Ok, I'll try to provice everything I can … First, I ran the smitfraudfix and am posting results here. I have had many many pages of pop-ups and other warnings. I thought I had it cleaned after removing the outlook/p.zip infection with the AVG Antispyware program, but now I have the biohazard desktop. If someone could please look this over and provide me with the next step I would GREATLY appreciate it. Oh, by the way, this was "caught" while trying to download a picture of a sailboat on the internet (don't remember the page, but I wouldn't post it anyway for the possibility of inadvertantly infecting someone else)….. It poped open windows Media Player and it sounded like a porn site, but no picture came through… we couldn't close it down and next thing we were infected. I appreciate any help you can give! ————————————— SmitFraudFix v2.274 Scan done at 20:30:44.93, Thu 12/27/2007 Run from C:\Documents and Settings\Charline.CHAR\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\System32\brsvc01a.exe C:\WINDOWS\System32\brss01a.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\Brmfrmps.exe C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\VIA\RAID\raid_tool.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Corel\Corel Graphics 12\Programs\CorelDRW.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FAMTABA.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FARNABA.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\privacy_danger FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Charline.CHAR »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Charline.CHAR\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CHARLI~1.CHA\FAVORI~1 C:\DOCUME~1\CHARLI~1.CHA\FAVORI~1\Error Cleaner.url FOUND ! C:\DOCUME~1\CHARLI~1.CHA\FAVORI~1\Privacy Protector.url FOUND ! C:\DOCUME~1\CHARLI~1.CHA\FAVORI~1\Spyware?Malware Protection.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm" "SubscribedURL"="" "FriendlyName"="Privacy Protection" »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix.exe by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: WAN (PPP/SLIP) Interface DNS Server Search Order: 198.164.30.62 DNS Server Search Order: 198.164.4.62 HKLM\SYSTEM\CCS\Services\Tcpip\..\{C5E6BA49-242D-4053-91DC-3202F3C35A2E}: NameServer=198.164.30.62 198.164.4.62 HKLM\SYSTEM\CS1\Services\Tcpip\..\{C5E6BA49-242D-4053-91DC-3202F3C35A2E}: NameServer=198.164.30.62 198.164.4.62 HKLM\SYSTEM\CS3\Services\Tcpip\..\{C5E6BA49-242D-4053-91DC-3202F3C35A2E}: NameServer=198.164.30.62 198.164.4.62 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Thanks! Kevliman