This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacktihs log...need help to understand...

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I do not know what I'm looking at, or for…but my comp. is very slow.
Hp compaq nc 8000, 1,4GHz, 1 Gig ram,

please help…does the log look ok??

Logfile of HijackThis v1.99.1
Scan saved at 14:45:13, on 23.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
D:\Programfiler\ZoneAlarm\zlclient.exe
C:\Programfiler\Messenger\MSMSGS.EXE
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
D:\PROGRA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\lvcomsx.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe
D:\Programfiler\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - d:\programfiler\steganos internett anonym 2006\sia2006iep.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Programfiler\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programfiler\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programfiler\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [SMSystemAnalyzer] "D:\Programfiler\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programfiler\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Create sURL - D:\Programfiler\Avant Browser\Extensions\Misc\lusURL.htm
O8 - Extra context menu item: Add to Restricted sites - D:\Programfiler\Avant Browser\Extensions\Misc\msZones_R.htm
O8 - Extra context menu item: Add to Trusted sites - D:\Programfiler\Avant Browser\Extensions\Misc\msZones_T.htm
O8 - Extra context menu item: Copy as HTML - D:\Programfiler\Avant Browser\Extensions\Misc\msCopyAsHTML.htm
O8 - Extra context menu item: Copy Image URL - D:\Programfiler\Avant Browser\Extensions\Misc\msCopyImageURL.htm
O8 - Extra context menu item: Create sURL - D:\Programfiler\Avant Browser\Extensions\Misc\lusURL_text.htm
O8 - Extra context menu item: Dictionary Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luDictionary.htm
O8 - Extra context menu item: Dissect Selected Link - D:\Programfiler\Avant Browser\Extensions\Misc\msDissect.html
O8 - Extra context menu item: Dissect Selected Text - D:\Programfiler\Avant Browser\Extensions\Misc\luDissect_text.htm
O8 - Extra context menu item: Dissect this page - D:\Programfiler\Avant Browser\Extensions\Misc\luDissect.htm
O8 - Extra context menu item: Download all links using BitComet - res://G:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://G:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://G:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Encarta Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luEncarta.htm
O8 - Extra context menu item: Fyll Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Get The Referer! - D:\Programfiler\Avant Browser\Extensions\Misc\Get The Referer!.url
O8 - Extra context menu item: Google Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luGoogle.htm
O8 - Extra context menu item: Lagre Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Lookup link on SiteAdvisor - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA_link.htm
O8 - Extra context menu item: Lookup site on SiteAdvisor - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA_text.htm
O8 - Extra context menu item: Open frame in new window - D:\Programfiler\Avant Browser\Extensions\Misc\msBOOF.htm
O8 - Extra context menu item: Open URL - D:\Programfiler\Avant Browser\Extensions\Misc\OpenURL.htm
O8 - Extra context menu item: Passord Generator - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RoboForm Verktøylinje - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Open Browser Windows - D:\Programfiler\Avant Browser\Extensions\Misc\mSaveOpenWindows.htm
O8 - Extra context menu item: Search AB Forums - D:\Programfiler\Avant Browser\Extensions\Lookup\luABF.htm
O8 - Extra context menu item: Send To Notepad - D:\Programfiler\Avant Browser\Extensions\Misc\SendToNotepad.htm
O8 - Extra context menu item: SiteAdvisor Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA.htm
O8 - Extra context menu item: Tilpass Meny - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Translate page with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish.htm
O8 - Extra context menu item: Translate selected text with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish_text.htm
O8 - Extra context menu item: Translate selected text with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle_text.htm
O8 - Extra context menu item: Translate URL with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish_URL.htm
O8 - Extra context menu item: Translate URL with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle_URL.htm
O8 - Extra context menu item: Translate with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle.htm
O8 - Extra context menu item: Verify Webpage Location - D:\Programfiler\Avant Browser\Extensions\Misc\Verify Webpage Location.url
O8 - Extra context menu item: Wikipedia Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luWikipedia.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fyll ut skjemaer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Lagre - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Lagre Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Generer - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra 'Tools' menuitem: Passord Generator - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Verktøylinje - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - http://www.buypass.no/Installasjoner/Buypa…ogram/setup.exe
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O18 - Protocol: bw+0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Programfiler\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I do not know what I'm looking at, or for…but my comp. is very slow.
Hp compaq nc 8000, 1,4GHz, 1 Gig ram,

please help…does the log look ok??

Logfile of HijackThis v1.99.1
Scan saved at 14:45:13, on 23.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
D:\Programfiler\ZoneAlarm\zlclient.exe
C:\Programfiler\Messenger\MSMSGS.EXE
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
D:\PROGRA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\lvcomsx.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe
D:\Programfiler\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - d:\programfiler\steganos internett anonym 2006\sia2006iep.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Programfiler\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programfiler\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programfiler\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [SMSystemAnalyzer] "D:\Programfiler\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programfiler\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Create sURL - D:\Programfiler\Avant Browser\Extensions\Misc\lusURL.htm
O8 - Extra context menu item: Add to Restricted sites - D:\Programfiler\Avant Browser\Extensions\Misc\msZones_R.htm
O8 - Extra context menu item: Add to Trusted sites - D:\Programfiler\Avant Browser\Extensions\Misc\msZones_T.htm
O8 - Extra context menu item: Copy as HTML - D:\Programfiler\Avant Browser\Extensions\Misc\msCopyAsHTML.htm
O8 - Extra context menu item: Copy Image URL - D:\Programfiler\Avant Browser\Extensions\Misc\msCopyImageURL.htm
O8 - Extra context menu item: Create sURL - D:\Programfiler\Avant Browser\Extensions\Misc\lusURL_text.htm
O8 - Extra context menu item: Dictionary Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luDictionary.htm
O8 - Extra context menu item: Dissect Selected Link - D:\Programfiler\Avant Browser\Extensions\Misc\msDissect.html
O8 - Extra context menu item: Dissect Selected Text - D:\Programfiler\Avant Browser\Extensions\Misc\luDissect_text.htm
O8 - Extra context menu item: Dissect this page - D:\Programfiler\Avant Browser\Extensions\Misc\luDissect.htm
O8 - Extra context menu item: Download all links using BitComet - res://G:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://G:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://G:\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Encarta Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luEncarta.htm
O8 - Extra context menu item: Fyll Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Get The Referer! - D:\Programfiler\Avant Browser\Extensions\Misc\Get The Referer!.url
O8 - Extra context menu item: Google Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luGoogle.htm
O8 - Extra context menu item: Lagre Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Lookup link on SiteAdvisor - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA_link.htm
O8 - Extra context menu item: Lookup site on SiteAdvisor - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA_text.htm
O8 - Extra context menu item: Open frame in new window - D:\Programfiler\Avant Browser\Extensions\Misc\msBOOF.htm
O8 - Extra context menu item: Open URL - D:\Programfiler\Avant Browser\Extensions\Misc\OpenURL.htm
O8 - Extra context menu item: Passord Generator - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RoboForm Verktøylinje - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Open Browser Windows - D:\Programfiler\Avant Browser\Extensions\Misc\mSaveOpenWindows.htm
O8 - Extra context menu item: Search AB Forums - D:\Programfiler\Avant Browser\Extensions\Lookup\luABF.htm
O8 - Extra context menu item: Send To Notepad - D:\Programfiler\Avant Browser\Extensions\Misc\SendToNotepad.htm
O8 - Extra context menu item: SiteAdvisor Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luSA.htm
O8 - Extra context menu item: Tilpass Meny - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Translate page with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish.htm
O8 - Extra context menu item: Translate selected text with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish_text.htm
O8 - Extra context menu item: Translate selected text with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle_text.htm
O8 - Extra context menu item: Translate URL with Babelfish - D:\Programfiler\Avant Browser\Extensions\Translators\tBFish_URL.htm
O8 - Extra context menu item: Translate URL with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle_URL.htm
O8 - Extra context menu item: Translate with Google - D:\Programfiler\Avant Browser\Extensions\Translators\tGoogle.htm
O8 - Extra context menu item: Verify Webpage Location - D:\Programfiler\Avant Browser\Extensions\Misc\Verify Webpage Location.url
O8 - Extra context menu item: Wikipedia Lookup - D:\Programfiler\Avant Browser\Extensions\Lookup\luWikipedia.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fyll ut skjemaer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Lagre - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Lagre Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Generer - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra 'Tools' menuitem: Passord Generator - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Verktøylinje - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - http://www.buypass.no/Installasjoner/Buypa…ogram/setup.exe
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O18 - Protocol: bw+0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {727F20FD-B1B2-45B0-9EBB-6B85CC298372} - D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Programfiler\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Illuminati :D

Welcome to Tom Coyote

Please reply to this thread only by using the Add-Reply button and not the New Topic button or else your posts will be all over the forum and we won't be able to keep track of you.

Keep in mind that this forum is for Malware and Virus removal, we don't speed up your computers. I see a slight problem on your log and if by removing it does not help than I can direct you to some tips and support sites that deal with that sort of issue.



We need to disable the Tea Timer in Spybot Search and Destroy as to not interfere with the fix.
  • Open Spybot and go to Mode> Advanced Mode> Tools> Resident and take the checkmark out of Tea Timer
Then Right click on the WinPatrol icon in your system tray and close the program


We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.


Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\BitComet\tools\BitCometBHO.dll

If you or an Administrator set this then leave it alone otherwise fix it
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Download all links using BitComet - res://G:\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://G:\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://G:\BitComet\BitComet.exe/AddLink.htm

O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - http://www.buypass.no/Installasjoner/Buypa…ogram/setup.exe




Delete this entire folder.

G:\BitComet <– You may have to boot to Safemode if it won't let you delete it.

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode




Run this system cleaner


If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



Defrag your Hard Drive.

Go to Start> All Programs> Assessories > System Tools> Disk Defragmenter. This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.


Post a new HJT log and let me know if any of this helped.
Hei igjen….fikk litt bedre hastighet, men tror jeg har mere å gå på…har dobblet minnet (til 1Gig), men slike prog. som FireFox blir ikke kjappere…jeg må vente (ca. 20sec.) før FireFox åpner seg…..og alt av dritt skal etter innstillingene slettes hver gang jeg logger av….ja ja, bedre er det blitt, og jeg vil takke deg for dette…nå blir det "Hijack This"…dette var jo et genialt prog…..spes. når en får hjelp her. Takk!





Logfile of HijackThis v1.99.1
Scan saved at 11:49:13, on 30.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
D:\Programfiler\ZoneAlarm\zlclient.exe
C:\Programfiler\Messenger\MSMSGS.EXE
D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
D:\PROGRA~1\ZONEAL~1\MAILFR~1\mantispm.exe
D:\Programfiler\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Google\Gmail Notifier\gnotify.exe
D:\Programfiler\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - d:\programfiler\steganos internett anonym 2006\sia2006iep.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Programfiler\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programfiler\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [LDM] D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SIA2006] "D:\Programfiler\Steganos Internett Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programfiler\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Fyll Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Lagre Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Passord Generator - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RoboForm Verktøylinje - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Tilpass Meny - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fyll ut skjemaer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Lagre - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Lagre Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Generer - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra 'Tools' menuitem: Passord Generator - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Verktøylinje - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Programfiler\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
He he….wrote in Norwegian…where's my head? I got a better speed on the computer, but not much…I've dubbled the memory (to 1gig), but prog.'s like Firefox uses about 20 sec.(!) to open…and all the trash is supposed to be deleated at once (every time) i shut down Firefox…well well…It's become better, and I'd like to thank you for that, now Hijck This is a basic prog. on my computer from now on….Thanks a lot!! Enjoy the day…and please tell me if there's more I can do with my comp. to make it faster…. Is there a prog. to test the battery? I need a nev one…….I guess…..
Lets try a few more things.

Remove these with HJT
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)



  • Open Hijackthis
  • Click on Misc Tools
  • Click on Uninstall Manager
  • Click on Save List
  • The list will open in Notepad
  • Copy and Paste the List into this thread.

Make sure windows is still enabled to show all files and folders and look in C:\Program Files for the Morpheus Tool Bar and delete it if its present.


Then post the Uninstall list and a new HJT log.
Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Adobe Reader 7.0.9 Agere Systems AC'97 Modem AI RoboForm (All Users) Apple Software Update Ashampoo WinOptimizer Platinum 3 ATI Control Panel ATI Display Driver Bikinicom_Groups_SS1 Screen Saver Buypass Smartkortstøtte Canon MP Drivers Canon Utilities Easy-PhotoPrint CCleaner (remove only) Drivrutiner for Logitech Camera Google Earth Google Gmail Notifier HijackThis 1.99.1 Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hurtigreparasjon for Windows XP (KB914440) Infra Recorder iolo technologies' System Mechanic Professional 7 IrfanView (remove only) iTunes J2SE Runtime Environment 5.0 Update 9 K-Lite Codec Pack 2.77 Standard Logitech Desktop Messenger Logitech iTouch Programvare Logitech MouseWare 9.79 Logitech QuickCam Software Messenger Plus! Live Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 1.1 Norwegian Language Pack Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider-pakke Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Mozilla Firefox (2.0.0.1) MSXML 4.0 SP2 (KB927978) O2Micro MemoryCardBus Windows Driver OpenOffice.org 2.1 Oppdatering for Windows XP (KB904942) Paradise Poker Picasa 2 PowerArchiver 2006 v9.64 Quick Launch Buttons 4.10 D1 QuickTime Screensavers Installer Version 2 Security Update for Microsoft .NET Framework 2.0 (KB917283) Security Update for Microsoft .NET Framework 2.0 (KB922770) Sikkerhetsoppdatering for Windows Media Player 6.4 (KB925398) Sikkerhetsoppdatering for Windows XP (KB913433) Sikkerhetsoppdatering for Windows XP (KB923689) Sikkerhetsoppdatering for Windows XP (KB923694) Sikkerhetsoppdatering for Windows XP (KB925454) Sikkerhetsoppdatering for Windows XP (KB926255) Skype 2.5 SoundMAX Spybot - Search & Destroy 1.4 Steganos Internet Anonym 2006 (8.0.1) Synaptics Pointing Device Driver VideoLAN VLC media player 0.8.6 WebEx Windows Internet Explorer 7 Windows Live Messenger Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Service Pack 2 WinMac World of Warcraft Yahoo! Messenger ZoneAlarm Security Suite p.s. thanks for doing this…
Lets run this free AV scan from Panda, it will show most things that may be hidden on your system.

Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
Since you are on a slow connection it will take about 15 minuites for the scanner to load.
10. Click on "Local Disks" to start the scan
11. Once scan is done, click "see report" then "save report"
Save the log someplace.
12. reboot
13. Post Panda scan results in your next reply


If Panda does not show anything bad I can direct you to some support sites that deal with slow computers.

Let me see the Panda log and a New HJT log
HJT:

Logfile of HijackThis v1.99.1
Scan saved at 01:07:29, on 01.02.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
D:\Programfiler\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Programfiler\Messenger\MSMSGS.EXE
D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
D:\Programfiler\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - d:\programfiler\steganos internett anonym 2006\sia2006iep.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Programfiler\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programfiler\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [LDM] D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SIA2006] "D:\Programfiler\Steganos Internett Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programfiler\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Fyll Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Lagre Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Passord Generator - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RoboForm Verktøylinje - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Tilpass Meny - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fyll ut skjemaer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Lagre - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Lagre Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Generer - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra 'Tools' menuitem: Passord Generator - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Verktøylinje - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Programfiler\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Panda :


Incident Status Location

Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.adtech.de/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.mediaplex.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Programdata\Orca Browser\Profiles\cookies.txt[.2o7.net/]
Potentially unwanted tool:Application/MyWebSearch Not disinfected D:\Programfiler\Mozilla Firefox\plugins\NPMorpBr.dll
Lets try a few other things.

Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5


Still in Safemode

You may have the Morpheus Toolbar installed, what I would like you to do is go to C:\Program Files and delete any of these that are present.


MyWebSearch
MorpheusBar
VSToolbar
Toolbar888


D:\Programfiler\Mozilla Firefox\plugins\NPMorpBr.dll

Reboot your computer


Post the AVG report and a new HJT log and let me know what you found or didn't find.
Hi agin.

I'm sorry to say, but there was about 20 malware detections whit AVG (safetymode), but the report needed to be done before my actions….witch I didn't do….but most was cokies.

The computer is getting better after every post here, but FireFox is still some slow (about 10 sec. to open).

Here's the HJT log….after rebooting again (after safemode)

Logfile of HijackThis v1.99.1
Scan saved at 19:00:30, on 01.02.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
D:\Programfiler\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe
C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
D:\Programfiler\ZoneAlarm\zlclient.exe
D:\Programfiler\AVG Anti-Spyware 7.5\avgas.exe
C:\Programfiler\Messenger\MSMSGS.EXE
D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
D:\PROGRA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\System32\alg.exe
D:\Programfiler\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - d:\programfiler\steganos internett anonym 2006\sia2006iep.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programfiler\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinPatrol] D:\Programfiler\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Programfiler\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Programfiler\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [LDM] D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SIA2006] "D:\Programfiler\Steganos Internett Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Programfiler\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programfiler\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Fyll Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Lagre Skjema - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Passord Generator - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RoboForm Verktøylinje - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Tilpass Meny - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Fyll ut skjemaer - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fyll Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Lagre - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Lagre Skjema - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Generer - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra 'Tools' menuitem: Passord Generator - {320AF880-6646-11D3-ABEE-C5DBF3571F50} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Verktøylinje - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programfiler\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Programfiler\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programfiler\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programfiler\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Programfiler\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programfiler\fellesfiler\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
…just a question…. Is there any program I should have, or programs I shouldn't have? …or to put it like this….what's the "must have" prog.'s….safety - local, and on the net. Trojan killers etc etc…. Asyou see, I bought "Zonealarm Internett Security", but do I need WinPatrol, System mechanics, etc etc.
Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - (no file)



  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Java website and download and install the update.
  • Java Runtime Environment (JRE) 6 <–This is what you need to download and install.
  • If you do an Online installation, it will install automatically.
  • If you do an Offline installation, you will have to save the setup file to your hard disk and run it. Your call.
  • Then after install you can verify your installation here Sun Java Verify
I like to do an Offline Installation and save the setup file in case I need it in the future




AVG is yours to keep after the trial, you can still check for updates, run scans and remove what it finds, you will just lose the background guard feature. So its your call if you want to keep it or not.

I like WinPatrol but I keep mine deactivated and use it just when I want.



Windows Tech Support Forums

Tom Coyote <– Our own forum
PcPitStop <– You can take your system in for a checkup here.
Bleeping Computer <–Good XP Forum
Windows Helpnet <– Excellent XP Forum
Hardwareguys <– Another good one


IE Freezes
It's Not Always Malware
Speedup Windows
TechBuilder
Windows Tips
Techruler
Kellys Korner



How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI