jholland1964 650 Posting Expert Team Colleague Featured Poster

Thanks! I will have a look at the pics. Ooh...see you have Charleston, SC on there. Headed there on Friday for the week. We go every year for family vacations. Folly Beach actually, just 9 miles from Charleston.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Office Startup is Unchecked not checked, meaning it is NOT starting. Turn off that Find Fast that is not needed for sure. Though neither of those are 16 bit programs.

jholland1964 650 Posting Expert Team Colleague Featured Poster

I certainly wouldn't recommend doing a wipe and reinstall. That really is a bit more than needed. I don't see a firewall on there, what do you use?
As far as pop ups, do you have a pop up blocker? I am pretty much grasping at straws here as I don't see infection on the scans.
I also see nothing that would be playing music without your knowing it. Of course pop ups sometime contain sound, they are ads of course.
I would advise that you install a firewall if you don't have one, and also install SpywareBlaster. A superb FREE program that will block ActiveX-based spyware, adware, dialers, browser hijackers, and other potentially unwanted programs. It can also block spyware/tracking cookies in IE, Mozilla Firefox and it DOESN'T run in the background. Just download, install Update, Enable ALL protection including Restricted Sites portion and close the program, that's it. Manually check for updates every week or so.
Also make sure your browsers are set to Accept 1st party cookies, and Block 3rd party cookies.
That's all I can think of for the moment, but a wipe and reinstall is certainly NOT necessary.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Winamp is my player of choice, I have the newest version.

Check to see if the volume slider in the main Winamp window is set at zero.
If so, turn it up to the desired level

jholland1964 650 Posting Expert Team Colleague Featured Poster

Don't know that I have been much help if you are still having these problems. Can't see anything in the logs which would indicate as being the cause of the .wav volume is still resetting to zero.
Still getting pop ups with IE mostly, not so much with Firefox.
Still Hearing ads in background.
Had a similar one a couple weeks ago on another forum and got all the pop ups stopped and the volume corrected but person was still hearing things from background. That one ended up being Real Player being up and running all the time. He hadn't used Real Player in a couple years but suddenly it "activated" itself evidently. He uninstalled it and no problem.
One totally unnecessary Service I see is Bonjour Service which is automatically installed and enabled with the iTunes software. It isn't needed at all. You might go into Administrative Tools, Services and Stop it and then Disable it.
What media player are you using? Have you updated all your Sound & Audio Devices or looked for new drivers?
Also noticed, which would likely have nothing to do with the sounds playing, but CDBurnerXP is running all the time in the background. This shows in nearly all of your logs. This is totally unnecessary and should only be running if you are actually using it.

jholland1964 650 Posting Expert Team Colleague Featured Poster

The search redirecting has stopped.
The .wav volume is still resetting to zero.
Still getting pop ups with IE mostly, not so much with Firefox.
Still Hearing ads in background.

Ok then do the following:

Please download ComboFix by sUBs from HERE
· You must download it to and run it from your Desktop
· Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
· Double click combofix.exe & follow the prompts.
· When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
· Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

jholland1964 650 Posting Expert Team Colleague Featured Poster

Are you still having the problems noted in your first post? Sounds though, because of the attempt by the trojan to come onto your system there is still "something" there "phoning home",

jholland1964 650 Posting Expert Team Colleague Featured Poster

You need to wait to do the updates until we are certain the computer is clean. That is one of the main requirements.
You are going to need to do those two scans again.
Update MBA-M and run the full scan again, be sure to remove everything found. Reboot and then do the ESET scan again, also remove everything found.
Then do a new HJT scan.
Post back with those three logs.

jholland1964 650 Posting Expert Team Colleague Featured Poster

You didn't answer my question, did you remove all those dangerous sites from the Host file?

jholland1964 650 Posting Expert Team Colleague Featured Poster

None of those removals should have caused this error but it can be caused by out of date software or hardware. Your computer is way out of date. SP3 has been out for well over two years and support for XP SP2 ended yesterday. Microsoft .NET Framework is now up to version 3.5 SP1, your Java is out of date it is currently at version 6 update 21.
You might try this:
To start your computer by using the Last Known Good Configuration feature, follow these steps:

1. Start your computer.
2. tap the "F8 key" continuously until you get the startup menu.
3. When the Windows Advanced Options menu appears, use the ARROW keys to select Last Known Good Configuration (your most recent settings that worked), and then press ENTER.
4. If you are running other operating systems on your computer, use the ARROW keys to select Microsoft Windows XP, and then press ENTER.
See if this allows you to boot up.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Run HiJackThis again, place check marks next to the following entries.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5577
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKCU\..\Run: [UpdateMyDrivers] C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe -t
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [ieabwrho] C:\Documents and Settings\LocalService\Local Settings\Application Data\sjnqmxnnr\nadcenatssd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ieabwrho] C:\Documents and Settings\LocalService\Local Settings\Application Data\sjnqmxnnr\nadcenatssd.exe (User 'Default user')

Once all the check marks are placed then click the Fix Checked button. Exit HJT, reboot and run a new system scan with HiJackThis and post back here with the new log. …

jholland1964 650 Posting Expert Team Colleague Featured Poster

Yes do the msconfig operation. Let me know what happens there. Very strange.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Are you still getting that 16 bit error notification?
Update MBA-M and run a new Full Scan with it.
Have it remove all items found.
Reboot and post back here with the log.
Judy

jholland1964 650 Posting Expert Team Colleague Featured Poster

Question, on your original OTL log you showed a multitude of extremely dangerous Host file listings, they do not show on other logs, did you manually remove them?
Then on the DDS log you also show a disreputable host file,spywareinfo.com did you remove this one also?

You have run a lot of scans but not the one that we always recommend, as it is really the top of the line, Malwarebytes'Anti-Malware (MBA-M)
I would like you to please first turn OFF the following programs as they may interfere with any fixes attempted:
Windows Defender and the AdAware Service.
Then do the following:
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Reboot …

jholland1964 650 Posting Expert Team Colleague Featured Poster

Just went back through all of your logs and found an entry I had overlooked in all your HJT logs I am very sorry to say:
O4 - HKLM\..\Run: [ToolCar] C:\WINDOWS\system32\cttfmon.exe Note the two "t's" there.

There is normal file with a similar name which is on the computer, ctfmon.exe (note just 1 "t".
but the one noted in red is a trojan. This "might" be your error message trigger, I cannot say for sure. But it ISN'T supposed to be there regardless.

Please do the following:
Please download ComboFix by sUBs from HERE
· You must download it to and run it from your Desktop
· Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
· Double click combofix.exe & follow the prompts.
· When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
· Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

jholland1964 650 Posting Expert Team Colleague Featured Poster

Ok then it obviously is one of your auto starting programs or services.
Begin by going to start, run, msconfig.
First thing I want you to do is click the Start Up tab. Make a note of all items noted there with check marks in them. Then take the check marks out and reboot the computer. See if you get the pop up error message. If you do not then you will know it is one of those auto starting programs. But if you DO still receive that message then you will know it wasn't one of those but a service that is causing this.
If you DON'T get the message however here is what you will have to do to narrow it down:
You will then have to go back into msconfig and add the check marks back, one at a time, restart after each one. When you finally get the pop up message then you will know which one is causing it and be sure to come back here and let me know what it was.
If you still got the message when removing those check marks come back here and report that.
Judy

jholland1964 650 Posting Expert Team Colleague Featured Poster

Please do the following:
Download HiJackThis.
Run a system scan with it, save the log and post back here with it.

jholland1964 650 Posting Expert Team Colleague Featured Poster

This happens randomly not when you have attempted to run a specific program?

jholland1964 650 Posting Expert Team Colleague Featured Poster

Now download HiJackThis

First I would like you to do a system scan, save the log and post it here.
Also do an Uninstall list with Hijackthis also.
To do this follow these steps:
Start HijackThis
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad into a reply also.
Judy

jholland1964 650 Posting Expert Team Colleague Featured Poster

Yes it most certainly can be happening because of spyware. Try following the steps given in our Read Me sticky and post the logs here.
If you cannot access them in normal mode then try Safe Mode with Networking.
http://www.daniweb.com/forums/thread134865.html

jholland1964 650 Posting Expert Team Colleague Featured Poster

Ok, there may be more infection on there so lets check all that out first then work on missing devices, ok?
Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.

* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

jholland1964 650 Posting Expert Team Colleague Featured Poster

n0pz, if rkill IS needed I will give instructions for it, for the moment let us wait and see what ssj4tim is able to accomplish.

ssj4tim please attempt the step as I have given it. If you are unable to complete the instructions then please post back and I will give you an alternate method of accessing the program.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Reboot the computer->VERY IMPORTANT.
Come back here and post the MBA-M log.
Judy

jholland1964 650 Posting Expert Team Colleague Featured Poster

Just give us a print screen of the error and attach it to a reply. We don't give assistance via email.

jholland1964 650 Posting Expert Team Colleague Featured Poster

You need to run the rest of the scans recommended and post back with those logs.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Try reinstalling the camera again, first though check in Add/Remove, if it is listed there uninstall it first.
I can't find anything either for the 16bit error but am still looking. Are you absolutely certain that it gives no program or file name in addition to the error message?

jholland1964 650 Posting Expert Team Colleague Featured Poster

What you need to do is follow all the steps given in our Read Me Sticky. Post back here with all the logs and we can better offer assistance.

http://www.daniweb.com/forums/thread134865.html

jholland1964 650 Posting Expert Team Colleague Featured Poster

Do you have a driver disk for the camera? If not, go to the Logitech page and see if there is a driver available.
Also a thought, it could possibly be the USB cable itself for the camera that is a problem.

jholland1964 650 Posting Expert Team Colleague Featured Poster

RegCure removal isn't the cause of this, that only removed a program and it would have absolutely nothing to do with the USB ports. Something you noted earlier but I didn't see originally very likely has caused this:
"The other thing I've noticed is that before I was able to restore the laptop to an earlier date but now it only gives the option to restore it to some of the points in the current period I have signed on (ie.: today)"
Why were you using System Restore? It sounds to me like you have restored it back too far.
System Restore actually operates only on a very few system files and settings. System Restore backs up your registry. System Restore does not backup your data. If you delete or damage a file, System Restore will not recover it. System Restore will NOT uninstall a program. In fact if you have installed a program and find you don't want it if you use System Restore it may leave you with much of the program but it just won't be listed in Add/Remove, making it much harder to uninstall. System Restore does not keep old copies of your files or settings. If you're looking for an "old version" of a file or program that you used to have on your machine, System Restore isn't going to have it. System Restore does not fix your system.
System Restore is meant to restore from very RECENT changes like just …

jholland1964 650 Posting Expert Team Colleague Featured Poster

Have you tried anything else in those USB slots to be sure they are working?

jholland1964 650 Posting Expert Team Colleague Featured Poster

I am not certain why you felt it necessary to uninstall any other programs other than that RegCure program I noted. The others would not likely have been 16 bit programs.
Have you tried the camera in another USB port? The wireless mouse is just that wireless so just because the computer sees that wouldn't apply to the camera, the camera IS being plugged into the system so they are not the same thing.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Yes remove that. It would not have installed on it's own however, you would have had to have installed it. It is a registry cleaning program which is totally unnecessary and can cause problems with the computer. Uninstall that and see if that helps. Hopefully it has not damaged the registry.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Since this only happens when you log on then it has to be something that you have set to run. This would be an old program. Something that you used on an older computer running an older operating system I would think. I cannot be certain though.
I looked through your latest HJT log and see nothing there. Have you always had this happen or is this new?
How old is this ClamWin program?

jholland1964 650 Posting Expert Team Colleague Featured Poster

I cannot honestly say. Am not familiar with the program. Is it a really old program?
When you get that message does it list a specific program with it or just that it cannot run the 16bit program?

jholland1964 650 Posting Expert Team Colleague Featured Poster

Well none of those would likely be a 16bit program.Do you possibly have a program on there that you used with a very old computer?

jholland1964 650 Posting Expert Team Colleague Featured Poster

A simple way might be to use Mike Lin's Startup Control Panel.
It will show you various items set to run at start up.

Or another which shows both auto starting programs and auto starting services is CodeStuff Starter.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Do you know what this 16bit program is that is trying to run? This would likely be a very old program.
As far as the Clamwin vs. AVG since you have paid for the AVG and Clamwin is free I believe then it would all right to remove the Clamwin and go back to the AVG. However, when the subscription runs out I would strongly advise against using it again. It just doesn't do the job it used to do. We usually recommend either Avira Free or Avast Free, both score much higher in tests than AVG. I myself use Avira free, have for several years and am extremely pleased with it.
Try the hotmail log in and see what happens. Also report back on what program it seems to be that is a 16bit program.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Looks better. Did you uninstall Combofix per PP's instructions?

jholland1964 650 Posting Expert Team Colleague Featured Poster

Update MBA-M and run another Full Scan with it. Allow it to remove everything found. Reboot the system.
Then run a new HJT scan, post back with both logs.
Judy

jholland1964 650 Posting Expert Team Colleague Featured Poster

I was just going to ask you...why the Chinese? I have never seen this before in a combofix log. Where did you download combofix from?

jholland1964 650 Posting Expert Team Colleague Featured Poster

Folks this thread is 5 years old. I imagine the poster has made his choice by now.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Hello AP, sorry for the delay. As you can tell we are short handed here. First thing I see is you are running two anti-virus programs, ClamWin and AVG 9. This is a big no-no. The absolute rule is ONE anti-virus program should be running on a computer. Running more than one actually reduces your protection because they do conflict with each other. At this time please Uninstall AVG 9 completely, I will give advice later on a better anti-virus program to use. For now, leave the ClamWin.
I would also advise that you Uninstall Spyware Doctor entirely also. There are much better anti-spyware programs that you can use.
After you have uninstalled AVG 9 and Spyware Doctor then run HiJackThis again and place checkmarks next to the following entries, IF they remain. Some may not show anymore after the uninstalls but check to be certain:

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O1 - Hosts: 14.13.91.1 merlgfoc.gustemrrbergo
O1 - Hosts: 43.66.12.75 figggura.sangfta
O1 - Hosts: 65.43.65.12 eikgfe.batgfista
O1 - Hosts: 95.43.25.65 lucigffer.anjobhgelo
O1 - Hosts: 54.41.66.43 caigfxao.vamgfpiro
O1 - Hosts: 54.65.75.124 contgfainers.sgfapobolha
O1 - Hosts: 124.154.123.1 elbgba.ramalgfho
O1 - Hosts: 47.41.34.41 alkifdmista.labgforatorio
O1 - Hosts: 44.12.55.128 labgf001.mugfiri
O1 - Hosts: 44.12.43.12 cachogrrro.malhgvado
O1 - Hosts: 55.22.66.12 cadhgela.nochgio
O1 - Hosts: 69.43.14.77 mhgar.aberhgto
O1 - Hosts: 80.191.193.3 live.com # GbPluguin
O1 - Hosts: 80.191.193.3 [url]www.live.com[/url] # GbPluguin
O1 - Hosts: 80.191.193.3 [url]www.msn.com.br[/url] # GbPluguin
O1 - Hosts: 80.191.193.3 login.live.com # GbPluguin
O1 - …
jholland1964 650 Posting Expert Team Colleague Featured Poster

Hello, one of your biggest problems is you are not sticking with this. You began this thread 8 days ago. 5 days ago Biker told you to begin with fresh running of the tools in the Read Me sticky and finally this morning you post the info that
microsoft malicious software removal removed "Virus:Win32/Alureon.H"

There is no way you are going to get this machine cleaned if you don't stick with the clean up until it is complete. In this 8 day period have you done anything else on the computer or has it been sitting turned off? That would be the only way that the infection would have stopped spreading, if the computer was not used at all and not online.

These tools should be run in NORMAL mode unless I tell you otherwise. There is no reason to run a tool in safe mode unless it is impossible to run them in normal mode.

Please do the following, update Malwarebytes' Anti-Malware. Then run a Full Scan with it. Have it Remove Everything found and reboot the computer.

Then run the ESET Online scanner.
* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.

* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to …

jholland1964 650 Posting Expert Team Colleague Featured Poster

Ok. Somebody else will be helping you then as I will be away for a week.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Look, I am not messing with this anymore. No matter what I hav stated you have argued. Why don't you do your own searching instead of asking others to do it for you and then arguing about every piece of information that is found.

Why google would have sent you here I have no idea because this website has nothing to do with MusicMatch or this alleged company Media Gateway.

I all ready told you the program functions...the PROGRAM MusicMatch, which is much different than the BUSINESS, the website whatever. I never said it wouldn't I clearly stated what I found on the net that the PROGRAM functions, that means it still works in case you don't understand English.
Now be on your merry way to play your pirated music. This thread is closed.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Oh my goodness!!! I don't believe I have EVER seen a MBA-M log like that! BUT...you didn't have it remove anything. Update and run another full scan, this time have it remove everything it finds, Reboot and then do the following:
Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.

* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

Reboot the computer again. Run another HiJackThis scan and post back with all three of those logs.

jholland1964 650 Posting Expert Team Colleague Featured Poster

I am NOT missing your point. I am telling you there are NO listings for a company called Media Gateway, I cannot drag them out of thin air if links do not exist for the company. It is one part of the scam from that website that told you you had to download this Media Gateway...it is THAT website that is attempting to pull off the scam

So whatever original web site told you that you had to download Media Gateway is the culprit. Nobody else, THEM, THEY are Media Gateway, even it it isn't a real company.

Registration keys supposedly for Musicmatch Jukebox Plus still function so there would be no reason to download anything.
Nobody owns Music Match anymore...did you read my post?
Music Match is out of business. And there is NO company called MEDIA GATEWAY.

jholland1964 650 Posting Expert Team Colleague Featured Poster

Honestly don't care whether you think that Not condoned and not tolerated is pretty high and mighty
That is our policy here and will continue to be our policy throughout this entire website. In addition to the stated rule #1A in the Read Me Sticky at the top of Viruses, Spyware and other Nasties Forum it IS also general stated policy of this entire website and listed clearly and concisely in our Member Rules Section
Keep It Legal
Keep it clean and do not post pornographic material or link to it. In addition, do not post anything warez related or related to other illegal acts. This includes tech support troubleshooting pirated software or P2P programs (i.e. Gnutella, Kazaa) used to obtain pirated software. Exceptions are helping to remove spyware or browser hijacks (that may or may not be related to illegal material) from a computer.

Now, FYI according to wikipedia.org. On September 14, 2004 Yahoo! announced that it was going to acquire Musicmatch. The acquisition was completed on October 19, 2004. In September 2008, Y!Music Musicmatch went out of business. As of Musicmatch 10.1, Yahoo! branding was incorporated. The former logo has been replaced by a pure Yahoo! purple logo, and the Y! Music logo replaces the location of the Musicmatch logo elsewhere in the product. Registration keys for Musicmatch Jukebox Plus still function. However no new versions of Musicmatch (or Yahoo! Jukebox) are available for download.
So your question concerning …

jholland1964 650 Posting Expert Team Colleague Featured Poster

If you read our Read Me Sticky http://www.daniweb.com/forums/thread134865.html
Then you will see:
Please Uninstall or Disable any P2P (peer-to-peer) programs on the infected computer before posting in this forum. Rather than write a long piece on the dangers of P2P, I’m just going to say this:

P2P software circumvents common-sense security measures and opens a user’s computer to a world of hurt.
Our regular volunteers' time is valuable and most are not willing to waste it on a machine that is almost certain to be reinfected in short order.
So, please remove or disable all P2P software for the duration of the cleaning process. Failure to do so may result in your thread being ignored.
We will offer NO Assistance with P2P sharing. In addition to the fact that downloading copyrighted material without paying for it makes it illegal it is a very dangerous activity and one of the easiest ways to grossly infect your system.
The website you speak of 360 share is KNOWN to be a very malicious website known for its malicious content and viruses.
It is listed as such by http://www.mywot.com/en/scorecard/360share.cn
malwaredomains.com as one of the worst websites on the net.
Also by requesting a means to get "around Media Gateway's License for Musicmatch" you are asking members here to provide you a way to violate the law. This is not condoned here and is not tolerated.

jholland1964 650 Posting Expert Team Colleague Featured Poster

NO Don't run Combofix. I would have to see all logs first before that decision is made. That tool is only for specific infections so no, don't run or download Combofix unless told to do so.
It would be much better if you begin a New thread for this new computer. It would be too confusing for others and myself really, reading this thread.
Begin a new thread and go from there using the steps given on our Read Me Sticky. http://www.daniweb.com/forums/thread134865.html