Double click on RSIT.exe to run RSIT.

Please download the Nail/Aurora Spyware Fix from NoIdea.US. (Alternate download link: dknoppix mirror) Unzip it to the desktop but do NOT run yet.

Double click on RSIT.exe to run RSIT. Record Number: 94 Source Name: Application Error Time Written: 20090621135148.000000+570 Event Type: error User: Computer Name: BAR Event Code: 1000 Message: Faulting application superantispyware.exe, version, faulting module superantispyware.exe, version, There is an instance of it in System32, i386 folder and two registry keys. Hello and welcome to the forums My name is Katana and I will be helping you to remove any infection(s) that you may have.

Logfile of HijackThis v1.99.1 Scan saved at 7:45:57 PM, on 1/14/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: ConnectSA Synchronisation.lnk = C:\Program Files\Eviivo\ConnectSA\bin\Eviivo.U-Sync.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk Display as a link instead × Your previous content has been restored. click here now Please post your HijackThis log as a reply to this thread and not as an attachment.

First the symptoms - it redirects your homepage, his system was slow and cluncky, lots of pop ups and it would not let me run HiJackthis. GMER will produce a log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop.

While in Safe Mode, run the SmitFraudFix tool per the instructions in the link I supplied above. Toolbar-->rundll32.exe C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YCOMP5~1.DLL,DllCommand ui Yahoo! Results 1 to 5 of 5 Thread: Huge Pop up problem - Trojan Warning - HJT log attached

Plus-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19} Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3} SPAMfighter-->"C:\Program Files\SPAMfighter\uninstall.exe" Remove Starfleet>"C:\Fsc\unins000.exe" UltraVNC 1.0.4-->"C:\Program Files\UltraVNC\unins000.exe" Unix Utilities for Yahoo! Thanks and sorry joe trinkley, Jan 15, 2006 #9 Cheeseball81 Moderator Joined: Mar 3, 2004 Messages: 84,310 It's okay. Companion - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll [2004-09-29 292947] {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-18 259696] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-08-20 155648] "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe You don't stop laughing when you get old; you get old when you stop laughing.A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)Malware Removal University Masters GraduateJoin The Fight

All Activity Home Malware Removal Help Malware Removal for Windows Resolved Malware Removal Logs Advanced Virus Remover Infection - Cannot Remove - HJT Log Attached The system clock is unsynchronized. It seems all issues are gone at this point, no more call outs to various IPs either.

Record Number: 27 Source Name: Userenv Time Written: 20090621112302.000000+570 Event Type: warning User: NT AUTHORITY\SYSTEM Computer Name: BAR Event Code: 1517 Message: Windows saved user BAR\Admin registry while an application or

Widgets-->C:\PROGRA~1\Yahoo!\Widgets\uninstall.exe ======Security center information====== AV: AVG Anti-Virus Free ======System event log====== Computer Name: BYRON Event Code: 3019 Message: The redirector failed to determine the connection type.

The program will begin to run. **Caution** These types of scans can produce false positives. While we are working on your HijackThis log, please: Reply to this thread; do not start another!

ATF Cleaner... Once the license is accepted, reset to 100%. I will run the Kaspersky scanner and GMER later today and report back.

The computer could quit running at any time.