In that reply, please include the following information:If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed button A list of tool components used in the Cleanup of malware will be downloaded. No, create an account now. Repeat as many times as necessary to remove each Java versions. http://technewsonline.net/general/hpqimzone.html

andyspeake, May 12, 2008 #2 Craig O2 Thread Starter Joined: Jan 13, 2006 Messages: 54 Thanks for your quick reply andyspeake...I have researched this topic after I posted this thread and Right click on the index.dat file(s) located in the Cookies folder. cybertech, Mar 26, 2008 #18 gator47 Thread Starter Joined: Aug 25, 2007 Messages: 38 Hi Cybertech, Here are the logs: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 03/25/2008 at 09:46 PM Application Version At each of these, Combofix finds and deletes several files located in this directory in all user accounts on the machine: c:\documents and settings\\Local Settings\Application Data\ApplicationHistory Unfortunately within a day or

However, you can also delete it oneself by opening My Computer>Local Disk (C:)>Windows>Temp which must open up the Temp folder that contains your temporary files, then vacant the folder by urgent Similar Threads - Solved Infected In Progress im infected trojan.kotver VIRUS please help tonytone026, Oct 17, 2016, in forum: Virus & Other Malware Removal Replies: 22 Views: 700 kevinf80 Oct 22, Well? Will do our best to clean the computer of any infections seen on the log.

Any more comments on this subject would be appreciated. This applies only to the originator of this thread.

There is a known bug in IE 6 with certain cache headers. Most common examples include: 1) incomplete software installation; 2) incomplete software uninstallation; 3) improperly deleted hardware drivers, and 4) improperly deleted software applications. This user C:\WINNT\Internet Logs\USER-OUSUQOD9X1.ldb <-- is controlling your machine You've been severely compromised. https://forums.spybot.info/showthread.php?11517-How-do-i-know-WinFix-is-gone Next, please visit this webpage for instructions for running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix When the tool is finished, it will produce a report for you.Please post the contents of C:\ComboFix.txt along with a

cybertech, Mar 25, 2008 #16 gator47 Thread Starter Joined: Aug 25, 2007 Messages: 38 I searched the forums and the internet and found a few things to do that could resolve I will definitely make a donation. Please do this even if you have previously posted logs for us.If you were unable to produce the logs originally please try once more.If you are unable to create a log Click the "Download" button to the right.

  • Craig O2, May 14, 2008 #7 Craig O2 Thread Starter Joined: Jan 13, 2006 Messages: 54 Kaspersky log: KASPERSKY ONLINE SCANNER REPORT Wednesday, May 14, 2008 2:31:07 AM Operating System: Microsoft
  Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.
  • What are Hpqimzone.exe errors?
  • catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-09-30 00:45 Windows 5.1.2600 Service Pack 3 NTFS .
  • Here are some free programs I recommend that could help you improve your computer's security.
  • Craig Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:36:07 PM, on 5/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe

The workstation is running Windows XP Pro SP3 and Office Small Business 2007, Publisher would open but freeze up and within minutes would freeze Windows itself, and also attempting to open gator47, Mar 27, 2008 #21 cybertech Moderator Joined: Apr 16, 2002 Messages: 71,969 The link is working, try it again.

Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix) Checkmark "Create a desktop icon" Click "Next" When the installation is completed, make sure that the checkmark "Launch Instructions on how to properly create a GMER log can be found here: How to create a GMER log

Next, download DDS by sUBs and save it to your Desktop. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if It seems to be the last script run when opening the page.

While the computer is still disconnected from the internet do the following: START>FIND>FILES OR FOLDERS. Click here to join today! If scripts are disabled, this does not occur.

HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.

Please perform the following scan again: Download DDS by sUBs from one of the following links if you no longer have it available. Conduct a search and install any update or patches. Once the scanner is installed and the definitions downloaded, click Next. These things show again after a few days and after some scans in between show nothing but cookies.

All were generated under safe-mode. The ESET program reported removing several files. Anything you can tell me would be greatly appreciated.

Craig Craig O2, May 12, 2008 #3 andyspeake Joined: May 10, 2007 Messages: 1,543 Hi Craig 02 I understand... However, because of the nature of this Trojan, cannot offer a total guarantee that there are no remnants left in the system, or that the computer will be trustworthy. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll O4 - HKLM\..\Run: [Cpqset] "C:\Program Files\HPQ\Default Settings\cpqset.exe" O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [UpdateManager]