| spyfalcon virus help me |  | 
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 03:45 |  Link to this message   | 
					
					
					
						| 
							
							I think i have spyfalcon infecting my computer. When i open my internet it is taking me to there home page asking my to buy software to resolve this problem. Ive tried running Adaware,sbybot search and destroy xoftspy and blueyonders own pc gaurd, they are finding this problem ( I think ) and quaratining it but it keeps coming back. I also have an anoying icon of theirs in may task bar. Can anyone please help, But bear in mind i am a real novice with computers. Thanks Inoeos
							
						 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						|  | 
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 06:58 |  Link to this message   | 
					
					
					
						| 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 09:39 |  Link to this message   | 
					
					
					
						| 
							
							thanks tapiira for your help here is copy of the log file  
 
 Logfile of HijackThis v1.99.1
 Scan saved at 18:26:57, on 21/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\blueyonder\PCguard\fws.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Common Files\Command Software\dvpapi.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
 C:\WINDOWS\mHotkey.exe
 C:\WINDOWS\CNYHKey.exe
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 C:\Program Files\Real\RealPlayer\RealPlay.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
 C:\Program Files\blueyonder\PCguard\RPS.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\DitExp.exe
 C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Neil\MYDOCU~1\NEIL'S\PROTEC~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32\hpF475.tmp
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
 O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
 O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\RPS.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
 O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
 O4 - Startup: Registration-Pinnacle Expression.lnk = C:\Program Files\Pinnacle\Pinnacle Expression\EReg\RegTool.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
 O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
 O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
 O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
 O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
 O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 09:54 |  Link to this message   | 
					
					
					
						| 
							
							Ok Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 (Some antiviruses, like nod32 recognises smitfraudfix's process.exe as a malware. It is not malware, it is a program that stops processes)
 
 Then un-plug internet cable.
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Save this textfile to your desktop.
 
 Post the contents of this smitfraudfix textfile to here.
 
 Post a HijackThis log to here (this time, take it in the normal mode)
 
 
 This message has been edited since posting. Last time this message was edited on 21. May 2006 @ 09:55 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 11:40 |  Link to this message   | 
					
					
					
						| 
							
							Hi tapiiri
iam a computer novice and dont no what you mean by " take it in the normal mode" thanks inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 12:10 |  Link to this message   | 
					
					
					
						| 
							
							So in windows  is two different mode Safe mode and Normal mode. You are in normal mode now. 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 12:36 |  Link to this message   | 
					
					
					
						| 
							
							Hi tapiiri heres logs as requested 
SmitFraudFix v2.45
 
 Scan done at 21:22:51.00, 21/05/2006
 Run from C:\Documents and Settings\Neil\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Neil\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Neil\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{a566f298-05a6-4b3d-b672-da7c27316430}"="AutoDisc Ware"
 
 [HKEY_CLASSES_ROOT\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
 @="C:\WINDOWS\system32\htey.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
 @="C:\WINDOWS\system32\htey.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 21:26:10, on 21/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\blueyonder\PCguard\fws.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Common Files\Command Software\dvpapi.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
 C:\WINDOWS\mHotkey.exe
 C:\WINDOWS\CNYHKey.exe
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 C:\Program Files\Real\RealPlayer\RealPlay.exe
 C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
 C:\Program Files\blueyonder\PCguard\RPS.exe
 C:\WINDOWS\DitExp.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Neil\MYDOCU~1\NEIL'S\PROTEC~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32\hpF475.tmp
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
 O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
 O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\RPS.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
 O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
 O4 - Startup: Registration-Pinnacle Expression.lnk = C:\Program Files\Pinnacle\Pinnacle Expression\EReg\RegTool.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
 O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
 O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
 O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
 O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
 O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 
 thanks again for your help inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 12:54 |  Link to this message   | 
					
					
					
						| 
							
							Reboot your computer in Safe Mode.
[*]If the computer is running, shut down Windows, and then turn off the power.
 [*]Wait 30 seconds, and then turn the computer on.
 [*]Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
 [*]Ensure that the Safe Mode option is selected.
 [*]Press Enter. The computer then begins to start in Safe mode.
 [*]Login on your usual account.
 
 
 Open the SmitfraudFix folder and double-click smitfraudfix.cmd
 Select option #4 - Generic Renos Fix by typing 4 and press Enter.
 The program will scan and fix the Registry and delete corresponding infected files on your computer, please be patient while it works.
 The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
 Reboot in Normal Mode.
 
 Send raport.txt and fresh HijackThis log
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 13:11 |  Link to this message   | 
					
					
					
						| 
							
							Hi tapiiri here's files as requested
 SmitFraudFix v2.45
 
 Scan done at 21:58:10.90, 21/05/2006
 Run from C:\Documents and Settings\Neil\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before GenericRenosFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{a566f298-05a6-4b3d-b672-da7c27316430}"="AutoDisc Ware"
 
 [HKEY_CLASSES_ROOT\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
 @="C:\WINDOWS\system32\htey.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
 @="C:\WINDOWS\system32\htey.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» GenericRenosFix
 
 GenericRenosFix by S!Ri
 
 C:\WINDOWS\system32\htey.dll -> Hoax.Win32.Renos.gen
 C:\WINDOWS\system32\htey.dll -> Deleted
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» After GenericRenosFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 22:04:16, on 21/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\blueyonder\PCguard\fws.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
 C:\WINDOWS\mHotkey.exe
 C:\WINDOWS\CNYHKey.exe
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 C:\Program Files\Real\RealPlayer\RealPlay.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
 C:\Program Files\blueyonder\PCguard\RPS.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\DitExp.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Common Files\Command Software\dvpapi.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virgin.net/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Neil\MYDOCU~1\NEIL'S\PROTEC~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32\hpF475.tmp
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
 O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
 O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\RPS.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
 O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
 O4 - Startup: Registration-Pinnacle Expression.lnk = C:\Program Files\Pinnacle\Pinnacle Expression\EReg\RegTool.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
 O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
 O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
 O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
 O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
 O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 
 again thanks for your help inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 13:33 |  Link to this message   | 
					
					
					
						| 
							
							When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 Tha log is saved to your local diskdrive, usually C:\rapport.txt.
 
 Warning : Running option 2 in a clean computer will delete your desktop wallpaper.
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 13:50 |  Link to this message   | 
					
					
					
						| 
							
							Hi tapiiri
here is the file as requested
 
 
 SmitFraudFix v2.45
 
 Scan done at 22:36:27.04, 21/05/2006
 Run from C:\Documents and Settings\Neil\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\hp????.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 
 agian thanks for your patience inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 13:58 |  Link to this message   | 
					
					
					
						| 
							
							yes now its gone. hope so.  
 To ensure that run smithfraudfix option #1 and send report.
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 14:04 |  Link to this message   | 
					
					
					
						| 
							
							hi tapiiri
hope your right
 
 
 SmitFraudFix v2.45
 
 Scan done at 22:58:50.70, 21/05/2006
 Run from C:\Documents and Settings\Neil\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Neil\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Neil\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 thanks again for your time
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 21. May 2006 @ 14:08 |  Link to this message   | 
					
					
					
						| 
							
							Hi inoeos, 
 Yes its gone :)
 
 Will you send a fresh hijack log. Now Ihave to go to sleep, Time is here 01:10 AM.
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 21. May 2006 @ 14:12 |  Link to this message   | 
					
					
					
						| 
							
							sorry to keep you up time here 11:10pm
 Logfile of HijackThis v1.99.1
 Scan saved at 23:06:51, on 21/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\blueyonder\PCguard\fws.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\Dit.exe
 C:\WINDOWS\system32\RunDll32.exe
 C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
 C:\WINDOWS\CNYHKey.exe
 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 C:\Program Files\Real\RealPlayer\RealPlay.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
 C:\Program Files\blueyonder\PCguard\RPS.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\WINDOWS\DitExp.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Common Files\Command Software\dvpapi.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\System32\svchost.exe
 C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 C:\Program Files\WinZip\WZQKPICK.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Neil\MYDOCU~1\NEIL'S\PROTEC~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [Dit] Dit.exe
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
 O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
 O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
 O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
 O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
 O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\WIRELE~1\GNETMOUS.EXE
 O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
 O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
 O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\RPS.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
 O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
 O4 - Startup: Registration-Pinnacle Expression.lnk = C:\Program Files\Pinnacle\Pinnacle Expression\EReg\RegTool.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
 O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
 O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
 O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
 O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom Edition.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe
 O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
 O4 - Global Startup: WinZIP Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net/
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.telewest.co.uk/motive/files/MotivePreQual.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
 O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
 O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
 
 
 
 Again thanks very much for all your help good to know there is people like you on our side thanks very much
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 22. May 2006 @ 08:33 |  Link to this message   | 
					
					
					
						| 
							
							It's Nothing. 
 Scan by hijack and check:
 
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
 
 Close all windows exept hijack and click Fix Checked.
 
 Boot comp.
 
 Are problems away ?
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 22. May 2006 @ 09:20 |  Link to this message   | 
					
					
					
						| 
							
							Hi tapiiri 
Remember I'm a real computer novice and didnt understand your last thread Inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 22. May 2006 @ 09:30 |  Link to this message   | 
					
					
					
						| 
							
							What is hard to understand ? Please ask. 
 Run HijackThis.
 Click "Do a system scan only"
 
 Put mark to box start off this line:
 
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
 
 Close all windows (programs) exept hijack and click Fix Checked.
 
 Restart your computer.
 
 Are your computer better, or are there any problems?
 
 
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 22. May 2006 @ 09:56 |  Link to this message   | 
					
					
					
						| 
							
							Hi Tapiiri
Did what you said, computer seems fine now thanks again for your time and help. By the way what was O2 - bho ( no name etc.)? Inoeos
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 22. May 2006 @ 10:50 |  Link to this message   | 
					
					
					
						| 
							
							Oh, very good question . 
I make mistake.
 
 Okei let take it back, because it belongs to Spybot.
 
 run hijackthis
 click "open Misc tool section"
 Then "bacups"
 Mark that line starts 22.5.2006;O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Neil\MYDOCU~1\NEIL'S\PROTEC~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
 
 Then click "restore" And "ok"
 
 close hijack and restart yor computer.
 
 Logs Looks fine, enjoy surff in internet.
 
 
 | 
				
				
			
				
				
				
				
				
					
						| inoeosNewbie 
   | 22. May 2006 @ 11:17 |  Link to this message   | 
					
					
					
						| 
							
							Nice one Tapiiri 
even the professionals get it wrong sometimes hey. Thanks to you i can get back surfing. Signing off thanks very much once more for your time and help Inoeos.
 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						| 
 | 
				
				
				
					
						| Senior Member 
   | 22. May 2006 @ 11:35 |  Link to this message   | 
					
					
					
						| 
							
							You're Wellcome.
 However, I lost my sleep and dreams because that mistake :D
 
 
 
 
 |