UNSOLVED

rafeelysayswoot

updated

20 years ago

0

488

June 27th, 2006 10:00

HJT Log Attached - Need help removing SysProtect!

Please help, no matter what I try, I can't seem to get rid of SysProtect. Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 7:22:25 AM, on 6/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\QuickTime\QuickTimePlayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Andy\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bucknell.edu/index.html
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\System32\awvtq.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Bucknell Bar - {4A773E21-FDD7-4E36-8254-6A44ED247D82} - C:\WINDOWS\BUBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O20 - Winlogon Notify: awvtq - C:\WINDOWS\System32\awvtq.dll
O20 - Winlogon Notify: byvvu - C:\WINDOWS\System32\byvvu.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
  • Bugbatter

    4 Apprentice

    20487 Posts

    245

    0

    Posted June 28th, 2006 19:00

    Hi, rafeelysayswoot,
    Welcome! :)

    Please download VundoFix.exe to your desktop.
      • * Double-click VundoFix.exe to run it.
        * Put a check next to Run VundoFix as a task.
        * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
        * When VundoFix re-opens,Click Scan for Vundo button.
        * Once the scan is complete, Right Click inside the listbox (white box) and click add more files
        * Copy&Paste the 2 entries below into the top 2 boxes

        C:\WINDOWS\System32\byvvu.dll
        C:\WINDOWS\System32\uvvyb.*

        * Click Add Files and Click Close Window
        * Click the Remove Vundo button.
        * You will receive a prompt asking if you want to remove the files, click YES
        * Once you click yes, your desktop will go blank as it starts removing Vundo.
        * When completed, it will prompt that it will shutdown your computer, click OK.
        * Turn your computer back on.



      Rightclick on an empty space on your desktop and choose New > Folder
      Name it HijackThis (HJT, or whatever)
      Rightclick HijackThis.exe, choose Cut.
      Doubleclick (to open) the folder you created.
      Rightclick inside and choose Paste.

    • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
  • 245

    0

    Posted July 4th, 2006 18:00

    VundoFix V4.2.84

    Running as SYSTEM
    from c:\windows\system32\VundoFix.exe

    Checking Java version...

    Java version is 1.4.2.5

    Scan started at 3:26:05 PM 7/4/2006

    Listing files found while scanning....

    C:\WINDOWS\System32\awvtq.dll
    C:\WINDOWS\System32\qtvwa.ini
    C:\WINDOWS\System32\qtvwa.bak1
    C:\WINDOWS\System32\qtvwa.bak2
    C:\WINDOWS\System32\qtvwa.ini2
    C:\WINDOWS\System32\qtvwa.tmp

    C:\WINDOWS\system32\qtvwa.bak1
    C:\WINDOWS\system32\qtvwa.bak2
    C:\WINDOWS\system32\qtvwa.tmp
    C:\WINDOWS\system32\qtvwa.ini
    C:\WINDOWS\system32\qtvwa.ini2
    C:\WINDOWS\system32\awvtq.dll
    C:\WINDOWS\system32\uvvyb.bak1
    C:\WINDOWS\system32\uvvyb.ini
    C:\WINDOWS\system32\byvvu.dll
    C:\WINDOWS\system32\qtvwa.ini2
    C:\WINDOWS\system32\qtvwa.bak2
    C:\WINDOWS\system32\qtvwa.tmp
    C:\WINDOWS\system32\qtvwa.ini
    C:\WINDOWS\system32\qtvwa.ini2
    C:\WINDOWS\system32\awvtq.dll
    Attempting to delete C:\WINDOWS\System32\awvtq.dll
    C:\WINDOWS\System32\awvtq.dll Has been deleted!

    Attempting to delete C:\WINDOWS\System32\qtvwa.ini
    C:\WINDOWS\System32\qtvwa.ini Has been deleted!

    Attempting to delete C:\WINDOWS\System32\qtvwa.bak1
    C:\WINDOWS\System32\qtvwa.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\System32\qtvwa.bak2
    C:\WINDOWS\System32\qtvwa.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\System32\qtvwa.ini2
    C:\WINDOWS\System32\qtvwa.ini2 Has been deleted!

    Attempting to delete C:\WINDOWS\System32\qtvwa.tmp
    C:\WINDOWS\System32\qtvwa.tmp Has been deleted!

    Attempting to delete C:\WINDOWS\system32\uvvyb.bak1
    C:\WINDOWS\system32\uvvyb.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\uvvyb.ini
    C:\WINDOWS\system32\uvvyb.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\byvvu.dll
    C:\WINDOWS\system32\byvvu.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    ==========================================================================

    Logfile of HijackThis v1.99.1
    Scan saved at 3:34:02 PM, on 7/4/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\WINDOWS\System32\hphmon03.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\Documents and Settings\Andy\Desktop\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bucknell.edu/index.html
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Bucknell Bar - {4A773E21-FDD7-4E36-8254-6A44ED247D82} - C:\WINDOWS\BUBar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
  • Bugbatter

    4 Apprentice

    20487 Posts

    245

    0

    Posted July 5th, 2006 16:00

    The only thing that I see out of the ordinary is your Bucknell Toolbar. As long as you know that it is safe, that's okay.

    You can delete the VundoFix tool if your problem has been resolved. We won't be needing that again (I hope!).

    You have two choices for follow-up cleaning:

    1. Run Disk Cleanup in each user's profile:
    Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
    Please make sure the following are checked:
    -- Downloaded Program Files
    -- Temporary Internet Files
    -- Recycle Bin
    -- Temporary Files
    Click "OK" and Disk Cleanup will delete those files for you.

    OR...

    2. Download and scan each user profile with CCleaner:
    http://www.ccleaner.com/downloadbuilds.asp
    ** Select to download the BASIC version.
    1. Before first use, select Options > Advanced and UNCHECK
    " Only delete files in Windows Temp folder older than 48 hours"
    2. Then select the items you wish to clean up.
    In the Windows Tab:
    • Clean all entries in the "Internet Explorer" section except Cookies (if you want to keep those).
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.
    In the Applications Tab:
    • Clean all except cookies (if you want to keep those) in the Firefox/Mozilla section if you use it.
    • Clean all in the Opera section if you use it.
    • Clean Sun Java in the Internet Section.
    • Clean any others that you choose.
    3. Click the " Run Cleaner" button.
    4. A pop up box will appear advising this process will permanently delete files from your system.
    5. Click " OK" and it will scan and clean your system.
    6. Click " exit" when done.
    REBOOT.

    Your outdated version of Java (Java version is 1.4.2.5) made you susceptible to the infection that you had.
    Please follow these steps to remove older version Java components:

    1. Close any open programs you may have running, especially your web
    browser
    2. Click Start > Control Panel
    * Depending on your OS or configuration, you may have to click Start
    >Settings > Control Panel
    3. Open Add or Remove Programs
    * If you have Windows 98 or Windows 2000, open Add/Remove
    Programs
    4. Click once on any item listing Java Runtime Environment in the name
    * Not every version of Java will begin with "Java" so be sure to read
    each entry in the list
    5. Click the Remove or Change/Remove button
    6. Follow steps 4 and 5 as many times as necessary to remove all
    versions of Java. ** If at any time during the uninstallations, you are asked to reboot, do so. Then return to Add/Remove and continue removing any other versions of Java until all components of Java have been removed.
    7. Delete the Java folder in Program Files.
    8. Proceed with reinstalling Java. You will need to use Internet Explorer for this.
    Go to Sun Java and click the link to download the Windows (Offline Installation) package: Save it, do not run it.

    When the download is complete, close the browser and install it.

    Reboot.

    After all that, it would be a good idea to purge the Restore Points and start fresh.
    If everything is running well....
    To flush the XP System Restore Points:
    (Using XP, you must be logged in as Administrator to do this.)

    Go to Start>Run and type msconfig Press enter.
    When msconfig opens, click the Launch System Restore Button.
    On the next page, click the System Restore Settings Link on the left.
    Check the box labeled Turn Off System Restore.

    Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

    Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

    You may have already taken some of these steps:
    1. Visit Windows Update:
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
    Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

    2. Adjust your security settings for ActiveX:
    Go to Internet Options/Security/Internet, press 'default level', then OK.
    Now press "Custom Level."
    In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

    3. Download and install the following free programs:
    a. SpywareBlaster:
    http://www.javacoolsoftware.com/spywareblaster.html
    Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
    b. SpywareGuard:
    http://www.javacoolsoftware.com/spywareguard.html
    Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
    Periodically check for updates in both programs.

    4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
    Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads
    Sunbelt Kerio has a free version: http://www.kerio.com/kpf_download.html

    5. You might consider installing Mozilla / Firefox.
    http://www.mozilla.org/

    6. Install spyware detection and removal programs:
    You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.

    a. Ad-aware: http://www.lavasoft.de/software/adaware/

    b. SpyBot S&D: http://safer-networking.org/en/news/2005-05-31.html

    I would check for updates in SpyBot once a week or so.
    Check for updates in Ad-aware frequently.

    If you have recently installed Ewido, it is a free trial product for 30 days. After that you can purchase it for full features OR you can also keep the free version to use as an on-demand scanner (recommended).
    You will still be able to manually update Ewido using the *update* button

    7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List.
    Here is the link:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm
    If you want to know just how effective your anti-spyware program is, or how well any of the "rogue" programs listed at the above link work, check this for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm

    8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
    ** UNcheck the option to install the Yahoo toolbr.

    9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 7.08. It would be best to remove prior versions before updating to a new version.
    Info here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
    If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html


    10. Make sure you are using the most udpated version of Java.
    If you need to update, remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
    You can go here to download the latest version: Sun Java and click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.
    Proceed with reinstalling Java. Reboot.

    11. Here are some helpful articles:
    "So how did I get infected in the first place?"
    http://computercops.biz/postlite7736-.html

    "I'm not pulling your leg, honest"
    by Sandi Hardmeier
    http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

    Let us know if we have not resolved your problem. Otherwise, you are good to go.
    Happy and Safe Surfing!