After installation it asked for restart, i restarted, ran fine till bootmenu, Win XP logo, and the password section, but after typing password and press enter it stays their 4 about I have some popups I can't get rid of.

Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following

Please be patient while it scans your computer. After the scan is complete a summary box will appear. When I rebooted I tried to do a windows update and it installed the express installer software and rebooted. This will bring up a Boot Menu with several options.

Then click the Fix button:O4 - HKLM\..\Run: [779h3Eh] fkuwapi.exeReboot your computer into Safe ModeThen delete these files or directories (Do not be concerned if they do not exist)c:\windows\system32\fkuwapi.exeReboot your computer to Please take a look at my HJT log and tell me what to do.

I had cleaned 714 instances of ad-ware using Ad_Warese. If you have an Explorer window open, do the following Click in the address bar to the right of the ... It appears also that it continues to run much like Spywareblaster.

  1. Anyway, here are the logs: SDFix: Version 1.77 Run by Administrator - Mon 04/09/2007 - 10:48:14.40 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry
This has been a persisent problem for more than a year. When I ran the HJT I was exactly in the middle of uninstalling NAV and installing Kaspersky instead. Any files you deleted in safe mode afterwards.

Open My Computer. HJT attached:Logfile of HijackThis v1.99.1Scan saved at 2:44:28 PM, on 6/5/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\savedump.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\sysan32.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\sysoa32.exeC:\PROGRA~1\STOMPS~1\SPYWAR~1\PPControl.exeC:\PROGRA~1\STOMPS~1\SPYWAR~1\PPMemCheck.exeC:\Program Files\Dell\Media Experience\PCMService.exeC:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exeC:\Program Files\MUSICMATCH\MUSICMATCH Logfile of HijackThis v1.99.1 Scan saved at 17:50:25, on 07/04/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab O16 - DPF:

then reboot and post a fresh HijackThis Log.

I'm currently amassing all the HJT files I've dealt with myself, but it seems that we can do this a heck of a lot quicker if we worked together

Go to a web-site that will analyze them. Antivirus] C:\Program Files\Alwil Software\Avast5\AvastUI.exeO4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32

Checking if ADS is attached to svchost.exe C:\WINDOWS\system32\svchost.exe No streams found.