This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help me with pop ups

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am getting 1 pop up each for each search in google. Some of the common popups are qwickfind.com, search.ebay.co.uk, stopzilla.com and it sometimes includes some nude stuff too.. Too much worried about it and some body please help me to resolve this. I have spyware doctor installed in it and I have McAfe Virus Scan Enterprise too.. All possible scannings are done, but no use. Here is my hijack this log file. Logfile of HijackThis v1.99.1 Scan saved at 12:06:37 PM, on 11/20/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\PROGRA~1\SPYWAR~1\swdoctor.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\DELL\Desktop\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: (no name) - {7797F524-B819-42d0-B35A-0DACAF93E977} - C:\WINDOWS\system32\pctxluys.dll O2 - BHO: (no name) - {871A54C1-1EB3-48bd-A879-5DBA4EF16BE6} - C:\WINDOWS\system32\ldhlyxlk.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Download Link Using Mega Manager… - E:\Program Files\Megaupload_download Manager\mm_file.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe Please let me know what I should do?????? Thanks in Advance..
vadakkemury

Welocme to Tom Coyote :)

Sorry for the delay :(

First Please download the Killbox.1)Save it to the desktop and run it.
2) Select "Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\WINDOWS\system32\pctxluys.dll
C:\WINDOWS\system32\ldhlyxlk.dll

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
Next Rerun Hijackthis and place checks beside the following entriesO2 - BHO: (no name) - {7797F524-B819-42d0-B35A-0DACAF93E977} - C:\WINDOWS\system32\pctxluys.dll
O2 - BHO: (no name) - {871A54C1-1EB3-48bd-A879-5DBA4EF16BE6} - C:\WINDOWS\system32\ldhlyxlk.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - (no file)

Close all other open windows except Hijackthis and Select "Fix checked"
Close Hijackthis->>Reboot your PC

Next 1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Thanks bamajim
Thank you very much for your reply… I think I did everything as you asked me to do… Here is the log from combofix DELL - 06-11-22 17:36:10.10 Service Pack 2 ComboFix 06.11.22 - Running from: "C:\Documents and Settings\DELL\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-10-22 to 2006-11-22 )))))))))))))))))))))))))))))))))) 2006-11-22 17:05 d——– C:\!KillBox 2006-11-22 12:18 159,744 –a—— C:\WINDOWS\system32\LexLog.dll 2006-11-22 12:18 d——– C:\Program Files\Lexmark 2006-11-20 11:26 d——– C:\VundoFix Backups 2006-11-17 19:16 138,752 –a—— C:\WINDOWS\system32\sndvol32.exe 2006-11-17 18:44 138,752 –a—— C:\WINDOWS\system32.exe 2006-11-17 18:34 d——– C:\WINDOWS\32D0A96335254FD09357B092253E9412.TMP 2006-11-17 18:32 d——– C:\Program Files\Sigmatel 2006-11-17 16:11 d——– C:\Documents and Settings\DELL\Application Data\Mathematica 2006-11-17 16:11 d——– C:\Documents and Settings\All Users\Application Data\Mathematica 2006-11-17 15:31 d——– C:\Documents and Settings\All Users\Application Data\Adobe Systems 2006-11-17 13:07 24,072 –a—— C:\WINDOWS\system32\uxtuneup.dll 2006-11-17 13:06 d——– C:\Documents and Settings\DELL\Application Data\TuneUp Software 2006-11-17 13:05 d——– C:\Program Files\Common Files\Wise Installation Wizard 2006-11-17 13:05 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software 2006-11-17 12:55 d——– C:\Program Files\MSXML 4.0 2006-11-17 12:42 d——– C:\Program Files\Common Files\soft602 2006-11-09 16:43 d——– C:\Program Files\Megaupload 2006-11-08 09:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2006-11-05 21:56 d——– C:\Program Files\Common Files\Adobe Systems Shared 2006-11-05 14:17 d——– C:\Documents and Settings\DELL\Application Data\Lavasoft 2006-11-05 14:16 d——– C:\Program Files\Lavasoft 2006-11-04 20:51 126,996 –a—— C:\WINDOWS\system32\epopwric.dll 2006-11-04 14:14 1,245,696 –a—— C:\WINDOWS\system32\msxml4.dll 2006-11-02 16:40 d——– C:\Documents and Settings\DELL\Application Data\Definiens 2006-10-23 21:16 122,900 –a—— C:\WINDOWS\system32\btwcxeme.dll 2006-10-23 18:08 d——– C:\Program Files\AdvancedSearchbar 2006-10-22 09:21 d——– C:\WINDOWS\WBEM 2006-10-22 09:21 d——– C:\WINDOWS\system32\en-US 2006-10-22 09:18 121,856 ——— C:\WINDOWS\system32\xmllite.dll 2006-10-22 09:17 d——– C:\WINDOWS\network diagnostic (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-11-22 13:07 ——– d——– C:\Program Files\epson 2006-11-22 09:59 ——– d——– C:\Program Files\Common Files\Adobe 2006-11-20 22:40 ——– d——– C:\Documents and Settings\DELL\Application Data\Skype 2006-11-17 18:27 ——– d——– C:\Program Files\Xmanager1.3.9 2006-11-17 18:26 ——– d-a—— C:\Program Files\Common Files 2006-11-17 17:42 ——– d——– C:\Documents and Settings\DELL\Application Data\AdobeUM 2006-11-17 15:10 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-11-17 13:14 ——– d——– C:\Documents and Settings\DELL\Application Data\uTorrent 2006-11-17 12:54 ——– d——– C:\Program Files\Internet Explorer 2006-11-17 12:24 ——– d——– C:\Program Files\SSH Communications Security 2006-11-17 12:24 ——– d——– C:\Documents and Settings\DELL\Application Data\SSH 2006-11-17 12:22 ——– d——– C:\Program Files\HP 2006-11-17 12:20 ——– d——– C:\Program Files\Google 2006-11-17 12:17 4931 –ahs—- C:\Documents and Settings\DELL\Application Data\10E02387BA5A43DEA27532A4670F0A8B.sta 2006-11-17 12:17 14933 –ahs—- C:\Documents and Settings\DELL\Application Data\10E02387BA5A43DEA27532A4670F0A8B.rul 2006-11-07 09:09 ——– d——– C:\Program Files\Adobe 2006-11-05 22:06 ——– d——– C:\Documents and Settings\DELL\Application Data\Adobe 2006-10-24 21:46 ——– d—s—- C:\Documents and Settings\DELL\Application Data\Microsoft 2006-10-23 11:18 ——– d——– C:\Program Files\Online Services 2006-10-23 11:17 ——– d——– C:\Program Files\Windows NT 2006-10-23 11:12 ——– d——– C:\Program Files\Yahoo! 2006-10-17 12:01 13312 –a—— C:\WINDOWS\system32\ieudinit.exe 2006-10-13 12:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll 2006-10-13 12:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll 2006-10-13 12:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll 2006-10-13 10:23 163584 –a—— C:\WINDOWS\system32\drivers\nwrdr.sys 2006-10-07 17:05 122900 –a—— C:\WINDOWS\system32\bblhjkdi.dll 2006-10-07 17:03 90320 –a—— C:\Documents and Settings\DELL\Application Data\errorsafespecialofferinstall[1].exe 2006-10-07 16:38 87760 –a—— C:\Documents and Settings\DELL\Application Data\errorsafenewreleaseinstall[1].exe 2006-09-29 20:45 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-09-28 12:08 49428 –a—— C:\WINDOWS\system32\lcwuytlj.dll 2006-09-25 03:38 ——– d——– C:\Program Files\NetMeeting 2006-09-23 22:32 ——– d——– C:\Documents and Settings\DELL\Application Data\Google 2006-09-18 13:20 43352 –a—— C:\Documents and Settings\DELL\Application Data\GDIPFONTCACHEV1.DAT 2006-09-13 05:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll 2006-09-10 00:33 1047552 –a—— C:\WINDOWS\system32\mfc71u.dll 2006-09-06 16:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe 2006-08-25 15:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Spyware Doctor"="E:\\PROGRA~1\\SPYWAR~1\\swdoctor.exe /Q" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\BtcMaestro] "ModelName"="5213URF" "Version"="2.2.1-155AU MUL" "Language"=dword:00000000 "KeyboardID"=dword:00000000 "MouseID"=dword:00000000 "KeyboardSID"=dword:00000000 "MouseSID"=dword:00000000 "RxSecret"=dword:00000000 "RMenuSel"=dword:00000000 "AddMouse"=dword:00000001 "JumpPickLevel"=dword:00000000 "KeyboardBat"=dword:00000000 "MouseBat"=dword:00000000 "KeyboardCh"=dword:00000000 "MouseCh"=dword:00000000 "FilterLMouse"=dword:00000000 "FilterRMouse"=dword:00000000 "MouseDPI"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\BtcMaestro\Config] "DisplayLabel"=dword:00000001 "TaskbarIcon"=dword:00000001 "Autoplay"=dword:00000000 "F091"="0Q;my music" "L091"="My Music" "F090"="0P;my pictures" "L090"="My Pictures" "F089"="0J;joystick on" "L089"="Joy Stick ON" "F088"="0J;joystick off" "L088"="Joy Stick OFF" "F087"="F;next track" "L087"="Next Track" "F086"="G;previous track" "L086"="Previous Track" "F085"="E;stop" "L085"="Stop" "F084"="0H;mouse fifth button" "L084"="Mouse 5th Button" "F083"="C;volume down" "L083"="Volume Down" "F082"="B;volume up" "L082"="Volume Up" "F081"="D;play" "L081"="Play/Pause" "F080"="0G;mouse fourth button" "L080"="Mouse 4th Button" "F079"="0F;scroll right" "L079"="Middle + Wheel Down" "F078"="0E;scroll left" "L078"="Middle + Wheel Up" "F077"="J;www(AC)" "L077"="www" "F076"="0I;quick jump" "L076"="Quick Jump" "F075"="0F;scroll right" "L075"="Middle + Right" "F074"="0E;scroll left" "L074"="Middle + Left" "F073"="m;scroll down" "L073"="Scroll Wheel Uown" "F072"="l;scroll up" "L072"="Scroll Wheel Up" "F071"="0I;quick jump" "L071"="Quick Jump" "F070"="0F;scroll right" "L070"="Scroll Right" "F069"="0E;scroll left" "L069"="Scroll Left" "F068"="0D:set SID final" "L068"="Set SID Final" "F067"="0C:paint" "L067"="Paint" "F066"="0B;mouse middle button" "L066"="Mouse Middle Button" "F065"="0A;europe dollar(OF)" "L065"="Europe Dollar" "F064"="0-;reply all(OF)" "L064"="Reply All" "F063"="09;eject 2" "L063"="Eject/Close 2" "F062"="08:help(OF)" "L062"="Help" "F061"="07;redo(OF)" "L061"="Redo" "F060"="06;undo(OF)" "L060"="Undo" "F059"="05;task pane(OF)" "L059"="Task pane" "F058"="04;send(OF)" "L058"="Send" "F057"="03;f'ward(OF)" "L057"="F'ward" "F056"="02;reply(OF)" "L056"="Reply" "F055"="01;bullets(OF)" "L055"="Bullets" "F054"="00;spell(OF)" "L054"="Spell" "F053"="z;bold(OF)" "L053"="Bold" "F052"="y;replace(OF)" "L052"="Replace" "F051"="x;save(OF)" "L051"="Save" "F050"="w;open(OF)" "L050"="Open" "F049"="v;new(OF)" "L049"="New" "F048"="u;copy(OF)" "L048"="Copy" "F047"="t;cut(OF)" "L047"="Cut" "F046"="s;mark(OF)" "L046"="Mark" "F045"="r;paste(OF)" "L045"="Paste" "F044"="q;calendar(OF)" "L044"="Calendar" "F043"="p;power point(OF)" "L043"="Power Point" "F042"="o;excel(OF)" "L042"="Excel" "F041"="n;word(OF)" "L041"="Word" "F040"="m;scroll down" "L040"="Scroll Down" "F039"="l;scroll up" "L039"="Scroll Up" "F038"="k;Configure" "L038"="Configure" "F037"="j;keyboard and mouse battery low" "L037"="Keyboard and Mouse Battery Low" "F036"="i;mouse battery low" "L036"="Mouse Battery Low" "F035"="h;keyboard battery low" "L035"="Keyboard Battery Low" "F034"="g;keyboard and mouse battery OK" "L034"="" "F033"="f:wake up" "L033"="Wake Up" "F032"="e:sleep" "L032"="Sleep" "F031"="d;power off" "L031"="Power Off" "F030"="c;mf" "L030"="F-Lock" "F029"="b;app. close" "L029"="App. Close" "F028"="a;app. switch" "L028"="App. Switch" "F027"="Z;log off" "L027"="Log Off" "F026"="Y;my computer" "L026"="My Computer" "F025"="X;refresh(AC)" "L025"="www Refresh" "F024"="W;print(OF)" "L024"="Print" "F023"="V;notepad" "L023"="Notepad" "F022"="U;explorer" "L022"="Explorer" "F021"="T;mediaplayer" "L021"="Mediaplayer" "F020"="S;my documents" "L020"="My Documents" "F019"="R;calculator" "L019"="Calculator" "F018"="Q;help(manual)" "L018"="KeyMaestro Help" "F017"="P;help(OS)" "L017"="OS Help" "F016"="O;favorite(AC)" "L016"="www Favorite" "F015"="N;search(AC)" "L015"="www Search" "F014"="M;forward(AC)" "L014"="www Forward" "F013"="L;back(AC)" "L013"="www Back" "F012"="K;stop(AC)" "L012"="www Stop" "F011"="J;www(AC)" "L011"="www" "F010"="I;email(AL)" "L010"="Email" "F009"="H;eject" "L009"="Eject/Close" "F008"="G;previous track" "L008"="Previous Track" "F007"="F;next track" "L007"="Next Track" "F006"="E;stop" "L006"="Stop" "F005"="D;play" "L005"="Play/Pause" "F004"="C;volume down" "L004"="Volume Down" "F003"="B;volume up" "L003"="Volume Up" "F002"="A;mute" "L002"="Mute" "F001"="-;none" "L001"="None" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE" "McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey" "Network Associates Error Reporting Service"="\"C:\\Program Files\\Common Files\\Network Associates\\TalkBack\\tbmon.exe\"" @="" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000005 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "BtcMaestro"="\"E:\\Program Files\\KMaestro\\KMaestro.exe\"" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe" "Acrobat Assistant 7.0"="\"E:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\"" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\1-Click Maintenance.job C:\WINDOWS\tasks\Low Battery Alarm Program.job Completion time: 06-11-22 17:37:09.48 C:\ComboFix.txt … 06-11-22 17:37
vadakkemury

You are most welcome :)

First Go to Add/Remove Programs (Click Start->>Control Panel->>Add/Remove Programs)
And uninstall this program (IF found)Error Safe
Next We need to make sure we can see hidden files and foldersClick Start.
Click My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Uncheck the Hide file extensions for known file types.
Click OK.
Next Using Windows Explorer(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following foldersC:\Program Files\Xmanager1.3.9
C:\WINDOWS\32D0A96335254FD09357B092253E9412.TMP

Locate and Delete the following filesC:\WINDOWS\system32\sndvol32.exe
C:\WINDOWS\system32.exe
<<- Make sure you get an exact match, because there is a system32 Folder which is legit->>
C:\WINDOWS\system32\epopwric.dll
C:\WINDOWS\system32\btwcxeme.dll
C:\WINDOWS\system32\bblhjkdi.dll
C:\Documents and Settings\DELL\Application Data\errorsafespecialofferinstall[1].exe
C:\Documents and Settings\DELL\Application Data\errorsafenewreleaseinstall[1].exe
C:\WINDOWS\system32\lcwuytlj.dll

Close Windows Explorer->>Reboot your PC->>Rerun Hijackthis and post a fresh log

Thanks bamajim
Thank you very much Mr. Benjamin… I have been free of pop ups from google after I did what you asked me to do yesterday… Now I removed everything you asked me today except Xmanager. Please let me know if I should still remove it because I use Xmanager to operate my UNIX machine from my laptop. Its a genuine and useful program and let me know if its been having some problems.. Once again thank you very much to you for helping me to correct my PC problems.. I am pasting the latest hijack this file below. Logfile of HijackThis v1.99.1 Scan saved at 4:05:34 PM, on 11/23/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\PROGRA~1\SPYWAR~1\swdoctor.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\DELL\Desktop\Tools\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
Dear Bamajim, I have got a new problem with my computer.. When I try to open Yahoo Messenger I am getting a YahooMessenger.exe Application error. The error messge is " The instruction at 0x004063e5 referenced memory at 0x01122008. The memory could not be read. Click OK to terminate program."" I reinstalled the yahoo twice,but dint work. Please help me with this too..
vadakkemury The one in question C:\Program Files\Xmanager1.3.9 It is corrupt. I think it best to remove it then download a clean copy. Once that is done, reply and we will move on. As far as the Yahoo issue, lets finish the cleaning and we will address that one. thanks bamajim
OK.. thanks for your advice… I removed Xmanager too.. I am pasting the hijack this log file below.. Please let me know what I should do next….

Logfile of HijackThis v1.99.1
Scan saved at 5:13:47 PM, on 11/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
E:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\DELL\Desktop\Tools\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wwwcache.ed.ac.uk/config/proxy-config.pac
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
vadakkemury

Go here and Download AVG Anti-Spyware
(30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menuUnder "Your computers Security"
Click change status on Resident shield to inactive
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tabUnder How to act? Set default action for detected malwareTo Quarantine
Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlited
Exit AVG(But do not run it yet)
 
Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
Run AVG Anti-SpywareClick scanner
Select Complete system scan
Once the scan finishes
Select Apply all actions (The items found will be quarantined)
Click save report as (Another window will open)
Save it to your desktop
(By default It will be saved in the AVG folder as)
C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
 
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.Double click the report-scan txt. you saved to your desktop
It will open in Notepad
Copy and paste that report as a reply to this thread
Your reply should includea fresh Hijackthis log
your report_scan.txt log from AVG
Thanks bamajim
I am done with the scanning…….. following are the reports…

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:29:19 AM 11/26/2006

+ Scan result:



C:\System Volume Information\_restore{BF77C1E1-ED57-44E3-95F6-8E6A1ED9A97B}\RP218\A0051173.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{BF77C1E1-ED57-44E3-95F6-8E6A1ED9A97B}\RP218\A0051174.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\DELL\Cookies\dell@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.27:C:\Documents and Settings\DELL\Application Data\Mozilla\Firefox\Profiles\17v0vsvd.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.28:C:\Documents and Settings\DELL\Application Data\Mozilla\Firefox\Profiles\17v0vsvd.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\DELL\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken.


::Report end



Hijack This Log..

Logfile of HijackThis v1.99.1
Scan saved at 10:38:34 AM, on 11/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\DELL\Desktop\Tools\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wwwcache.ed.ac.uk/config/proxy-config.pac
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe

Please lemme know what I should do now………..
Dear Bamajim, PC is running smooth and the only problem I have now is following.. When I try to open Yahoo Messenger I am getting a YahooMessenger.exe Application error. The error messge is " The instruction at 0x004063e5 referenced memory at 0x01122008. The memory could not be read. Click OK to terminate program."" I reinstalled the yahoo twice,but dint work. Please help me with this too..
vadakkemury

Lets see what we can do. Lets remove whats left of that program, then see if you can reinstall it.

First open Task Manager (Rt click a blank space on your lower toolbar->>Taskmanager)
Under the prcesses tab Locateymsgr_tray.exe
Higlight and Select End Process and close Taskmanager Next Go to Add/Remove programs and uninstall Yahoo Messenger
And every other program with Yahoo in it's name

Close Add/Remove programs

Next Rerun Hijackhtis (scan only) and place checks beside the follwoing entriesR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

Close all other open windows except Hijackthis and Select "Fix checked" and close Hijackthis

Next Using Windows Explorer(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following folderC:\Program Files\Yahoo!<<-ALL FILES AND FOLDERS->>
Close windows explorer->>Reboot your PC

Then get a clean copy of the program and reply with the results
Please note: that of late McAfee has been interfering with downloading legitimate programs. So check and see if it interferes

thanks bamajim
Sorry for the delay in replying.. I am getting the same error message after doing all these.. Here is the fresh hijackthis log Please let me know what else I can try.. Logfile of HijackThis v1.99.1 Scan saved at 12:22:47 PM, on 11/30/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\PROGRA~1\SPYWAR~1\swdoctor.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\DELL\Desktop\Tools\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [Spyware Doctor] E:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI