I tried following some steps posted at

but i just cant delete these things.

im new here and
any help would be greatly appreciated.

here is my hijackthis log file:

Logfile of HijackThis v1.99.1
Scan saved at 5:00:01 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BurnQuick\BQTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ntno.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Danny\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ebght.dll/sp.html#14414
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ebght.dll/sp.html#14414
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ebght.dll/sp.html#14414
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ebght.dll/sp.html#14414
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ebght.dll/sp.html#14414
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ebght.dll/sp.html#14414
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {073D5A0C-5151-8F0F-C7E0-9D9FED5FEB3F} - C:\WINDOWS\apiaa32.dll
O2 - BHO: Class - {4C8A9B6F-E22A-47B8-3681-57CF60399D4A} - C:\WINDOWS\addzq.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {CBCBACBA-B5C6-0928-434A-CE4EEBE36A38} - C:\WINDOWS\ntno.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [BurnQuick Queue] C:\Program Files\BurnQuick\BQTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ntno.exe] C:\WINDOWS\ntno.exe
O4 - HKLM\..\RunOnce: [winlg32.exe] C:\WINDOWS\system32\winlg32.exe
O4 - HKLM\..\RunOnce: [sdkxx32.exe] C:\WINDOWS\sdkxx32.exe
O4 - HKLM\..\RunOnce: [winsj.exe] C:\WINDOWS\winsj.exe
O4 - HKLM\..\RunOnce: [wincf.exe] C:\WINDOWS\system32\wincf.exe
O4 - HKLM\..\RunOnce: [javahz32.exe] C:\WINDOWS\system32\javahz32.exe
O4 - HKLM\..\RunOnce: [msgm32.exe] C:\WINDOWS\system32\msgm32.exe
O4 - HKLM\..\RunOnce: [javabn32.exe] C:\WINDOWS\system32\javabn32.exe
O4 - HKLM\..\RunOnce: [addvw.exe] C:\WINDOWS\addvw.exe
O4 - HKLM\..\RunOnce: [d3bq32.exe] C:\WINDOWS\d3bq32.exe
O4 - HKLM\..\RunOnce: [wintj32.exe] C:\WINDOWS\system32\wintj32.exe
O4 - HKLM\..\RunOnce: [mfcvc32.exe] C:\WINDOWS\mfcvc32.exe
O4 - HKLM\..\RunOnce: [atlrr32.exe] C:\WINDOWS\system32\atlrr32.exe
O4 - HKLM\..\RunOnce: [d3ql.exe] C:\WINDOWS\system32\d3ql.exe
O4 - HKLM\..\RunOnce: [ntdr.exe] C:\WINDOWS\ntdr.exe
O4 - HKLM\..\RunOnce: [javayl32.exe] C:\WINDOWS\javayl32.exe
O4 - HKLM\..\RunOnce: [apien.exe] C:\WINDOWS\apien.exe
O4 - HKLM\..\RunOnce: [ntoi32.exe] C:\WINDOWS\ntoi32.exe
O4 - HKLM\..\RunOnce: [atlbl.exe] C:\WINDOWS\atlbl.exe
O4 - HKLM\..\RunOnce: [ieay32.exe] C:\WINDOWS\ieay32.exe
O4 - HKLM\..\RunOnce: [d3qv32.exe] C:\WINDOWS\d3qv32.exe
O4 - HKLM\..\RunOnce: [netdq.exe] C:\WINDOWS\system32\netdq.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chess -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\winlg32.exe" /s (file missing)

Dani AI

Generated

Quick diagnosis: this looks like a classic browser‑hijack/adware infection that persistently drops malicious autoruns, browser helper objects and local resource handlers that replace your search/homepage and proxy settings. The fact that two different HJT logs from show the problem reappearing under new names means the infection is actively reinstalling itself on every boot — removal needs to be done offline or from Safe Mode and should be done carefully.

Recommended triage (in order):

  • Immediately disconnect the PC from the Internet and back up any personal files to external media.
  • Follow ’s step: put HijackThis in its own folder, then reboot into Safe Mode (press F8) and run a fresh HJT scan. Save that new log to a text file.
  • Use HJT only to remove clearly malicious autoruns and BHOs (unknown add-ons and entries that point to executables in the Windows folder with random names). Do not use “Fix All.” If you are not sure about an entry, post the new log before removing it.
  • Run at least one up‑to‑date on‑demand scanner (Spybot/Ad‑Aware historically; use a modern scanner such as Malwarebytes or an online AV scan if available). If files are locked, delete them from Safe Mode or from a bootable rescue environment.

Further cleanup and checks:

  • Clear any proxy settings and reset Internet Explorer options (homepage/search) to defaults.
  • Inspect Services, Scheduled Tasks and the HOSTS file for unknown entries and remove with care (export the registry or create a restore point before editing).
  • If the infection prevents removal or keeps returning, consider an offline rescue disk or a repair install / clean reinstall. After cleanup, change online passwords and monitor accounts.

If uncertain at any step, post the new HijackThis log (saved as text) and note which removals you attempted.

Recommended Answers

All 2 Replies

heres the same log
now that hijack is in a folder on my desktop.

Logfile of HijackThis v1.99.1
Scan saved at 6:03:33 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BurnQuick\BQTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ntno.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Danny\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\dhqga.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {8EB47657-BB7C-EE46-7E07-788E22830E97} - C:\WINDOWS\system32\netxt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {CBCBACBA-B5C6-0928-434A-CE4EEBE36A38} - C:\WINDOWS\ntno.dll
O2 - BHO: Class - {FDF7C470-8C5B-1326-678C-D33C9AE9414B} - C:\WINDOWS\system32\msdp32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [BurnQuick Queue] C:\Program Files\BurnQuick\BQTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ntno.exe] C:\WINDOWS\ntno.exe
O4 - HKLM\..\RunOnce: [winlg32.exe] C:\WINDOWS\system32\winlg32.exe
O4 - HKLM\..\RunOnce: [sdkxx32.exe] C:\WINDOWS\sdkxx32.exe
O4 - HKLM\..\RunOnce: [winsj.exe] C:\WINDOWS\winsj.exe
O4 - HKLM\..\RunOnce: [wincf.exe] C:\WINDOWS\system32\wincf.exe
O4 - HKLM\..\RunOnce: [javahz32.exe] C:\WINDOWS\system32\javahz32.exe
O4 - HKLM\..\RunOnce: [msgm32.exe] C:\WINDOWS\system32\msgm32.exe
O4 - HKLM\..\RunOnce: [javabn32.exe] C:\WINDOWS\system32\javabn32.exe
O4 - HKLM\..\RunOnce: [addvw.exe] C:\WINDOWS\addvw.exe
O4 - HKLM\..\RunOnce: [d3bq32.exe] C:\WINDOWS\d3bq32.exe
O4 - HKLM\..\RunOnce: [wintj32.exe] C:\WINDOWS\system32\wintj32.exe
O4 - HKLM\..\RunOnce: [mfcvc32.exe] C:\WINDOWS\mfcvc32.exe
O4 - HKLM\..\RunOnce: [atlrr32.exe] C:\WINDOWS\system32\atlrr32.exe
O4 - HKLM\..\RunOnce: [d3ql.exe] C:\WINDOWS\system32\d3ql.exe
O4 - HKLM\..\RunOnce: [ntdr.exe] C:\WINDOWS\ntdr.exe
O4 - HKLM\..\RunOnce: [javayl32.exe] C:\WINDOWS\javayl32.exe
O4 - HKLM\..\RunOnce: [apien.exe] C:\WINDOWS\apien.exe
O4 - HKLM\..\RunOnce: [ntoi32.exe] C:\WINDOWS\ntoi32.exe
O4 - HKLM\..\RunOnce: [atlbl.exe] C:\WINDOWS\atlbl.exe
O4 - HKLM\..\RunOnce: [ieay32.exe] C:\WINDOWS\ieay32.exe
O4 - HKLM\..\RunOnce: [d3qv32.exe] C:\WINDOWS\d3qv32.exe
O4 - HKLM\..\RunOnce: [netdq.exe] C:\WINDOWS\system32\netdq.exe
O4 - HKLM\..\RunOnce: [msey.exe] C:\WINDOWS\msey.exe
O4 - HKLM\..\RunOnce: [ntra32.exe] C:\WINDOWS\system32\ntra32.exe
O4 - HKLM\..\RunOnce: [ieru32.exe] C:\WINDOWS\system32\ieru32.exe
O4 - HKLM\..\RunOnce: [sdkxp32.exe] C:\WINDOWS\system32\sdkxp32.exe
O4 - HKLM\..\RunOnce: [syssa32.exe] C:\WINDOWS\syssa32.exe
O4 - HKLM\..\RunOnce: [appxf.exe] C:\WINDOWS\appxf.exe
O4 - HKLM\..\RunOnce: [sdkpm32.exe] C:\WINDOWS\sdkpm32.exe
O4 - HKLM\..\RunOnce: [syskk.exe] C:\WINDOWS\system32\syskk.exe
O4 - HKLM\..\RunOnce: [mfcvo32.exe] C:\WINDOWS\system32\mfcvo32.exe
O4 - HKLM\..\RunOnce: [d3pa.exe] C:\WINDOWS\system32\d3pa.exe
O4 - HKLM\..\RunOnce: [atlkj.exe] C:\WINDOWS\atlkj.exe
O4 - HKLM\..\RunOnce: [sysfj.exe] C:\WINDOWS\system32\sysfj.exe
O4 - HKLM\..\RunOnce: [adddo32.exe] C:\WINDOWS\adddo32.exe
O4 - HKLM\..\RunOnce: [iehs32.exe] C:\WINDOWS\system32\iehs32.exe
O4 - HKLM\..\RunOnce: [winlw.exe] C:\WINDOWS\winlw.exe
O4 - HKLM\..\RunOnce: [crry.exe] C:\WINDOWS\system32\crry.exe
O4 - HKLM\..\RunOnce: [crlp.exe] C:\WINDOWS\crlp.exe
O4 - HKLM\..\RunOnce: [winvi.exe] C:\WINDOWS\system32\winvi.exe
O4 - HKLM\..\RunOnce: [syseo.exe] C:\WINDOWS\syseo.exe
O4 - HKLM\..\RunOnce: [javaji32.exe] C:\WINDOWS\javaji32.exe
O4 - HKLM\..\RunOnce: [ntns.exe] C:\WINDOWS\system32\ntns.exe
O4 - HKLM\..\RunOnce: [atlyl32.exe] C:\WINDOWS\system32\atlyl32.exe
O4 - HKLM\..\RunOnce: [msdf.exe] C:\WINDOWS\msdf.exe
O4 - HKLM\..\RunOnce: [d3mf32.exe] C:\WINDOWS\system32\d3mf32.exe
O4 - HKLM\..\RunOnce: [iprh.exe] C:\WINDOWS\system32\iprh.exe
O4 - HKLM\..\RunOnce: [mstl.exe] C:\WINDOWS\mstl.exe
O4 - HKLM\..\RunOnce: [javaxp.exe] C:\WINDOWS\system32\javaxp.exe
O4 - HKLM\..\RunOnce: [mfclr32.exe] C:\WINDOWS\system32\mfclr32.exe
O4 - HKLM\..\RunOnce: [d3dr.exe] C:\WINDOWS\system32\d3dr.exe
O4 - HKLM\..\RunOnce: [addoo32.exe] C:\WINDOWS\addoo32.exe
O4 - HKLM\..\RunOnce: [winsd32.exe] C:\WINDOWS\winsd32.exe
O4 - HKLM\..\RunOnce: [javafx.exe] C:\WINDOWS\system32\javafx.exe
O4 - HKLM\..\RunOnce: [cram.exe] C:\WINDOWS\cram.exe
O4 - HKLM\..\RunOnce: [apiop32.exe] C:\WINDOWS\system32\apiop32.exe
O4 - HKLM\..\RunOnce: [addmc32.exe] C:\WINDOWS\addmc32.exe
O4 - HKLM\..\RunOnce: [atlyn.exe] C:\WINDOWS\atlyn.exe
O4 - HKLM\..\RunOnce: [msdp32.exe] C:\WINDOWS\system32\msdp32.exe
O4 - HKLM\..\RunOnce: [syswa32.exe] C:\WINDOWS\system32\syswa32.exe
O4 - HKLM\..\RunOnce: [sdkcd32.exe] C:\WINDOWS\sdkcd32.exe
O4 - HKLM\..\RunOnce: [crvo32.exe] C:\WINDOWS\crvo32.exe
O4 - HKLM\..\RunOnce: [apiak32.exe] C:\WINDOWS\system32\apiak32.exe
O4 - HKLM\..\RunOnce: [winfm.exe] C:\WINDOWS\system32\winfm.exe
O4 - HKLM\..\RunOnce: [mfcqn32.exe] C:\WINDOWS\system32\mfcqn32.exe
O4 - HKLM\..\RunOnce: [iedh.exe] C:\WINDOWS\system32\iedh.exe
O4 - HKLM\..\RunOnce: [crca.exe] C:\WINDOWS\crca.exe
O4 - HKLM\..\RunOnce: [ntrq.exe] C:\WINDOWS\ntrq.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chess -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\winlg32.exe" /s (file missing)

Hi tibsone, welcome to DaniWeb :D

Please follow the suggestions in the following threads:

http://www.daniweb.com/techtalkforums/thread27519.html

http://www.daniweb.com/techtalkforums/thread27570.html

Then, right-click in an open area of your desktop and select New, Folder; give the new folder a name (like HJT or HijackThis), and then drag the hijackthis.exe icon that is on your desktop into the new folder.

Close any open browser windows, scan with HJT, and post a new log please.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.