gerbil 216 Industrious Poster

If you had typed %systemroot% in the Run window it would have opened that folder for you in Explorer, same as with any file or folder...
If you Run a folder path it will open the folder; if you run a file's pathname it will open the file, eg a pdf or jpg will open in the associated application, an exe file will start.
Just putting this up for general information.

gerbil 216 Industrious Poster

This tool usually does the trick cleanly and simply, sittas.
Unlocker 1.8.5
==This one is a general purpose deleter, Unlocker: http://filehippo.com/download_unlocker/
Dclick the exe to install it, unchecking the updater and assistant boxes. It runs from the rclick context menu, and that is cool.

gerbil 216 Industrious Poster

I could add that you were infected by a known piece of malware, most likely via an infected thumdrive. Try this:
==Download SDFix from here: http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
and save it to your desktop. Dclick SDFix.exe and choose Run to extract it to %systemdrive%, which commonly will be C:\

** ==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF. Run ATF in any other accounts.
=You must restart your computer in Safe Mode:
- press F8 several times while POST is running and before IDE detection completes.
- On the Windows Advanced Options Menu, select Safe Mode and press Enter.
- When the Boot Menu appears again, select Microsoft Windows XP and press Enter.
- Log in by using the Administrator account and password. NOTE: The password is blank by default unless you set a password.
=Open the extracted SDFix folder, C:\SDFix and double click RunThis.bat to start the script. Type Y to begin the cleanup.
You will be prompted to press any key to Reboot - the pc will then restart.
The tool will run again and complete the removal process then display Finished; press any key to …

gerbil 216 Industrious Poster

Interesting lil problem that you have. Have you already checked that when you type the full command in the run window that you get the same thing..? ie type cmd.exe instead of cmd
And have you checked that in these two keys below that cmd points to system32\cmd.exe ? This reg file will fix that for you...

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Folder\shell\Command_Prompt\command]
@="C:\\WINDOWS\\system32\\cmd.exe \"%1\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shell\Command_Prompt\command]
@="C:\\WINDOWS\\system32\\cmd.exe \"%1\""
gerbil 216 Industrious Poster

"I can go to sleep tonight! Gosh! What did I do before computers ???"
Well... you probably got more sleep, were fitter, possibly even happier... who knows? But heck, I'm glad your sys is fine. I se I forgot to put up the link for the .net update in my earlier post... sigh... here it is: http://www.microsoft.com/downloads/details.aspx?FamilyId=262D25E3-F589-4842-8157-034D1E7CF3A3&displaylang=en

gerbil 216 Industrious Poster

Fine, that msg merely is indicating that you have a later version of .net framework in your sys compared to the one on your Repair CD. If the repair works just go to this site and dl the latest version of .net, vsn 1.1

gerbil 216 Industrious Poster

If you followed those instructions of his your sys would come to no harm... Doug Knox is a king.

gerbil 216 Industrious Poster

"a black screen with a lot off line of partion stuff comes up"... I think you mean the scrolling list of drivers being loaded? Anyway, if you cannot fully enter Safe Mode, and it does sound like you cannot, and Windows either, then I cannot help further except to say it looks like a Windows Repair [not Recovery Console...] is called for. I know you said you did it already with a Dell disk [it does take about an hour to complete cos it is pretty much like a full reinstallation job], but that's all that remains. Or just a plain new installation of Windows. As far as I know.
A Repair job lets you keep [most of] your third party software intact, a fresh installation requires you to reinstall it all. Repair will not destroy your data files, neither will a fresh installation as long as you DO NOT delete OR do a format of the partition when it is suggested during Setup. To have your data absolutely safe you could place your hard drive in someone else's machine and copy out all the stuff you wish to keep. I would....
Both require you to reload all Windows updates.
God luck.

gerbil 216 Industrious Poster

A bad hd of any type should not stop you seeing POST on the monitor [and it would report the bad hd as not detected]. I gues you tried just one RAM module as well...
Tried the IGP video output with no vid card installed? Do you hear the floppy give a jerk? Sys and CPU fans run? Check the 12V, 5V, 3.3V levels, and if you can locate it in your mainboard manual, the PG level [Power Good; high ie 5V is the Good level].
If none of those, then accept that mainboards do die too.

gerbil 216 Industrious Poster

When starting and selecting Safe mode [any safe mode] you are given the option of running System Restore. Choose that and restore to any earlier point that is available, but the later the better.
If you do not have Restore points, then continue to safe mode... can you get past the login screen? Use the Administrator login [just select and press Enter if no password on that], then go Ctrl-Alt-Del to start Task Manager. Iside that go File, New Task[Run], type explorer.exe, press Enter.
If that opens explorer you will get your Start button etc. Open the Registry breaker you ran and head straight for the Restore button.
Say how you get on...

gerbil 216 Industrious Poster

G'day, Joseph... it sounds like you installed a second op sys when you tried that. Two steps to take to solve that... when inside the XP that you choose to start, open My Computer and check for a second C:\WINDOWS folder. Delete it [if it is the one you are currently using you will not be permitted to do it].
Done that? Good, now go CP > System, Advanced tab, press Settings in Startup and Recovery, press Edit button. In the notepad that opens you will see your two XP installations listed under [operating systems] -delete the one you are not using. eg if you selected no.1, the top selection when you were given the choice then delete no.2. The names are a guide. Next make sure the WINDOWS name in [default] matches the remaining one in [operating systems] entry. Then just save the file.
eg, here is my boot.ini file:
[boot loader]
timeout=4
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

If you are confused by that feel free to post a copy of your boot.ini file.

gerbil 216 Industrious Poster

You do not say what the site is... but you the client have communicated successfully with the server, and it has refused you access. It is not your browser which is doing the blocking, it is the server you accessed. Normally, you cannot gain access when you receive such a code, even by password etc.
Not all sites on the web are public.

gerbil 216 Industrious Poster

Hi, the first tool will remove an obvious infection, the second will check further and disclose some info I would like to see. Please run them both in the order given/
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or: http://www.besttechie.net/tools/mbam-setup.exe
=Dclick that file to install the application and ensure that it is set to update and start, else start it via the icon.
Select "Perform Full Scan", then click Scan; the application will guide you through the remaining steps.
Make sure that everything is checked, and click Remove Selected.
Post the Notepad log [it is also saved under Logs tab in MBAM].
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
So, two logs in total, please.

gerbil 216 Industrious Poster

Naturally enough, you could check the monitor with some other system. If it is not the monitor, then check the HDD lamp on the fron tpanel fro a lot of activity after the POST phase ompletes. No activity? ... then power off and swap RAM sticks. No RAM means no post and no video memory if you are using the IGP -graphics integrated on the MB..

gerbil 216 Industrious Poster

Quite mysteriously, you most likely will now not get any help at all.

gerbil 216 Industrious Poster

Or for free, dl Gparted Livecd, burn it tp a cd and boot from it. If you want instructions they are in the help file, and also on the web with pictures.
Easy as. Okay, the ui is basic, but everything you need is there and it is straightforward.

gerbil 216 Industrious Poster

You need to use your original XP installation cd to follow the Recovery Console method given on this site: http://support.microsoft.com/KB/875350
This will uninstall XP; you then follow that up [if your sys then will start] by completing the SP2 uninstallation via control panel, Add/Remove pgms.
And then try again to install SP2.
If you use your original XP cd to do a Windows Repair that will also remove SP2 but you will have to dl and install updates afresh.... but I gues you have not been doing that anyway, so..
A windows Repair will not [normally] cause you to lose any data files - it only overwrites some windows system files and resets some of the registry..

gerbil 216 Industrious Poster

config.sys? In XP?

gerbil 216 Industrious Poster

I do not know why your sys will not boot fom your recovery cd... but perhaps you can borrow someone's XP installation cd and try that? This is what you need to do when you can finally boot from a cd...
http://support.microsoft.com/kb/330184

gerbil 216 Industrious Poster

If you wish to change the drive alone to end up in its root, then type
E:
If you wish to change the drive AND specify a directory or file at the same time then type
cd /D E:\"other stuff"
Then when inside the directory "other stuff" you can open a file this_one.fil by typing
this_one.fil
See the D switch? Use the "" when there is a space in the pathname. It could also be this...
cd /D "E:\other stuff"
And I doubt you are using MS-DOS in XP?... it is likely the command line in cmd.exe.
cd .. takes you to the parent of the directory you are in, and is a one-way street ending at the root, with no branching possible.
Also type cd /?

gerbil 216 Industrious Poster

I must admit it never occurred to me to put a shortcut to my desktop on my desktop.
I most likely will not. It sounds like something Mobius would do.
Edit: Oops!... there is the icone in my quicklaunch bar which I use... forgot that one... but anyway it's a command, not a true shortcut.

gerbil 216 Industrious Poster

Don't forget to disturb the PS also. Mostly a PS is designed to monitor only a couple of the voltages it puts out, the assumption being that if they are fine, well, there's a pretty good chance the others are too. Further, only some of the voltages are actually regulated because from the design if they are in tolerance then associated outputs should be also.

gerbil 216 Industrious Poster

Nope, it's gone, crunchie, is now a part of AVG8 commercial. Good scans are still GMER, RKR, RKUnhooker and Icesword.

gerbil 216 Industrious Poster

Ok, your log is clean... this is part of what I wrote for someone else concerned by the same rb files appearing [rb for recycle bin..]:
Some of the smaller Antivirus service providers use common software "engines", rebadging commercial software, if you like. An antispyware example is your CA [computer associates] service, which is eTrust PestPatrol.
Internet service providers like to provide an in-house AV service, mostly they are rebadged commercial versions. One they provide is Command AV, which is the same as Authentium AV.
Authentium\AntiVirus\dvpapi.exe is also part of Freedom AV, amongst others. They will pop rbn.tmp files in your Recycle Bin [n is a digit]... is that where your rb.tmp files appear?
PCGuard will do it, also. Lots of ISPs offer that.
If those files pop in your RB as I surmise, then ignore them.
I think I have all that straight up.

gerbil 216 Industrious Poster

I have not checked you log for problems, but you might search for a post I made within the last month on this subject... it is your Verizon AV which is creating those files in the RB.

gerbil 216 Industrious Poster

Burning an image with Nero 6...
Okay, say you have the Nero window up, the one with all the icons, not Nero Express. Across the top icons hover over Copy and Backup, when the options below change select Burn Image to Disc.
Nero Burning ROM window opens, and on top pops the Open window - browse to your .iso, .nrg, .cue file, whatever... and select it [open it].
A new window, Burn Compilation will open: Write will be checked; if you do NOT wish to add further files to the disc check Finalize CD also. Press Burn.
Do not use Data CD or any other mode cos all you will get is a copy of the iso on the cd [ you have one already in your hd!...]; if you look at the files on your new cd and see .iso mentioned anywhere, start over. If you use Nero 6 then the defaults for image burning are fine.
Reacp: you merely select Burn an Image, browse to and select the .iso and press Burn. That is all it takes. If you use a CD-RW then hold the burn speed lowish, say 4x.

gerbil 216 Industrious Poster

JG, it is starting to look like a piece of your legitimate software has gone bad. Something needs to be reinstalled, most likely one of the softwares that appears in your rclick context menu, perhaps it also has some shortcut keys assigned to it.
I'd go offline and start with the AV service, and then move onto the others. Explorer reads the contextmeuhandler reg keys when it loads; a bad one could be stalling it.

gerbil 216 Industrious Poster

You might get rid of these files and folder...
D:\SETUP.EXE
E:\autoplay.exe
-these two were on plug-in media.
C:\Program Files\Common Files\fmmm

Does it start easily into Safe Mode?

gerbil 216 Industrious Poster

Pinki, you never did run Combofix for me... if you have 32bit Vista it will work:
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.

And lemme see these values, please:
==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as showkey.bat, as type "all files", to your desktop; dclick it to run, then post the file C:\showkey.txt

reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}"  >C:\showkey.txt
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\ {AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcserver32" >>C:\showkey.txt
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]" >> C:\showkey.txt
start C:\showkey.txt
pause
gerbil 216 Industrious Poster

You may notice there are 2 sections to the All Programs list... top section starts with a few, select M$ shortcuts, but you can drag others into there to keep them at head of the queue, or remove any from there.

gerbil 216 Industrious Poster

Can your friend use the exact same search feature via IE - go View, Explorer Bar, check Search; Change prefs, Change file, folder search behaviour, Advanced and OK...?
Oops... an oldish thread..

gerbil 216 Industrious Poster

Aw, I think life would go on... but thanks.

gerbil 216 Industrious Poster

ARRRRGHHH... I unny noticed the time on the second post. Geez, now I've bin caught too by ppl digging up ancient history.
Hang on, no I wasn't.. I was err.. replying to the respondent above. Yeah.

gerbil 216 Industrious Poster

With that new installation of Windows [the one you did not want] on the different drive, naturally your old desktop will not be there. It should not have been there with the original reinstallation either.
Run chkdsk on the C: drive, then unplug the drive that has the second windows on it [you do not want that one to be detected by Setup], format C: and install.
Your third party pgms will require reinstallation.
I don't think that game on the website you quoted works with SP2 installations...?

gerbil 216 Industrious Poster

The message should be "Your Windows is infected with annoying trojan", but heck, you don't really expect honesty from those folks?
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
We can fix this without a reinstallation.

gerbil 216 Industrious Poster

Yep. Keep the Windows closed an it oughta be safe.

gerbil 216 Industrious Poster

My IE6 does single word searches on the net quite happily. It invokes the msn engine http://search.live.com - that has to be something native to IE... ie built into one of the dlls it uses. Because the microsoft search engine has been updated, the dll containing that info is probably in one of the windows updates.
I could easily be talking through my hat here.

gerbil 216 Industrious Poster

Hello, JG... a couple of problems with those logs:
MBAM - this step was missed: "Make sure that everything is checked, and click Remove Selected." Malware and adware were detected but not quarantined.
Combofix - the top half of the log is missing.

gerbil 216 Industrious Poster

Cool. Easy as, huh?

gerbil 216 Industrious Poster

Those logs are clean, but your LSP stack [an intermediary in internet access] is damaged by a file deletion - this should cure that...
==Download LSPfix from here http://cexx.org/LSPFix.exe -start it by dclicking the .exe....
On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "mdnsnsp.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish.
That should be all.

gerbil 216 Industrious Poster

galex, if you just run this you will be clear, no further action needed:
==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as fixkey.reg, as type "all files", to your desktop; dclick it to run... agree; if it opens in notepad instead rclick the icon [file], choose Open with, Registry editor....

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\x>g3D70E-1895-11CF-8E15-001234567890}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\°$g49E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
gerbil 216 Industrious Poster

Hi, Luke, check the stickies and post a hijackthis log, please.
Further, whose Virus Alert is it? Click it and tell us what they are trying to sell. "Virus Alert" is a bit generic to target properly.
Heck, do this..
==Download SDFix from here: http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
and save it to your desktop. Dclick SDFix.exe and choose Run to extract it to %systemdrive%, which commonly will be C:\

==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF. Run ATF in any other accounts.
=You must restart your computer in Safe Mode:
- press F8 several times while POST is running and before IDE detection completes.
- On the Windows Advanced Options Menu, select Safe Mode and press Enter.
- When the Boot Menu appears again, select Microsoft Windows XP and press Enter.
- Log in by using the Administrator account and password. NOTE: The password is blank by default unless you set a password.
=Open the extracted SDFix folder, C:\SDFix and double click RunThis.bat to start the script. Type Y to begin the cleanup.
You will be prompted to press any key to Reboot - the pc will …

gerbil 216 Industrious Poster

Somewhere in the midst of that Yahoo, Google and Symantec bog is possibly the reason for the slowness. Other than those, nothing bad shows... ;)

gerbil 216 Industrious Poster

Hello, galex, I can see that you had something there once; so that we can remove its remaining entries would you please do this [this procedure will show me the reg key entires it is using]
==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as showkey.bat, as type "all files", to your desktop; dclick it to run, then post the file C:\showkey.txt

reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" >C:\showkey.txt
reg query "HKLM\SOFTWARE\Windows\CurrentVersion\Explorer\Browser Helper Objects" >>C:\showkey.txt
start C:\showkey.txt
pause

Delete your copy of an old hijackthis, and....
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.

gerbil 216 Industrious Poster

Did you set your home page to \blank.htm? Fine if you did... I use about:blank, it does the same job.
Last job.. start hijackthis, select Scan Only, place checkmarks against all the entries listed below that still exist, and then press Fix Checked.

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

And if all seems fine, we're finished.
Was I gentle?

gerbil 216 Industrious Poster

Whoops! with the combofix run!! But you got there... the umm.. pre-runs were unnecessary, just the one with the script.
I see Radial Point AV in your machine, too, a part of your Verizon suite? eTrust PestPatrol must be, also. See how confusing rebadged software can get? But the rbn.tmp files - are you satisfied on that point? [was my explanation somewhere near to the actuality?]
Symantec AV is putting up a fight. This will get the last trace:
==Please copy the text in the box to a notepad [format/wordwrap unchecked] and save as fixkey.reg, as type "all files", to your desktop; dclick it to run... agree; if it opens in notepad instead rclick the icon [file], choose Open with, Registry editor....

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"=-

And that would be all. If you are happy, then so am I. Tell me about the rbn.tmp files though, are they in the Recycle Bin?

gerbil 216 Industrious Poster

That would be handy. But first, run this:
==Please download Malwarebytes' Anti-Malware
from: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
or: http://www.besttechie.net/tools/mbam-setup.exe
=Dclick that file to install the application and ensure that it is set to update and start, else start it via the icon.
Select "Perform Full Scan", then click Scan; the application will guide you through the remaining steps.
Make sure that everything is checked, and click Remove Selected.
Post the Notepad log [it is also saved under Logs tab in MBAM].
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here.

gerbil 216 Industrious Poster

Some of the smaller Antivirus service providers use common software "engines", rebadging commercial software, if you like. An antispyware example is your CA [computer associates] service, which is eTrust PestPatrol.
Internet service providers like to provide an in-house AV service, mostly they are rebadged commercial versions. That is why [and being blind to what you had] I mentioned Telus, an ISP. They provide Command AV, which is the same as Authentium AV.
Your Authentium\AntiVirus\dvpapi.exe is also part of Freedom AV, amongst others. Such as Command AV. They will pop rbn.tmp files in your Recycle Bin [n is a digit]... is that where your rb.tmp files appear?
PCGuard will do it, also. Lots of ISPs offer that.
If those files pop in your RB as I surmise, then ignore them.
I think I have all that straight up.
Now I look at some of your files and running processes, and truly I cannot tell if you have one AV mongrel of many colours running, or a whole pack of AV and AS services:

Verizon Internet Security Suite
CA\PPRT\bin\ITMRTSVC.exe
Authentium\AntiVirus\dvpapi.exe
RpsSecurityAware

Believe me, you must only run ONE active AV service. Multiple AS services do not seem to matter, apart from simply bogging your machine down with over-zealous string checking.
Once you had Symantec AV :
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
-to remove that completely, cleanly you must download the correct version of their removal …

gerbil 216 Industrious Poster

Hello, dolfy, try this...
[you know, when you bump a thread it can get missed ... I tend to go first for posts with zero replies]. Not posting a hijackthis log as per the stickies above does make things a little difficult... I have almost nothing to go on...!
So I shall make a guess. You have Telus AV? Yes?... then this applies: those rb.tmp files I think may be associated with your AV/AS service, Telus. If you wish to test that go offline, disable TELUS and then delete them. If they stay gone then that is the reason, they are files used by Telus..... Don't foget to reactivate Telus before you connect again. It will regenerate them.
==Download this file to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- to run it dclick combofix.exe and follow the prompts to start it. When finished, it will produce a log, C:\Combofix.txt - post that log in your next reply.
A word of caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs reboot to restore the desktop.
==download hijackthis: http://www.majorgeeks.com/download5554.html
-copy it to a new FOLDER placed either alongside your program files or on your desktop and then... rename hijackthis.exe to imabunny.exe
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer …

gerbil 216 Industrious Poster

By the way, did you successfully delete these two files [in Safe mode if needs be]?:
C:\WINDOWS\system32\fcccbAPJ.dll
C:\WINDOWS\system32\byXPJCUO.dll

If you have trouble with that, this tool would do it:
==Download killbox from here:- http://www.downloads.subratam.org/KillBox.zip -unzip it onto your desktop.
Dclick killbox to start it.
>Highlight the pathnames in the following block and copy them into clipboard [press Ctrl+C] [ or rclick, copy...]:-

C:\WINDOWS\system32\fcccbAPJ.dll
C:\WINDOWS\system32\byXPJCUO.dll

-in killbox, go File menu, choose Paste from clipboard.

Select "Delete on reboot", "Unregister dll before deleting" if available, click the "all files" button.
Click the red and white X button, click Yes on the reboot prompt, click OK if a pendingfilerenameoperation box opens. [do not be concerned if it says it cannot find a file...]
If your computer does not reboot please restart it manually.