This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Adaware/Malware problem

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been playing up a lot lately. I found this site and dowloaded Malawarebytes AntiMalware and did a scan of my system. Following is the log. Can anyone tell me how to remove these or at least which ones it would be safe to remove. Any help would be greatly appreciated. Malwarebytes' Anti-Malware 1.28 Database version: 1203 Windows 5.1.2600 Service Pack 2 25/09/2008 11:41:01 PM mbam-log-2008-09-25 (23-40-53).txt Scan type: Full Scan (C:\|) Objects scanned: 128095 Time elapsed: 1 hour(s), 6 minute(s), 27 second(s) Memory Processes Infected: 1 Memory Modules Infected: 2 Registry Keys Infected: 55 Registry Values Infected: 3 Registry Data Items Infected: 0 Folders Infected: 27 Files Infected: 311 Memory Processes Infected: C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\QuickInstallPack.exe (Rogue.Multiple) -> No action taken. Memory Modules Infected: C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\iercpt.dll (Rogue.Multiple) -> No action taken. C:\WINDOWS.0\system32\msxml71.dll (Trojan.FakeAlert) -> No action taken. Registry Keys Infected: HKEY_CLASSES_ROOT\iercpt.iercptbho (Rogue.Multiple) -> No action taken. HKEY_CLASSES_ROOT\TypeLib\{a6fbd2e4-1c7e-4eab-80dd-01de2645566a} (Rogue.Multiple) -> No action taken. HKEY_CLASSES_ROOT\Interface\{59c345ba-3d5e-44e3-9d10-d3848af15d73} (Rogue.Multiple) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{d4cdc21d-43be-4101-a1ef-e379f134771e} (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d4cdc21d-43be-4101-a1ef-e379f134771e} (Rogue.Multiple) -> No action taken. HKEY_CLASSES_ROOT\iercpt.iercptbho.1 (Rogue.Multiple) -> No action taken. HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> No action taken. HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\TypeLib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken. HKEY_CLASSES_ROOT\AppID\{3a9377a6-be7f-485d-908c-d44114691389} (Rogue.Multiple) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000162-9980-0010-8000-00aa00389b71} (Rogue.WinAntivirus) -> No action taken. HKEY_CLASSES_ROOT\AppID\iercpt.DLL (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3p_usec_is1 (Rogue.SecureExpertCleaner) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QuickInstallPack (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=0.2.0 (Adware.VideoEgg) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/updater,version=0.2.0 (Adware.VideoEgg) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoEgg (Adware.VideoEgg) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\quickinstallpack (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SecureExpertCleaner (Rogue.SecureExpertCleaner) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Somefox (Trojan.FakeAlert) -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> No action taken. C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> No action taken. C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> No action taken. C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> No action taken. C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> No action taken. C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> No action taken. C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> No action taken. C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> No action taken. C:\Program Files\Antivirus Protection (Rogue.AntivirusProtection) -> No action taken. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\VideoEgg (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2364 (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2663 (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655 (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\messages (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\3461 (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\3461\resources (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\images (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\messages (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip (Rogue.Multiple) -> No action taken. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SEC (Rogue.SecureExpertCleaner) -> No action taken. Files Infected: C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\iercpt.dll (Rogue.Multiple) -> No action taken. C:\Program Files\VideoEgg\Loader\2364\npvideoegg-loader.dll (Adware.VideoEgg) -> No action taken. C:\WINDOWS.0\system32\msxml71.dll (Trojan.FakeAlert) -> No action taken. C:\Program Files\CORE10k.EXE (Trojan.Agent) -> No action taken. C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken. C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> No action taken. C:\Program Files\Antivirus Protection\antivirusprotection.exe (Rogue.AntivirusProtection) -> No action taken. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\updater.ver (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2364\updater.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2364\libcurlve.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2663\updater.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Updater\2663\libcurlve.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\npvideoegg-publisher.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\VideoEgg_FLVWriter.ax (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\LevelMeter.ax (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\FLVEncoder.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\libpng.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\libcurlve.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\crashRpt.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\lame_enc.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\zlib.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\avcodec.dll (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\report.log (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\dataCollection.tmp (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\remoteblacklist (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\aol_watermark.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\audio_combo.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\audio_source.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\big_gray_logo.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\big_logo_cropped.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\blank_slide.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\button_browse_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\button_browse_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\button_browse_up.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\camcorder_slide.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\camcorders_title.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\corners_bottom_left.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\corners_bottom_right.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\corners_top_right.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done_capture.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done_capture_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done_capture_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\done_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dropshadow_horiz.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dropshadow_vertical.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dropzone.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dv_fast_forward.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dv_pause.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dv_play.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dv_rewind.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\dv_stop.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\email_instructions.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\email_sent.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\email_sent_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\email_sent_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\eraser_cursor.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\file_btn_highlighted.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\file_slide.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\help.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_camcorder.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_camcorder_dark.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_camcorder_light.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_camcorders.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_ff.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_file_dark.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_file_light.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_pause.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_phone_dark.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_phone_light.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_play.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_rewind.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_stop.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_webcam.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_webcam_dark.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_webcam_light.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\icon_webcams.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\loading.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\loading_movie.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\locating.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\logo.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\logo_bottom.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\logo_middle.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\logo_top.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\mobile_slide.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\mobile_slide_disabled.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\movie_placeholder.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\ok.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\ok_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\ok_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_fast_forward.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_fill.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_pause.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_play.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_rewind.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_rewind_disabled.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\player_rewind_to_start.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\playhead.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\powered_by.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\progress.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\refresh_list_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\refresh_list_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\refresh_list_up.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\restart.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\restart_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_capture.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_capture_disabled.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_capture_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_capture_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_over_highlight.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\start_slider.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\stop_capture.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\stop_capture_disabled.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\stop_capture_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\stop_capture_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\stop_slider.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\tab_slide_deselected.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\tape_control.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_camcorder.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_camcorder_highlight.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_file.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_file_highlight.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_phone.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_phone_highlight.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_webcam.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\text_webcam_highlight.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\title.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\upload.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\upload_down.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\upload_from.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\upload_over.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading_fill.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading_high.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading_low.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading_medium.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\uploading_thumbnail.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_gray.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_green.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_high.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_low.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_orange.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_red.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\volume_slider.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\waiting_for_email.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\webcam_slide.png (Adware.VideoEgg) -> No action taken. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Application Data\VideoEgg\Publisher\2655\resources\VideoEgg\images\webcams_title.png (Adware.VideoEgg) -> No action taken.
Howdy millsugar and welcome to the forums,

My name is flashh4 and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
1. If you don't know, stop and ask! Don't keep going on.
2. Please reply to this thread. Do not start a new topic.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)
4. Please note you'll need to have Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
5. Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

If you can do those things, everything should go smoothly

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Note: I am still in training at Malware Removal, however I will be working under the direct supervision of one of our Malware Experts. Any recommendations will first be approved before being given to you. Because of this, there may be a short delay in getting our responses to you, however be assured that we will be working diligently on your problem.

I will be back as soon as possible with a fix !!
In the mean time can you give me an Uninstall list please !!

  • Open HijackThis.
  • Click on the Open the Misc Tools section button.
  • Look under System tools.
  • Click on the Open Uninstall Manager… button.
  • Click on the Save list… button.
  • It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  • Notepad will open. Please post this log in your next reply.


Thanks
Chuck
Howdy millsugar, Your MBAM log shows "No action taken". This usually occurs if you forget to click "Remove Selected" and instead just click "Save Logfile".
Please review these instructions and rescan.

Open MBAM:

[*]Before clicking the Finish button, make sure that these 2 boxes are checked (ticked): Update Malwarebytes' Anti-Malware

Launch Malwarebytes' Anti-Malware
[*]Malwarebytes' Anti-Malware will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update Mirror, select one of the websites and click on Check for Updates.

[*]Select the Scanner tab. Click on Perform full scan, then click on Scan.

[*]Leave the default options as it is and click on Start Scan.

[*]When done, you will be prompted. Click OK, then click on Show Results.

[*]Checked (ticked) all items and click on Remove Selected.

[*]After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.

NEXT


Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.


Post in this topic your next reply:
1. Malwarebytes log/report
2. HJT log/report
3. Uninstall list if not already posted.

Thanks
Chuck
Here is the Malwarebytes log/report. This time I ticked "Remove Selected" Malwarebytes' Anti-Malware 1.28 Database version: 1217 Windows 5.1.2600 Service Pack 2 28/09/2008 5:53:03 PM mbam-log-2008-09-28 (17-53-03).txt Scan type: Full Scan (C:\|) Objects scanned: 120148 Time elapsed: 1 hour(s), 17 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 55 Registry Values Infected: 3 Registry Data Items Infected: 0 Folders Infected: 11 Files Infected: 13 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\iercpt.dll (Rogue.Multiple) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\iercpt.iercptbho (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{a6fbd2e4-1c7e-4eab-80dd-01de2645566a} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{59c345ba-3d5e-44e3-9d10-d3848af15d73} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d4cdc21d-43be-4101-a1ef-e379f134771e} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d4cdc21d-43be-4101-a1ef-e379f134771e} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\iercpt.iercptbho.1 (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{3a9377a6-be7f-485d-908c-d44114691389} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000162-9980-0010-8000-00aa00389b71} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\iercpt.DLL (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3p_usec_is1 (Rogue.SecureExpertCleaner) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QuickInstallPack (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/updater,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SecureExpertCleaner (Rogue.SecureExpertCleaner) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QuickInstallPack (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Somefox (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\Antivirus Protection (Rogue.AntivirusProtection) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SEC (Rogue.SecureExpertCleaner) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\iercpt.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\VideoEgg\Loader\2364\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully. C:\Program Files\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\Antivirus Protection\antivirusprotection.exe (Rogue.AntivirusProtection) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS.0\Application Data\SEC\schedule.dat (Rogue.SecureExpertCleaner) -> Quarantined and deleted successfully. C:\Documents and Settings\Administrator.SUE-YGH8L51RNVA\Local Settings\Application Data\qip\QuickInstallPack.exe (Rogue.Multiple) -> Delete on reboot. C:\WINDOWS.0\system32\I4ivoR34.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully. C:\win_update418.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS.0\system32\filekiller.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\WINDOWS.0\system32\drivers\etc\services (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Here is the HJT log/report

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:22:40 PM, on 28/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS.0\System32\khooker.exe
C:\WINDOWS.0\Hcontrol.exe
C:\WINDOWS.0\LTSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\WINDOWS.0\ATKOSD.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\eMPIA\EM2801\emRemote.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\WINDOWS.0\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.altavista.yellowpages.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bigpond.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = BigPond Dial-Up Residential Internet Explorer
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {C3F50901-871A-4650-85D8-9D53E2534A3B} - C:\Program Files\Pink Ribbon Toolbar\Helper.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: FCTB00107Pos - {7679B913-4B4F-4E84-8A80-E190D08D45E7} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Pink Ribbon Toolbar - {68C70CAA-478A-4E77-ADF7-A4566A68B4AE} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS.0\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS.0\sisUSBrg.exe
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS.0\Hcontrol.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS.0\system32\ALiUSB20.exe
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Reminder] C:\Program Files\SecureExpertCleaner\Reminder.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [BPS Spyware Remover] C:\Program Files\BPS Remover\BPSRem.exe /STARTUP
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: emRemote.lnk = C:\Program Files\eMPIA\EM2801\emRemote.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
Here is the Uninstall list: 3ivx MPEG-4 5.0.2 (remove only) Adobe Acrobat 5.0 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 8.1.1 Adobe Shockwave Player Adobe Stock Photos 1.0 Adobe® Photoshop® Album Starter Edition 3.2 Ahead InCD Ahead InCD EasyWrite Reader Ahead Nero Burning ROM Ahead NeroMIX Ahead NeroVision Express ALi USB2.0 Driver AnyDVD ASUS ATK0100 ACPI UTILITY Audacity 1.2.4 Audio DVD Creator 1.9.0.0 AudioShell 1.2 AVG Free 8.0 AVI Codec Pack AVS DVDMenu Editor 1.0.0.5 AVS Video Tools 5.5 BearShare Bebo - Skype 2.5 BitComet 1.02 Canon CanoScan Toolbox 4.1 Canon ScanGear Toolbox CS 2.2 CaptureWizPro 3.60 Cashflow Manager 2004 ccCommon CCleaner (remove only) Central and Handitax CloneCD CloneDVD2 Codec Pack - All In 1 [removed] Compatibility Pack for the 2007 Office system Computer Based Testing 2.0 ConvertXtoDVD 2.99.9.600 Crystal Reports DivX Codec DivX Converter DivX Player DivX Web Player D-Link DSL-200 ADSL Modem DVD Decrypter (Remove Only) DVD Shrink 3.2 DVD Solution Easy Video Joiner 5.21 e-tax 2007 e-tax 2008 e-tax Baby Bonus 2006 ffdshow Fraps (remove only) Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer GPL MPEG-1/2 DirectShow Decoder Filter GSpot Codec Information Appliance HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB929120) Hotfix for Windows XP (KB952287) J2SE Runtime Environment 5.0 Update 9 Java™ SE Runtime Environment 6 Update 1 Lavasoft Reghance 2.1 LEAD MPEG-4 Video Decoder Lucent Technologies Soft Modem AMR Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft ActiveX Control Pad Microsoft AntiSpyware Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Windows XP Video Decoder Checkup Utility Movie Player Pro ActiveX Control MP3 Player Utilities 1.47 MP3 Player Utilities 3.68 MP3 Player Utilities 4.00 Multimedia Launcher MySpaceIM Norton Internet Security Norton WMI Update Pink Ribbon Toolbar 1.1 PowerDVD PowerProducer QuickTime Registry Mechanic 5.1 Replay AV 8 Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090)
Howdy millsugar,

REMOVE P2P PROGRAMS

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

BearShare
BitComet 1.02


P2P programs

We have noticed that most people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we felt we needed to change our policy on the use of P2P file sharing programs.

* If your helper detects the presence of such programs on your computer he/she will ask you to remove them. We will withdraw our help should you not agree to their removal.
* If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programmes, we will refuse our help.



We do not ask you to do this without reason.

P2P programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P programme is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured programme.

This article from InfoWorld illustrates perfectly the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.


If you have removed the P2P as mentioned above !!

Then post these in your next reply to this topic:
1. Uninstall List
2. New HJT

Thanks
Chuck
Hi Chuck I fully understand what your saying and I'm happy to follow the rules. I have uninstalled those 2 programs. The only way I know how to uninstall anything is to go to MyComputer and use add/remove program. That is what I have done. If they are not uninstalled could you please tell me how to do it. Assuming they are uninstalled, I have done the reports you require. Thank you very much for your help, it is really appreciated. Sue UNINSTALL LIST 3ivx MPEG-4 5.0.2 (remove only) Adobe Acrobat 5.0 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 8.1.1 Adobe Shockwave Player Adobe Stock Photos 1.0 Adobe® Photoshop® Album Starter Edition 3.2 Ahead InCD Ahead InCD EasyWrite Reader Ahead Nero Burning ROM Ahead NeroMIX Ahead NeroVision Express ALi USB2.0 Driver AnyDVD ASUS ATK0100 ACPI UTILITY Audacity 1.2.4 Audio DVD Creator 1.9.0.0 AudioShell 1.2 AVG Free 8.0 AVI Codec Pack AVS DVDMenu Editor 1.0.0.5 AVS Video Tools 5.5 Bebo - Skype 2.5 Canon CanoScan Toolbox 4.1 Canon ScanGear Toolbox CS 2.2 CaptureWizPro 3.60 Cashflow Manager 2004 ccCommon CCleaner (remove only) Central and Handitax CloneCD CloneDVD2 Codec Pack - All In 1 [removed] Compatibility Pack for the 2007 Office system Computer Based Testing 2.0 ConvertXtoDVD 2.99.9.600 Crystal Reports DivX Codec DivX Converter DivX Player DivX Web Player D-Link DSL-200 ADSL Modem DVD Decrypter (Remove Only) DVD Shrink 3.2 DVD Solution Easy Video Joiner 5.21 e-tax 2007 e-tax 2008 e-tax Baby Bonus 2006 ffdshow Fraps (remove only) Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer GPL MPEG-1/2 DirectShow Decoder Filter GSpot Codec Information Appliance HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB929120) Hotfix for Windows XP (KB952287) J2SE Runtime Environment 5.0 Update 9 Java™ SE Runtime Environment 6 Update 1 Lavasoft Reghance 2.1 LEAD MPEG-4 Video Decoder Lucent Technologies Soft Modem AMR Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft ActiveX Control Pad Microsoft AntiSpyware Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Windows XP Video Decoder Checkup Utility Movie Player Pro ActiveX Control MP3 Player Utilities 1.47 MP3 Player Utilities 3.68 MP3 Player Utilities 4.00 Multimedia Launcher MySpaceIM Norton Internet Security Norton WMI Update Pink Ribbon Toolbar 1.1 PowerDVD PowerProducer QuickTime Registry Mechanic 5.1 Replay AV 8 Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) SiS 900 PCI Fast Ethernet Adapter Driver SiS Audio Driver SiS M650_651_650_740 SPBBC SUPER © Version 2006.19 (FIX) SweetIM For Internet Explorer 3.0b Symantec Script Blocking Installer SymNet Synaptics TouchPad Total Recorder 6.0 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) USB Video/Audio Device Driver WinAVI Video Converter Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live Messenger Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinPcap 4.0 WinRAR archiver WM Recorder + RM Recorder 10.21 Wondershare Photo Collage Studio ([removed]) XP Codec Pack Xvid 1.1.2 final uninstall YV12 QuickTime Codec
HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:56 PM, on 1/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS.0\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS.0\System32\khooker.exe
C:\WINDOWS.0\Hcontrol.exe
C:\WINDOWS.0\LTSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\WINDOWS.0\ATKOSD.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\eMPIA\EM2801\emRemote.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.altavista.yellowpages.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bigpond.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = BigPond Dial-Up Residential Internet Explorer
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {C3F50901-871A-4650-85D8-9D53E2534A3B} - C:\Program Files\Pink Ribbon Toolbar\Helper.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: FCTB00107Pos - {7679B913-4B4F-4E84-8A80-E190D08D45E7} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Pink Ribbon Toolbar - {68C70CAA-478A-4E77-ADF7-A4566A68B4AE} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS.0\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS.0\sisUSBrg.exe
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS.0\Hcontrol.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS.0\system32\ALiUSB20.exe
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Reminder] C:\Program Files\SecureExpertCleaner\Reminder.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [BPS Spyware Remover] C:\Program Files\BPS Remover\BPSRem.exe /STARTUP
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: emRemote.lnk = C:\Program Files\eMPIA\EM2801\emRemote.exe
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1178168450126
O16 - DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} (POLi Pay Online) - https://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E747AFCA-CDBE-4E21-BFBB-7A65A23EAE06}: NameServer = 123.2.6.197 122.148.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

–
End of file - 12434 bytes
Howdy Howdy millsugar, good job so far, lets finish this up !

Now Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

Look for Spyware Remover ( BPS Spyware Remover ) or anything with bulletproof in the description or name. If found, click the "Change/Remove" button to Remove/un-install.


:Remove bad HijackThis entries:
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
      R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
      R3 - URLSearchHook: FCToolbarURLSearchHook Class - {C3F50901-871A-4650-85D8-9D53E2534A3B} - C:\Program Files\Pink Ribbon Toolbar\Helper.dll
      R3 - URLSearchHook: (no name) - - (no file)
      O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
      O2 - BHO: FCTB00107Pos - {7679B913-4B4F-4E84-8A80-E190D08D45E7} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
      O3 - Toolbar: Pink Ribbon Toolbar - {68C70CAA-478A-4E77-ADF7-A4566A68B4AE} - C:\Program Files\Pink Ribbon Toolbar\Toolbar.dll
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      Go to control panel => system => advanced => startup and recovery => settings
      Change the "write debugging information " to "NONE"
      Unless of course you are a software engineer trying to debug your code.
      O4 - HKLM\..\Run: [Reminder] C:\Program Files\SecureExpertCleaner\Reminder.exe
      O4 - HKCU\..\Run: [BPS Spyware Remover] C:\Program Files\BPS Remover\BPSRem.exe /STARTUP
  • Close all open windows and browsers/email, etc…
  • Click on the "Fix Checked" button
  • When completed, close the application.



NEXT


Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK
We will rehide these after the fix !


Useing Windows Explorer by right-clicking the Start button and left clicking Explore navigate to and find the following files: if found, delete the following files: (if present):
C:\Program Files\BPS Remover\BPSRem.exe


Reboot

NEXT


Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 7.


Reboot and post a new HJT log !

Let me know how it running !!

Thanks
Chuck
Hi Chuck here is the latest HJT Log after I followed your instructions. My computer is running great now thanks. Thank you so much for all your help.

Sue

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:39:03 PM, on 5/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS.0\System32\khooker.exe
C:\WINDOWS.0\Hcontrol.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS.0\LTSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS.0\ATKOSD.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\eMPIA\EM2801\emRemote.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.altavista.yellowpages.com.au/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bigpond.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = BigPond Dial-Up Residential Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS.0\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS.0\sisUSBrg.exe
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS.0\Hcontrol.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS.0\system32\ALiUSB20.exe
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: emRemote.lnk = C:\Program Files\eMPIA\EM2801\emRemote.exe
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1178168450126
O16 - DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} (POLi Pay Online) - https://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E747AFCA-CDBE-4E21-BFBB-7A65A23EAE06}: NameServer = 123.2.6.197 122.148.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

–
End of file - 10649 bytes
Just another question. I notice there are a lot of Symantic files there. I no longer use Nortons Anti Virus so would it be ok to get rid of those files? Thanks Sue
Howdy millsugar (Sue), log is looking real good some minor clean up.
Yes we can remove Symantic files !

Download and save Norton Removal Tool to your desktop.

Run it to remove Norton. After this, please restart your computer.


NEXT

Please download JavaRa and unzip it to your desktop.

  • Double-click on JavaRa.exe to start the program.
  • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 7.


Post a New HJT log !

Thanks
Chuck
Hi Chuck

Here is the latest HJT log;

Cheers Sue

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:04 AM, on 9/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS.0\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS.0\System32\khooker.exe
C:\WINDOWS.0\Hcontrol.exe
C:\WINDOWS.0\LTSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\WINDOWS.0\ATKOSD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\eMPIA\EM2801\emRemote.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.altavista.yellowpages.com.au/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bigpond.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = BigPond Dial-Up Residential Internet Explorer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS.0\System32\khooker.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS.0\sisUSBrg.exe
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS.0\Hcontrol.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS.0\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS.0\system32\ALiUSB20.exe
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: emRemote.lnk = C:\Program Files\eMPIA\EM2801\emRemote.exe
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1178168450126
O16 - DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} (POLi Pay Online) - https://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E747AFCA-CDBE-4E21-BFBB-7A65A23EAE06}: NameServer = 123.2.6.197 122.148.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 8846 bytes
Howdy millsugar (Sue), you can remove these:You may keep the Malwarebytes' its a great program, run it about every 4 weeks depending on the amount of surfing you do !

1.FIX HIJACKTHIS ENTRIES
Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar … /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab


Then close all windows except Hijackthis and click Fix Checked
Close HijackThis.



NEXT



Congratulation you are clean !!!

Disable and Enable System Restore. - If you are using Windows XP or Vista then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide


Re-enable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety



Free Antivirus; I use Avast !!
avast! 4 Home Edition
AntiVir Free Edition


Free firewalls:
1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")
2) Online Armor
3) PC Tools
4) Sunbelt/Kerio
5) ZoneAlarm (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.


Stand Up and Be Counted —> Malware Complaints <— where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing !

How is it running,any problems ??

Thanks
Chuck

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI