<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[TechSpot OpenBoards - Virus & Malware removal]]></title>
		<link>http://www.techspot.com/vb/</link>
		<description>Is your PC troubled? Viruses, malware support and how to prevent them.</description>
		<language>en</language>
		<lastBuildDate>Fri, 20 Nov 2009 22:36:31 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.techspot.com/vb/images/misc/rss.jpg</url>
			<title><![CDATA[TechSpot OpenBoards - Virus & Malware removal]]></title>
			<link>http://www.techspot.com/vb/</link>
		</image>
		<item>
			<title>Cpu 100% randomly</title>
			<link>http://www.techspot.com/vb/topic138350.html</link>
			<pubDate>Fri, 20 Nov 2009 13:35:40 GMT</pubDate>
			<description>So my cpu goes to 100% alot but its not any one program, it jumps around. one minute its firefox then some svchosts... basically random programs. Iv already tried anti-virus and other programs and none work. Im running windows XP btw. hope this all helps 
 
some info: 
Model - Aspire 5520...</description>
			<content:encoded><![CDATA[<div>So my cpu goes to 100% alot but its not any one program, it jumps around. one minute its firefox then some svchosts... basically random programs. Iv already tried anti-virus and other programs and none work. Im running windows XP btw. hope this all helps<br />
<br />
some info:<br />
Model - Aspire 5520<br />
Processor - AMD Turion(tm) 64*2 Mobile technology TL-60 2.00 GHz<br />
Memory RAM - 3.00 Gb<br />
<br />
Processes:<br />
<br />
Logfile of Your Anti-Hijack Program v0.2.0<br />
Scan saved at 13:18:21, on 20/11/2009<br />
Platform: Windows 2000<br />
MSIE: Internet Explorer 6.0.6002<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Windows\system32\TASKENG.EXE<br />
C:\Windows\system32\DWM.EXE<br />
C:\WINDOWS\EXPLORER.EXE<br />
C:\PROGRAM FILES\WINDOWS DEFENDER\MSASCUI.EXE<br />
C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSNMSGR.EXE<br />
C:\PROGRAM FILES\WINDOWS LIVE\CONTACTS\WLCOMM.EXE<br />
C:\USERS\MICKNAKA\APPDATA\LOCAL\TEMPIMG\CHECKVER104.EXE<br />
C:\USERS\MICKNAKA\APPDATA\LOCAL\TEMPIMG\REGVER.EXE<br />
C:\PROGRAM FILES\YOUR ANTI-HIJACK PROGRAM\YOURANTI-HIJACKREGNOW.EXE<br />
<br />
O4 - HKLM\..\Run: [Windows Defender] <br />
O4 - HKLM\..\Run: [Acer Tour] <br />
O4 - HKLM\..\Run: [eRecoveryService] <br />
O4 - HKLM\..\Run: [MSConfig] &quot;C:\Windows\system32\MSCONFIG.exe&quot; /auto<br />
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
O9 - (Extra Button) Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - HKLM\Software\Microsoft\Internet Explorer\Extensions<br />
O9 - (Extra Button) PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - HKLM\Software\Microsoft\Internet Explorer\Extensions<br />
O9 - (Extra Button) Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - HKLM\Software\Microsoft\Internet Explorer\Extensions<br />
O9 - (Extra Menu) Spybot - Search &amp;&amp; Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - HKLM\Software\Microsoft\Internet Explorer\Extensions<br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O14 - C:\Windows\inf\iereset.inf: [IEReset.inf is missing]: <br />
O16 - DPF: desktop.ini - desktop.ini - C:\Windows\Downloaded Program Files<br />
O2 - BHO: Yahoo! Toolbar Helper C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO: Adobe PDF Reader Link Helper C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO: Spybot-S&amp;D IE Protection C:\Program Files\Spybot - Search &amp; Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO:   - {5C255C8A-E604-49b4-9D64-90988571CECB} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO: ShowBarObj Class C:\Windows\system32\ActiveToolBand.dll - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO: Windows Live ID Sign-in Helper C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O2 - BHO: AIM Toolbar Loader C:\Program Files\AIM Toolbar\aimtb.dll - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects<br />
O22 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler  : [{8C7461EF-2B13-11d2-BE35-3078302C2030}]: Component Categories cache daemon<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main = [url]http://en.uk.acer.yahoo.com[/url]<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main = [url]http://en.uk.acer.yahoo.com[/url]<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks = {03402f96-3dc7-4285-bc50-9e81fefafe43}<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks = {03402f96-3dc7-4285-bc50-9e81fefafe43}<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks = {EF99BD32-C1FB-11D2-892F-0090271D4F88}<br />
O23 - Service: Extensible Authentication Protocol - EapHost - C:\Windows\System32\svchost.exe -k netsvcs<br />
O23 - Service: eDataSecurity Service - eDataSecurity Service - &quot;C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe&quot;<br />
O23 - Service: eLock Service - eLockService - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe<br />
O23 - Service: eNet Service - eNet Service - C:\Acer\Empowering Technology\eNet\eNet Service.exe<br />
O23 - Service: eRecovery Service - eRecoveryService - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe<br />
O23 - Service: eSettings Service - eSettingsService - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe<br />
O23 - Service: IKE and AuthIP IPsec Keying Modules - IKEEXT - C:\Windows\system32\svchost.exe -k netsvcs<br />
O23 - Service: LightScribeService Direct Disc Labeling Service - LightScribeService - &quot;C:\Program Files\Common Files\LightScribe\LSSrvc.exe&quot;<br />
O23 - Service: Network Location Awareness - NlaSvc - C:\Windows\System32\svchost.exe -k NetworkService<br />
O23 - Service: NVIDIA Display Driver Service - nvsvc - C:\Windows\system32\nvvsvc.exe<br />
O23 - Service: IPsec Policy Agent - PolicyAgent - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
O23 - Service: Cyberlink RichVideo Service(CRVS) - RichVideo - &quot;C:\Program Files\CyberLink\Shared Files\RichVideo.exe&quot;<br />
O23 - Service: SBSD Security Center Service - SBSDWSCService - C:\Program Files\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
O23 - Service: System Event Notification Service - SENS - C:\Windows\system32\svchost.exe -k netsvcs<br />
O23 - Service: Secure Socket Tunneling Protocol Service - SstpSvc - C:\Windows\system32\svchost.exe -k LocalService<br />
O23 - Service: Windows Time - W32Time - C:\Windows\system32\svchost.exe -k LocalService<br />
O23 - Service: Windows Live ID Sign-in Assistant - wlidsvc - &quot;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE&quot;<br />
O23 - Service: ePower Service - WMIService - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe<br />
O23 - Service: Windows Driver Foundation - User-mode Driver Framework - wudfsvc - C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted<br />
O23 - Service: XAudioService - XAudioService - C:\Windows\system32\DRIVERS\xaudio.exe</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>micknaka</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138350.html</guid>
		</item>
		<item>
			<title>Severe.exe, conime.exe, ÖØÒª×ÊÁÏ.exe  - i need urgent help to remove it please</title>
			<link>http://www.techspot.com/vb/topic138345.html</link>
			<pubDate>Fri, 20 Nov 2009 08:40:49 GMT</pubDate>
			<description><![CDATA[Hi i need urgent help to remove these viruses. Everytime i attempt to delete them it reappears, and i can tell its slowing down my computer quite badly. 
 
Furthermore, there are occasions when they automatically open internet explorer and randomly spam a site called "www.ctv...something" and then...]]></description>
			<content:encoded><![CDATA[<div>Hi i need urgent help to remove these viruses. Everytime i attempt to delete them it reappears, and i can tell its slowing down my computer quite badly.<br />
<br />
Furthermore, there are occasions when they automatically open internet explorer and randomly spam a site called &quot;www.ctv...something&quot; and then i have to end the iexplorer process in task manager. I've also noticed that this virus doesn't allow me to open hidden files...when i go Tools &gt; Folder Options &gt; View &gt; Tick view hidden files. It has also stuffed up my msn messenger i think.<br />
<br />
Can someone please assist me as soon as possible !<br />
<br />
Kind Regards, <br />
David</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53671&amp;d=1258706199">hijackthis.log</a> (10.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>citrusjuice</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138345.html</guid>
		</item>
		<item>
			<title>Need help w/ virues, malware, etc..</title>
			<link>http://www.techspot.com/vb/topic138321.html</link>
			<pubDate>Thu, 19 Nov 2009 22:54:38 GMT</pubDate>
			<description>Umm.. I attached the Hijackthis log, so whats next?</description>
			<content:encoded><![CDATA[<div>Umm.. I attached the Hijackthis log, so whats next?</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53659&amp;d=1258671223">hijackthis.log</a> (12.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>partik614</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138321.html</guid>
		</item>
		<item>
			<title>Lauching IE7 creates a shortcut</title>
			<link>http://www.techspot.com/vb/topic138319.html</link>
			<pubDate>Thu, 19 Nov 2009 22:26:20 GMT</pubDate>
			<description>I recently had to reload XP Home on an infected PC that was rendered usless by a fake Anti-Virus.  After cleaning the HD of all traces of the Viruses and Malware, it was working fine until, IE7 was updated, since then whenever I click on the IE7 icon it creates a shortcut on the desktop.  I tried...</description>
			<content:encoded><![CDATA[<div>I recently had to reload XP Home on an infected PC that was rendered usless by a fake Anti-Virus.  After cleaning the HD of all traces of the Viruses and Malware, it was working fine until, IE7 was updated, since then whenever I click on the IE7 icon it creates a shortcut on the desktop.  I tried to uninstall IE7 but it won't let me.  I was about to install IE8, but I want to make sure it's OK before going to IE8.<br />
<br />
Attached are the log files from Hi-Jack This and ComboFix.<br />
<br />
Thanks in advance.<br />
<br />
CB</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53655&amp;d=1258669553">ComboFix111809.txt</a> (18.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53656&amp;d=1258669567">hijackthis111809.log</a> (4.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Code Butcher</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138319.html</guid>
		</item>
		<item>
			<title>Google Redirect Virus</title>
			<link>http://www.techspot.com/vb/topic138318.html</link>
			<pubDate>Thu, 19 Nov 2009 22:23:44 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I'm really please to have found this forum!  I'm in the same boat as a few others here, I seem to have a google redirect virus. 
 
A couple of days ago I got a virus which appeared to install "advanced spyware" software. Dialog boxes kept popping up saying I had a virus.  It hijacked my...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I'm really please to have found this forum!  I'm in the same boat as a few others here, I seem to have a google redirect virus.<br />
<br />
A couple of days ago I got a virus which appeared to install &quot;advanced spyware&quot; software. Dialog boxes kept popping up saying I had a virus.  It hijacked my desktop background and replaced it with a blue background with a box in the middle saying I was infected.  It blocked me from accessing sites like myspace, youtube etc.  And it redirected my google search engine.<br />
<br />
Prior to finding this site I downloaded Malwarebytes' Anti-Malware and it seems to have removed most of the problem, except for the google re-directs.  Either the search doesn't run properly at all, or if it does, any links I click get redirected to other sites, It is doing this in both IE and Firefox.  I have XP on my computer.<br />
<br />
I have followed the 8 Step virus removal as best I can and attached the logs.  Any help to get rid of the problem (and advice on how to speed up my pc if I have too many things starting up etc) would really be appreciated.<br />
<br />
Thanks.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53652&amp;d=1258669349">mbam-log-2009-11-19 (23-37-46).txt</a> (1.4 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53653&amp;d=1258669359">SUPERAntiSpyware Scan Log - 11-20-2009 - 00-55-07.log</a> (1.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53654&amp;d=1258669370">hijackthis.log</a> (24.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>BEB</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138318.html</guid>
		</item>
		<item>
			<title>2 sessions of iexplore.exe</title>
			<link>http://www.techspot.com/vb/topic138301.html</link>
			<pubDate>Thu, 19 Nov 2009 19:48:51 GMT</pubDate>
			<description>I am seeing 2 sessions of iexplore.exe running in my task manager. I also suspect that I have a virus or two. I am attaching a HJT log file. Can someone please give this a lookover and help me out? Thanks in advance 
 
Rockon</description>
			<content:encoded><![CDATA[<div>I am seeing 2 sessions of iexplore.exe running in my task manager. I also suspect that I have a virus or two. I am attaching a HJT log file. Can someone please give this a lookover and help me out? Thanks in advance<br />
<br />
Rockon</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53634&amp;d=1258660048">hijackthis.log</a> (7.5 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Rockon</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138301.html</guid>
		</item>
		<item>
			<title><![CDATA[Getting blue screen 'your system is infected']]></title>
			<link>http://www.techspot.com/vb/topic138289.html</link>
			<pubDate>Thu, 19 Nov 2009 16:34:54 GMT</pubDate>
			<description><![CDATA[Looking for help...I am running windows XP and get a [B]blue screen [/B]with an error message in a black box on the center of the screen saying [B]' [U]Your system is infected' and that spyware has been detected[/U][/B]. I also get a [B][U]red circle with an X in it on the taskbar on my screen....]]></description>
			<content:encoded><![CDATA[<div>Looking for help...I am running windows XP and get a [B]blue screen [/B]with an error message in a black box on the center of the screen saying [B]' [U]Your system is infected' and that spyware has been detected[/U][/B]. I also get a [B][U]red circle with an X in it on the taskbar on my screen. [/U][/B]<br />
<br />
I ran AVAST and AD-AWARE and corrupted files are removed but I still get the error message and red circle. <br />
<br />
I ran Trend Micro HijackThis and received the following log....Can anyone tell me how to correct? Thanks in advance. <br />
<br />
Logfile of Trend Micro HijackThis v2.0.2<br />
Scan saved at 11:32:32 AM, on 11/19/2009<br />
Platform: Windows XP SP3 (WinNT 5.01.2600)<br />
MSIE: Internet Explorer v7.00 (7.00.6000.16915)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\WINDOWS\System32\smss.exe<br />
C:\WINDOWS\system32\winlogon.exe<br />
C:\WINDOWS\system32\services.exe<br />
C:\WINDOWS\system32\lsass.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\WINDOWS\System32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
C:\WINDOWS\system32\winupdate86.exe<br />
C:\Program Files\Microsoft IntelliType Pro\type32.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\Program Files\Real\RealPlayer\RealPlay.exe<br />
C:\WINDOWS\system32\LVCOMSX.EXE<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br />
C:\Program Files\Microsoft IntelliPoint\point32.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br />
C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Program Files\DellSupport\DSAgnt.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\WINDOWS\system32\svchost.exe<br />
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe<br />
C:\Program Files\Windows Defender\MsMpEng.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Documents and Settings\Darin Hartwell\Desktop\HijackThis.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.dell.ca/myway[/url]<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url]http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DC[/url]<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://www.google.ca/[/url]<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]<br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]<br />
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url]http://search.aol.ca/dirsearch.adp?query=google[/url]<br />
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)<br />
O1 - Hosts: ::1 localhost<br />
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll<br />
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll<br />
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll<br />
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe<br />
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe<br />
O4 - HKLM\..\Run: [type32] &quot;C:\Program Files\Microsoft IntelliType Pro\type32.exe&quot;<br />
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER<br />
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\qttask.exe&quot; -atboottime<br />
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE<br />
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;<br />
O4 - HKLM\..\Run: [ISUSScheduler] &quot;C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe&quot; -start<br />
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup<br />
O4 - HKLM\..\Run: [IntelliPoint] &quot;C:\Program Files\Microsoft IntelliPoint\point32.exe&quot;<br />
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe<br />
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe<br />
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe<br />
O4 - HKLM\..\Run: [DVDLauncher] &quot;C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe&quot;<br />
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe<br />
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br />
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe<br />
O4 - HKLM\..\Run: [Windows Defender] &quot;C:\Program Files\Windows Defender\MSASCui.exe&quot; -hide<br />
O4 - HKCU\..\Run: [swg] &quot;C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe&quot;<br />
O4 - HKCU\..\Run: [DellSupport] &quot;C:\Program Files\DellSupport\DSAgnt.exe&quot; /startup<br />
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] &quot;C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe&quot;<br />
O8 - Extra context menu item: Add to Google Photos Screensa&amp;ver - res://C:\WINDOWS\system32\GPhotos.scr/200<br />
O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000<br />
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL<br />
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br />
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br />
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe<br />
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe<br />
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe<br />
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br />
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br />
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br />
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe<br />
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)<br />
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>navanite</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138289.html</guid>
		</item>
		<item>
			<title>Google Hijack. Is that it?</title>
			<link>http://www.techspot.com/vb/topic138282.html</link>
			<pubDate>Thu, 19 Nov 2009 14:19:07 GMT</pubDate>
			<description>I just want to thank Bobbye for all his help. He has been patient and courteous with me. 
I believe my problem is now solved, but unfortunately our thread itself got hijacked and closed before resolution could be confirmed.</description>
			<content:encoded><![CDATA[<div>I just want to thank Bobbye for all his help. He has been patient and courteous with me.<br />
I believe my problem is now solved, but unfortunately our thread itself got hijacked and closed before resolution could be confirmed.</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Shaftmonde</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138282.html</guid>
		</item>
		<item>
			<title>Problem: Malware in registry</title>
			<link>http://www.techspot.com/vb/topic138274.html</link>
			<pubDate>Thu, 19 Nov 2009 08:26:35 GMT</pubDate>
			<description><![CDATA[I've been able to delete malware that sends command to load this program that msconfig blocks. I want to get rid of this program that appears in msconfig. According to msconfig the program, I want rid of, resides in HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Run. When I go there I can find one...]]></description>
			<content:encoded><![CDATA[<div>I've been able to delete malware that sends command to load this program that msconfig blocks. I want to get rid of this program that appears in msconfig. According to msconfig the program, I want rid of, resides in HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Run. When I go there I can find one registry key that could be it but when I try to delete it an error appears. I've tried to delete it in safemode and I have tried to delete it as administrator but even then I get an error. I have all the permissions that should allow me to delete that key. Anyone have any idea how to solve this problem?</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Ventress</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138274.html</guid>
		</item>
		<item>
			<title>Plethora of Malware (Google Redirect, too) 8 Steps</title>
			<link>http://www.techspot.com/vb/topic138259.html</link>
			<pubDate>Thu, 19 Nov 2009 02:40:49 GMT</pubDate>
			<description><![CDATA[I've been trying to figure out how to fix this for a few days now. I have the annoying Google Redirect Virus, as well as something that prevents my computer from rebooting in Safe Mode. Any help is GREATLY appreciated.]]></description>
			<content:encoded><![CDATA[<div>I've been trying to figure out how to fix this for a few days now. I have the annoying Google Redirect Virus, as well as something that prevents my computer from rebooting in Safe Mode. Any help is GREATLY appreciated.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53619&amp;d=1258598326">mbam-log-2009-11-18 (20-36-23).txt</a> (125.3 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53620&amp;d=1258598338">SUPERAntiSpyware Scan Log - 11-18-2009 - 21-21-26.log</a> (1.2 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53621&amp;d=1258598348">hijackthis.log</a> (11.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Liam414</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138259.html</guid>
		</item>
		<item>
			<title>Another Google Redirect Virus</title>
			<link>http://www.techspot.com/vb/topic138213.html</link>
			<pubDate>Wed, 18 Nov 2009 05:34:37 GMT</pubDate>
			<description>Links that appear in Google search lead to random advertising pages.  Have run the 8 step process.  Any help is much appreciated.  Here are the logs:</description>
			<content:encoded><![CDATA[<div>Links that appear in Google search lead to random advertising pages.  Have run the 8 step process.  Any help is much appreciated.  Here are the logs:</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53606&amp;d=1258522394">hijackthis.log</a> (18.3 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53607&amp;d=1258522410">mbam-log-2009-11-17 (16-30-57).txt</a> (842 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53608&amp;d=1258522427">SUPERAntiSpyware Scan Log - 11-17-2009 - 16-47-02.log</a> (549 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>reubencahn</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138213.html</guid>
		</item>
		<item>
			<title>Possible infection?</title>
			<link>http://www.techspot.com/vb/topic138203.html</link>
			<pubDate>Wed, 18 Nov 2009 01:08:12 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I have a problem with my Avira Antivir. Just recently when I performed a complete scan it stucks on the [i]tracking.log[/i]. So I did the necessary steps in the [url]http://www.techspot.com/vb/topic58138.html[/url] thread and Malwarebytes' Quick Scan resulted in nothing but SuperAntiSpyware...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I have a problem with my Avira Antivir. Just recently when I performed a complete scan it stucks on the [i]tracking.log[/i]. So I did the necessary steps in the [url]http://www.techspot.com/vb/topic58138.html[/url] thread and Malwarebytes' Quick Scan resulted in nothing but SuperAntiSpyware caught Tracking Cookies which I  ultimately removed after the scan has finished.<br />
<br />
I was thinking that a virus/malware must be causing the graphical distortion of a recent game that I installed, or maybe I'm just being paranoid.  Anyway, the logs are attached below.<br />
<br />
Thanks in advance. :)</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53601&amp;d=1258506387">mbam-log-2009-11-18 (08-03-43).txt</a> (834 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53602&amp;d=1258506394">SUPERAntiSpyware Scan Log - 11-18-2009 - 08-51-06.log</a> (1.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53603&amp;d=1258506402">hijackthis.log</a> (4.1 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>iCharles</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138203.html</guid>
		</item>
		<item>
			<title>No virus but perhaps policies and RA problems</title>
			<link>http://www.techspot.com/vb/topic138202.html</link>
			<pubDate>Wed, 18 Nov 2009 00:40:53 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I've had all 8 machines from my company infected in Thailand and now returned to australia to start over.  
 
There doesn't appear to be any viruses on the surface but somethings not right. I've found strange entries etc but i'm far from an expert. If you could take a look for me would be...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I've had all 8 machines from my company infected in Thailand and now returned to australia to start over. <br />
<br />
There doesn't appear to be any viruses on the surface but somethings not right. I've found strange entries etc but i'm far from an expert. If you could take a look for me would be appreciated. Thanks.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53598&amp;d=1258504819">hijackthis.log</a> (5.9 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53599&amp;d=1258504829">mbam-log-2009-11-18 (09-47-00).txt</a> (834 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53600&amp;d=1258504838">SUPERAntiSpyware Scan Log - 11-18-2009 - 10-20-48.log</a> (465 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>FleetX</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138202.html</guid>
		</item>
		<item>
			<title>Psw.onlinegames3 / done all 8 steps but still stays</title>
			<link>http://www.techspot.com/vb/topic138200.html</link>
			<pubDate>Wed, 18 Nov 2009 00:15:01 GMT</pubDate>
			<description>guess the topic says it all, ive done all 8 steps but after restarting my pc my AVG still reporting it and cant heal it . pls heeeeeeeeeeeeeelp , my wow account has been suspended for 24 hrs because of this trojan and i cant get rid of it  
 
Attachment 53594...</description>
			<content:encoded><![CDATA[<div>guess the topic says it all, ive done all 8 steps but after restarting my pc my AVG still reporting it and cant heal it . pls heeeeeeeeeeeeeelp , my wow account has been suspended for 24 hrs because of this trojan and i cant get rid of it <br />
<br />
<a href="http://www.techspot.com/vb/attachment.php?attachmentid=53594" target="_blank">Attachment 53594</a><br />
<br />
<a href="http://www.techspot.com/vb/attachment.php?attachmentid=53595" target="_blank">Attachment 53595</a><br />
<br />
<a href="http://www.techspot.com/vb/attachment.php?attachmentid=53596" target="_blank">Attachment 53596</a></div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53594&amp;d=1258503134">hijackthis.log</a> (5.2 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53595&amp;d=1258503141">mbam-log-2009-11-18 (02-47-16).txt</a> (1.7 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53596&amp;d=1258503148">SUPERAntiSpyware Scan Log - 11-18-2009 - 03-28-26.log</a> (594 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Kold</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138200.html</guid>
		</item>
		<item>
			<title>Analyze a Log</title>
			<link>http://www.techspot.com/vb/topic138193.html</link>
			<pubDate>Tue, 17 Nov 2009 20:31:49 GMT</pubDate>
			<description>Hi, having problems with slooowwww, Microsoft XP 2002. Was getting tons of Spam in Outlook Express. I have a log ready and wanted to see how i can get someone to tell me what i should do with it. 
 
Thanks!! 
Huckleberry</description>
			<content:encoded><![CDATA[<div>Hi, having problems with slooowwww, Microsoft XP 2002. Was getting tons of Spam in Outlook Express. I have a log ready and wanted to see how i can get someone to tell me what i should do with it.<br />
<br />
Thanks!!<br />
Huckleberry</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>huckleberry</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138193.html</guid>
		</item>
		<item>
			<title><![CDATA[I can't get rid of Google Redirect Virus]]></title>
			<link>http://www.techspot.com/vb/topic138184.html</link>
			<pubDate>Tue, 17 Nov 2009 18:48:55 GMT</pubDate>
			<description><![CDATA[I've tried every forum, installed every spyware scanner I could get.  Removed IE 8, installed Firefox and Safari, but all 3 still exhibit symptoms of Redirect Virus.  They are now also popping up new, tabs/pages. 
 
I am attaching my hijackthis.log 
 
Can anyone help me get rid of this malware?]]></description>
			<content:encoded><![CDATA[<div>I've tried every forum, installed every spyware scanner I could get.  Removed IE 8, installed Firefox and Safari, but all 3 still exhibit symptoms of Redirect Virus.  They are now also popping up new, tabs/pages.<br />
<br />
I am attaching my hijackthis.log<br />
<br />
Can anyone help me get rid of this malware?</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53589&amp;d=1258483824">hijackthis.log</a> (12.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>davejake</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138184.html</guid>
		</item>
		<item>
			<title>Google Redirect, 8 steps completed</title>
			<link>http://www.techspot.com/vb/topic138179.html</link>
			<pubDate>Tue, 17 Nov 2009 17:51:01 GMT</pubDate>
			<description>My roommate apparently got a virus or more, on her computer.  It was one of those fake shields with pop-ups saying things were infected that asking you to pay for software.  I managed to get rid of that (I think).  But then she noticed that google links were being re-directed to random sites. 
 
I...</description>
			<content:encoded><![CDATA[<div>My roommate apparently got a virus or more, on her computer.  It was one of those fake shields with pop-ups saying things were infected that asking you to pay for software.  I managed to get rid of that (I think).  But then she noticed that google links were being re-directed to random sites.<br />
<br />
I searched here, and found several similar cases, so I ran through the 8 steps.  Log sheets are attached.<br />
<br />
I also ran combofix, which seemed to be the next step in all the posts.  Though I now see the sticky saying not to run it unless told, my bad.  It did seem to have some issues running.  I ran it once, and it downloaded a new version then during autoscan, a Microsoft error window (PEV.exe needed to close... do you want to send report...), but Combofix was still running so I just ignored the window.  CF then restarted the computer after saying it found an infection.  On start-up it CF came up and said it couldn't find Combo-fix.sys, then said it was creating a log sheet, then the computer just restarted, and CF never came back up.  I renamed combofix to combo-fix and re-ran.  This time, no windows popped up, it found no infections, but after it said it was creating a log sheet, it just restarted again and combofix never came back up.  I looked and found the log sheet but it didn't really have any details, basically same as the one attached.  I ran it a third time, and it found an infection, restarted, said it was creating log sheet, then restarted again, with no log sheet displayed.<br />
<br />
The google redirect is still there.  Any help would be greatly appreciated.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53585&amp;d=1258479605">mbam-log-2009-11-17 (01-31-54).txt</a> (1.0 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53586&amp;d=1258479643">SUPERAntiSpyware Scan Log - 11-17-2009 - 02-02-52.log</a> (651 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53587&amp;d=1258479684">hijackthis.log</a> (5.2 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53588&amp;d=1258479725">ComboFix.txt</a> (350 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>christo76</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138179.html</guid>
		</item>
		<item>
			<title>The Shield Deluxe 2010 antivirus question</title>
			<link>http://www.techspot.com/vb/topic138165.html</link>
			<pubDate>Tue, 17 Nov 2009 04:32:07 GMT</pubDate>
			<description>Anybody know much about this av program.  It is cheap but rated an editors choice.</description>
			<content:encoded><![CDATA[<div>Anybody know much about this av program.  It is cheap but rated an editors choice.</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>ingeborgdot</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138165.html</guid>
		</item>
		<item>
			<title>A Case of the Vundo</title>
			<link>http://www.techspot.com/vb/topic138122.html</link>
			<pubDate>Mon, 16 Nov 2009 15:44:40 GMT</pubDate>
			<description><![CDATA[A computer for the company I work for just got this nasty bugger on one of our computers. 
 
I followed the steps here: 
[url]http://www.techspot.com/vb/topic58138.html[/url] 
 
And I had initially found you guys from this thread: 
[url]http://www.techspot.com/vb/topic119190.html[/url] 
 
I...]]></description>
			<content:encoded><![CDATA[<div>A computer for the company I work for just got this nasty bugger on one of our computers.<br />
<br />
I followed the steps here:<br />
[url]http://www.techspot.com/vb/topic58138.html[/url]<br />
<br />
And I had initially found you guys from this thread:<br />
[url]http://www.techspot.com/vb/topic119190.html[/url]<br />
<br />
I downloaded ComboFix, but have not ran it yet and I won't until its required.<br />
<br />
I had seen many other posts about this trojan and how to get rid of it.  Tried a few.  But to no avail.  My logs are attached.<br />
<br />
Note that, the McAfee VirusScan log I copied and created from the results of the scan.  Looks the exact same.  Also, the program &quot;VirtumundoBeGone.exe&quot; is a program I had found on another forum to use (I'm sure y'all have heard of it).  I didn't try it yet.  So, let me know if its worthless.<br />
<br />
We didn't want to do any registry deletions/changes ourselves without a going through y'all first.  We did manage to delete some files via FileAssassin and renaming.<br />
<br />
Also, at one point, we thought it was just the sdra64.exe virus.  But I'm guessing it all comes back to Vundo.  If there's any other info you need, just let me know in reply.<br />
<br />
(Btw, I work in IT at a company.  I understand that this is y'alls specialty.  I don't mind consulting with experts.)  ;-)<br />
<br />
Thanks in advance,<br />
FO4R</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53552&amp;d=1258386173">hijackthis.log</a> (7.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53553&amp;d=1258386228">mbam-log-2009-11-16 (08-46-35).txt</a> (876 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53554&amp;d=1258386239">SUPERAntiSpyware Scan Log - 11-16-2009 - 09-15-46.log</a> (1,019 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53555&amp;d=1258386248">McAfeeVirusScan_log.txt</a> (541 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>FO4R</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138122.html</guid>
		</item>
		<item>
			<title>Stupid bad image pop ups</title>
			<link>http://www.techspot.com/vb/topic138110.html</link>
			<pubDate>Mon, 16 Nov 2009 04:58:25 GMT</pubDate>
			<description>I have done all the eight steps because of the stupid bad image pop ups.  here are the logs that you requested.  thank you. 
 
al</description>
			<content:encoded><![CDATA[<div>I have done all the eight steps because of the stupid bad image pop ups.  here are the logs that you requested.  thank you.<br />
<br />
al</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53538&amp;d=1258347369">mbam-log-2009-11-14 (23-42-42).txt</a> (3.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53539&amp;d=1258347395">hijackthis.log</a> (11.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53540&amp;d=1258347421">SUPERAntiSpyware Scan Log - 11-15-2009 - 00-58-14.log</a> (1.8 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>acvaneg</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138110.html</guid>
		</item>
		<item>
			<title>Google redirect... again</title>
			<link>http://www.techspot.com/vb/topic138108.html</link>
			<pubDate>Mon, 16 Nov 2009 03:26:26 GMT</pubDate>
			<description><![CDATA[I need help fixing my computer again. The same thing happened to me 6 months ago and I was able to get the problem fixed using this site. I followed the 8 step guide and I've attached the logs. I hope you can help me again.]]></description>
			<content:encoded><![CDATA[<div>I need help fixing my computer again. The same thing happened to me 6 months ago and I was able to get the problem fixed using this site. I followed the 8 step guide and I've attached the logs. I hope you can help me again.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53535&amp;d=1258341689">hijackthis.log</a> (9.9 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53536&amp;d=1258341698">mbam-log-2009-11-15 (20-43-42).txt</a> (1.4 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53537&amp;d=1258341736">SUPERAntiSpyware Scan Log - 11-15-2009 - 21-45-07.log</a> (2.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>yinato</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138108.html</guid>
		</item>
		<item>
			<title>Another Google Redirect</title>
			<link>http://www.techspot.com/vb/topic138094.html</link>
			<pubDate>Sun, 15 Nov 2009 21:45:45 GMT</pubDate>
			<description><![CDATA[I've followed the 8 step guide but this does seem to be a difficult one based on the other threads I've read. 
 
I would appreciate any help you can provide.  
 
Just for clarity - when I do a google search this virus redirects the results I click on to another site.  It seems to affect Firefox,...]]></description>
			<content:encoded><![CDATA[<div>I've followed the 8 step guide but this does seem to be a difficult one based on the other threads I've read.<br />
<br />
I would appreciate any help you can provide. <br />
<br />
Just for clarity - when I do a google search this virus redirects the results I click on to another site.  It seems to affect Firefox, IE, Chrome and Safari.  <br />
<br />
Attached are the requested logs.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53516&amp;d=1258321505">hijackthis.log</a> (14.5 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53517&amp;d=1258321515">mbam-log-2009-11-15 (10-06-28).txt</a> (5.1 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53518&amp;d=1258321521">SUPERAntiSpyware Scan Log - 11-15-2009 - 11-01-20.log</a> (30.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Creighton</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138094.html</guid>
		</item>
		<item>
			<title>Do Not Run Combofix without our guidance</title>
			<link>http://www.techspot.com/vb/topic138086.html</link>
			<pubDate>Sun, 15 Nov 2009 18:41:20 GMT</pubDate>
			<description><![CDATA[I'm seeing some frequent suggestions by new members  that Combofix will resolve just about any problem! The latest suggestion is that it it THE fix for the Google Direct. [b]It isn't[/b] for the simple reason that there is no one cause for this redirect. 
 
Combofix IS a good program and malware...]]></description>
			<content:encoded><![CDATA[<div>I'm seeing some frequent suggestions by new members  that Combofix will resolve just about any problem! The latest suggestion is that it it THE fix for the Google Direct. [b]It isn't[/b] for the simple reason that there is no one cause for this redirect.<br />
<br />
Combofix IS a good program and malware cleaning helpers do recommend it frequently, but only AFTER the preliminary programs have been run and then only if it's appropriate.<br />
<br />
[B]Combofix should only be run if the malware helper instructs you to run it and then it will be with guidance.[/B]<br />
<br />
The number of posts here doesn't mean much, but when a newbie starts recommending malware cleaning programs, it will not be in your best interest to run them.. Sometimes the initial problem may be resolved after running Combofix, but that does NOT mean that the system is clean, or that it was the most appropriate program to run.</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>Bobbye</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138086.html</guid>
		</item>
		<item>
			<title><![CDATA[CiD ads won't go away]]></title>
			<link>http://www.techspot.com/vb/topic138076.html</link>
			<pubDate>Sun, 15 Nov 2009 10:18:29 GMT</pubDate>
			<description><![CDATA[for around a week now ive been getting annoying CiD ads ive tried the 8 step thing where it says download hijack this, superanti and malwarebytes but it still exists. 
Some help plz? i attached the notes that were asked 
sorry i couldn't find the superanti note]]></description>
			<content:encoded><![CDATA[<div>for around a week now ive been getting annoying CiD ads ive tried the 8 step thing where it says download hijack this, superanti and malwarebytes but it still exists.<br />
Some help plz? i attached the notes that were asked<br />
sorry i couldn't find the superanti note</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53502&amp;d=1258280258">mbam-log-2009-11-15 (15-49-03).txt</a> (2.0 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53503&amp;d=1258280272">hijackthis.log</a> (11.9 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>jjusttonyy</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138076.html</guid>
		</item>
		<item>
			<title>Help with Browser Redirect - I have tried everything</title>
			<link>http://www.techspot.com/vb/topic138073.html</link>
			<pubDate>Sun, 15 Nov 2009 05:15:35 GMT</pubDate>
			<description>Any help is appreciated. And, please know that I have spent hours reading everything already posted, reviewing what appears to be the exact same thing that is happening to me, but mine I cannot for the life of me get to go away. Some point about 4 days ago, while browsing through a link off of a...</description>
			<content:encoded><![CDATA[<div>Any help is appreciated. And, please know that I have spent hours reading everything already posted, reviewing what appears to be the exact same thing that is happening to me, but mine I cannot for the life of me get to go away. Some point about 4 days ago, while browsing through a link off of a news site, I got directed to a shady &quot;anti spyware&quot; and eventually a XXX site. Some program had automatically loaded and was doing all of the &quot;security scanning&quot; etc etc.. By browser would launch automatically repeatedly and go to dozens of malicious sites...Through a combination of cleansing any and all cookies, temp files and running malwarebytes, I got rid of the program and the apparent problem. NOW - my computer seems to be working fine, Except - when I do a simple google search, and click on the search-result-links, my browser redirects to random shady websites.<br />
<br />
I have closed everything, updated and run full scans of all of the following - malwarebytes, mccaffee av, adware se, ccleaner, and srubbed and removed every possible temp/cookie file known to mankind. On this forum, there were &quot;8 steps to remove malware&quot; - which I pretty much had done it all already. But, the one step said to disable real time scanning of my AV program, and install, update, and run &quot;Superantispyware&quot; - which to be honest sounded a lot like the malware program that I had fought to removed the day before, but oh well I did it and it is running right now. I also am attaching &quot;hijackthis log, and malwarebytes log...&quot; If you guys need the superantispyware log lemme know. I would never normally install and run this many separate 3rd party programs to &quot;fix&quot; anything, but this issue pas me perplexed. <br />
<br />
If one of you guys can figure this out, I will be impressed!<br />
<br />
Thanks,<br />
<br />
JR</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53499&amp;d=1258262094">hijackthis.log</a> (6.4 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53500&amp;d=1258262100">mbam-log-2009-11-14 (09-50-17).txt</a> (846 Bytes)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>kazzma</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138073.html</guid>
		</item>
		<item>
			<title>Google redirect problem please help</title>
			<link>http://www.techspot.com/vb/topic138072.html</link>
			<pubDate>Sun, 15 Nov 2009 05:11:39 GMT</pubDate>
			<description>Hi, 
 
I recently had a spyware virus that I thought I eradicated but not fully.  From time to time I get a pop ups on my browser that look like they are from an anti-spyware program but they are a virus. 
 
Two days ago, in addition to to my spyware problem I have encountered the google re-direct...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I recently had a spyware virus that I thought I eradicated but not fully.  From time to time I get a pop ups on my browser that look like they are from an anti-spyware program but they are a virus.<br />
<br />
Two days ago, in addition to to my spyware problem I have encountered the google re-direct problem.  I have run everything: spyware blaster, malwarebytes' anti-malware, super anti-spyware, ccleaner, avast antivirus, drweb-cureit and also hijack this.  However, the problem still persists.  <br />
<br />
What the @## is going on? Arrgh.  Also, once this virus/spyware/malware is eradicated, do I have to continually run these free programs? I heard that it is not a good idea to have so many anti-virus programs.  Which ones should I keep/get rid of? <br />
  <br />
Thank you.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53497&amp;d=1258261705">hijackthis.log</a> (8.6 KB)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53498&amp;d=1258261716">GooredFix.txt</a> (1.6 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>hatemalware</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138072.html</guid>
		</item>
		<item>
			<title>IE8 hangs up and even Task manager will not run</title>
			<link>http://www.techspot.com/vb/topic138064.html</link>
			<pubDate>Sun, 15 Nov 2009 01:24:58 GMT</pubDate>
			<description>When I run IE8 it will periodically hang my system so badly that even Task Manager does not run.   I noticed that when I start IE8 it shows TWO copies in task manager.  I have attached a hijack this log of my system. 
I have gone into IE8 manage add ons and disabled all of them to see if that...</description>
			<content:encoded><![CDATA[<div>When I run IE8 it will periodically hang my system so badly that even Task Manager does not run.   I noticed that when I start IE8 it shows TWO copies in task manager.  I have attached a hijack this log of my system.<br />
I have gone into IE8 manage add ons and disabled all of them to see if that solves the problem.  I think something is periodically going out to the internet for an update check but I have disabled update checks.  I do use a time sync service.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53492&amp;d=1258248284">hijackthis.log</a> (6.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>weightwatcherph</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138064.html</guid>
		</item>
		<item>
			<title>Exception processing message error - Windows hijack log attached</title>
			<link>http://www.techspot.com/vb/topic138052.html</link>
			<pubDate>Sat, 14 Nov 2009 21:11:19 GMT</pubDate>
			<description>Dear members 
 
             I keep on getting this weird error . I have attached the log please help. 
 
             Is thia  VIRUS or a USB drive problem etc ... please help... 
 
Regards 
Kunal</description>
			<content:encoded><![CDATA[<div>Dear members<br />
<br />
             I keep on getting this weird error . I have attached the log please help.<br />
<br />
             Is thia  VIRUS or a USB drive problem etc ... please help...<br />
<br />
Regards<br />
Kunal</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53489&amp;d=1258232992">hijackthis.log</a> (6.4 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>kunnu123</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138052.html</guid>
		</item>
		<item>
			<title>Possible google hijack, 8 step preliminary removal complete</title>
			<link>http://www.techspot.com/vb/topic138051.html</link>
			<pubDate>Sat, 14 Nov 2009 20:11:13 GMT</pubDate>
			<description>Just recently noticed that my google results (in both Firefox and IE browswers) have been redirected to some 3rd party site. 
 
I completed the 8 step prelim. removal as recommended and hope that I can be helped as this redirect is exceptionally frustrating.  Thanks in advance.</description>
			<content:encoded><![CDATA[<div>Just recently noticed that my google results (in both Firefox and IE browswers) have been redirected to some 3rd party site.<br />
<br />
I completed the 8 step prelim. removal as recommended and hope that I can be helped as this redirect is exceptionally frustrating.  Thanks in advance.</div>


	<br />
	<div style="padding:7px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/txt.gif" alt="File Type: txt" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53486&amp;d=1258229444">mbam-log-2009-11-10 (22-32-36).txt</a> (835 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53487&amp;d=1258229455">SUPERAntiSpyware Scan Log - 11-10-2009 - 22-56-13.log</a> (631 Bytes)</td>
</tr><tr>
	<td><img class="inlineimg" src="http://www.techspot.com/vb/images/attach/log.gif" alt="File Type: log" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.techspot.com/vb/attachment.php?attachmentid=53488&amp;d=1258229461">hijackthis.log</a> (9.0 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>savmipls</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138051.html</guid>
		</item>
		<item>
			<title><![CDATA[Win32/heur, sin32/virut, Vundo B & Trohan Generic 15. AUWC]]></title>
			<link>http://www.techspot.com/vb/topic138037.html</link>
			<pubDate>Sat, 14 Nov 2009 15:24:51 GMT</pubDate>
			<description><![CDATA[I download remove virus programme but I could not open and run them. like comboFix & Malwarebytes, and now won't let me open avg web page or other helpful webpage. 
 
Could not go to safe mode either. 
 
I am using AVG 8.5 and it is wdw xp 
 
could not go to helpful website but being hackjact to...]]></description>
			<content:encoded><![CDATA[<div>I download remove virus programme but I could not open and run them. like comboFix &amp; Malwarebytes, and now won't let me open avg web page or other helpful webpage.<br />
<br />
Could not go to safe mode either.<br />
<br />
I am using AVG 8.5 and it is wdw xp<br />
<br />
could not go to helpful website but being hackjact to other malicious page.<br />
<br />
It seems that I could not do anything becasue the registry being infected?<br />
<br />
sorry I don't know any technical term to describe or run the dot programme to show the problem<br />
<br />
Any advice please please, I just get on the internet in 2 days and haven't backed up all my personal file, so worry now....<br />
<br />
If I reinstalled xp, would all my pre-factory installed things like 'nero' gone as well.<br />
<br />
Thanks in advance.</div>

]]></content:encoded>
			<category domain="http://www.techspot.com/vb/menu28.html"><![CDATA[Virus & Malware removal]]></category>
			<dc:creator>bear</dc:creator>
			<guid isPermaLink="true">http://www.techspot.com/vb/topic138037.html</guid>
		</item>
	</channel>
</rss>
