This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

McAfee download and Windows update issues

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here it is. Tahnks
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromGroup + 20 71BFA1C9 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromGroup + 27 71BFA1D0 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromGroup + 41 71BFA1EA 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromGroup + 43 71BFA1EC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromGroup + 4C 71BFA1F5 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInGroup + 20 71BFA251 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInGroup + 26 71BFA257 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInGroup + 2A 71BFA25B 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInGroup + 2E 71BFA25F 102 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInGroup + 95 71BFA2C6 1 Byte [ 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetMemberAttributesOfGroup + 20 71BFA329 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetMemberAttributesOfGroup + 27 71BFA330 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetMemberAttributesOfGroup + 44 71BFA34D 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetMemberAttributesOfGroup + 46 71BFA34F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetMemberAttributesOfGroup + 4F 71BFA358 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamOpenAlias + 20 71BFA3B1 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamOpenAlias + 26 71BFA3B7 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamOpenAlias + 3A 71BFA3CB 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamOpenAlias + 40 71BFA3D1 62 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamOpenAlias + 7F 71BFA410 1 Byte [ 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamQueryInformationAlias + 20 71BFA491 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamQueryInformationAlias + 29 71BFA49A 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamQueryInformationAlias + 2D 71BFA49E 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamQueryInformationAlias + 48 71BFA4B9 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamQueryInformationAlias + 4A 71BFA4BB 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationAlias + 20 71BFA519 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationAlias + 27 71BFA520 28 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationAlias + 44 71BFA53D 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationAlias + 46 71BFA53F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationAlias + 4F 71BFA548 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteAlias + 4 71BFA585 26 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteAlias + 20 71BFA5A1 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteAlias + 27 71BFA5A8 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteAlias + 41 71BFA5C2 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteAlias + 43 71BFA5C4 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMemberToAlias + 20 71BFA631 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMemberToAlias + 27 71BFA638 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMemberToAlias + 41 71BFA652 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMemberToAlias + 43 71BFA654 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMemberToAlias + 4C 71BFA65D 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromAlias + 20 71BFA6B9 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromAlias + 27 71BFA6C0 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromAlias + 41 71BFA6DA 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromAlias + 43 71BFA6DC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromAlias + 4C 71BFA6E5 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromForeignDomain + 20 71BFA741 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromForeignDomain + 27 71BFA748 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromForeignDomain + 41 71BFA762 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromForeignDomain + 43 71BFA764 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMemberFromForeignDomain + 4C 71BFA76D 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInAlias + 19 71BFA7C2 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInAlias + 27 71BFA7D0 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInAlias + 3E 71BFA7E7 53 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInAlias + 74 71BFA81D 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamGetMembersInAlias + 76 71BFA81F 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMultipleMembersToAlias + 17 71BFA878 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMultipleMembersToAlias + 2E 71BFA88F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMultipleMembersToAlias + 35 71BFA896 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMultipleMembersToAlias + 59 71BFA8BA 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamAddMultipleMembersToAlias + 5B 71BFA8BC 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMultipleMembersFromAlias + 17 71BFA918 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMultipleMembersFromAlias + 2E 71BFA92F 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMultipleMembersFromAlias + 35 71BFA936 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMultipleMembersFromAlias + 59 71BFA95A 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamRemoveMultipleMembersFromAlias + 5B 71BFA95C 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteUser + 20 71BFA9C1 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteUser + 27 71BFA9C8 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteUser + 41 71BFA9E2 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteUser + 43 71BFA9E4 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamDeleteUser + 4C 71BFA9ED 50 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationUser + 5 71BFAAA7 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationUser + 12 71BFAAB4 46 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationUser + 41 71BFAAE3 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationUser + 5C 71BFAAFE 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamSetInformationUser + 62 71BFAB04 20 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiLmChangePasswordUser + 17 71BFB074 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiLmChangePasswordUser + 23 71BFB080 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiLmChangePasswordUser + 3A 71BFB097 43 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiLmChangePasswordUser + 66 71BFB0C3 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiLmChangePasswordUser + 68 71BFB0C5 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangePasswordUser + 5 71BFB10E 12 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangePasswordUser + 12 71BFB11B 55 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangePasswordUser + 4B 71BFB154 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangePasswordUser + 51 71BFB15A 19 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangePasswordUser + 66 71BFB16F 4 Bytes [ 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser + F 71BFB350 30 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser + 2F 71BFB370 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser + 35 71BFB376 3 Bytes [ 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser + 39 71BFB37A 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser + 51 71BFB392 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser3 + B 71BFBA00 2 Bytes [ 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser3 + E 71BFBA03 57 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser3 + 48 71BFBA3D 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser3 + 4F 71BFBA44 34 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser3 + 73 71BFBA68 48 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser2 + B 71BFBADA 2 Bytes [ 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser2 + E 71BFBADD 67 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser2 + 53 71BFBB22 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser2 + 7E 71BFBB4D 37 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamChangePasswordUser2 + A4 71BFBB73 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiSetBootKeyInformation + 20 71BFBB98 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiSetBootKeyInformation + 27 71BFBB9F 31 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiSetBootKeyInformation + 47 71BFBBBF 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiSetBootKeyInformation + 49 71BFBBC1 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiSetBootKeyInformation + 52 71BFBBCA 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiGetBootKeyInformation + 20 71BFBC21 6 Bytes [ 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiGetBootKeyInformation + 27 71BFBC28 25 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiGetBootKeyInformation + 41 71BFBC42 1 Byte [ 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiGetBootKeyInformation + 43 71BFBC44 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiGetBootKeyInformation + 4C 71BFBC4D 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangeKeys + B 71BFBC94 49 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangeKeys + 3F 71BFBCC8 16 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangeKeys + 52 71BFBCDB 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangeKeys + 59 71BFBCE2 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiChangeKeys + 65 71BFBCEE 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamConnectWithCreds + 36 71BFBE6F 70 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamConnectWithCreds + 7E 71BFBEB7 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamConnectWithCreds + 8A 71BFBEC3 7 Bytes [ 00, 00, 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamConnectWithCreds + 92 71BFBECB 35 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamCreateUser2InDomain + 20 71BFBEF0 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamCreateUser2InDomain + 26 71BFBEF6 18 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamCreateUser2InDomain + 3A 71BFBF0A 4 Bytes [ 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamCreateUser2InDomain + 40 71BFBF10 21 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamCreateUser2InDomain + 57 71BFBF27 57 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text …
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiEncryptPasswords + B 71BFC115 5 Bytes [ 00, 00, 00, 00, 00 ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiEncryptPasswords + 11 71BFC11B 8 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiEncryptPasswords + 1A 71BFC124 47 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiEncryptPasswords + 4A 71BFC154 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text C:\Program Files\Internet Explorer\iexplore.exe[3404] SAMLIB.dll!SamiEncryptPasswords + 64 71BFC16E 4 Bytes [ 00, 00, 00, 00 ]
.text …

—- Files - GMER 1.0.12 —-

ADS C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\SentItems\S-1-5-21-887630737-3162568201-1315621338-1003$201c5736afc2221.tif:Xj1phwzh5qcwungrN45kt3kiCe
ADS C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\SentItems\S-1-5-21-887630737-3162568201-1315621338-1003$201c5736afc2221.tif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\Owner\Favorites\AccuWeather.com - Lincolnton, GA Weather Forecast - Local Weather Forecasts.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Black Friday Ads - The OFFICIAL Site for the Hottest Day of the Year.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Buck Stoves and Pool specializing in Buck and Appalachian wood and gas stoves and gas logs,Doughboy swimming pools with prefab.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\Games\Flash Games - eBaum's World - Flash games, online games, action games, puzzle games, strategy games, and more..url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\Games\Free Online Games .com.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\Games\Jardinains!.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\KOS JOTR Medal-Award tracker.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\Nintendo.url:favicon
ADS C:\Documents and Settings\Owner\Favorites\Dakota's Stuff\Nova Warfare Novalogic Tournaments, Gaming & Squads Community - Brought to you by Freaks Network.url:favicon
ADS …

—- EOF - GMER 1.0.12 —-



Logfile of HijackThis v1.99.1
Scan saved at 11:06:30 PM, on 1/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Secure Online Account Numbers\SOAN.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Owner\My Documents\Pete's Stuff\Programs\Ad-Spy ware\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINNT\system32\BhoDshop.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SecureOnlineAccountNumbers] C:\Program Files\Secure Online Account Numbers\SOAN.exe /dontopenmycards
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - C:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119403683843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1121143058593
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAEB8818-608B-40D2-8AD6-193753623CEB} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…876/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4979\SiteAdv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4979\SAService.exe (file missing)
Download and Save blacklight to your desktop.
F-Secure Blacklight: http://www.europe.f-secure.com/exclude/blacklight/blbeta.exe
Double-click blbeta.exe then accept the agreement.
click > scan then > next,
You'll see a list of all items found.
Don't choose for rename yet! I want to see the log first, because legit items can also be present there…
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
Post the contents of the log in your next reply together with a new hijackthislog.
here they are,
01/24/07 17:51:44 [Info]: BlackLight Engine 1.0.55 initialized
01/24/07 17:51:44 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/24/07 17:51:44 [Note]: 7019 4
01/24/07 17:51:44 [Note]: 7005 0
01/24/07 17:51:49 [Note]: 7006 0
01/24/07 17:51:49 [Note]: 7011 1608
01/24/07 17:51:49 [Note]: 7026 0
01/24/07 17:51:49 [Note]: 7026 0
01/24/07 17:51:58 [Note]: FSRAW library version 1.7.1021
01/24/07 18:07:29 [Note]: 7007 0

Logfile of HijackThis v1.99.1
Scan saved at 6:08:56 PM, on 1/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Secure Online Account Numbers\SOAN.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Owner\My Documents\Pete's Stuff\Programs\Ad-Spy ware\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINNT\system32\BhoDshop.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SecureOnlineAccountNumbers] C:\Program Files\Secure Online Account Numbers\SOAN.exe /dontopenmycards
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - C:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119403683843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1121143058593
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAEB8818-608B-40D2-8AD6-193753623CEB} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…876/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4979\SiteAdv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4979\SAService.exe (file missing)
Lets try System Restore: In order to restore your machine, start System Restore. Start->All Programs->Accessories->System Tools->System Restore. Click the radio button that says "Restore my computer to an earlier time" and press next. Select a date from before your system wigged out and then highlight a restore point from that day. Click next. It will forward to a screen giving the details of the restore point you are about to use, if everything looks good to you, click next. Your system will then start the restore process. This can either be a quick or a drawn-out process, depending on how far back the point is, and how much has changed since then. If for some reason you don't like the point you've chosen you can tell Sys Restore to undo the revert, or you can choose a different point and restore to it. Let me know if that works.
Did not get PM before trying restore. Tried restore, first attempt told me that restore could not protect computer to shut down and restart. Did that and tried again this time it went through with restore but told me it could not restore after resarting. What is going on, never had problems before. Thanks; Onegun
Ok here is where I am at, downloaded AVG and installed. Updated and ran scan. 1st attempt locked up an scanning system restore file. Could not get out or close, had to hard reboot. 2nd attempt locked up at same place, had to do same thing to escape. Up to that point nothing found. This is the same place that the other program locked up at(AVG anti spyware). Is it posible to delete just that file, since it seems to be causing problems. Here is the path to it (C:\ system volume information \_restore{cf79470c-79f7-8..\a0157397.rbf}). Here is the latest HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 11:20:31 PM, on 1/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Secure Online Account Numbers\SOAN.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\Pete's Stuff\Programs\Ad-Spy ware\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINNT\system32\BhoDshop.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SecureOnlineAccountNumbers] C:\Program Files\Secure Online Account Numbers\SOAN.exe /dontopenmycards
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - C:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119403683843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1121143058593
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAEB8818-608B-40D2-8AD6-193753623CEB} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…876/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4979\SiteAdv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4979\SAService.exe (file missing)
Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.
OK done as instructed. Ran AVG, nothing found. Also ran defrag. New HJT log.


Logfile of HijackThis v1.99.1
Scan saved at 10:35:08 AM, on 1/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Secure Online Account Numbers\SOAN.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Owner\My Documents\Pete's Stuff\Programs\Ad-Spy ware\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINNT\system32\BhoDshop.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SecureOnlineAccountNumbers] C:\Program Files\Secure Online Account Numbers\SOAN.exe /dontopenmycards
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - C:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119403683843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1121143058593
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAEB8818-608B-40D2-8AD6-193753623CEB} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…876/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4979\SiteAdv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4979\SAService.exe (file missing)
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119403683843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1121143058593
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…876/mcfscan.cab

Close ALL windows and browsers except HijackThis and click "Fix checked"

Reboot.
Can you get the windows updates now?
Done and no keeps getting stuck at checking if computer has latest version of update software. After a few min it changed to another page that has this error [Error number: 0x8DDD0004]. When restarting apopup window came up and had coping file cobrand to startup, also noticed this morning that one also came up but did not notice what it was coping. This is after shut down for a few min. Could it be that something bad has happened and may need to do a repair instal. Here is a new HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 7:52:32 PM, on 1/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CTHELPER.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Secure Online Account Numbers\SOAN.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINNT\system32\fxssvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Owner\My Documents\Pete's Stuff\Programs\Ad-Spy ware\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINNT\system32\BhoDshop.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\ppe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SecureOnlineAccountNumbers] C:\Program Files\Secure Online Account Numbers\SOAN.exe /dontopenmycards
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - C:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://*.download.microsoft.com
O15 - Trusted Zone: http://*.update.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAEB8818-608B-40D2-8AD6-193753623CEB} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4979\SiteAdv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4979\SAService.exe (file missing)
Import registry key.
=====================
Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD Quote Box below to it.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0000031A-0000-0000-C000-000000000046}]
@="ClassMoniker"
[HKEY_CLASSES_ROOT\CLSID\{0000031A-0000-0000-C000-000000000046}\InprocServer32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{0000031A-0000-0000-C000-000000000046}\ProgID]
@="clsid"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\CLSID]
@="{0000031A-0000-0000-C000-000000000046}"


Make sure you add a blank line at the bottom by tapping the enter key

On the desktop, doubleclick fix.reg and allow it to run. Let it merge.

After the machine reboots use Windows Update and see if the problem has
gone away.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI