first you should have posted this in you original thread to carry on ,instead of creating a new one and making us go look for the orignal.!:)
I suggest running ad-aware again ,but make sure you set it up in this way !
Setup Ad-Aware !
After installing AAW, and before running the program, update reference files by using the bottom right button in the program, labeled "Check for Updates."
Launch the program, and click on the Gear at the top of the start screen.
Click the "Scanning" button.
Under Drives & Folders, select "Scan within Archives".
Click "Click here to select Drives + folders" and select your installed hard drives.
Under Memory & Registry, select all options.
Click the "Advanced" button.
Under "Log-file detail", select all options.
Click the "Tweaks" button.
Under "Scanning Engine", select the following:
"Include additional Ad-aware settings in logfile" and
"Unload recognized processes during scanning."
Under "Cleaning Engine", select the following:
"Let Windows remove files in use after reboot."
Click on 'Proceed' to save these Preferences.
Please make sure that you activate IN-DEPTH scanning before you proceed
Reboot and post a fresh log
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
NOTE: Please copy and paste this post into notepad and save to you desktop. or print a copy of these instructions because you will be working with all windows closed except HijackThis.
O2 - BHO: TEAM NAME PING - {2CB0EC4C-4750-3EB0-26E8-A417B52951FD} - C:\PROGRAM FILES\EQ DOWNLOAD SECOND\JUNK PROC.DLL
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\QUESTMOD-1.DLL
O3 - Toolbar: Burn Safe Program - {0BDD997F-4C81-27D5-5A76-7535B038238A} - C:\PROGRAM FILES\EQ DOWNLOAD SECOND\JUNK PROC.DLL
O4 - HKLM\..\Run: [drive idle] C:\PROGRA~1\Idol Bone Seek\TitleFlagDupe.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/24369f021d1a5e...tzip/RdxIE2.cab
Now reboot into safe mode and delete the following files and folders if found .
C:\PROGRA~1\Idol Bone Seek\TitleFlagDupe.exe....delete file and folder
to delete the above files and folder you will need to do the following
go to
Show hidden files & folders
"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode
reboot computer and post a new log
After you get it all fixed and things are working good ,Download and install these two programs to help stop Spyware .
Spywareblaster
SpywareGuard
Keep Up-to-Date!
The most important key to maintaining a secure computer is keeping your protection up-to-date.
also check how i got infected in the first place .
http://www.computercops.biz/postlite7736-.html
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Your problems probably started when you installed Bear Share
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
...how do I boot in to safe mode?
Hit the "F8" key just as or just before the "Starting Windows" type message appears. The timing can be kind of tricky; if you hit F8 too late your computer will boot into normal statup mode. If that happens, reboot and just start tapping the F8 key a little earlier as the computer is restarting.
Once you get into the "safe mode" boot options screen, just choose the plain "Safe Mode" option.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Good to see you got it fixed .
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Are there any other things I could try?
If you're going to still be using IE at all, make sure you use Windows Update to install the lastest critical fixes; some recently-discovered security holes in IE have been addresses in these patches.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370