Run Kill2Me. 3. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Scan and when it finishes, put an X in the boxes, only next to these following items:O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exeO16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\ba.exeO16 - DPF: {30CE93AE-4987-483C-9ABE-F2BD5301AB70} Can you help?

Heres what I've done so far:Run numerous scans on: Microsoft AntiSpyware, Spybot S&D, Ad-Aware SE Personal and Norton Antivirus and cleared off all reccomended spyware. There will/should be two new DLLs. -- If those O1 entries do return in HijackThis, paste those two files into KillBox (in Step 3 above) and kill them. It will take more than a couple of tries to fix this. Diese Domain kaufen. http://www.loadingwebsite.com/

a) Click on the 'Replace on Reboot' button and check the box that says 'Use Dummy'. After a reboot, your desktop and icons will appear, then disappear (this is normal). Run CleanUp!

With that said (when ready): Please download the following programs required for the removal process: Kill2Me http://www.greyknight17.com/spy/Kill2Me.exe PV http://www.greyknight17.com/spy/pv.zip VX2Finder(126) http://www.greyknight17.com/spy/VX2Finder(126).exe Hoster http://www.greyknight17.com/spy/Hoster.exe CleanUp! Content size by content type Requests by content type Content size by domain Requests by domain File requests Sort by Load order File size File type URL Load time Filter DNS As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged Exit Program.Please run the following free, online virus scans.http://www.pandasoft...n_principal.htmhttp://housecall.tre.../start_corp.aspPlease post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLLO9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (file missing) (HKCU)O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)O12 - Plugin for .jps: Tested from New York City on March 10 at 13:58 Performance insights Grade Suggestion -... ... You should not have any open browsers when you are following the procedures below. see here Is that odd?The HJT log is below.

Just follow the instructions on the site to run the online scan. Check your Downloaded Program Files folder for any program that you do not recognize and remove anything in question. 2. log, please carefully read the instructions about the process:http://www.bleepingcomputer.com/forums/How...s_Log-t956.htmlRegards,John Whereof one cannot speak, thereof one should be silent. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.IMPORTANT: Do NOT run any other files in the l2mfix folder unless you

Here is the latest log from hijackthis: Randy --------------------------------------------- Logfile of HijackThis v1.99.0 Scan saved at 1:01:31 AM, on 2/15/05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v5.00 SP1

Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. I will take a look at it. 02-09-2005, 12:08 PM #3 dshanna Registered Member Join Date: Feb 2005 Posts: 2 OS: WIN2K Result.txt from HijackThis Analyzer ==================================================================== Log URL Test from Start test Hang on, running test! Also, cleanout the prefetch folder and the recycle bin.Reboot when prompted to let it clean out the remaining files.Please read through the instructions before you start (you may want to print

Towers 2.0 - http://download.game...ts/y/ywt0_x.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...up1.0.0.8-2.exeO16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) - http://www.wildtange...ave/Install.cabStartupList report, 02/02/2005, 5:15:28 PMStartupList version: 1.52Started from : C:\WINDOWS\DESKTOP\STARTUPLIST.EXEDetected: Windows 98 SE (Win9x 4.10.2222A)Detected: Internet If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell Log for VX2.BetterInternet File Finder (msg126) Files Found--- Additional Files--- C:\WINNT\system32\spOrder.dll Keys Under Notify---crypt32chain Keys Under Notify---cryptnet Keys Under Notify---cscdll Keys Under Notify---NavLogon Keys Under Notify---sclgntfy Keys Under Notify---SensLogn Keys Under This infection requires us to detect and remove it without rebooting or restarting your computer (unless the instructions say so).