyware User Manual

              SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
              * Using SpywareBlaster to protect your computer from Spyware and Malware

              Comodo BOClean - Stops trojans and many more malicious attacks.

              Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
              * Click here for a list of free firewalls.
              * Why would I consider a third party firewall?
              * Understanding and Using Firewalls

              UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
              * Help with Windows updates

              Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

              Let us know if anything else comes up.
              4244.

              Solve : Infected with win32: tratBHO [Tri] and need help?

              Answer»

              Hello, i have been INFECTED with win32: tratBHO [TRI] (it was detected by avast anti virus).
              I cannot get into any administrative tools, like control panel or cmd and i have no idea on computer specs. because this is my friends computer. If SOMEONE could tell me how to fix his pc that would be awesome. Thankyou all Moved to the Computer Virus and Spyware forum.

              Start HERE. Post the LOGS when complete and a malware will be along to help you.ok, thankyou evil.ok, finished scanning here's what came up: (I had to attatch the pic because it wont let me copy it so i just print screened it)

              [recovering space - attachment DELETED by admin]We need the logs from the instructions.

              Quote

              Start HERE. Post the logs when complete and a malware specialist will be along to help you.
              4245.

              Solve : Bootup?

              Answer»

              I have a problem that has existed on my computer for some time[XP Home Edition]
              1.When it boots up there is a long pause between the wallpaper showing and the desktop icons appearing.
              2.I have tried to boot up in safe mode but cannot do so. When I get to the screen setting out the boot up options neither the mouse nor the up and down keys have any effect. I cannot select any option, not even exit. I have to turn-off the computer and re boot.
              I am not very technically minded!
              Help please
              DLoad and install Startup CPL by Mike Lin...
              This will place a Startup icon inside Control Panel that will tell you all applications that are loading on startup...
              Post back with a list and we'll see if we can trim it down.As Patio said its cause by programs running in the taskbar. Even changing a few of these from starting up when your pc starts will cause a small change in the way it starts up.Many thanks



              The results are:
              Start up (user) :
              A Note
              Microsoft Greetings
              OpenOffice

              Startup (Common):

              Adobe Reader Speed
              Bitware Print Monitor
              Corel Family and Friends
              Image Transfer
              Kodak Easy Share
              Microsoft Office
              Privoxy
              WinKey
              WinManager
              WinZip
              ymetray
              In Startup/Common they can all be disabled...

              Same goes for Startup/User.

              This should not affect the programs themselves and your boot time should improve...Thanks - I will try that.I have unchecked all those boxes. Sadly it has made no difference.Try defragmenting the hard drive and scanning for malware.Yeah. Let's see, if your computer is clean...

              Print these instructions out.

              1. Download SUPERAntiSpyware Free for Home Users:
              http://www.superantispyware.com/

              * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
              * An icon will be created on your desktop. Double-click that icon to launch the program.
              * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
              * Close SUPERAntiSpyware.

              Restart computer in Safe Mode.
              To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

              * Open SUPERAntiSpyware.
              * Under "Configuration and Preferences", click the Preferences button.
              * Click the Scanning Control tab.
              * Under Scanner Options make sure the following are CHECKED (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
              * Click the "Close" button to leave the control center screen.
              * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
              * On the left, make sure you check C:\Fixed Drive.
              * On the right, under "Complete Scan", choose Perform Complete Scan.
              * Click "Next" to start the scan. Please be patient while it scans your computer.
              * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
              * Make sure everything has a checkmark next to it and click "Next".
              * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
              * If asked if you want to reboot, click "Yes".
              * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/LOGS tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply.
              * Click Close to exit the program.
              Post SUPERAntiSpyware log.

              RESTART COMPUTER!

              2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

              * Double-click mbam-setup.exe and follow the prompts to install the program.
              * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
              * If an update is found, it will download and install the latest version.
              * Once the program has loaded, select Perform full scan, then click Scan.
              * When the scan is complete, click OK, then Show Results to view the results.
              * Be sure that everything is checked, and click Remove Selected.
              * When completed, a log will open in Notepad.
              * Post the log back here.

              The log can also be found here:
              C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
              Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

              RESTART COMPUTER!

              3. Download HijackThis:
              http://www.snapfiles.com/get/hijackthis.html
              Post HijackThis log.many thanks this for your careful analysis of the problem. I managed to follow your instructions The logs are too long for one post so I'll try to send them separately.

              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 03/29/2008 at 01:50 PM

              Application Version : 4.0.1154

              Core Rules Database Version : 3427
              Trace Rules Database Version: 1419

              Scan type : Complete Scan
              Total Scan Time : 00:24:50

              Memory items scanned : 757
              Memory threats detected : 1
              Registry items scanned : 7329
              Registry threats detected : 20
              File items scanned : 23313
              File threats detected : 4

              Trojan.Net-VBG/NMC
              C:\WINDOWS\VBGTORFD.DLL
              C:\WINDOWS\VBGTORFD.DLL
              HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#vbgtorfd [ {7A923D01-D475-43CF-9E8F-FB7BFA93F8E8} ]
              HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#dwnrpofk [ {CA35414A-D8A2-4216-B4AB-BA055C22694F} ]

              Trojan.Unclassified/GTS
              HKLM\Software\Classes\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\InprocServer32
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\InprocServer32#ThreadingModel
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\ProgID
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\Programmable
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\TypeLib
              HKCR\CLSID\{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}\VersionIndependentProgID
              C:\WINDOWS\QVDNTLMW.DLL
              HKLM\Software\Microsoft\Internet Explorer\Toolbar#{1FB1DDAE-EB2C-42AD-801B-8C7245FE9F48}
              HKCR\qvdntlmw.1
              HKCR\qvdntlmw
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}\1.0
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}\1.0\0
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}\1.0\0\win32
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}\1.0\FLAGS
              HKCR\TypeLib\{599E1E2E-7236-4C6E-A8DD-A2D74EB1ED74}\1.0\HELPDIR

              Adware.Tracking Cookie
              C:\Documents and Settings\Al.YOUR-5511792FEB\Cookies\[emailprotected][2].txt

              Desktop Hijacker.AboutYourPrivacy
              C:\Documents and Settings\Al.YOUR-5511792FEB\Desktop\Privacy Protector.url

              Malawarebytes log:

              Malwarebytes' Anti-Malware 1.09
              Database version: 564

              Scan type: Full Scan (A:\|C:\|D:\|G:\|H:\|I:\|J:\|L:\|)
              Objects scanned: 149324
              Time elapsed: 37 minute(s), 31 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 5
              Registry Values Infected: 1
              Registry Data Items Infected: 0
              Folders Infected: 1
              Files Infected: 6

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_CLASSES_ROOT\qvdntlmw.bpkr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\qvdntlmw.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{51bd4840-e17b-4789-836f-5787cdc64bd1} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Classes\qvdntlmw.bpkr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Classes\qvdntlmw.ToolBar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.



              Registry Values Infected:
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\vbgtorfd (Trojan.FakeAlert) -> Quarantined and deleted successfully.

              Registry Data Items Infected:
              (No malicious items detected)

              Folders Infected:
              C:\Program Files\SudoPlanet (Adware.EGDAccess) -> Quarantined and deleted successfully.

              Files Infected:
              C:\Program Files\SudoPlanet\Privacy Policy.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
              C:\Program Files\SudoPlanet\Terms and conditions.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
              C:\Program Files\SudoPlanet\Website.url (Adware.EGDAccess) -> Quarantined and deleted successfully.
              C:\WINDOWS\norlatmx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\hbobuhcvie_navps.dat (Adware.EGDAccess) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\hbobuhcvie_nav.dat (Adware.EGDAccess) -> Quarantined and deleted successfully.


              Hijackthis Log: [PART1]

              Logfile of HijackThis v1.99.1
              Scan saved at 18:52:23, on 29/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\system32\crypserv.exe
              C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
              C:\Program Files\HistorySweep\HSSvc.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
              C:\WINDOWS\system32\vmnat.exe
              C:\WINDOWS\system32\vmnetdhcp.exe
              C:\Program Files\VMware\VMware Player\vmware-authd.exe
              C:\Program Files\Canon\CAL\CALMAIN.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\TalkTalk\bin\sprtcmd.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\Picasa2\PicasaMediaDetector.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\DOCUME~1\AL914F~1.YOU\LOCALS~1\Temp\40000010c00069dd890027\hs.exe
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\VMware\VMware Player\hqtray.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\MSN Messenger\MsnMsgr.Exe
              C:\Program Files\Eraser\eraser.exe
              C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
              C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Program Files\Vidalia Bundle\Tor\tor.exe
              C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Kontiki\KService.exe
              C:\Program Files\ViaVoice\bin\MSAADMN.EXE
              C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
              C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
              C:\Program Files\Microsoft Works\WkDStore.exe
              C:\PROGRA~1\WINZIP\winzip32.exe
              C:\Documents and Settings\Al.YOUR-5511792FEB\Local Settings\Temp\HijackThis.exe


              PART 2 FOLLOWS IN NEXT POST

              I previously had AVG and Norton on my computer but tried to remove them. I know that bits remain will I be able to clean these off please?
              I keep getting messages from Spybot about attempted registry changes: including Shelf up Services value deleted,, VALUED changes and Regedit EXE change all of which I have told Spybot to deny.

              Thanks again for your patience
              HIJACKTHIS LOG PART2

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mama.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.supanet.com/search/iepanel/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ABEL Internet
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand201013011.dll
              O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
              O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
              O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
              O4 - HKLM\..\Run: [HistorySweep] "C:\PROGRA~1\HISTOR~1\HistorySweep.exe" /autostart
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [ABBYY Community Agent] K:\Program Files\ABBYY FineReader 5.0 Home Edition\CAgent.exe
              O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
              O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
              O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Al"
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
              O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
              O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
              O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
              O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
              O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

              STILL TOO LONG SO PART 3 FOLLOWS!



              b]HIJACKTHIS LOG PART [/b]
              3
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
              O9 - Extra button: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
              O9 - Extra 'Tools' menuitem: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
              O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [INTERNATIONAL] International*
              O14 - IERESET.INF: START_PAGE_URL=http://home.abelgratis.co.uk
              O16 - DPF: FirstViewer - http://barnet.documentretrieval.co.uk/alchemyweb/Components/FirstVwr.CAB
              O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} - https://signup.msn.com/pages/MsnInstC.cab
              O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
              O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
              O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
              O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O21 - SSODL: vbgtorfd - {1DA0BFDD-942B-43FD-902C-2BFD92FA6A85} - C:\WINDOWS\vbgtorfd.dll (file missing)
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
              O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Canon Camera Access LIBRARY 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
              O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
              O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HistorySweepService - Unknown owner - C:\Program Files\HistorySweep\HSSvc.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
              O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
              O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
              O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
              O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
              O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
              O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              1. Download, and run Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039 to remove Norton's leftovers.

              2. Your HJT version is outdated, and you ran it from temporary directory.
              Please, download HJT from my link, and repost the log.Thanks. This has to be posted in at least 2 parts because of the large number of characters.

              PART1
              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:45:36, on 30/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\system32\crypserv.exe
              C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
              C:\Program Files\HistorySweep\HSSvc.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
              C:\WINDOWS\system32\vmnat.exe
              C:\WINDOWS\system32\vmnetdhcp.exe
              C:\Program Files\VMware\VMware Player\vmware-authd.exe
              C:\Program Files\Canon\CAL\CALMAIN.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\TalkTalk\bin\sprtcmd.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Program Files\Picasa2\PicasaMediaDetector.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\DOCUME~1\AL914F~1.YOU\LOCALS~1\Temp\40000010c00069dd890027\hs.exe
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\VMware\VMware Player\hqtray.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\MSN Messenger\MsnMsgr.Exe
              C:\Program Files\Eraser\eraser.exe
              C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
              C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Program Files\Vidalia Bundle\Tor\tor.exe
              C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Kontiki\KService.exe
              C:\Program Files\ViaVoice\bin\MSAADMN.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\AntiVir PersonalEdition Classic\avscan.exe
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mama.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.supanet.com/search/iepanel/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Abel Internet
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
              O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand201013011.dll
              O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
              O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
              O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
              O4 - HKLM\..\Run: [HistorySweep] "C:\PROGRA~1\HISTOR~1\HistorySweep.exe" /autostart
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [ABBYY Community Agent] K:\Program Files\ABBYY FineReader 5.0 Home Edition\CAgent.exe
              O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
              O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
              Hijackthis Log Part2


              O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
              O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Al"
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
              O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
              O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
              O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
              O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
              O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
              O4 - HKUS\S-1-5-21-312397509-71834488-3752936468-1009\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" (User '?')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
              O9 - Extra button: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
              O9 - Extra 'Tools' menuitem: Xstream Radio - {7A0815F1-6B65-4e3a-B198-709807B4042A} - C:\Program Files\XstreamRadio 3.02\RadioHelper.dll
              O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=http://home.abelgratis.co.uk
              O16 - DPF: FirstViewer - http://barnet.documentretrieval.co.uk/alchemyweb/Components/FirstVwr.CAB
              O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} - https://signup.msn.com/pages/MsnInstC.cab
              O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
              O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
              O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/SymAData.cab
              O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
              O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
              O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
              O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
              O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HistorySweepService - Unknown owner - C:\Program Files\HistorySweep\HSSvc.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
              O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
              O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
              O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
              O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
              O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
              O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              O24 - Desktop Component 0: (no name) - http://images.thetimes.co.uk/images/TIMESHeadBGLogo_1.gif
              O24 - Desktop Component 1: (no name) - http://nudes2.hegre-art.com/hegre-naomi-20051207/1000/016.jpg

              --
              End of file - 16336 bytes

              I hope that this is what you need

              4246.

              Solve : Why do I need to scan in Safemode??

              Answer»

              This make me confuse guys.

              Lots of topics I read and they always advice to BOOT into safemode then scan and DELETE the virus.

              Now my question is:
              Why do I need to scan and delete viruses in Safemode if can scan and delete viruses in Normal mode?
              When the machine is in Safe Mode, most viruses cannot run, and Anti-virus scans are often more effective. If you've tried to remove a virus in Windows, and have been told by your Anti-virus program that "access is denied," a scan in Safe Mode is a good idea.

              Access MAY be denied due to a file being in use by your OS, in Safe Mode that file may not be in use..

              So not all viruses can't run in safemode, some viruses still run even in safemode?Yeah some viruses will run even in safe mode.Safe mode has a minimal amount of drivers/programs/services running so it makes removal much easier. Many virus/trojans/worms will run as a service or background program. Removing them when they are not running gives a much greater chance of removal with no errors.

              Safe mode with no windows open is the preferred METHOD of removal.Thanks guys for your answers. Your answers are helpful!

              4247.

              Solve : System File or Virus?

              Answer»

              Friends there are some folders and files in my c: drive i am unable to find out whether they are system files or any virus.
              How can i recognise them ?What are they called and where are they located?

              You can use GOOGLE to find out what files are. Just type the exact file name (like explorer.exe) in google and search.Suspicious file scanners.

              Thanks for the list. i will have to STAY AWAY from them.Quote from: fred333 on April 10, 2008, 09:11:33 AM
              Thanks for the list. i will have to stay away from them.

              Those are for SCANNING files on a PC to determine if it is malware or not. It is a safe list to use.
              4248.

              Solve : Certan webpages crashing browsers?

              Answer»

              Hi! I am having a strange problem. Certain webpages are causing my browser to crash. The two that are a big problem are my AIM mail which crashes as soon as I log in, and Horsecity.com to which I am a member of the BB.

              I use XP Pro, normally use Slimbrowser, but it also does it with IE.

              I tried to reinstall Firefox (used before, but I prefer Slimbrowser) to see if it also does it and it says the proxy server is refusing connection. I have no idea how to make that work. I have a wireless ROUTER. Would that have something to do with it?

              Now I have some basic PC smarts but nothing in depth. I have no idea what is going on here or how to fix it. If I still had my XP Pro disk I swear I would wipe my drive and just start over, only it was stolen so now I am stuck grrrrrr......

              This happened to some nature once before and it was some sort of malware but this is not the same. Super Anti SPYWARE check shows nothing but the cookie trackers so far.

              Oh and I ran a search on google and someone said to install java again to fix this issue which I tried and it did not help.

              Any suggestions on what to do to make this stop?Here is a Hijack this report. I had to do it last time when I was having issue so I ran it again..Maybe it shows something helpful? Let me know if I can run any other reports...


              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 1:48:44 PM, on 2/26/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16574)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\System32\CTsvcCDA.exe
              C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\MsPMSPSv.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\Program Files\SlimBrowser\sbrowser.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://horsecity.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no NAME) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: (no name) - {99509409-1B72-4767-B5BD-1E2601601601} - (no file)
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) - https://install.charter.com/diskless/bin/ssctlsma.dll
              O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
              O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
              O16 - DPF: {26522409-8BBF-4C5B-A4D3-CF4B1D6F255B} (UMediaPlayer Class) - http://www.umediaserver.net/bin/UMediaControl5.cab
              O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
              O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
              O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN PHOTO Upload Tool) - http://by128fd.bay128.hotmail.msn.com/resources/MsnPUpld.cab
              O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://cc.iwon.com/ct/pm3/iwonpm_12_1,0,2,5.cab
              O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://everquest2.station.sony.com/systemscan/soesysinfo.cab
              O16 - DPF: {CA11EB7C-1C85-4577-8A49-9E28EFB30184} (UMediaPlayer Class) - http://www.umediaserver.net/bin/UMediaControl4.cab
              O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://pcpitstop.com/antivirus/PitPav.cab
              O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
              O22 - SharedTaskScheduler: za - {99509409-1B72-4767-B5BD-1E2601601601} - (no file)
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
              O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe

              --
              End of file - 5476 bytes

              Quote

              it says the proxy server is refusing connection
              In Firefox, go Tools>Options>Advanced>Network tab>Settings tab....what's checked there?*** There is no antivirus installed.
              Download, and install AVG free antivirus: http://free.grisoft.com/
              Run full scan.

              *** Is Windows firewall ON?

              *** Download SUPERAntiSpyware Free for Home Users:
              http://www.superantispyware.com/

              * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
              * An icon will be created on your desktop. Double-click that icon to launch the program.
              * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
              * Close SUPERAntiSpyware.

              Restart computer in Safe Mode.
              To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

              * Open SUPERAntiSpyware.
              * Under "Configuration and Preferences", click the Preferences button.
              * Click the Scanning Control tab.
              * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
              * Click the "Close" button to leave the control center screen.
              * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
              * On the left, make sure you check C:\Fixed Drive.
              * On the right, under "Complete Scan", choose Perform Complete Scan.
              * Click "Next" to start the scan. Please be patient while it scans your computer.
              * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
              * Make sure everything has a checkmark next to it and click "Next".
              * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
              * If asked if you want to reboot, click "Yes".
              * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
              * Click Close to exit the program.
              Post SUPERAntiSpyware log.

              *** Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

              * Double-click mbam-setup.exe and follow the prompts to install the program.
              * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
              * If an update is found, it will download and install the latest version.
              * Once the program has loaded, select Perform full scan, then click Scan.
              * When the scan is complete, click OK, then Show Results to view the results.
              * Be sure that everything is checked, and click Remove Selected.
              * When completed, a log will open in Notepad.
              * Post the log back here.

              Be sure to restart the computer.

              The log can also be found here:
              C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
              Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

              *** Post new HijackThis log.Hi!

              Well, I tried to DL the antivirus and I crash when I get to the final download page. Yeah I know its not good but antivirus programs annoy me so I usually use PC pitstop every once in awhile but it seems they are having some issues...IDK...

              Modified to say I sneaked around the CRASHING and am now DLing AVG...

              Firewall is ON

              I will try the rest now and post back.Hello,
              I seem to have this problem with IE 5.0. I'm using Windows 98se. When I try to visit Web MD, IE closes and some of my icons next to my clock are gone, as well as my wallpaper. I tried to reinstall IE, to no avail. Since then, I have avoided visiting Web MD. Any ideas on how to resolve this issue?
              Thank you
              P.S. This has happened every time I visited that website for the past few months, so I don't think it was them.Haseo
              You need to start your own topic.Quote from: Broni on March 03, 2008, 06:49:17 PM
              Haseo
              You need to start your own topic.

              I'm sorry, my mistake.
              Trinity3205, please forgive mr for jumping in like that. m(_ _)m
              4249.

              Solve : ??Fake Spyware?

              Answer»

              sweeteyes
              You need to start your own topic.Broni, All seem FINE. Thank you. JIM You're most welcome That seems like a nasty one. I have USED TRENDMICRO in the past and have some good success with them. I just hae how sometimes they can not GET rid certain viruses.

              4250.

              Solve : Have I a Virus??

              Answer» CHEERS EF,

              I'll look AROUND the forums on here.

              Regards,

              DAVE