Please try again. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/xpreload.ocx (Heuristics.Malware) -> Quarantined and deleted successfully. Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value Corporations are ...

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing) O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing) C:\WINDOWS\Fonts\'\Dreamfall The Longest Journey iSO.zip (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\'\Adrosoft AD Sound Recorder v3.8.zip (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\'\Devil May Cry 4-RELOADED iSO.zip (Trojan.Agent) -> Quarantined and deleted successfully.

  1. Starting to scan the registry.
  2. Tick the checkbox of the malicious entry, then click Fix Checked.   Check and fix the hostfile Go to the "C:\Windows\System32\Drivers\Etc" directory, then look for the hosts file.
  3. Post SUPERAntiSpyware log.
  5. C:\System Volume Information\_restore{A9DBCA75-73DB-405C-8B8D-490FB41B1A52}\RP182\A0114831.exe [DETECTION] Contains recognition pattern of the DR/Click.Agent.bvr dropper [NOTE] The file was moved to '48f19860.qua'!
  7. C:\WINDOWS\Fonts\'\Finns Girl 2007 DVDRip XviD-VoMiT.zip (Trojan.Agent) -> Quarantined and deleted successfully.
  8. C:\System Volume Information\_restore{A9DBCA75-73DB-405C-8B8D-490FB41B1A52}\RP189\A0122572.dll [DETECTION] Is the TR/Monder.95744.7.A Trojan [NOTE] The file was moved to '48f19c75.qua'!
  9. The F1 items are usually very old programs that are safe, so you should find some more info on the filename to see if it's good or bad.

Logfile of HijackThis v1.99.1 Scan saved at 12:44:51 PM, on 8/1/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most its really urgent!

Yes No Thanks for your feedback. C:\WINDOWS\Fonts\'\BlackSite Area 51 iSO.zip (Trojan.Agent) -> Quarantined and deleted successfully. Register now! In fact, quite the opposite.

C:\System Volume Information\_restore{A9DBCA75-73DB-405C-8B8D-490FB41B1A52}\RP188\A0122315.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was moved to '48f19c02.qua'!

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [SoundMan] soundman.exe O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" O4 - Pacman's Startup List can help with identifying an item.N1, N2, N3, N4 - Netscape/Mozilla Start & Search pageWhat it looks like:N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C:\Program Files\Netscape\Users\default\prefs.js)N2 - Netscape The service needs to be deleted from the Registry manually or with another tool.

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing) O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing) In the last case, have HijackThis fix it.O19 - User style sheet hijackWhat it looks like: O19 - User style sheet: c:\WINDOWS\Java\my.css What to do:In the case of a browser slowdown PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode.

C:\System Volume Information\_restore{A9DBCA75-73DB-405C-8B8D-490FB41B1A52}\RP178\A0113157.dll [DETECTION] Is the TR/Vundo.FIX Trojan [NOTE] The file was moved to '48f196b2.qua'! Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears,

C:\System Volume Information\_restore{A9DBCA75-73DB-405C-8B8D-490FB41B1A52}\RP183\A0117215.dll [DETECTION] Is the TR/Monder.gdp Trojan [NOTE] The file was moved to '48f199d6.qua'! HKEY_CLASSES_ROOT\Interface\{c089afbe-c9bb-4e8b-89d9-8ce993e46adc} (Heuristics.Malware) -> Quarantined and deleted successfully.

