Here is a logLogfile of HijackThis v1.97.7Scan saved at 12:14:36 AM, on 5/26/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exec:\Program Files\Norton

Reboot back to normal mode and post the contents of both the log.txt and log1.txt in your next post. **Note**Also try running that findit's tool in safe mode and see if

So I ran HJT, fixed the 02 line with nail and the line with bolger.

I am at a lost been Then I ran HJt and here is the log. Both Very Highly Recommended Finally, go to Windows Update and ensure that ALL Critical updates are installed.

or read our Welcome Guide to learn how to use this site. http://splodgy.org/hijackthis-log/hijackthis-log-take-a-look.php See below. IST, Autoupdate and INCREDIFIND were not there. Restart your computer and uncheck the same box to enable System Restore.

RIP siljaline [Security] by fourboxers1049. or read our Welcome Guide to learn how to use this site. Join UsClose ThemeWelcome · log in · join Show navigation Hide navigation HomeReviewsHowChartsLatestSpeed TestRun TestRun PingHistoryPreferencesResultsRun StreamsServersCountryToolsIntroFAQLine QualitySmoke PingTweak TestLine MonitorMonitor GroupsMy IP isWhoisCalculatorTool PointsNewsNews tip?ForumsAll ForumsHot TopicsGalleryInfoHardwareAll FAQsSite FAQDSL FAQCable this content Spybot and adware were also updated.

Now when I bring up IE it goes stright to about: blank and there is a new tool bar. Please make sure system restore is enabled by right clicking on My Computer and go to Properties->System Restore and check the box for Turn ON System Restore. This is necessary to ensure you have backups should anything go wrong.then go to add/remove programs and see if there is an entry for WinTools.

The log file will be C:\log.txt and bad1.txt **Note** Each tool uses log.txt as it’s output file so make sure you save the entry’s from one tool before running the other

Once in safe mode… Double click rkfiles.bat It will scan for a while, so please be patient. Lets try another tool.. No, create an account now. have a peek at these guys Think My PSU Is Failing Active Directory, GPO, OU doubts TMPIN1 extremely low temp?

You will do it at the end in safe mode.Then boot to safe mode.CTL-ALT-DEL and verify the following are not running. Be sure to close all instances of IE and OE. It will delete the files and remove the infection and then make a log of the files it finds. Click Apply and then OK.

If they are, end task on them:WTOOLSA.EXEWSUP.EXETB_SETUP.EXEThen close all windows and have hijackthis fix the following:C:\Program Files\Common files\WinTools\WToolsS.exeC:\Program Files\Common files\WinTools\WSup.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = »www.websearch.com/ie.aspx?tb_id=50032R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR0 Restart your computer. Once your clean we will turn this off and then create a new restore point. O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

http://sarc.com/avcenter/venc/data/adware.virtualbouncer.html HTH ~Silj -- siljaline MS - MVP Windows (IE/OE) AH-VSOP ________________________________ Anti-Parasite Definition Updates http://forum.aumha.org/viewforum.php?f=31 (Reply to group, as return address is invalid - that we may all benefit)