This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

The Best Offers Adware Removal - Please Help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Forum:

Here is my logfile. Please help me remove this adware/spyware from my computer. Thanks for any help.

Cliff

Logfile of HijackThis v1.99.1
Scan saved at 11:11:22 AM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\Cyb2k.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Linksys\WUSB11 v25 Config Utility\WUSB11Cfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Krism\Desktop\HiJack This\HijackThis.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.family.org/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - URLSearchHook: (no name) - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [flrefj] C:\WINDOWS\system32\tormjw.exe r
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Internet Washer Pro] C:\Program Files\Internet Washer Pro\iw.exe min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Krism\My Documents\max's stuff\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/wi…FreeInstall.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
Welcome to the forum :wavey:

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O4 - HKLM\..\Run: [flrefj] C:\WINDOWS\system32\tormjw.exe r

O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column look for:

System Startup Service (SvcProc)

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: c:\windows\SvcProc.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
If you have Firefox, Under Firefox choose: Firefox cache and Firefox cookies
Click the Empty Selected button.
Close the program.

Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds.

Save the logfile from the scan.

Boot normally.

Post:

1. The log from the Ewido scan.

2. A new HijackThis! log

into this thread.
:)
Thank you very much for your help! I really appreciate your time. Here is the Hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 7:12:17 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\Cyb2k.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Linksys\WUSB11 v25 Config Utility\WUSB11Cfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Documents and Settings\Krism\Desktop\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.family.org/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
O2 - BHO: NavErrRedir Class - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Internet Washer Pro] C:\Program Files\Internet Washer Pro\iw.exe min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Krism\My Documents\max's stuff\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/wi…FreeInstall.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe




Here is the ewido log:

——————————————————–
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 6:54:42 PM 8/27/2006

+ Scan result:



C:\WINDOWS\SYSTEM32\mbbi8016.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP917\A0074545.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP918\A0074946.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP924\A0075581.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP925\A0075983.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\akiohqdkdtw.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\svcproc.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bsto-1 -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\SvcProc -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\SvcProc\Enum -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\SvcProc\Security -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKU\S-1-5-21-473436651-1075026919-2245216776-1006\Software\aurora -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKU\S-1-5-21-473436651-1075026919-2245216776-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00F1D395-4744-40F0-A611-980F61AE2C59} -> Adware.DrSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\Xcite2.exe -> Adware.F1Organizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tdbTs.dll -> Dropper.Agent.of : Cleaned with backup (quarantined).
C:\Documents and Settings\New Account Name\Cookies\new account name@msnportal.112.2o7[1].txt -> .2o7 : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@admonitor[1].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@admonitor[2].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@admonitor[3].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@admonitor[1].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@admonitor[2].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@admonitor[3].txt -> .Admonitor : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@advertising[2].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@advertising[3].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@servedby.advertising[1].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@servedby.advertising[2].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@advertising[2].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@advertising[3].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@servedby.advertising[1].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@servedby.advertising[2].txt -> .Advertising : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@atdmt[2].txt -> .Atdmt : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@atdmt[2].txt -> .Atdmt : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@bfast[1].txt -> .Bfast : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@bfast[2].txt -> .Bfast : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@bfast[1].txt -> .Bfast : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@bfast[2].txt -> .Bfast : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@bluestreak[1].txt -> .Bluestreak : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@bluestreak[1].txt -> .Bluestreak : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@centrport[1].txt -> .Centrport : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@centrport[1].txt -> .Centrport : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@www.commission-junction[1].txt -> .Commission-junction : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@www.commission-junction[1].txt -> .Commission-junction : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@data.coremetrics[1].txt -> .Coremetrics : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@data.coremetrics[1].txt -> .Coremetrics : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@doubleclick[2].txt -> .Doubleclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@doubleclick[2].txt -> .Doubleclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@engage[1].txt -> .Engage : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@engage[1].txt -> .Engage : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@ads.enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ads.enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ads.enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@enliven[1].txt -> .Enliven : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@fastclick[2].txt -> .Fastclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@fastclick[3].txt -> .Fastclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@fastclick[2].txt -> .Fastclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@fastclick[3].txt -> .Fastclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@flycast[1].txt -> .Flycast : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@flycast[1].txt -> .Flycast : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@focalink[1].txt -> .Focalink : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@focalink[2].txt -> .Focalink : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@focalink[1].txt -> .Focalink : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@focalink[2].txt -> .Focalink : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\[removed][1].txt -> .Hightrafficads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\[removed][1].txt -> .Hightrafficads : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\[removed][1].txt -> .Hightrafficads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ehg-dig.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ehg-espn.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ehg-nationalpublicradio.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ehg-verticalwebventures.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ehg.hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@w116.hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ehg-dig.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ehg-espn.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ehg-nationalpublicradio.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ehg-verticalwebventures.hitbox[2].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ehg.hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@w116.hitbox[1].txt -> .Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[1].txt -> .Link4ads : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[2].txt -> .Link4ads : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[4].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ads.link4ads[1].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ads.link4ads[2].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@ads.link4ads[4].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[1].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[2].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@ads.link4ads[4].txt -> .Link4ads : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@linksynergy[2].txt -> .Linksynergy : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@linksynergy[2].txt -> .Linksynergy : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@mediaplex[2].txt -> .Mediaplex : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@mediaplex[3].txt -> .Mediaplex : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@mediaplex[4].txt -> .Mediaplex : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@mediaplex[2].txt -> .Mediaplex : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@mediaplex[3].txt -> .Mediaplex : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@mediaplex[4].txt -> .Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@overture[1].txt -> .Overture : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@overture[1].txt -> .Overture : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@overture[1].txt -> .Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@pointroll[2].txt -> .Pointroll : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@pointroll[2].txt -> .Pointroll : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@pointroll[2].txt -> .Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@gm.preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@gm.preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@gm.preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@preferences[1].txt -> .Preferences : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@www.qksrv[1].txt -> .Qksrv : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@www.qksrv[1].txt -> .Qksrv : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@questionmarket[1].txt -> .Questionmarket : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@questionmarket[1].txt -> .Questionmarket : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@questionmarket[1].txt -> .Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@healthsquare.spinbox[2].txt -> .Spinbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@healthsquare.spinbox[2].txt -> .Spinbox : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@healthsquare.spinbox[2].txt -> .Spinbox : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@valueclick[1].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@valueclick[2].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@valueclick[3].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@valueclick[1].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@valueclick[2].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@valueclick[3].txt -> .Valueclick : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@statse.webtrendslive[1].txt -> .Webtrendslive : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@statse.webtrendslive[1].txt -> .Webtrendslive : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@x10[1].txt -> .X10 : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@x10[3].txt -> .X10 : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@x10[1].txt -> .X10 : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@x10[3].txt -> .X10 : Cleaned with backup (quarantined).
C:\Documents and Settings\Krism\WINDOWS\Profiles\default\Cookies\….@zedo[2].txt -> .Zedo : Cleaned with backup (quarantined).
E:\WINDOWS\Cookies\….@zedo[2].txt -> .Zedo : Cleaned with backup (quarantined).
E:\WINDOWS\Profiles\default\Cookies\….@zedo[2].txt -> .Zedo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP920\A0075376.exe -> Trojan.Stervis.e : Cleaned with backup (quarantined).


::Report end


Thanks again, I really appreciate your help.

Cliff
Disable Microsoft Windows Defender:
We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
  • Click on Tools, General Settings.
  • Under Real-time protection options, unselect the Turn on real-time protection check box
  • Click Save
After all of the fixes are complete it is very important that you enable Real-time Protection again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: NavErrRedir Class - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)

O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe

O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm

O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\common files\searchupgrader <— FOLDER

C:\Program Files\Ebates_MoeMoneyMaker <— FOLDER

C:\Program Files\WebRebates4 <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Thank you very much. I can't tell you how much I appreciate the help.

Here is the log file. I couldn't find Ebates_MoeMoneyMaker or WebRebates4 even by doing a search for files and folders showing hidden files.

Logfile of HijackThis v1.99.1
Scan saved at 10:14:56 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\Cyb2k.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Linksys\WUSB11 v25 Config Utility\WUSB11Cfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Krism\Desktop\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.family.org/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Internet Washer Pro] C:\Program Files\Internet Washer Pro\iw.exe min
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Krism\My Documents\max's stuff\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/wi…FreeInstall.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Seems to be great! Thank you very much for helping. I will eagerly contribute to your site for this help. You helped me once before in 2005 and I was pleasantly suprised to hear from you again. Your committment and work combating this kind of problem is worth more than words can describe. I've also taken note of your recommendations and will install these security measures now that everything seems to be cleaned up. Thank you very much and may God richly bless you and yours!
Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI