This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Suddenly the way you log on to XP changed itself

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, the xp logon screen suddenly went from the good looking one to the one where you have to enter username.
This has happened for a year or so, that time it was a virus, and I think it is now.
I can neither change it by going in the controll panel, I clik on it, the procces starts but no window comes up.

Here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 23:04:44, on 01.08.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
M:\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
M:\Executive Software\DiskeeperLite\DKService.exe
C:\WINDOWS\Explorer.EXE
C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
M:\ewido anti-spyware 4.0\guard.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
M:\OO Software\CleverCache\OOCCSVC.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Analog Devices\Core\smax4pnp.exe
C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
M:\DAEMON Tools\daemon.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
M:\ewido anti-spyware 4.0\ewido.exe
M:\Nero 7\InCD\InCD.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe
M:\iTunes\iTunesHelper.exe
C:\Programfiler\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
M:\Browser Sentinel\BrowserSentinel.exe
C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe
C:\Programfiler\iPod\bin\iPodService.exe
C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
M:\SpywareGuard\sgmain.exe
M:\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\mshta.exe
M:\Opera\Opera.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\WINDOWS\Explorer.EXE
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.no/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Mikael
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - M:\COPERN~1\COPERN~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - M:\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - M:\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - M:\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - m:\steganos internet anonym pro 7\siapro7iep.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "M:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [OpwareSE2] "M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [!ewido] "M:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [imekrmig7.0] "C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programfiler\Fellesfiler\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] M:\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "M:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "M:\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Browser Sentinel] "M:\Browser Sentinel\BrowserSentinel.exe" -autorun
O4 - HKCU\..\Run: [SIAPRO7] "M:\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: SpywareGuard.lnk = M:\SpywareGuard\sgmain.exe
O4 - Global Startup: Cordless DUALphone Oppstart.lnk = C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
O8 - Extra context menu item: Download all by Free Download Manager - file://M:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://M:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://M:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://M:\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://M:\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Search Using Copernic Agent - res://M:\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra 'Tools' menuitem: Track Page Using Copernic Agent - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - M:\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.pcpitstop.com
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Norton Internet Security\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - M:\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - M:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - M:\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - M:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: O&O CleverCache Pro (OOCleverCache) - O&O Software GmbH - M:\OO Software\CleverCache\OOCCSVC.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello and welcome to the TC forums

Not seeing anything bad in your log, but give this a go :thumbup:

Please go HERE and do a online scan.
Let me know what is found.

After scan, reboot and post a new HijackThis log

Also let me know how the computer is running now.
Hi, I tried your online scan but it didn't work, probably because of IE7, I hvae had som problems with that stuff.
By the way, I've managed to change the way I log on, but it took five minutes for the window to open, just like that is it when i try to open the services list.
[external image: Posted Image]

I couldn't find any other way to upload images so!

here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 13:19:10, on 09.08.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
M:\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
M:\Executive Software\DiskeeperLite\DKService.exe
C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
M:\ewido anti-spyware 4.0\guard.exe
C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
M:\OO Software\CleverCache\OOCCSVC.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programfiler\Analog Devices\Core\smax4pnp.exe
C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
M:\DAEMON Tools\daemon.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
M:\ewido anti-spyware 4.0\ewido.exe
M:\Nero 7\InCD\InCD.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe
M:\iTunes\iTunesHelper.exe
C:\Programfiler\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
M:\Browser Sentinel\BrowserSentinel.exe
C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe
C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
M:\USB Wireless LAN\BK_USB_Monitor.exe
M:\SpywareGuard\sgmain.exe
M:\SpywareGuard\sgbhp.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
M:\Opera\Opera.exe
C:\WINDOWS\system32\WISPTIS.EXE
M:\Opera\Opera.exe
S:\BitComet\BitComet.exe
C:\WINDOWS\Explorer.EXE
M:\Opera\Opera.exe
C:\Hijackthis\HijackThis.exe
C:\Programfiler\Fellesfiler\Ahead\Lib\NMIndexStoreSvr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.no/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Mikael
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - M:\COPERN~1\COPERN~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - M:\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - M:\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - M:\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - m:\steganos internet anonym pro 7\siapro7iep.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "M:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [OpwareSE2] "M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [imekrmig7.0] "C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programfiler\Fellesfiler\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] M:\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "M:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "M:\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Browser Sentinel] "M:\Browser Sentinel\BrowserSentinel.exe" -autorun
O4 - HKCU\..\Run: [SIAPRO7] "M:\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: SpywareGuard.lnk = M:\SpywareGuard\sgmain.exe
O4 - Global Startup: Cordless DUALphone Oppstart.lnk = C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
O4 - Global Startup: USB Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: Download all by Free Download Manager - file://M:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://M:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://M:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://M:\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://M:\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Search Using Copernic Agent - res://M:\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra 'Tools' menuitem: Track Page Using Copernic Agent - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - M:\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.pcpitstop.com
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Norton Internet Security\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - M:\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - M:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - M:\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - M:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: O&O CleverCache Pro (OOCleverCache) - O&O Software GmbH - M:\OO Software\CleverCache\OOCCSVC.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
If you have a virus, I don't see it.

* Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
Hi again, sorry for not responding sooner, I've had a lot to do so. Here's the log you asked for: Start Time= 14.08.2006 16:09:21,48 Running from: C:\Documents and Settings\[removed]\Skrivebord QuickScan did not find any signs of infected files (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-08-13 14:06:10 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\InterTrust" 2006-08-13 14:06:10 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Adobe" 2006-08-02 16:50:42 98304 ( A…. ) "C:\WINDOWS\system32\CmdLineExt.dll" 2006-07-27 18:36:58 139264 ( A…. ) "C:\WINDOWS\War3Unin.exe" 2006-07-25 17:13:08 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Apple Computer" 2006-07-24 13:27:48 ( .D… ) "C:\Programfiler\Symantec" 2006-07-19 13:34:12 ( .D… ) "C:\Programfiler\Fellesfiler\L&H" 2006-07-19 13:33:50 ( .D… ) "C:\Programfiler\Microsoft ActiveSync" 2006-07-19 13:33:06 ( .D… ) "C:\Programfiler\Fellesfiler\DESIGNER" 2006-07-19 13:33:02 ( .D… ) "C:\Programfiler\Microsoft Works" 2006-07-19 13:32:52 ( .D… ) "C:\Programfiler\Microsoft Visual Studio" 2006-07-19 13:32:40 ( .D… ) "C:\Programfiler\Microsoft.NET" 2006-07-18 15:27:30 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Steganos Internet Anonym Pro 7" 2006-07-18 14:50:28 ( .D… ) "C:\Programfiler\Secure Surfing Engine" 2006-07-14 17:41:10 332288 ( A…. ) "C:\WINDOWS\system32\netapi32.dll" 2006-07-14 16:59:26 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Ahead" 2006-07-11 01:23:32 ( .D… ) "C:\Programfiler\Belarc" 2006-07-05 20:18:16 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\InstallShield Installation Information" 2006-06-29 15:53:20 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\ArcSoft" 2006-06-28 01:25:50 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\CyberLink" 2006-06-27 15:03:06 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Free Download Manager" 2006-06-23 09:28:56 5512704 ( ….. ) "C:\WINDOWS\system32\ieframe.dll" 2006-06-23 09:28:56 454144 ( ….. ) "C:\WINDOWS\system32\msfeeds.dll" 2006-06-23 09:28:56 413696 ( A…. ) "C:\WINDOWS\system32\vbscript.dll" 2006-06-23 09:28:56 223744 ( A…. ) "C:\WINDOWS\system32\webcheck.dll" 2006-06-23 09:28:56 179200 ( ….. ) "C:\WINDOWS\system32\ieui.dll" 2006-06-23 09:28:56 155648 ( A…. ) "C:\WINDOWS\system32\msls31.dll" 2006-06-23 09:28:56 47616 ( ….. ) "C:\WINDOWS\system32\msfeedsbs.dll" 2006-06-23 05:41:42 172544 ( ….. ) "C:\WINDOWS\system32\WinFXDocObj.exe" 2006-06-23 05:40:44 78848 ( A…. ) "C:\WINDOWS\system32\ieencode.dll" 2006-06-23 05:40:04 40960 ( A…. ) "C:\WINDOWS\system32\url.dll" 2006-06-23 05:39:52 39424 ( A…. ) "C:\WINDOWS\system32\licmgr10.dll" 2006-06-23 05:39:08 99328 ( A…. ) "C:\WINDOWS\system32\occache.dll" 2006-06-23 05:37:18 14336 ( A…. ) "C:\WINDOWS\system32\corpol.dll" 2006-06-23 05:34:30 228864 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll" 2006-06-23 05:34:16 167936 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll" 2006-06-23 05:34:06 81920 ( A…. ) "C:\WINDOWS\system32\admparse.dll" 2006-06-23 05:34:06 50688 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe" 2006-06-23 05:34:02 372736 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll" 2006-06-23 05:33:42 54272 ( A…. ) "C:\WINDOWS\system32\iesetup.dll" 2006-06-23 05:33:22 41984 ( A…. ) "C:\WINDOWS\system32\iernonce.dll" 2006-06-23 05:33:00 121856 ( A…. ) "C:\WINDOWS\system32\advpack.dll" 2006-06-23 05:30:22 11776 ( ….. ) "C:\WINDOWS\system32\msfeedssync.exe" 2006-06-23 05:29:56 55296 ( ….. ) "C:\WINDOWS\system32\icardie.dll" 2006-06-23 05:29:22 35328 ( A…. ) "C:\WINDOWS\system32\imgutil.dll" 2006-06-23 05:27:56 251392 ( ….. ) "C:\WINDOWS\system32\iertutil.dll" 2006-06-23 05:26:52 45568 ( A…. ) "C:\WINDOWS\system32\mshta.exe" 2006-06-23 04:46:30 377856 ( ….. ) "C:\WINDOWS\system32\ieapfltr.dll" 2006-06-23 04:45:30 48640 ( A…. ) "C:\WINDOWS\system32\mshtmler.dll" 2006-06-23 04:41:42 172032 ( A…. ) "C:\WINDOWS\system32\ieakui.dll" 2006-06-19 15:18:34 22752 ( A…. ) "C:\WINDOWS\system32\spupdsvc.exe" 2006-06-19 15:18:16 23552 ( ….. ) "C:\WINDOWS\system32\idndl.dll" 2006-06-19 15:18:16 20480 ( ….. ) "C:\WINDOWS\system32\normaliz.dll" 2006-06-17 23:15:58 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\Canon" 2006-06-17 21:42:50 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\CD-LabelPrint" 2006-06-17 21:40:46 ( .D… ) "C:\Documents and Settings\Mikael.MM.000\Programdata\ScanSoft" 2006-06-17 21:40:28 ( .D… ) "C:\Programfiler\Fellesfiler\ScanSoft Shared" 2006-06-17 21:36:40 ( .D… ) "C:\Programfiler\Canon" 2006-06-16 14:34:44 48936 ( A…. ) "C:\WINDOWS\system32\sirenacm.dll" 2006-06-15 23:55:04 778240 ( A…. ) "C:\WINDOWS\system32\divx_xx0c.dll" 2006-06-15 23:55:04 778240 ( A…. ) "C:\WINDOWS\system32\divx_xx07.dll" 2006-06-15 23:55:04 761856 ( A…. ) "C:\WINDOWS\system32\divx_xx11.dll" 2006-06-15 23:55:04 620180 ( A…. ) "C:\WINDOWS\system32\DivX.dll" 2006-06-14 19:49:08 118784 ( A…. ) "C:\WINDOWS\system32\DivXCodecUpdateChecker.exe" 2006-06-12 21:22:08 520192 ( A…. ) "C:\WINDOWS\system32\DivXsm.exe" 2006-06-08 12:08:36 534208 ( A…. ) "C:\WINDOWS\system32\SymNeti.dll" 2006-06-08 12:08:36 161472 ( A…. ) "C:\WINDOWS\system32\SymRedir.dll" 2006-06-02 23:35:56 8464 ( A…. ) "C:\WINDOWS\system32\sporder.dll" 2006-06-01 21:30:18 47564 ( A.SHR ) "C:\NTDETECT.COM" 2006-05-31 17:10:46 62 ( A.SH. ) "C:\Documents and Settings\Mikael.MM.000\Programdata\desktop.ini" 2006-05-25 00:48:04 109568 ( ….. ) "C:\WINDOWS\system32\pxinsi64.exe" 2006-05-25 00:48:04 108544 ( ….. ) "C:\WINDOWS\system32\pxcpyi64.exe" 2006-05-25 00:47:12 3596288 ( A…. ) "C:\WINDOWS\system32\qt-dx331.dll" 2006-05-25 00:46:52 53248 ( A…. ) "C:\WINDOWS\system32\dpuGUI10.dll" 2006-05-25 00:46:44 593920 ( A…. ) "C:\WINDOWS\system32\dpuGUI11.dll" 2006-05-25 00:46:44 344064 ( A…. ) "C:\WINDOWS\system32\dpus11.dll" 2006-05-25 00:46:44 294912 ( A…. ) "C:\WINDOWS\system32\dpu11.dll" 2006-05-25 00:46:44 294912 ( A…. ) "C:\WINDOWS\system32\dpu10.dll" 2006-05-25 00:46:44 200704 ( A…. ) "C:\WINDOWS\system32\dtu100.dll" 2006-05-25 00:46:44 90112 ( A…. ) "C:\WINDOWS\system32\dpl100.dll" 2006-05-25 00:46:44 57344 ( A…. ) "C:\WINDOWS\system32\dpv11.dll" 2006-05-25 00:43:44 1044480 ( A…. ) "C:\WINDOWS\system32\libdivx.dll" 2006-05-25 00:43:44 200704 ( A…. ) "C:\WINDOWS\system32\ssldivx.dll" 2006-05-25 00:43:40 245408 ( A…. ) "C:\WINDOWS\system32\unicows.dll" 2006-05-19 15:48:38 148480 ( A…. ) "C:\WINDOWS\system32\dnsapi.dll" 2006-05-19 15:48:38 111616 ( A…. ) "C:\WINDOWS\system32\dhcpcsvc.dll" 2006-05-19 15:48:38 94720 ( A…. ) "C:\WINDOWS\system32\iphlpapi.dll" 2006-05-16 14:34:38 87808 ( A…. ) "C:\WINDOWS\system32\S32EVNT1.DLL" (((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))) 2006-08-13 14:05 306ÿ688 C:\WINDOWS\IsUn0414.exe 2006-08-10 13:53 61ÿ136 C:\WINDOWS\system32\xinput9_1_0.dll 2006-08-10 13:53 230ÿ096 C:\WINDOWS\system32\xactengine2_0.dll 2006-08-10 13:53 2ÿ332ÿ368 C:\WINDOWS\system32\d3dx9_29.dll 2006-08-10 13:53 2ÿ323ÿ664 C:\WINDOWS\system32\d3dx9_28.dll 2006-08-10 13:53 2ÿ297ÿ552 C:\WINDOWS\system32\d3dx9_26.dll 2006-08-10 13:53 14ÿ032 C:\WINDOWS\system32\x3daudio1_0.dll 2006-08-07 21:32 1ÿ072ÿ746ÿ496 C:\hiberfil.sys 2006-08-05 18:14 61ÿ440 C:\WINDOWS\system32\ZDTRLib.DLL 2006-08-05 18:14 49ÿ152 C:\WINDOWS\system32\ZD12APP.dll 2006-08-05 17:50 94ÿ285 C:\WINDOWS\system32\MSVCIRTD.DLL 2006-08-05 17:50 929ÿ844 C:\WINDOWS\system32\MFC42D.DLL 2006-08-05 17:50 798ÿ773 C:\WINDOWS\system32\MFCO42D.DLL 2006-08-05 17:50 61ÿ440 C:\WINDOWS\system32\ZDN50.dll 2006-08-05 17:50 41ÿ013 C:\WINDOWS\system32\MFCN42D.DLL 2006-08-05 17:50 385ÿ100 C:\WINDOWS\system32\MSVCRTD.DLL 2006-08-05 17:50 323ÿ584 C:\WINDOWS\system32\ISRT.DLL 2006-08-05 17:50 24ÿ576 C:\WINDOWS\system32\ZyDelReg.exe 2006-08-05 17:50 16ÿ157 C:\WINDOWS\system32\ZDNDIS5.sys 2006-08-02 16:50 98ÿ304 C:\WINDOWS\system32\CmdLineExt.dll 2006-08-01 19:43 322ÿ832 C:\WINDOWS\system32\MFC30.DLL 2006-08-01 19:40 18ÿ944 C:\WINDOWS\system32\simptcp.dll 2006-07-27 18:20 139ÿ264 C:\WINDOWS\War3Unin.exe 2006-07-24 13:28 87ÿ808 C:\WINDOWS\system32\S32EVNT1.DLL 2006-07-19 20:18 117ÿ760 C:\WINDOWS\system32\xmllite.dll 2006-07-19 13:35 17ÿ920 C:\WINDOWS\system32\mdimon.dll 2006-07-14 16:58 24ÿ064 C:\WINDOWS\system32\msxml3a.dll 2006-07-08 20:51 5ÿ632 C:\WINDOWS\system32\ptpusb.dll 2006-07-08 20:51 159ÿ232 C:\WINDOWS\system32\ptpusd.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "SoundMAXPnP"="C:\\Programfiler\\Analog Devices\\Core\\smax4pnp.exe" "SunJavaUpdateSched"="C:\\Programfiler\\Java\\jre1.5.0_07\\bin\\jusched.exe" "DAEMON Tools"="\"M:\\DAEMON Tools\\daemon.exe\" -lang 1033" "ATIPTA"="\"C:\\Programfiler\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\"" "ATICCC"="\"C:\\Programfiler\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay" "OpwareSE2"="\"M:\\ScanSoft\\OmniPageSE2.0\\OpwareSE2.exe\"" "imekrmig7.0"="\"C:\\Programfiler\\Fellesfiler\\Microsoft Shared\\IME\\IMKR7\\IMEKRMIG.EXE\"" "IMSCMig"="C:\\PROGRA~1\\FELLES~1\\MICROS~1\\IME\\IMSC40A\\IMSCMIG.EXE /Preload" "CJIMETIPSYNC"="C:\\Programfiler\\Fellesfiler\\Microsoft Shared\\IME\\IMTC65\\CHANGJIE\\CINTLCFG.EXE /CJIMETIPSync" "PHIMETIPSYNC"="C:\\Programfiler\\Fellesfiler\\Microsoft Shared\\IME\\IMTC65\\PHONETIC\\TINTLCFG.EXE /PHIMETIPSync" "IMJPMIG9.0"="C:\\PROGRA~1\\FELLES~1\\MICROS~1\\IME\\IMJP9\\IMJPMIG.EXE /Preload /Migration32" "NeroFilterCheck"="C:\\Programfiler\\Fellesfiler\\Ahead\\Lib\\NeroCheck.exe" "InCD"="M:\\Nero 7\\InCD\\InCD.exe" "ccApp"="\"C:\\Programfiler\\Fellesfiler\\Symantec Shared\\ccApp.exe\"" "iTunesHelper"="\"M:\\iTunes\\iTunesHelper.exe\"" "QuickTime Task"="\"C:\\Programfiler\\QuickTime\\qttask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "MsnMsgr"="\"C:\\Programfiler\\MSN Messenger\\MsnMsgr.Exe\" /background" "Skype"="\"M:\\Skype\\Phone\\Skype.exe\" /nosplash /minimized" "Browser Sentinel"="\"M:\\Browser Sentinel\\BrowserSentinel.exe\" -autorun" "SIAPRO7"="\"M:\\Steganos Internet Anonym Pro 7\\SIAPRO7.exe\" -boot" "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Programfiler\\Fellesfiler\\Ahead\\Lib\\NMBgMonitor.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] "DJSNetCN"="C:\\Programfiler\\Fellesfiler\\Symantec Shared\\DJSNETCN.exe" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE" [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "SIAPRO7"="\"M:\\Steganos Internet Anonym Pro 7\\SIAPRO7.exe\" -firstboot" [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce] "SIAPRO7"="\"M:\\Steganos Internet Anonym Pro 7\\SIAPRO7.exe\" -firstboot" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" "{81559C35-8464-49F7-BB0E-07A383BEF910}"="" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ISUSPM" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Fellesfiler\\InstallShield\\UpdateService\\ISUSPM.exe\" -startup" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="issch" "hkey"="HKLM" "command"="\"C:\\Programfiler\\Fellesfiler\\InstallShield\\UpdateService\\issch.exe\" -start" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareQuake.com] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spyware-Quake" "hkey"="HKLM" "command"="C:\\Programfiler\\SpywareQuake.com\\Spyware-Quake.exe /h" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "InstallShield Licensing Service"=dword:00000003 HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system DisableRegistryTools REG_DWORD 0 (0x0) Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Norton AntiVirus - Kj›r fullstendig systems›k - Mikael.job (run full system search) C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: 14.08.2006 16:09:40,95 ComboFix ver 06.07.15/30 - This logfile is located at C:\ComboFix.txt
Do you know what this file is?
C:\WINDOWS\IsUn0414.exe


Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareQuake.com]



On the desktop, doubleclick fix.reg and allow it to run. Let it merge.


Delete these Files if listed:
C:\Programfiler\SpywareQuake.com\\Spyware-Quake.exe
C:\Programfiler\SpywareQuake.com



Empty Recycle Bin

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Hi, the file you asked me about seems to be InstallShield® unInstaller, but I don't know.

I don't notise any changes because spywarequake was removed with smithfraudfix a long time a go so there was probably just some parts of it left

here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 23:45:39, on 14.08.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
M:\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
M:\Executive Software\DiskeeperLite\DKService.exe
C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
M:\ewido anti-spyware 4.0\guard.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
M:\OO Software\CleverCache\OOCCSVC.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programfiler\Analog Devices\Core\smax4pnp.exe
C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
M:\DAEMON Tools\daemon.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
M:\Nero 7\InCD\InCD.exe
C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe
M:\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\iPod\bin\iPodService.exe
M:\Browser Sentinel\BrowserSentinel.exe
C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
M:\USB Wireless LAN\BK_USB_Monitor.exe
M:\SpywareGuard\sgmain.exe
M:\SpywareGuard\sgbhp.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe
C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
M:\iTunes\iTunes.exe
M:\Opera\Opera.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\Explorer.EXE
C:\Programfiler\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.no/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Mikael
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - M:\COPERN~1\COPERN~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - M:\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - M:\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - M:\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - M:\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - m:\steganos internet anonym pro 7\siapro7iep.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programfiler\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "M:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Programfiler\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [OpwareSE2] "M:\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [imekrmig7.0] "C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE"
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Programfiler\Fellesfiler\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\FELLES~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programfiler\Fellesfiler\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] M:\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "M:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "M:\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Browser Sentinel] "M:\Browser Sentinel\BrowserSentinel.exe" -autorun
O4 - HKCU\..\Run: [SIAPRO7] "M:\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: SpywareGuard.lnk = M:\SpywareGuard\sgmain.exe
O4 - Global Startup: Cordless DUALphone Oppstart.lnk = C:\Programfiler\Cordless USB Phone\Cordless DUALphone Suite.exe
O4 - Global Startup: USB Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: Download all by Free Download Manager - file://M:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://M:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://M:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://M:\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://M:\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://M:\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Search Using Copernic Agent - res://M:\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra 'Tools' menuitem: Track Page Using Copernic Agent - {0BCBCDD8-E5D9-417D-A752-C2DA929A21BF} - M:\COPERN~1\COPERN~1.DLL
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - M:\Copernic Agent\CopernicAgent.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - M:\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.pcpitstop.com
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Programfiler\Norton Internet Security\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - M:\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - M:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - M:\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - M:\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: O&O CleverCache Pro (OOCleverCache) - O&O Software GmbH - M:\OO Software\CleverCache\OOCCSVC.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
Good Job :thumbup:

Log looks good :D :thumbup: How is it running any issues?


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have any programs like these, I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
The services an account windows still takes extremly long time to open, if it acctually opens, but other than that it's fine
lets see if this will help speed it up.

Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.

NOTE: To be extra safe you can choose to only remove the items in RED.
HI, thanks for a great program, it made my hole computer much faster :D Sadly I still have the same issues with services and "account manager" (you know what I mean) :(
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI