C:\Program Files\PlayMP3z\uninstall.exe (Adware.PlayMP3Z) -> No action taken. Stay logged in Sign up now! Back to top #13 IndiGenus IndiGenus Teacher Emeritus Authentic Member 5,251 posts Interests:Computer Security, Music, Sports Posted 21 February 2008 - 09:02 PM You're not asking too many questions.

Oldsod. Follow this Microsoft article to learn how to backup. If you wish to post a HJT log, then please do so and I will examine it for further instructions. It is greatly appreciated.

that was irresponsible of me.. Here are couple couple of other links with that process which confirms your diagnosis. Sorry to hear of your troubles. I run a couple of virtual machines to test malware and removal techniques for myself.

THis time, when I restarted & saw the malware bytes starting. Usually if you take this computer to a shop they will give an estimate of the malware removal and often at the same time a lesser amount cost for the reformat Confirm that the Winhlp32 Reactivator Class file is no longer present. mommydaniseJanuary 10th, 2009, 12:04 PMHi Oldsod, I am trying to do the scanning in safe mode but I think I was suppose to save those programs to the desktop in order

unable to locate C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip ..removed C:\WINDOWS\system32\drivers\video.exe .. I'm very confused. It was stubborn to remove ( meaning it took quite awhile to remove, for such a small program ) And I didnt know that the IObit programs werte rouge programs. visit C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Splash ID.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).

Right click this file and open the Properties. Find More Posts by DJ Egg 11th July 2004, 05:44 #68 Mad_skillz_n00b Junior Member Join Date: Jul 2004 Posts: 5 OK guys i need help with it now...i read Copy and paste the content of 'hijackthis.log' and post it at one of these forums. Sometimes the curser moves on its own.

Any malware that is on my computer is in the quarenteens of the programs. C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe C:\Program Files\Common Files\Stardock\SDMCP.exe C:\Program Well, I was doing fine with the uninstall, until I tried to uninstall the Firefox. Advertisements do not imply our endorsement of that product or service.

I'm no expert, just a thought. http://bornsunsoft.com/solved-please/solved-please-help-w-hjt-log.html Please also post a new HijackThis log and let me know how it's running. Stops malicious software from invading via flash, java, javascript, and many other entry points. Consistently helpful members with best answers are invited to staff.

It is great software, if it's working for you then....it may be fine. Because I didnt have the "privleges" to do so. This alone can save you a lot of trouble with malware in the future. Source If you use Opera browser Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS Click the Empty Selected button.

You can also checkmark the follow entries for HJT to fix: O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll O8 - Extra context menu item: &Viewpoint Search - It should automatically extract a folder called SDFix to your system drive (usually C:\). The program will either update or inform you that no update was available.

C:\System Volume Information\_restore{3A9EE681-DC56-427A-B78E-063D3A0BD6EC}\RP150\A0070537.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

If you do need to use them, use them sparingly. When I did that, the lil warning bubble popped up saying my firewall had been turned off. Flag Permalink This was helpful (0) Collapse - The next step Sarah which by roddy32 / May 1, 2005 8:39 PM PDT In reply to: No Luck Would determine whether the You can try downloading a trial of Kaspersky to a *known clean* system and creating a rescue disk, then booting the infected system from the rescue disk.

If so you should call your banks and advise them. Save the 'hijackthis.log' in your desktop. Good Winamp plugins by Joonas, DrO and shaneh. have a peek here I solved the problem myself after using HJT to examine the processes running on my computer and see if any were suspicious.I found the task32.exe process running and after disabling the

Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Jump to Music Engine\WMP_Upgrade.wma (Error whilst scanning file: I/O Error (0x00000000)) C:\WORKSSETUP\Office 2003 Editions 60 Day Trial.exe (Infected with Malware.ADRA) Deleted file Scanning: c:\System Volume Information\*.* c:\System Volume Information\_restore{3A9EE681-DC56-427A-B78E-063D3A0BD6EC}\RP151\A0075656.exe (Infected with Malware.ADRA) Deleted mommydaniseJanuary 10th, 2009, 04:29 PMcould the playmp3s be the apple program I have otherwise there isn't one listed on the ad and remove oldsodJanuary 10th, 2009, 04:32 PMA few will need Is there a way to copy and paste the results of items found of the scans?, Has your onboard antivirus found these or were they just online?

If so: Press Start button in the taskbar > select Run... Any malware that is on my computer is in the quarenteens of the programs. Log in to Spiceworks Reset community password Agree to Terms of Service Oops, something's wrong below. Here are some free and evalutation versions that provide better security than the Windows Firewall.

Save your installers and licenses on a flash drive for the re-install of windows. I'll remove it, now that youve told me its not a good idea. dont you recommend nod32 for future use? Yet, my friends performing the same searches do not have the same problem, and thus, I feel it is something on my computer prompting this spam -- not a Google issue

Follow this article by Microsoft to restore your backups. Do the same for the MyWebSearch toolbar. Follow the prompts, provide the required info, select: Scan Now! Number of processes/threads found: 2179 Number of processes/threads scanned: 2178 Number of processes/threads not scanned: 1 Number of infected processes/threads terminated: 0 Total scanning time: 12m 54s Scanning file system...

Select the option for Safe Mode using the arrow keys. C:\System Volume Information\_restore{3A9EE681-DC56-427A-B78E-063D3A0BD6EC}\RP151\A0075650.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. I guess since I removed the later two programs from my computer. But I guess you have already figured out these things anyways for your self.

Eventually turned out he was using a cheap deal ISP @ $5/month (kind of like 3.com which gives free web in exchange for leaving their spyware on your machine). C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Splash Photo v4.05.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined). Try these too and see if they find anything Sarah.They are all free except for the trojan removers but you can get a 30 trial with them.Spybot S&D (download, check for then format the drive and re-install windows.....

