I ran HijackThis again in normal mode and it listed another R1 HKCU with the entire alphabet (or so it seemed).

OTL.Txt and Extras.Txt.

File not foundO4 - HKCU..\Run: [TouchMemo] Reg Error: Invalid data type. Run the Trend Micro

Stay logged in Sign up now!

now, tell me what's better for your company - a slow dripfeed of useless articles pushing software that get banned, buried and reinforce your product with spam amongst one of the I think they are preparing for a massive spamvertizing campaign. I went back to safe mode and deleted yet another generated Main Search Bar. Maybe some of my priorities have changed in the last 3 years -- because the malware scene has changed, and is a lot more serious that it was.

Folders like "Casino on line, movie, games, webhosting", etc. We "Attack" no one; however, we do point out unethical behavior when we see fit. Apparently I'm too small to stop the big "Ugnius". The right click menu would only appear on items I put in there before, not the other ones.Heres the new log:Logfile of HijackThis v1.99.0Scan saved at 11:25:18 PM, on 1/17/2005Platform: Windows

It opens the browser to home page (MSN) every time.QUOTE Cannot Find File:///C:Program%20Files/Common%20Files/Remove-tols.html Was tools misspelled that way in the message?Could you use My Computer/Windows Explorer and navigate to the C:ProgramFiles\CommonFiles

Just paste your complete logfile into the textbox at the bottom of this page. Post in the Forums instead and we will all learn. A Norton AntiVirus update had gone awry and, as a result, my system was crippled for weeks.

Open the registry editor (START>Run>regedit). Don't do anything to it, just tell me if it is there.3. If you have problems create a thread in the forum, please.Don't post your log into other user's topic, create a new one. Provided removal instructions are meant to be used in the correspondent user's case only.

Sometimes, we can even weigh in and offer a little sanity in an otherwise bezerk thread. If there is some abnormality detected on your computer HijackThis will save them into a logfile.

After posting this I plan to run Housecall again and see what comes up.Thanks,Radiumlight "And in the end, it's not the years in your life that count.

Please overwrite the old version of HijackThis that you have.Run HijackThis and post a new log here using the Add Reply button. Current Boot Mode: NormalScan Mode: Current userInclude 64bit ScansCompany Name Whitelist: OffSkip Microsoft Files: OffFile Age = 30 DaysOutput = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit:

Two were listed as SWIZZOR and one listed as APROPO.C. Under the Hidden Files and Folders heading select Show Hidden Files and Folders. When I right-click on selected text in IE6.0 one of the menu options is "iSearch" -- which doesn't do anything.

Help stop the muzzling by bullies, defend free speech and ensure BC continues to help people for free. I would be working with researchers from several companies and all over the word by sharing information and malware files behind the scenes about this rogue and other malware. They want to profit from editorial sites. combine them with the regular, non security users and I don't see a lot to worry about.

http://www.spywarewarrior.com/rogue_anti-spyware.htm#criteria Quote: 1. File not foundO4 - Startup: C:\Users\jayandjuls\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: You may find it helpful to print these instructions before you tackle them.Remove IE Host MaxSpeed and PGate Basic through Add/Remove Programs.

Then right click on the saved reg file, choose Open With>Notepad. During the download and scan the toolbars and popups came back. Quote: Ad-Eliminator spam-driven, aggressive advertising (1, 2, 3); browser hijacking (1); Note, the numbers are links to other information. "Spam driven" in that case means email spam.

Posted: Tue Jul 31, 2007 6:15 am Post subject: Yeah, I remember him trying to defend having one of those fake "YOU HAVE SPYWARE" dialogs pop up on his website, for Please advise. but you know, if Suzi Turner of spywarewarrior fame (or whoever else for that matter) doesn't feel the need to hurl themselves with guns blazing at what YOU feel to be Post in the Forums instead and we will all learn.