This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline - trojan.metajuan infection

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks in advance for any help you can provide. Booting my computer normally no longer allows me to do anything, as it is painfully slow. When it does come up successfully, it takes at least 30 minutes for Windows XP to fully boot, and actions are still very slow even then. Everything is continually interrupted by a Trend-Micro PC-cillin window that is continually locating, and deleting, trojan.metajuan.

I've been doing all my troubleshooting, etc. in Safe Mode with Networking, which seems to work fine.

As you suggest, I've run the CC cleaner and Spybot. I also ran AVG antispyware and Lavasoft Ad-Aware.

My Hijack this log follows. Help! Thanks, Kristy.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:44 PM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O1 - Hosts: 63.240.6.184
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [WD NetCenter EasyLink] C:\Program Files\Western Digital Technologies\NetCenter EasyLink\WDEzLink.exe -s
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\RunOnce: [SpybotDeletingC8171] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_15_40_08.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2867] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_21_59_11.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8814] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_21_59_11.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9498] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_12_55_10.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4051] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_12_55_10.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3240] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_16_46_24.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5243] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_16_46_24.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3793] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_09_40_08.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8331] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_09_40_08.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7429] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_17_25_06.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC785] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_17_25_06.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2348] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_08_50_25.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2182] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_08_50_25.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7060] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_09_14_55.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9189] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_09_14_55.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6769] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_12_53_57.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1047] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_12_53_57.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9788] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_09_42_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1355] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_09_42_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2088] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_16_48_58.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2192] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_16_48_58.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8011] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_17_17_23.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7798] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_17_17_23.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9548] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_09_26_27.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4372] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_09_26_27.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3311] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_11_47_41.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3068] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_11_47_41.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6365] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_10_05_50.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3681] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_10_05_50.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4862] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_19_59_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9756] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_19_59_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7548] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_10_10_54.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5791] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_10_10_54.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7904] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_13_49_53.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4633] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_13_49_53.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9941] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_17_39_56.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7863] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_17_39_56.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2877] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_08_13_45_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5386] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_08_13_45_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8091] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_09_12_48.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC437] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_09_12_48.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7405] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_14_00_02.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3360] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_14_00_02.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3440] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_17_18_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8388] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_17_18_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2750] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_10_48_13.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4008] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_10_48_13.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9019] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_17_35_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5591] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_17_35_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4851] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_17_12_31_34.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4086] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_17_12_31_34.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5300] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_43_37.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5689] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_43_37.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5443] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_59_34.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7750] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_59_34.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2340] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_20_43_29.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5925] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_20_43_29.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4891] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_19_13_21_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2484] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_19_13_21_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9400] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_10_51_53.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9729] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_10_51_53.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4265] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_12_49_22.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1155] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_12_49_22.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6451] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_15_07_08.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8955] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_15_07_08.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4318] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_21_47_25.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9132] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_21_47_25.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4871] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_09_00_38.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5292] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_09_00_38.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4679] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_10_41_41.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC492] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_10_41_41.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6410] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_09_49_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC118] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_09_49_18.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7270] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_12_53_03.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2024] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_12_53_03.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA389] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_21_09_46.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6268] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_21_09_46.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6141] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_26_13_34_13.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3850] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_26_13_34_13.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6240] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_11_34_05.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8646] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_11_34_05.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4263] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_15_07_14.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3510] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_15_07_14.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5873] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_17_36_40.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8595] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_17_36_40.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4242] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_09_51_47.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1940] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_09_51_47.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1194] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_20_59_59.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC274] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_20_59_59.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2101] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_08_37_24.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2680] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_08_37_24.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3096] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_45_57.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8584] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_45_57.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4962] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_54_04.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9341] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_54_04.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5426] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_11_24_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6162] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_11_24_21.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8147] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_09_46_00.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6075] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_09_46_00.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5119] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_14_18_16.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5192] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_14_18_16.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5121] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_17_34_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5332] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_17_34_45.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3938] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_08_07_59_58.eklog"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6705] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_08_07_59_58.eklog"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB403] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_13_27_07.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9049] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_13_27_07.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7752] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_07_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1700] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_07_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6229] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_10_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4745] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_10_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6537] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_21_50.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD158] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_14_21_50.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7480] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_15_36_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6517] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_07_15_36_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2257] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_09_41_27.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9524] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_09_41_27.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1446] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_13_11_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1802] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_13_11_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1063] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_18_02_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9514] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_10_18_02_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB144] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_11_14_09_19.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8146] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_11_14_09_19.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5296] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_12_09_42_02.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9638] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_12_09_42_02.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8494] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_12_18_22_56.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9815] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_12_18_22_56.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7726] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_15_13_53_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2618] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_15_13_53_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1782] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_10_04_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9270] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_10_04_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7193] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_15_40_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1926] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_15_40_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4756] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_21_59_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD308] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_17_21_59_11.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6349] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_12_55_10.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5720] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_12_55_10.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9243] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_16_46_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1845] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_19_16_46_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8354] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_09_40_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1436] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_09_40_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2415] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_17_25_06.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD673] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_24_17_25_06.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7738] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_08_50_25.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7352] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_08_50_25.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6497] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_09_14_55.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1945] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_09_14_55.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9321] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_12_53_57.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9173] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_25_12_53_57.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8196] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_09_42_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8081] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_09_42_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6205] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_16_48_58.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9946] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_16_48_58.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6689] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_17_17_23.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8106] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_26_17_17_23.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6283] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_09_26_27.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6849] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_09_26_27.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4579] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_11_47_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD445] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_29_11_47_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1704] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_10_05_50.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9525] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_10_05_50.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7845] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_19_59_18.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2143] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_01_31_19_59_18.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2797] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_10_10_54.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9587] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_10_10_54.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9427] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_13_49_53.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4395] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_13_49_53.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4575] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_17_39_56.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8913] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_07_17_39_56.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6050] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_08_13_45_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3061] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_08_13_45_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1735] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_09_12_48.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4214] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_09_12_48.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB289] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_14_00_02.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3324] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_14_00_02.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6724] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_17_18_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD439] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_09_17_18_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB793] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_10_48_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5857] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_10_48_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB353] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_17_35_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3650] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_14_17_35_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3189] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_17_12_31_34.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9963] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_17_12_31_34.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3764] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_43_37.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1881] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_43_37.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6336] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_59_34.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD370] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_19_59_34.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9469] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_20_43_29.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7621] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_18_20_43_29.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4986] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_19_13_21_18.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6150] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_19_13_21_18.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1755] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_10_51_53.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3257] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_10_51_53.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2463] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_12_49_22.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4618] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_12_49_22.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5334] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_15_07_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7030] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_15_07_08.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1507] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_21_47_25.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7648] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_20_21_47_25.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6281] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_09_00_38.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6102] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_09_00_38.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3792] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_10_41_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4293] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_21_10_41_41.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5973] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_09_49_18.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6506] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_26_13_34_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9219] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_12_53_03.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6548] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_12_53_03.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6333] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_21_09_46.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6662] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_22_21_09_46.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9537] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_26_13_34_13.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4610] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_11_34_05.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5425] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_11_34_05.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB178] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_15_07_14.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6152] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_15_07_14.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8485] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_17_36_40.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD607] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_02_28_17_36_40.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3345] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_09_51_47.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9977] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_09_51_47.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4085] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_20_59_59.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5886] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_02_20_59_59.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5867] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_08_37_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4184] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_08_37_24.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8128] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_45_57.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD132] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_45_57.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8077] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_54_04.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8514] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_10_54_04.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2937] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_11_24_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1885] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_06_11_24_21.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5944] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_09_46_00.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2653] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_09_46_00.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB504] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_14_18_16.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1326] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_14_18_16.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9794] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_17_34_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7061] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_07_17_34_45.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1117] command /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_08_07_59_58.eklog"
O4 - HKCU\..\RunOnce: [SpybotDeletingD500] cmd /c del "C:\Program Files\ErrorKiller\Log\log_2007_03_08_07_59_58.eklog"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 35715 bytes
You could try System Restore. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked.
Well, per the instructions I found on another site, I disabled system restore before I initially booted into safe mode. I think that erased all of my existing restore points…

Well, per the instructions I found on another site, I disabled system restore before I initially booted into safe mode. I think that erased all of my existing restore points…

What stupid site suggested that?
Are you using 2 anti-virus programs? Symantec AntiVirus and Trend Micro 1.Click Start > Settings > Control Panel. 2.Next, open Add/Remove Programs and remove either: Symantec AntiVirus or Trend Micro Also uninstall Spybot as it's stuck trying to remove ErrorKiller\Log\
Thanks again for the help! I uninstalled PC-Cillin, as well as spybot. The PC-Cilling uninstall required a reboot, and interestingly, it booted much more cleanly this time, albeit very slowly. I re-ran hijack this, and here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:16 PM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Western Digital Technologies\NetCenter EasyLink\WDEzLink.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [WD NetCenter EasyLink] C:\Program Files\Western Digital Technologies\NetCenter EasyLink\WDEzLink.exe -s
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 7959 bytes

Thanks!

Kristy
Click Start > Run > and type in:

services.msc

Click OK.

In the services window find COM+ Messages Bonjour Service if listed
Right click and choose "Properties". On the "General" tab under "Service
Status" click the "Stop" button to stop the service. Beside "Startup Type"
in the dropdown menu select "Disabled". Click Apply then OK. Exit the
Services utility.


These aren't bad but not needed at startup

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [WD NetCenter EasyLink] C:\Program Files\Western Digital Technologies\NetCenter EasyLink\WDEzLink.exe -s
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"




You need to update SunJava.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 4
    The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on 6-windowsi586-p.exe to install the newest version.
Once installed you can test to see that it is in fact installed
Sun Java Test
http://www.java.com/en/download/installed.jsp



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Great– I've taken all the actions you mentioned. It is booting much faster now, and I haven't seen any more pop-ups regarding trojan.metajuan. Hopefully, that's everything (although I still think it should boot faster)! The latest Hijack This log is below. Thanks again!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:31 PM, on 2/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 7014 bytes
The only other thing that I see that would help speed it up would be getting rid of Symantec / Nortons, and using a different Anti-Virus.


You can remove any programs / Tools I had you install. Use Add/Remove Programs to remove if listed there otherwise just delete them and empty recycle bin.

Here's my usual all clean post

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.
    You should also scan your computer with this program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI