Click OK. It's just a registration reminder as used by Iomega, Hasbro & Microprose - amongst others. If bundled with another installer or not installed by choice then remove itNobanegygafaciXbanegygafaci.exeDetected by Malwarebytes as Trojan.Agent.US. Also access to 'My Computer' and 'My files' from the desktop icons does not work.

C:\System Volume Information\_restore{CD2212FC-6BCF-4EE7-9874-055F2BDF00E7}\RP155\A0008451.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\avenger\backup.zip/avenger/instcat.dll -> Worm.Locksky.bh : Cleaned with backup (quarantined). ::Report end Just other info if it helps. Back to top #13 SifuMike SifuMike malware expert Staff Emeritus 15,385 posts OFFLINE Gender:Male Location:Vancouver (not BC) WA (Not DC) USA Local time:05:48 AM Posted 03 April 2007 - 11:39 Now replaced by SpywareGuardNoMozillaIEXBHC.exeDetected by Malwarebytes as Trojan.Downloader.

You will need to continue with your repairs there, and please do not post the same request at different forums, to avoid duplication of effort. The file is located in %Windir%\InstallDirNoHKCUXbbbbbbbbb.exeDetected by Malwarebytes as Backdoor.HMCPol.Gen. I don't understand why I can't.Please find the below the AVG anti-spyware report and the new Hijackthis log. Here are the logs:--------------------------------------------------------- ewido anti-malware - Scan report--------------------------------------------------------- + Created on: 10:20:44 PM, 12/28/2005 + Report-Checksum: C637E2C + Scan result: :mozilla.42:C:\Documents and Settings\Darrell\Application Data\Mozilla\Firefox\Profiles\u9lyj131.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup

  1. Thanks.
  2. This program loads some Microsoft Office components into memory, even if you're not currently using MS Office.
  3. A menu will appear with several options.
  4. Unless it was in an email from someone you didn't know - and you clicked on it any way.
  5. Thanks again!Logfile of HijackThis v1.99.1Scan saved at 3:13:47 PM, on 12/26/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\WINDOWS\system32\spoolsv.exeC:\Program
  7. Backup your computer, backup your life." Detected by Malwarebytes as PUP.Optional.BackupGenie.
  8. Required for dial-up if you have one of these modemsNobcmwls32.exeXbcmwls32.exeDetected by Intel Security/McAfee as RDN/Generic BackDoor!ri and by Malwarebytes as Backdoor.Agent.DCENobcmwltry?bcmwltry.exeBroadcom Corporation Wireless Network Tray Applet.

I will purchase a full version as soon as my situation improves, which should be soon, i hope. If you still can't delete something, right-click it and rename it to a random word.

Blocks malicious files that attempt to change the home page, search page, search engine settings, favourites, etc.

C:\Documents and Settings\Guo Jian\Cookies\guo_jian@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.

Norton keeps it from running, but the warning window keeps appearing over and over. C:\avenger\backup.zip/avenger/kwinsndv.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).

Real-time protection for IE users that helps them avoid getting infected while browsing the web.

The file is located in %Root%NobargainsXbargainbuddy.exeBargainBuddy adwareNobargainsXbargains.exeBargainBuddy adwareNoBullsEye NetworkXbargains.exeBullseye adwareNo[various names]Xbarint.exeFake startup entry created by the Wareout rogue spyware and dialer remover - not recommended, removal instructions here.

To do this restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly.

If you have such a device, you can configure Backup4all to execute a backup job or a backup group when this button is pressed (works only with certain USB enclosures)"YesBackup4all Professional Logfile of HijackThis v1.99.1 Scan saved at 21:22:46, on 24/05/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: E:\WINNT\System32\smss.exe E:\WINNT\system32\winlogon.exe E:\WINNT\system32\services.exe E:\WINNT\system32\lsass.exe E:\WINNT\system32\svchost.exe E:\WINNT\system32\spoolsv.exe E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe Archived version of Andrew Clover's original pageNoBHRUBHR.exeBrowser Hijack Retaliator from Zamaan's Software. It can also be licensed by other products such as versions of The Shield Deluxe from PCSecurityShield (see here) - who's reputation is poorYesIntelXBDE3B7.exeDetected by Malwarebytes as Trojan.Downloader.H.

Thank you! C:\Documents and Settings\Guo Jian\Cookies\guo_jian@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.

Logfile of HijackThis v1.99.1 <--- LOGFILE REMOVED - SEE CURRENT ONE BELOW --->

C:\Documents and Settings\Guo Jian\Cookies\guo jian@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.

I have therefore installed Firefox browser and this seems to be working OK at the moment.Karen.Logfile of HijackThis v1.99.1Scan saved at 17:40:41, on 24/03/2007Platform: Windows 2000 SP2 (WinNT 5.00.2195)MSIE: Internet Explorer PC now running well, thanks again.No sign of infections Im running Bit Defender8 (free edition) & AVG (free

The file is located in %AppData%\MicrosoftNoWinSetBrowseXBasicUpdate.dll.vbsDetected by Symantec as VBS.Biscuit.A@mmNotypeXbat.exeDetected by Sophos as W32/Anskya-ANoadobeupdateXbat99.batDetected by Dr.Web as Tool.BtcMine.140 and by Malwarebytes as Trojan.Agent.ADBNoadobeupdatessXbat99.batDetected by Malwarebytes as Trojan.BCMiner. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!" If you prefer forgoing resident protection, the application can also be run on Let's empty the temp files: Run CCleaner. It creates, stores and edits scan images, and delivers them to each application"NoBackupSysXBackupSys.exeDetected by Intel Security/McAfee as Generic PWS.di and by Malwarebytes as Trojan.AgentNoBackUp[8 or more digits]XBackUp[8 or more digits].exeDetected by