I have had this really annoying red circle with a white cross in mhy system tray which every so often, flashes up with a message saying viruses detected. If i click on the message it takes me to a companies website to buy there anti-virus product.

I have tried to download AVG but it wont open, ive tried to download spybot, but that wont open. Ive read a few of your other threads but HijackThis wont open either. Im really stuck for ideas and its REALLY frustrating ha.

Hope to hear from someone soon.


Hi and welcome to the Daniweb forums :).


Download Itty Bitty Process Manager (IBProcMan.zip)(direct download) http://www.merijn.org/files/ibprocman.zip
Run the process manager. Near the top right there are a couple of icons. Select the one to the left to copy to the clipboard. Paste the results back here.

Process list saved on 17:18:19, on 30/03/2008
Platform: WinNT 5.01.2600 SP2

[pid] [full path to filename] [file version] [company name]
1156 C:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation
1296 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2508 Microsoft Corporation
1340 C:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation
1352 C:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation
1528 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1660 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
404 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.2696 Microsoft Corporation
524 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Apple, Inc.
556 C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe Authentium, Inc.
592 C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe CA, Inc.
632 C:\Program Files\Network Associates\Common Framework\FrameworkService.exe Network Associates, Inc.
748 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 7.0.9466.0 Microsoft Corporation
852 C:\Program Files\Raxco\PerfectDisk\PDAgent.exe Raxco Software, Inc.
1188 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1788 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe ATI Technologies Inc.
1780 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Synaptics, Inc.
1948 C:\WINDOWS\RTHDCPL.EXE Realtek Semiconductor Corp.
1708 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe Cyberlink Corp.
2972 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe Sun Microsystems, Inc.
2992 C:\Program Files\Common Files\Real\Update_OB\realsched.exe RealNetworks, Inc.
3012 C:\Program Files\iTunes\iTunesHelper.exe Apple Inc.
3268 C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe Network Associates, Inc.
3364 C:\Program Files\MSN Messenger\MsnMsgr.Exe Microsoft Corporation
3604 C:\WINDOWS\system32\ctfmon.exe 5.1.2600.2180 Microsoft Corporation
3840 C:\Program Files\BitTorrent\bittorrent.exe
232 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe Safer Networking Limited
1928 C:\Program Files\FinePixViewerS\QuickDCF2.exe FUJIFILM Corporation
2476 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe ATI Technologies Inc.
2500 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe ATI Technologies Inc.
2468 C:\WINDOWS\system32\nod32se.exe
2548 C:\Program Files\Internet Explorer\IEXPLORE.EXE 7.0.6000.16608 Microsoft Corporation
2628 C:\WINDOWS\system32\msiexec.exe 3.1.4000.1823 Microsoft Corporation
3164 C:\Program Files\iPod\bin\iPodService.exe Apple Inc.
3032 C:\Program Files\MSN Messenger\usnsvc.exe Microsoft Corporation
3160 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
3256 C:\WINDOWS\system32\rundll32.exe 5.1.2600.2180 Microsoft Corporation
2340 C:\WINDOWS\explorer.exe 6.0.2900.3156 Microsoft Corporation
2988 C:\PROGRA~1\WINZIP\winzip32.exe 21.0.6698.0 WinZip Computing LP
3816 C:\Documents and Settings\Ollie\Local Settings\Temp\wz5cbf\IBProcMan.exe Soeperman Enterprises Ltd.

This is what come up. Thanks a lot

Delete the following file; C:\WINDOWS\system32\nod32se.exe If you cannot delete it in normal mode, try it in safe mode.
Once done. post an hijackthis log.

Thanks. But HiJackThis wont open. I've downloaded both the old version and new version, i download them, extract them and double click them, then click run the programme but nothing happens.


Have tried it in safe mode after deleting that file and it still doesn't work. Kind of stuck now ha

Ive tried all that, and still not loading. now saying that its not a valid win32 application(slight improvement ha).

Download Dial-a-Fix and run it. Select the 'Check all' (green arrow) and then hit 'GO.'
Reboot when done and see how things are now.