EXE" /Spoil /Rem Adv Def /Migration32 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend] C:\Program Files\Common Files\AOL\IPHSend\[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero Filter Check] C:\WINDOWS\system32\Nero [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP. Select option #2 - Clean by typing 2 and press Enter.EXE /IMEName [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP. EXE /SYNC [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh] "D:\Program Files\Veoh\Veoh Client.exe" /Veoh Hide [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background "Steam"= [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] ""= "Remote Control"="C:\Program Files\Cyber Link\Power DVD\PDVDServ.exe" "Logitech Utility"=LOGI_MWX. Mirrors: Alternate official download locations for Run the application. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. Wait for the tool to complete and disk cleanup to finish.

Deckard's System Scanner v20070826.66 Run by Calvin on 2007-09-02 Computer is in Normal Mode.

EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\C:\Program Files\Common Files\EPSON\EBAPI\SAgent2C:\Program Files\Network Associates\Common Framework\Framework C:\Program Files\Network Associates\Virus Scan\C:\Program Files\Network Associates\Virus Scan\C:\Program Files\Norton Anti Virus\IWP\C:\Program Files\Analog Devices\Sound MAX\C:\WINDOWS\system32\C:\WINDOWS\System32\C:\WINDOWS\system32\C:\Documents and Settings\Calvin\Desktop\C:\PROGRA~1\TRENDM~1\HIJACK~1\R0 - HKCU\Software\Microsoft\Internet Explorer\Main, Start Page = O2 - BHO: Adobe PDF Reader Link Helper - - C:\Program Files\Adobe\Acrobat 7.0\Active X\Acro O2 - BHO: Bit Comet Click Capture - - C:\Program Files\Bit Comet\tools\Bit Comet BHO_1.1.5.19O2 - BHO: (no name) - - E:\PROGRA~1\SPYBOT~1\O2 - BHO: Drive Letter Access - - C:\WINDOWS\System32\DLA\DLASHX_W.

The tool will create a log named in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

Please post that log along with all others requested in your next reply.

Please post: c:\A new Hijack This log Your may need several replies to post the requested logs, otherwise they might get cut off ===================================== Download Superantispyware (SAS) free home version it and double-click the icon on your desktop to run it.

It will ask if you want to update the program definitions, click Yes.

- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\O23 - Service: Symantec Event Manager (cc Evt Mgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\cc Evt O23 - Service: Symantec Password Validation (cc Pwd Svc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\cc Pwd O23 - Service: Symantec Settings Manager (cc Set Mgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\cc Set O23 - Service: EPSON Printer Status Agent2 (EPSONStatus Agent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2O23 - Service: Mc Afee Framework Service (Mc Afee Framework) - Network Associates, Inc.

- C:\Program Files\Network Associates\Common Framework\Framework O23 - Service: Network Associates Mc Shield (Mc Shield) - Network Associates, Inc.

EXE "Registry Mechanic"= "Spy Doctor"="C:\Program Files\Spy Doctor\spydoctor\Spy Doctor.exe" -sh "Symantec Net Driver Monitor"=C:\PROGRA~1\SYMNET~1\/Consumer "Winamp Agent"=E:\Program Files\Winamp\"MSConfig"=C:\WINDOWS\PCHealth\Help Ctr\Binaries\/auto "Sun Java Update Sched"=C:\Program Files\Java\jre1.5.0_06\bin\*Newly Created Service* - ENTDRV51 -- End of Deckard's System Scanner: finished at 2007-09-02 ------------ Hi.................. Open the Smitfraud Fix folder and double-click Reboot your computer in Safe Mode. To resolve this, restart the computer and try again. You will be prompted : "Registry cleaning - Do you want to clean the registry ?

If the computer is running, shut down Windows, and then turn off the power. " answer Yes by typing Y and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection The tool will also check if is infected.

DLL O2 - BHO: SSVHelper Class - - C:\Program Files\Java\jre1.5.0_06\bin\O2 - BHO: (no name) - - (no file) O2 - BHO: Windows Live Sign-in Helper - - C:\Program Files\Common Files\Microsoft Shared\Windows Live\Windows Live O2 - BHO: Ie Catch2 Class - - E:\PROGRA~1\Flash Get\O3 - Toolbar: Flash Get Bar - - E:\PROGRA~1\Flash Get\O3 - Toolbar: Veoh Browser Plug-in - - D:\Program Files\Veoh\Plugins\reg\Veoh O4 - HKLM\..\Run: [Sh Stat EXE] "C:\Program Files\Network Associates\Virus Scan\SHSTAT.