I don't see any AntiVirus program on your PC, but loads of other crap!
When finished, go to
http://free.grisoft.com and get their free AVG.
Boot in Safe Mode.
Switch System restore OFF.
Press Ctrl/Alt/Del simultaneously, select Taskmanager/Processes, select the process (if there), click "End Process" for:
em2.exe
story.exe
scvhost.exe ==>> watch the SPELLING !<<==
mdmdrv.exe
Msnmrg.exe ==>> watch the SPELLING !<<==
svchost32.exe
rundllnt.exe
crsvvc.exe
svcsr32.exe
Next, UNinstall anything to do with:
C:\Program Files\Zango Messenger\em2.exe
Next, click Start/Run and type
services.msc and click OK. Look for the services:
story.exe
svchost32.exe
rundllnt.exe
Msnmrg.exe ==>> watch the SPELLING !<<==
crsvvc.exe
svcsr32.exe
mdmdrv.exe
Doubleclick each one, click Stop if it's running, and change the Startup type to Disabled.
Next, run a HJT scan and place a tick-mark in the little square before (if still there):
...................................................................................................
O4 - HKLM\..\Run: [EasyMessage] "C:\Program Files\
Zango Messenger\em2.exe" -wait
O4 - HKLM\..\Run: [Internet Suspention]
story.exe
O4 - HKLM\..\Run: [Windows Update]
scvhost.exe ==>> watch the SPELLING !<<==
O4 - HKLM\..\Run: [Modem Driverz Updates]
mdmdrv.exe
O4 - HKLM\..\Run: [MSN]
Msnmrg.exe ==>> watch the SPELLING !<<==
O4 - HKLM\..\Run: [WINRUN]
svchost32.exe
O4 - HKLM\..\RunServices: [Internet Suspention] story.exe
O4 - HKLM\..\RunServices: [WINRUN] svchost32.exe
O4 - HKLM\..\RunServices: [Microsoft Run The Dll Needing]
rundllnt.exe
O4 - HKLM\..\RunServices: [MSN] Msnmrg.exe
O4 - HKLM\..\RunServices: [System32]
crsvvc.exe
O4 - HKLM\..\RunServices: [Windows Update]
svcsr32.exe
O4 - HKLM\..\RunServices: [Modem Driverz Updates] mdmdrv.exe
O4 - HKLM\..\RunOnce: [Internet Suspention] story.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
...................................................................................................
Now click on the
Fix Checked button in HJT.
When done, from between the dotted lines, delete the highlighted
bold files.
When a \
directory-name\ is
bold, delete everything in it, including that directory itself.
Delete all files and directories from: C:\Documents and Settings\[username]\Local Settings\Temp
Repeat this for ALL [usernames].
Boot normal. When all OK, switch System Restore back on.