This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] A little bit of everything

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

One thing that doesn't work on here is Java, but most other sites load fine. The PC is also very slow. Can you take a look at this log file and see if there is anything that can be improved?

Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:45:47 PM, on 4/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/The%20Hidden%20Prophecies%20of%20Nostradamus/Images/stg_drm.ocx
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} (SDANetConClass Class) - file:///C:/Program%20Files/Pantheon/Images/stg_drm.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226634633187
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B12213CD-4189-415D-A054-7999528459F7} (pixelStormLauncher Class) - http://aolsvc.aol.com/onlinegames/tryrumbl…ormlauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://playgames.comcast.net/online2/mahjo…ameLauncher.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 11373 bytes
Hi mohawk, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Please make an uninstall list
  • Start HijackThis
  • Click the Config button
  • Click the Misc Tools button
  • Click the Open Uninstall Manager button.
  • Click the Save list button and save it to your desktop.
When you press Save, a notepad will open with the contents. Copy/paste the contents of the notepad file in your next reply along with a new HJT log.


There is some Norton (Symantec) showing in your log. Is this a product you no longer use?

Please post back with
  • uninstall list
  • new HJT log
Thanks
Yes. I previously used Norton on the PC but I do not at this time.



Pictureka Museum Mayhem (remove only)
10 Days Under the Sea
10 Days Under The Sea
303 Game Collection
4 Elements
4 Elements
5 Realms of Cards
7 Artifacts
7 Wonders 2
7 Wonders Treasures Of Seven
7 Wonders Treasures of Seven (remove only)
A-B-O-O (remove only)
Abra Academy
Acrobat.com
Acrobat.com
Action Ball 2 (remove only)
Ad-Aware SE Personal
Adobe Acrobat 6.0 Standard
Adobe AIR
Adobe AIR
Adobe Reader 9.1
Agatha Christie: Peril at End House (remove only)
Age of Japan
Agere Systems PCI Soft Modem
Alabama Smith Escape from Pompeii (remove only)
Alex Gordon
Alices Magical Mahjong
Amazing Adventures Around The World
Amazing Adventures Around The World
Amazing Adventures Around the World (remove only)
Amazing Finds (remove only)
Amulet of Tricolor
Ancient Quest of Saqqarah
Ancient Wonderland
Animal Agents
Anne's Dream World
Apple Pie (remove only)
Archipelago (remove only)
Arctic Quest 2
Are You Smarter Than A 5th Grader Make The Grade (remove only)
Around the World in 80 Days
Around the World in 80 Days
Art Detective
AVG Free 8.0
Azada
Azada: Ancient Magic
Azkend
Balloon Bliss
Bejeweled Twist
Between The Worlds
Between the Worlds (remove only)
Big City Adventure: Sydney, Australia (remove only)
Big Fish Games Client
Bird Pirates
Block Breaker Deluxe
Blood Ties
Bloom (remove only)
Book of Legends
Bottle Busters
Brain Challenge
Brain Challenge (remove only)
Brainiversity
Brick Quest 2
Bubble Town
Buku Dominoes
Cake Mania 3
Call of Atlantis
Call of Atlantis (remove only)
Camelias Locket A Tale of Dead Jim Cane
Camelias Locket The Tale of Dead Jim Cane (remove only)
Can You See What I See?
Can You See What I See? Dream Machine
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon PIXMA iP4000
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities Easy-PhotoPrint
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Caribbean Hideaway
Caribbean Riddle
Cate West - The Vanishing Files
Cate West The Vanishing Files
CCleaner (remove only)
CCScore
Chameleon Gems (remove only)
Charm Tale 2 Mermaid Lagoon
Chicken Invaders 3 XMAS
Christmasville (remove only)
Chroma Crash
Chromentum 2
ColorUp Wedding Scrapbook (remove only)
Comcast Toolbar
Cradle of Persia
Crazy Machines
Cribbage Quest
Critical Update for Windows Media Player 11 (KB959772)
Cryptex of Time (remove only)
Curse of the Pharaoh: The Quest for Nefertiti
Dangerous Mines Deluxe
DeductionPro 2004-05
DeductionPro 2005-06
DeductionPro 2006
DeductionPro 2007
DeductionPro 2008
Deep Blue Sea
Deep Blue Sea (remove only)
Destiny Architect
Detective Stories Hollywood
Diamond Drop 2
Diamond Drop 2
Discovering Nature
Discovery A Seek & Find Adventure (remove only)
Dr Lynch Grave Secrets
Dragons Abode
Dragons Abode
Dragonstone
Dream Chronicles
Dream Chronicles 2 - The Eternal Maze
Dream Chronicles ™ 2: The Eternal Maze
Dream Day First Home
Dream Day First Home
Dream Day Wedding 2
Dream Day Wedding Married in Manhattan
Dream Day Wedding Married in Manhattan (remove only)
Dream Day Wedding: Married in Manhattan
Easy CD & DVD Creator 6
Easy Internet Sign-up
Easy-WebPrint
eGames Toolbar
Egyptian Ball
Elements
Elias the Mighty
Elizabeth Find MD: Diagnosis Mystery
Emoticons
Empire of the Gods
Enchanted Cavern
Enchanted Cavern (remove only)
Enchanted Fairy Friends Secret of the Fairy Queen (remove only)
Enchanted Fairy Friends: Secret of the Fairy Queen
Enigma
Enigma (remove only)
Enigma 7 (remove only)
EPSON Printer Software
Escape the Museum
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
Eye for Design
Fabulous Finds
Fairway Solitaire
Fairy Island
Fashion Solitaire
Fenomen Games Downloader (remove only)
Finders Keepers (remove only)
Fishdom
Flowers Story - Fairy Quest
Flowery Vale (remove only)
FLV Player Ver 1.00
Forgotten Riddles The Moonlight Sonatas
Forgotten Riddles The Moonlight Sonatas
Fruit Lockers 2 - The Enchanting Islands
GamesBar [removed]
Gemsweeper
Gemsweeper
Gemsweeper (remove only)
GHOST Hunters
Glyph 2
Glyph 2
Go Go Gourmet
Goddesses of Solitaire
Gold Rush Treasure Hunt
Google Desktop
Google Toolbar for Internet Explorer
Governor of Poker
GradeQuick
GradeQuick Web Plugin
Great Secrets Da Vinci
Greetings Workshop
Hawaiian Explorer - Lost Island
Hawaiian Explorer 2
Hawaiian Explorer 2 (remove only)
Hawaiian Explorer 2: Lost Island
Hawaiian Explorer Pearl Harbor
Hawaiian Explorer The Lost Island
Heart of Egypt
Herod's Lost Tomb
Hidden Expedition Amazon
Hidden Expedition Everest
Hidden Jewel Adventure
Hidden Mysteries - Civil War
Hidden Wonders Of The Depths
Hidden Wonders of the Depths (remove only)
Hidden Wonders of the Depths version 1.0
Hidden World of Art
Hide And Secret 2
HijackThis 2.0.2
Holly - A Christmas Tale
Holly A Christmas Tale (remove only)
Holly: A Christmas Tale (remove only)
Home Sweet Home 2 Kitchens And Baths
Hotel Mahjong Deluxe
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
House of Wonders Babies Come Home
House of Wonders Babies Come Home (remove only)
House of Wonders Kitty Kat Wedding (remove only)
Hoyle Enchanted Puzzles
Hoyle Enchanted Puzzles (remove only)
HP Deskjet Preloaded Printer Drivers
HP Image Zone 3.5
HP Image Zone Plus 3.5
HP Instant Support
HP Photo & Imaging 3.5 - HP Devices
HP PSC & OfficeJet 3.5
HP Software Update
HPIZ350
Ice Princess
In Living Colors
In Living Colors!
IntelliMover Data Transfer Demo
Interpol 2 Most Wanted
Interpol The Trail of Dr Chaos
InterVideo WinDVD Creator 2
InterVideo WinDVD Player
IQ Identity Quest
IQ Identity Quest
iTunes
iWin Games (remove only)
Jabber
Java™ 6 Update 11
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Jewel Craft
Jewel Match 2
Jewel Match 2
Jewel Match 2 (remove only)
Jewel Quest 2
Jewel Quest 3
Jewel Quest 3
Jewel Quest III
Jewel Quest III (remove only)
Jewel Quest Mysteries
Jewel Quest Mysteries - Curse of the Emerald Tear
Jewel Quest Solitaire (remove only)
Jewel Quest Solitaire 2
Jewelix
JeweliX (remove only)
Jigsaw Deluxe (remove only)
Jigsaw World
Jigsaw World (remove only)
Jump Jump Jelly Reactor (remove only)
Jungle Quest
Jungle Quest
KBD
kgcbase
Kodak EasyShare software
Land of Runes
Laura Jones and the Gates of Good and Evil
Laura Jones and the Gates of Good and Evil
Letter Lab
Lex Venture: A Crossword Caper
Liong: The Dragon Dance (remove only)
Liong: The Lost Amulets
Little Shop - City Lights
Little Shop - Road Trip
Little Shop Road Trip
Lost in Reefs
Lost in Reefs (remove only)
Lost Treasures of Alexandria (remove only)
Lost Worlds
Luck Charm Deluxe
Lucky Clover
Lucky Clover
Luckys Rainbow
Luxor Quest for the Afterlife
Macromedia Shockwave Player
Magic Aces
Magic Encyclopedia First Story
Magic Encyclopedia. First Story
Magic Match Adventures
Magic Shop
Mah Jong Quest 3
Mah Jong Quest III: Balance of Life
Mahjong Adventures
Mahjong Escape - Ancient Japan
Mahjong Mysteries of the Past (remove only)
Mahjong Quest 2
Mahjong Song of Season
Mahjong Tales
Mahjongg Investigations
Mark & Mandi's Love Story (remove only)
Masters of Mystery - Crime of Fashion
Matchblox 2 Abrams Quest
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Visio Professional 2003
Microsoft Plus! Digital Media Edition
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Miriel The Magical Merchant
Miss Teri Tale 2 Vote 4 me
Mortimer Beckett And The Secrets Of Spooky Manor
Mortimer Beckett and the Time Paradox
Mortimer Beckett Regular
MostFun Game Player
Mozilla Firefox (2.0.0.7)
Mr Biscuits - The Case of the Ocean Pearl
Mr Biscuits The Case of the Ocean Pearl (remove only)
MSN
MSN Toolbar
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musaic Box
Mysteries of Horus
Mysterious City Golden Prague
Mystery Case Files - Madame Fate
Mystery Case Files Madame Fate
Mystery Case Files Madame Fate (remove only)
Mystery Case Files: Return to Ravenhearst ™
Mystery Chronicles Murder Among Friends
Mystery Chronicles: Murder Among Friends
Mystery Cookbook
Mystery Cookbook
Mystery Cookbook
Mystery In London
Mystery Museum
Mystery of Unicorn Castle
Mystery P.I. - The New York Fortune
Mystery PI
Mystery PI - The New York Fortune
Mystery PI The Lottery Ticket
Mystery PI The Vegas Heist
Mystery Solitaire
Mystery Stories Berlin Nights
Mystery Stories Island Of Hope
Mystery Stories Island of Hope (remove only)
Mystery Stories: Island of Hope
Mysteryville
Mythic Mahjong
Nancy Drew The White Wolf of Icicle Creek (remove only)
Natalie Brooks
Natalie Brooks - The Treasures of the Lost Kingdom
Natalie Brooks Secrets of Treasure House (remove only)
Natalie Brooks: Secrets of Treasure House
National Geographic Games Herods Lost Tomb
National Geographic's Herod's Lost Tomb (remove only)
Neopets Codestone Quest
netbrdg
Neverland
Neverland (remove only)
Nocturnal: Boston Nightfall ™
OfotoXMI
OpenAL
OpenOffice.org Installer 1.0
Paranormal Agency
Pastry Passion
PC-Doctor for Windows
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
Pearl Diversion (remove only)
Peggle Deluxe
Pendulum Quest (remove only)
Photo Mania (remove only)
Photosmart 140,240,7200,7600,7700,7900 Series
PictoWords
Pipe World
Pirate Poker
Pirate Stories Kit And Ellis
Pirate Stories Kit Ellis
Polly Pride Pet Detective
Post Mortem The White Case (remove only)
Private Eye
PS2
Puzzle Hero
Puzzle Hero
Puzzle Park (remove only)
Puzzle Quest
Puzzleville (remove only)
PyraCubes
Python 2.2 combined Win32 extensions
Python 2.2.1
Qbeez 2
Quicken 2004
QuickTime
Rainbow Web 2
Rainbow Web 2
Rainbow Web 2
Rainbow Web II
RealArcade
RealPlayer
Remedy (remove only)
Restaurant Rush
Restoring Rhonda
Rhapsody Player Engine
Righteous Kill
Righteous Kill
Righteous Kill
Ringies (remove only)
Rise of Atlantis
Rock Garden
Roogoo
Rooms: The Main Building
Ruckus Bucks Dangerous Mines
Rune of Fate (remove only)
Runes Of Avalon 2
Runes of Avalon 2 (remove only)
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
Safecracker (remove only)
Samantha Swift and the Hidden Roses of Athen
Santa's Super Friends
Santa's Super Friends (remove only)
Saqqarah
Scepter of Ra
Scrapbook Paige
Scrapbook Paige (remove only)
Season Match
Season Match (remove only)
Season Match 2
Secret Missions: Mata Hari and the Kaiser's Submarines ™
Secrets Of Great Art
Secrets of Olympus
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
SFR
SHASTA
Sherlock Holmes Mystery of Persian Carpet
Sherlock Holmes The Mystery of the Persian Carpet (remove only)
Sherlock Holmes: The Mystery of the Persian Carpet
skin0001
SKINXSDK
Slingo Quest Hawaii
Slingo Quest Hawaii
Slingo Supreme
Smartparts Desktop
Snow Queen Mahjong
Snow Queen Mahjongg (remove only)
Solitaire Cruise
Solitaire for Dummies
SolSuite 2007 v7.5
Spandex Force
Spandex Force
Spirit of Wandering The Legend (remove only)
Spooky Spirits
Sprill - The Mystery of The Bermuda Triangle
Sprill The Mystery of The Bermuda Triangle
Sprill: The Mystery of the Bermuda Triangle
Spybot - Search & Destroy 1.2
Squirgle
Starcrossed
staticcr
Steam
Steve The Sheriff ™
StoneLoops
StoneLoops
Sunset Studio
Sunset Studio Deluxe
Super Collapse Puzzle Gallery 2
Suspects and Clues
Svetlograd
System Mania
TaxCut 2004
TaxCut Deluxe 2005
TaxCut Pennsylvania 2007
TaxCut Pennsylvania 2008
TaxCut Premium + State + Efile 2007
TaxCut Premium + State + Efile 2008
TaxCut Premium 2006
The Age of Atlantis (remove only)
The Amazing Brain Train
The Clumsys
The Clumsys (remove only)
The Count of Monte Cristo
The Count of Monte Cristo
The Count of Monte Cristo (remove only)
The Exchange Student - Episode 1
The Great Indian Quest (remove only)
The Great Tree
The Hedgehogs (remove only)
The Hidden Object Show
The Hidden Object Show
The Hidden Object Show (remove only)
The Hidden Object Show 2 (remove only)
The Hidden Object Show Season 2
The Hidden Prophecies of Nostradamus
The History Channel Lost Worlds
The Lost Cases of Sherlock Holmes
The Lost Treasures Of Alexandria
The Mushroom Age
The Mysterious City Golden Prague (remove only)
The Mystery of the Crystal Portal
The Nightshift Code
The Nightshift Code (remove only)
The Pharaohs Mystery (remove only)
The Pini Society
The Pini Society
The Princess Bride
The Race
The Race (remove only)
The Scruffs
The Secret of Margrave Manor
The Secret of Margrave Manor (remove only)
The Sultan's Labyrinth
The Three Stooges Treasure Hunt Hijinks
The Three Stooges Treasure Hunt Hijinks (remove only)
The Treasures Of Mystery Island
The Tuttles Madcap Misadventures (remove only)
The Unicorn Castle (remove only)
Tibet Quest
Time Quest (remove only)
Time Stand Still Strategy Guide
TiQal
TiQal
TiQal (remove only)
Toolkit View(HP)
tooltips
Totem Quest
Totem Tribe
Towers
Travelogue 360 Rome
Treasure Masters, Inc.
Treasures of Ancient Cavern
Treasures of Mystery Island
Treasures of the Ancient Cavern (remove only)
Tri-Peaks 2 Quest for the Ruby Ring (remove only)
Tropicabana
Tropico Jong
Tropico Jong Butterfly Expedition (remove only)
Tropix 2 Quest For The Golden Banana
Turtix 2: Rescue Adventures
Unicorn Castle
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Updates from HP
Val Gor
Venice Mystery
VIA Rhine-Family Fast Ethernet Adapter
VIA/S3G Display Driver
Virtual Villagers: The Secret City
VPRINTOL
Wild West Quest
Wild West Quest
Wild West Quest
Winamp (Remove Only)
Windows Defender
Windows Defender Signatures
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Resource Kit Tools - SubInAcl.exe
Windows XP Service Pack 3
Winferno Registry Power Cleaner
WinZip
WIRELESS
Wizard's Pen
Womens Murder Club
World Mosaics
Yahoo! Toolbar
Yard Sale Hidden Treasures: Sunnyville
Yard Sale Junkie
Yumsters
Zeal
Zen Fashion (remove only)
Zenerchi
ZoomBook



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:00:49 PM, on 4/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/The%20Hidden%20Prophecies%20of%20Nostradamus/Images/stg_drm.ocx
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} (SDANetConClass Class) - file:///C:/Program%20Files/Pantheon/Images/stg_drm.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226634633187
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B12213CD-4189-415D-A054-7999528459F7} (pixelStormLauncher Class) - http://aolsvc.aol.com/onlinegames/tryrumbl…ormlauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://playgames.comcast.net/online2/mahjo…ameLauncher.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 11460 bytes
Hi mohawk,

Let's see if we can get rid of some spyware/adware, Norton leftovers and get your java working.


Download the Norton Removal Tool from HERE and save it to your desktop.

Next Double click on Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.



Next
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java SE Runtime Environment (JRE)
    JRE 6 Update 13 (it's the first one in the list)
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u13-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.



You may want to copy and paste the next instructions into a notepad and save to your desktop for reference as your browser should be closed for the uninstalls.



Please go to Add/remove programs and uninstall these programs if present

GamesBar 2.0.1.12
Java™ 6 Update 11
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


After all old versions have been uninstalled, please double click jre-6u13-windows-i586-p.exe to install the new Java.



Next
Open hijackthis, do a system scan only and checkmark these lines, if present

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Next

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\GamesBar
    C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
    C:\Program Files\Common Files\Symantec Shared
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please post back with
  • OTMOVEIT3
  • OTMOVEIT3 log
  • new HJT log
How's the computer?

Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:01 PM, on 4/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: eGames Toolbar - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\PROGRA~1\EGAMES~1\EGAMES~1.DLL
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/The%20Hidden%20Prophecies%20of%20Nostradamus/Images/stg_drm.ocx
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {255B1372-180C-4A22-A02D-1D4AB65F6AC2} (SDANetConClass Class) - file:///C:/Program%20Files/Pantheon/Images/stg_drm.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226634633187
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {B12213CD-4189-415D-A054-7999528459F7} (pixelStormLauncher Class) - http://aolsvc.aol.com/onlinegames/tryrumbl…ormlauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://playgames.comcast.net/online2/mahjo…ameLauncher.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\PROGRA~1\IWINGA~1\iWinTrusted.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 10458 bytes



I tried to send everything but got an error message that , "it was too long to post". I will try to send the rest shortly.
Thanks for your help!
Hi Mohawk,

I'm not sure what the long series of numbers are, but I do see an error in my log requests. It should have been
  • OTMOVEIT3 log
  • new HJT log

Please post the OTMOVEIT3 log, it can be found at C:\_OTMoveIt\MovedFiles

It will be a series of numbers followed by .log


Thanks
Hi, I had trouble trying to find the information for you. Your directions have been very helpful. I need to follow them better. I hope I will be able to do it right this time. Thanks for all of your help! Mohawk Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Program Files\GamesBar moved successfully. C:\PROGRA~1\IWINGA~1\iWinGamesHookIE.dll unregistered successfully. C:\PROGRA~1\IWINGA~1\iWinGamesHookIE.dll moved successfully. C:\Program Files\Common Files\Symantec Shared\CCPD-LC moved successfully. C:\Program Files\Common Files\Symantec Shared moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF1FF5.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF34E7.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF34F2.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\ZEMDJ40U\01[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\ZEMDJ40U\data[6].xml scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\XJ5T7NAI\de[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\V3YRU639\iframe[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\OY6YAMGT\little_bit_everything_t101914[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\default[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\im[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\InboxLight[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\ToastFull[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\ToastMini[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_d80.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_085642 Files moved on Reboot… C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF1FF5.tmp moved successfully. File C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF34E7.tmp not found! File C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF34F2.tmp not found! C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\ZEMDJ40U\01[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\ZEMDJ40U\data[6].xml moved successfully. File C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\XJ5T7NAI\de[1].htm not found! File C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\V3YRU639\iframe[2].htm not found! File C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\OY6YAMGT\little_bit_everything_t101914[1].htm not found! C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\default[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\im[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\InboxLight[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\ToastFull[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\DGDC0NCF\ToastMini[1].htm moved successfully. File move failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_d80.dat not found! ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\Program Files\GamesBar not found. File/Folder C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL not found. File/Folder C:\Program Files\Common Files\Symantec Shared not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF7964.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF7971.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\blank[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\de[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\ToastFull[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\ToastMini[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\01[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\iframe[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\InboxLight[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\little_bit_everything_t101914[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\msn_com[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\R0WF5HZQ\data[4].xml scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\R0WF5HZQ\Sync[2].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\default[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\iframe[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\im[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\Include[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_750.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\TMP000000447A361652BAC74F17 scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_225858 Files moved on Reboot… File C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF7964.tmp not found! File C:\DOCUME~1\Jay\LOCALS~1\Temp\~DF7971.tmp not found! C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\blank[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\de[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\ToastFull[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\X5UMPJQ1\ToastMini[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\01[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\iframe[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\InboxLight[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\little_bit_everything_t101914[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\T4QI6ENK\msn_com[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\R0WF5HZQ\data[4].xml moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\R0WF5HZQ\Sync[2].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\default[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\iframe[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\im[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\Content.IE5\7HZ02YRA\Include[1].htm moved successfully. C:\Documents and Settings\Jay\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully. File C:\WINDOWS\temp\Perflib_Perfdata_750.dat not found! File C:\WINDOWS\temp\TMP000000447A361652BAC74F17 not found! OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_231301 OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_231427
Hi Mohawk,

You're doing fine. sorry for the confusion.

How is your computer at the moment?

Test your java by clicking HERE

On that page please click
Test the version of Java your browser is using

A new page will open, scroll down to Method 1: Ask Java], give it few seconds and a pink box should appear with your java version in it. Please tell me what is displayed even if it blank or the pink box isn't shown.

📎java.PNG


Thanks
The Java Version is: 1.6.0_13 from Sun Microsystems Inc. The computer is still slow at times. I also had trouble downloading Adobe Flash Player. There are a lot of games on the computer that I really do not need if they are part of the problem. Thanks again for your help!
Hi Mohawk,

Thanks for the info. The games shouldn't be a problem as they are not running. They are just taking up hard drive space.

Click your start button, click on My Computer
-right click on Local drive C:
-click properties

Tell me what it says for Used Space and Free Space


We haven't looked very deep into this system yet, so lets start.

Next, Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.



Next, Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • Rooter log
  • MBAM log
  • new HJT log
Let us know if the same symptoms are present or any new ones.

Thanks
Hi Oldman960, My Used Space is: 76.1 GB and my Free Space is: 68.0 GB. Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 C:\ [Fixed] - NTFS - (Total:147707 Mo/Free:130 Mo) D:\ [Fixed] - FAT32 - (Total:4899 Mo/Free:732 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) G:\ [Removable] (Total:0 Mo/Free:0 Mo) H:\ [Removable] (Total:0 Mo/Free:0 Mo) I:\ [Removable] (Total:0 Mo/Free:0 Mo) J:\ [Removable] (Total:0 Mo/Free:0 Mo) Mon 04/20/2009|16:46 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\Program Files\Windows Defender\MsMpEng.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\windows\system\hpsysdrv.exe ———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe ———- C:\WINDOWS\System32\hphmon05.exe ———- C:\HP\KBD\KBD.EXE ———- C:\WINDOWS\system32\VTTimer.exe ———- C:\WINDOWS\AGRSMMSG.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\QuickTime\qttask.exe ———- C:\Program Files\Windows Defender\MSASCui.exe ———- C:\PROGRA~1\AVG\AVG8\avgtray.exe ———- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe ———- C:\WINDOWS\System32\gearsec.exe ———- C:\Program Files\iWin Games\iWinGamesInstaller.exe ———- C:\Program Files\Java\jre6\bin\jusched.exe ———- C:\PROGRA~1\IWINGA~1\iWinTrusted.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe ———- C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\PROGRA~1\AVG\AVG8\avgrsx.exe ———- C:\Program Files\Canon\CAL\CALMAIN.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Internet Explorer\iexplore.exe ———- C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Mon 04/20/2009|16:47 ———————-\\ Scan completed at 16:47 I will work on the other information you requested shortly. Thanks, Mohawk
Hi Oldman960, I clicked on Malwarebytes anti-Malware and a screen for Major Geeks.com appeared. It recommended a Download of Registry Booster. Am I at the right location? I couldn't find mbam-setup.exe or any of the other information you listed. Is there a charge for the software? Mohawk
Hi Oldman960, My son helped me get things worked out with Malwarebytes. Thanks again! Malwarebytes' Anti-Malware 1.36 Database version: 2017 Windows 5.1.2600 Service Pack 3 4/21/2009 12:02:59 AM mbam-log-2009-04-21 (00-02-59).txt Scan type: Quick Scan Objects scanned: 152925 Time elapsed: 32 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5b4c3b43-49b6-42a7-a602-f7acdca0d409} (Adware.OneStepSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ONESTEP_SEARCH_SERVICE (Adware.OneStepSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\seekmo programs (Adware.Seekmo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\bfgtoolbar (Adware.OneToolBar) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Mohawk,

Glad you got it worked out. MBAM is free, though you can buy the version that has real time scanning.

MBAM cleaned out some left overs. Have you tried to install FlashPlayer again?


You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.




Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI