This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 5:12:05 PM, on 12/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\keith\LOCALS~1\Temp\Rar$EX01.281\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: - {2560B574-29BE-4CC7-8A44-F263FD4FE3E1} - C:\WINDOWS\lbbho.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Copperhead] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe





I have this pre-release Microsoft office MUI Edotopm (Enlish) [pre-release] in my add and remove under control panel that can't be delete. if you have any idea how please gice me some help thanks.
I just did a AVG Antio-Spyware 7.5 scan trying to fix my problem and it found a Trojan.Mezzia. I know your not suppose to reply to ur post but I reply since i found this.New hijack log. Also I still have the problem with Microsoft office beta which I cant remove from my add & remove under control panel since it doesnt have the button of change or remove under the programs….I tryed to GOOGLE it myself but can't find anything about this problem..




Logfile of HijackThis v1.99.1
Scan saved at 3:49:00 PM, on 12/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\keith\LOCALS~1\Temp\Rar$EX00.359\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: - {2560B574-29BE-4CC7-8A44-F263FD4FE3E1} - C:\WINDOWS\lbbho.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Copperhead] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/K
krome8800

Welcome to Tom Coyote, sorry for the delay

You are running Hijackthis from a temp or unzipped location. Hijackthis creates backups that we may need, which could be easily lost or deleted from a temp location, so

Click http://ralphcaddell.com/Uploads/HjThis.exe to download a self extractable version of hijackthis.Double-click on hijackthis.exe to extract hijackthis to folder c:\hijackthis.
It will extract it to that folder and open the folder for you.
It will also create a shortcut on your desktop to Hijackthis.
Then run Hijackthis Select Scan and save logfile

When the scan complete's it will open in Notepad. Press Cntrl+A, Rt Click to copy and past that log as a reply to this thread

Next Re Run HijackthisAt the Main window select "Open the misc tool section"
Then select "Open uninstall manager"
Then "save list" and save it to your desktop
Copy and paste that list as a reply to this thread

Your reply should includea fresh Hijackthis log
your uninstall_list.txt from Hijackthis
thanks bamajim
Logfile of HijackThis v1.99.1
Scan saved at 10:01:39 PM, on 12/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\Program Files\QuickTime\qttask.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: - {2560B574-29BE-4CC7-8A44-F263FD4FE3E1} - C:\WINDOWS\lbbho.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Copperhead] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

3DMark05
Ad-Aware SE Personal
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0.1
Adobe Reader Korean Fonts
AnalogX MaxMem
AnyDVD
AOL Uninstaller (Choose which Products to Remove)
Apple Software Update
AVG Anti-Spyware 7.5
Azureus
Battlefield 2142
Brother MFL-Pro Suite
Call of Duty
Call of Duty - United Offensive
Call of Duty® 2
Call of Duty® 2 Mod Tools
CCHelp
CCScore
CloneDVD 3.9.1
Doom 3
DVD-CLONER V3.06 Build 889
ESSAdpt
ESSANUP
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSvpaht
ESSvpot
ewido anti-malware
Far Cry
FEARCombat
Futuremark Measurement Services Client
HijackThis 1.99.1
Hitman 2 Silent Assassin
HLPIndex
HLPRFO
iMesh
iMesh 5
iPod for Windows 2006-01-10
iTunes
J2SE Runtime Environment 5.0 Update 6
Kaput Version 4
Kodak EasyShare software
KSU
LimeWire 4.10.9
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft DirectX 9.0 SDK
mIRC
Mozilla Firefox (1.5.0.8)
Nero 7 Demo
Notifier
NVIDIA Drivers
OTtBP
PaperPort
PCDADDIN
PCDHELP
PCDLNCH
Presto! ImageFolio 4.2
Presto! Mr. Photo
Presto! VideoWorks 4.5
Prey
QuickTime
Razer Copperhead
Razer Copperhead
RCON 4 Call Of Duty 2 V1.0 (10/Nov/05)
Realtek AC'97 Audio
Scrapbooks Plus
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Seismovision 3 (remove only)
SFR
SFR2
Spy Sweeper
Spybot - Search & Destroy 1.4
Steam™
TeamSpeak 2 RC2
The Godfather™ The Game
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Ventrilo Client
Viewpoint Media Player
Webcam Basic
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Related
Windows XP Service Pack 2
WinRAR archiver
Xfire (remove only)
Yahoo! Messenger
krome8800

Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
Next Go to Add/Remove programs (Click Start->>Control Panel->>Add/Remove Programs)
And uninstall the following programWindows XP Related
And as an optional removalLimeWire 4.10.9 <<-THIS ARTICLE->>
If you decide to keep the LimeWire program, at the very least turn it off untill your PC is clean

Close Add/Remove programs->>Reboot your PC->>Rerun Hijcakthis and post a fresh log

thanks bamajim
Ok did what you said I did get rid of LimeWire but when i tried to get rid of the Windows Xp Related I got the following message. Error loading C:\Windows\lbbho.dll The Specified module could not be found. So this is why there is not new Log.
krome8800

We will do it another way

Go HERE and Download System Repair Engine by smallfrogsSave it to your Desktop
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread
Do not run any other options with this tool unless instructed to do so.

thanks bamajim
Here you go. 2006-12-08,21:05:23 System Repair Engineer 2.2.6.605 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed Follow item(s) have been choosed: All Boot Items (Including Registry, Startup Folders, Services and so on) Browser Add-ons Runing Processes (Including process model information) File Associations Winsock Provider Autorun.Inf HOSTS File Boot Items Registry [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] <"c:\program files\steam\steam.exe" -silent> [Valve Corporation] [(Verified)Microsoft Corporation] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [Ahead Software Gmbh] [Sun Microsystems, Inc.] <"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot> [Scansoft, Inc.] [ScanSoft, Inc.] [(Verified)NVIDIA Corporation] [N/A] <"C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.] [N/A] [N/A] <"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{54D9498B-CF93-414F-8984-8CE7FDE0D391}> [N/A] <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}> [Anti-Malware Development a.s.] ================================== Startup Folders N/A ================================== Services [AVG Anti-Spyware Guard / AVG Anti-Spyware Guard] [Brother Popup Suspend service for Resource manager / brmfrmps] <"C:\WINDOWS\system32\Brmfrmps.exe" -service > [BrSplService / Brother XP spl Service] [ewido security suite control / ewido security suite control] [InstallDriver Table Manager / IDriverT] <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"> [iPod Service / iPod Service] <"C:\Program Files\iPod\bin\iPodService.exe"> [Kodak Camera Connection Software / KodakCCS] [NVIDIA Display Driver Service / NVSvc] [STI Simulator / STI Simulator] ================================== Drivers [Service for Realtek AC97 Audio (WDM) / ALCXWDM] [AnyDVD / AnyDVD] [Aspi32 / Aspi32] [AVG Anti-Spyware Driver / AVG Anti-Spyware Driver] <\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys> [AVG Anti-Spyware Clean Driver / AvgAsCln] [Brother USB Still Image driver / BrScnUsb] [Kodak Camera Proxy / DcCam] [DcFpoint / DcFpoint] [Kodak DCFS2K Driver / DCFS2K] [Legacy Polling Service / DcLps] [DcPTP / DcPTP] [dtscsi / dtscsi] <\SystemRoot\System32\Drivers\dtscsi.sys> [ElbyCDIO Driver / ElbyCDIO] [ENTECH / ENTECH] <\??\C:\WINDOWS\System32\DRIVERS\ENTECH.sys> [Exportit / Exportit] [GEARAspiWDM / GEARAspiWDM] [InCD File System / InCDFs] [InCDPass / InCDPass] [InCD Reader / InCDRm] [ATK0110 ACPI UTILITY / MTsensor] <> [nv / nv] [nvata / nvata] <\SystemRoot\System32\DRIVERS\nvata.sys> [NVIDIA nForce Networking Controller Driver / NVENETFD] [NVIDIA Network Bus Enumerator / nvnetbus] [oreans32 / oreans32] <\??\C:\WINDOWS\system32\drivers\oreans32.sys> [Webcam Basic / PAC207] <> [Low level access layer for CD devices / Pcouffin] [Direct Parallel Link Driver / Ptilink] [PxHelp20 / PxHelp20] <\SystemRoot\system32\DRIVERS\PxHelp20.sys> [Secdrv / Secdrv] [sptd / sptd] <\SystemRoot\System32\Drivers\sptd.sys> [vaxscsi / vaxscsi] <\SystemRoot\System32\Drivers\vaxscsi.sys> ================================== Browser Add-ons [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [ ] {2560B574-29BE-4CC7-8A44-F263FD4FE3E1} [] {53707962-6F74-2D53-2644-206D7942484F} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [&Research] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [Yahoo! Messenger] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [YInstStarter Class] {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} [Java Plug-in] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in] {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [Measurement Services Client v.3.7] {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [AcroIEHlprObj Class] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [ ] {2560B574-29BE-4CC7-8A44-F263FD4FE3E1} [] {53707962-6F74-2D53-2644-206D7942484F} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [Messenger Class] {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A> [&Search] [E&xport to Microsoft Excel] ================================== Running Processes [PID: 656][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 704][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 728][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 776][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 788][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 944][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 1004][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 1104][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 1148][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 1312][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 1560][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)] [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll] [Nero AG, 2, 0, 0, 6] [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A] [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49] [C:\WINDOWS\system32\CmdLineExt.dll] [Sony DADC Austria AG., 1,0,201,0] [C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300] [C:\Program Files\ewido anti-malware\shellhook.dll] [N/A, N/A] [C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47] [C:\PROGRA~1\SPYBOT~1\SDHelper.dll] [Safer Networking Limited, 1, 4, 0, 0] [C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll] [Sun Microsystems, Inc., 5.0.60.5] [C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll] [Nero AG, 2, 0, 0, 8] [PID: 1668][C:\WINDOWS\system32\brsvc01a.exe] [brother Industries Ltd, 1, 0, 0, 3] [PID: 1680][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\brmfpp1.dll] [Brother Industries ,Ltd , 1.10] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\ppbipr.dll] [Black Ice Software, 2.00] [PID: 1696][C:\WINDOWS\system32\brss01a.exe] [brother Industries Ltd, 1.004] [PID: 1920][C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe] [Sun Microsystems, Inc., 5.0.60.5] [PID: 1968][C:\Program Files\iTunes\iTunesHelper.exe] [Apple Computer, Inc., 7.0.0.70] [C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL] [Apple Computer, Inc., 7.0.0.70] [C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] [Apple Computer, Inc., 7.0.0.70] [PID: 1980][C:\Program Files\Razer\Copperhead\razerhid.exe] [, 1, 0, 0, 1] [C:\Program Files\Razer\Copperhead\download.dll] [, 1, 0, 0, 1] [C:\Program Files\Razer\Copperhead\ISPdll.dll] [mot, 1, 0, 0, 1] [PID: 2004][C:\program files\steam\steam.exe] [Valve Corporation, 1.0.0.0] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [C:\program files\steam\Steam.dll] [Valve Corporation, 2.0.0.0] [C:\program files\steam\SteamUI.dll] [N/A, N/A] [C:\program files\steam\tier0_s.dll] [N/A, 1, 0, 0, 1] [C:\program files\steam\vstdlib_s.dll] [Valve Corporation, 3, 0, 0, 1] [C:\program files\steam\steam_api.dll] [N/A, N/A] [C:\program files\Steam\bin\FileSystem_Steam.dll] [Valve Corporation, 3, 0, 0, 1] [C:\program files\Steam\bin\vgui2.dll] [Valve Corporation, 3, 0, 0, 1] [C:\program files\steam\steamclient.dll] [Valve Corporation, 3, 0, 0, 1] [c:\program files\steam\Friends\friendsUI.dll] [Valve Corporation, 3, 0, 0, 1] [c:\program files\steam\Servers\serverbrowser.dll] [N/A, N/A] [C:\WINDOWS\system32\Macromed\Flash\Flash9.ocx] [Adobe Systems, Inc., 9,0,16,0] [PID: 2012][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 620][C:\WINDOWS\system32\Brmfrmps.exe] [Brother Industries, Ltd., 1.10.10.144] [PID: 680][C:\Program Files\ewido anti-malware\ewidoctrl.exe] [ewido networks, 3, 0, 0, 1] [C:\Program Files\ewido anti-malware\lang.dll] [privat, 1, 0, 0, 1] [PID: 904][C:\WINDOWS\system32\drivers\KodakCCS.exe] [Eastman Kodak Company, 1.1.5100.4] [PID: 1068][C:\WINDOWS\System32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.8185] [PID: 1224][C:\WINDOWS\System32\PAStiSvc.exe] [N/A, N/A] [PID: 1428][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\BrWia04a.dll] [Brother Industries, Ltd., 3.0.5.0 built by: WinDDK] [C:\WINDOWS\System32\BrUSi04a.dll] [Brother Industries, Ltd., 1, 0, 0, 1] [PID: 1568][C:\WINDOWS\System32\wdfmgr.exe] [Microsoft Corporation, 5.2.3790.1230 built by: dnsrv(bld4act)] [PID: 2108][C:\Program Files\iPod\bin\iPodService.exe] [Apple Computer, Inc., [removed]] [C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL] [Apple Computer, Inc., 7.0.0.70] [C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] [Apple Computer, Inc., 7.0.0.70] [PID: 2456][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 2668][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2820][C:\Program Files\Razer\Copperhead\razerofa.exe] [Razer Inc., 4.0.0.4] [PID: 2980][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] [PID: 2488][C:\Program Files\mIRC\mirc.exe] [mIRC Co. Ltd., 6.17] [C:\Program Files\mIRC\script\dlls\nnscript.dll] [N/A, N/A] [C:\Program Files\mIRC\script\dlls\winevent.dll] [N/A, N/A] [C:\Program Files\mIRC\script\dlls\mdx.dll] [DragonZap, 0.91b] [C:\Program Files\mIRC\script\dlls\views.mdx] [DragonZap, 0.91b] [C:\Program Files\mIRC\script\dlls\ctl_gen.mdx] [DragonZap, 0.91b] [C:\Program Files\mIRC\script\dlls\bars.mdx] [DragonZap, 0.91b] [C:\Program Files\mIRC\script\dlls\dialog.mdx] [DragonZap, 0.91b] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [PID: 1424][C:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.8.0.8: 2006102516] [C:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0] [C:\Program Files\Mozilla Firefox\nspr4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\xpcom_core.dll] [Mozilla Foundation, 1.8.0.8: 2006102516] [C:\Program Files\Mozilla Firefox\plc4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\plds4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\smime3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\nss3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\softokn3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\ssl3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\xpcom_compat.dll] [Mozilla Foundation, 1.8.0.8: 2006102516] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] [C:\Program Files\Mozilla Firefox\components\jar50.dll] [Mozilla Foundation, 1.8.0.8: 2006102516] [C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll] [N/A, N/A] [C:\Program Files\Mozilla Firefox\xpcom.dll] [Mozilla Foundation, 1.8.0.8: 2006102516] [C:\Program Files\Mozilla Firefox\nssckbi.dll] [Netscape Communications Corporation, 1.53] [C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTime.qts] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\CoreVideo.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeAudioSupport.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeAuthoring.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeCapture.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeEffects.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeEssentials.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeH264.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeImage.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeInternetExtras.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.qtx] [Apple Computer, Inc, 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeMusic.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeQD3D.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeStreaming.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx] [Apple Computer, Inc., 7.1.3] [C:\Program Files\QuickTime\QTSystem\QuickTimeVR.qtx] [Apple Computer, Inc, 7.1.3] [PID: 3148][C:\Documents and Settings\keith\Desktop\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605] [C:\WINDOWS\system32\ua_lsp.dll] [N/A, N/A] ================================== File Associations .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock Provider ULTIMATE_ARENA_LSP MSAFD Tcpip [TCP/IP] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD Tcpip [UDP/IP] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD Tcpip [RAW/IP] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP RSVP UDP Service Provider C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP RSVP TCP Service Provider C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD nwlnkipx [IPX] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD nwlnkspx [SPX] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD nwlnkspx [SPX] [Pseudo Stream] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD nwlnkspx [SPX II] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP MSAFD nwlnkspx [SPX II] [Pseudo Stream] C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ULTIMATE_ARENA_LSP C:\WINDOWS\system32\ua_lsp.dll(N/A, N/A) ================================== Autorun.Inf N/A ================================== HOSTS File 127.0.0.1 localhost 127.255.255.255 serial.alcohol-soft.com 127.255.255.255 www.alcohol-soft.com 127.255.255.255 images.alcohol-soft.com 127.0.0.1 Preymaster.humanhead.com ==================================
krome8800

Sorry for the delay, have been out of town.

Rerun SRE2In the Left Pane Select "Boot Items"
In the Rt Pane Select the "Services" tab
Then the "Win32 Services" Button
Locate under Service Nameoreans32 / oreans32
Highlite that Service
Select the Delete Service Radio button
Then Select Set
Another window will open Select No to delete the service
A confirmation window will open Select O.k.
Then close the Win32 Services window
In the Left Pane Select "System Repair"In the Right pane under the "Browser Add-ons" tab
Locate{2560B574-29BE-4CC7-8A44-F263FD4FE3E1}
{2560B574-29BE-4CC7-8A44-F263FD4FE3E1}

The name column will show with no name, but the information will be displayed in the other columns.
If unsure, before deletion, you can higlite the entry and Select the "Detailed Info" button to confirm its the right one
Then Highlite the entries one at a time and Select "Delete Selected"
Close SRE2->>Reboot your PC->>Rerun Hijackthis and post a fresh log

thanks bamajim
Not a problem people have lives understandable. :rant2: J/K In the Left Pane Select "Boot Items" In the Rt Pane Select the "Services" tab Then the "Win32 Services" Button Locate under Service Name oreans32 / oreans32 When I did this I dont see a thing listed in the list name oreans32/oreans32. Unless I'm blind I look at the list a few times…I didnt want to move to the next set until you say too.
Ok skipping the Oreans thing and moved on to the next step. I only found one of the

{2560B574-29BE-4CC7-8A44-F263FD4FE3E1}
here is the new log.

Logfile of HijackThis v1.99.1
Scan saved at 2:51:42 PM, on 12/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\program files\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\System32\svchost.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Copperhead] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE12\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
krome8800

Rerun HijackthisAt the Main window Select "Open the Misc tool Section"
Select "Open Uninstall Manager"
In the left pane LocateWindows XP Related
Highlite and Select "Delete this entry"
Close Hijackthis->>Reboot your PC->>In your reply let me know if you were able to remove the entry

thanks bamajim
No still not able to take this .Misrosoft Office Professional Edition 12 [pre-releaes] when u try an remove it .It says Fatal error during installation. and it has everything now installed Excel,Access, InfoPath,Powerpoint,Proof,Publisher,Shared,Word. Then when u open something that is suppose to open with word or whatever then is say Your beta software has expired. Its killing me. But I did delete the Windows XP related
krome8800

No still not able to take this .Misrosoft Office Professional Edition 12 [pre-releaes]

Forgive me I'm not fimilar with that product. Are you talking about Office 2007 BETA?

I see no entry in your Uninstall list for Microsoft office at all.
And how are you accessing the program; from a Shortcut, or from the All programs list?

bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI