optimumpc
asked on
Computer has started running very slow. hijack this attached.
My computer has started running very slowly. Can someone take a look at this hijack this file for me?
I'm not exactly sure what I should be looking for.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 5:22:29 AM, on 11/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\McAfee\HackerWatch\H WAPI.exe
C:\PROGRA~1\McAfee\MSC\mcm scsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.e xe
C:\PROGRA~1\McAfee\VIRUSS~ 1\mcods.ex e
C:\PROGRA~1\McAfee\MSC\mcp romgr.exe
c:\PROGRA~1\COMMON~1\mcafe e\mcproxy\ mcproxy.ex e
c:\PROGRA~1\COMMON~1\mcafe e\redirsvc \redirsvc. exe
C:\PROGRA~1\McAfee\VIRUSS~ 1\mcshield .exe
C:\PROGRA~1\McAfee\VIRUSS~ 1\mcsysmon .exe
C:\Program Files\McAfee\MPF\MPFSrv.ex e
C:\PROGRA~1\McAfee\MPS\mps .exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.ex e
c:\PROGRA~1\mcafee.com\age nt\mcagent .exe
C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\Java\jre1.5.0_09\bin \jusched.e xe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxpe rs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Nikon\PictureProject \NkbMonito r.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_09\bin \jucheck.e xe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsr vc.exe
C:\Documents and Settings\DETTE\Desktop\HiJ ackThis_v2 .exe
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\In ternet Explorer\SearchURL,(Defaul t) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB- 00C04FD644 97} - (no file)
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0 090271D4F8 8} - (no file)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4 A4827C2E4C 8} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D 4DAF1D92D4 3} - C:\Program Files\Java\jre1.5.0_09\bin \ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6 309F01C523 1} - c:\PROGRA~1\mcafee\VIRUSS~ 1\scriptcl .dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0 EA71C0748E 4} - (no file)
O2 - BHO: AIMSite Class - {D70E6A20-7060-4829-B3D7-B 6624A1DE7C 6} - C:\Program Files\AIM Toolbar\aimhelper.dll (file missing)
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\ DRIVERS\W3 2X86\3\DLB Utime.dll, _RunDLLEnt ry@16
O4 - HKLM\..\Run: [DellMCM] C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin \jusched.e xe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr ay.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd. exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe rs.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe " /background
O4 - HKCU\..\Run: [Myuctwx] C:\WINDOWS\system32\??rss. exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\DETTE\Application Data\eetu.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD etector.ex e (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD etector.ex e (User 'Default user')
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject \NkbMonito r.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear ch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4 \OFFICE11\ EXCEL.EXE/ 3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_09\bin \npjpi150_ 09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_09\bin \npjpi150_ 09.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0 0B0D0A1DE4 5} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B 7D41EF1CB5 2} - C:\Program Files\AWS\WeatherBug\Weath er.exe (file missing) (HKCU)
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-9 92EE8E6BAD 6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c20.cab
O16 - DPF: {17492023-C23A-453E-A040-C 7C580BBF70 0} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D 8356294013 4} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5 A1EDB1D8A2 1} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-6 2B522420EC C} (Facebook Photo Uploader Control) -
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-5 81F119A8AB 8} - http://static.zangocash.com/cab/Zango/ie/bridge-c32.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C 18E1ADA438 9} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4 4455354000 0} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5 FAE815A3B4 5} -
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-0 0A0C90312E 1} - C:\WINDOWS\System32\browse ui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3 078302C203 0} - C:\WINDOWS\System32\browse ui.dll
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbuco ms.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfe e\EmProxy\ emproxy.ex e
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver \11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\driver s\KodakCCS .exe (file missing)
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\H WAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcu pdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm scsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.e xe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~ 1\mcods.ex e
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcp romgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe e\mcproxy\ mcproxy.ex e
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe e\redirsvc \redirsvc. exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~ 1\mcshield .exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~ 1\mcsysmon .exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.ex e
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps .exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing)
O24 - Desktop Component 0: (no name) - http://a80.ac-images.myspacecdn.com/images01/104/l_1290a8b210e58c215e8dd34dc72bd10f.jpg
--
End of file - 8898 bytes
I'm not exactly sure what I should be looking for.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 5:22:29 AM, on 11/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\McAfee\HackerWatch\H
C:\PROGRA~1\McAfee\MSC\mcm
c:\program files\common files\mcafee\mna\mcnasvc.e
C:\PROGRA~1\McAfee\VIRUSS~
C:\PROGRA~1\McAfee\MSC\mcp
c:\PROGRA~1\COMMON~1\mcafe
c:\PROGRA~1\COMMON~1\mcafe
C:\PROGRA~1\McAfee\VIRUSS~
C:\PROGRA~1\McAfee\VIRUSS~
C:\Program Files\McAfee\MPF\MPFSrv.ex
C:\PROGRA~1\McAfee\MPS\mps
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.ex
c:\PROGRA~1\mcafee.com\age
C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\Java\jre1.5.0_09\bin
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Nikon\PictureProject
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_09\bin
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxsr
C:\Documents and Settings\DETTE\Desktop\HiJ
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0
O2 - BHO: AIMSite Class - {D70E6A20-7060-4829-B3D7-B
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [DellMCM] C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Myuctwx] C:\WINDOWS\system32\??rss.
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\DETTE\Application
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-9
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {48DD0448-9209-4F81-9F6D-D
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
O16 - DPF: {5F8469B4-B055-49DD-83F7-6
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-5
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {DBA230D1-8467-4e69-987E-5
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-0
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbuco
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\driver
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\H
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcu
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.e
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcp
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.ex
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing)
O24 - Desktop Component 0: (no name) - http://a80.ac-images.myspacecdn.com/images01/104/l_1290a8b210e58c215e8dd34dc72bd10f.jpg
--
End of file - 8898 bytes
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
rpgamergirl, Just thought I'd let you know that I appreciate your quick response and will take the steps you've suggested, but I just haven't had a chance to get back to the computer. I'm trying to become more proficient with hijack this and malware removal in general. I've read through many threads that you've commented in and I'm thoroughly impressed (envious) with your knowledge on the subject.
I just didn't want to leave this hanging without a response.
I just didn't want to leave this hanging without a response.
optimumpc,
Thank you for the compliment, very much appreciated.
You've closed the question so I assume the problem has been sorted out, if not, then just post back.
Thanks for the points and the A grade, :)
Thank you for the compliment, very much appreciated.
You've closed the question so I assume the problem has been sorted out, if not, then just post back.
Thanks for the points and the A grade, :)
ASKER
rpgamergirl. You are welcome. I'm a little concerned with the oin uninstaller. When I ran the uninstaller, mcafee balked at two files installed: wsu.exe and ue.exe. Have you used this program before?
Yes, I have used this program many times and so are other helpers when nothing else works to uninstall purityscan.
Of course many scanners flag the uninstaller as nasties, their site is even blocked by most security programs.
Once the purityscan is no longer present in your pc, get rid of the uninstaller and if the outerinfo folder is still present in the program files delete it too.
C:\Program Files\Outerinfo
Of course many scanners flag the uninstaller as nasties, their site is even blocked by most security programs.
Once the purityscan is no longer present in your pc, get rid of the uninstaller and if the outerinfo folder is still present in the program files delete it too.
C:\Program Files\Outerinfo
1. Download and install Superantispyware
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
Load Superantispyware and click the "check for updates" button.
Once the update is finished, close SuperAntispyware again, we'll perform the scan later in safe mode
* Start Superantispyware.
Click the "scan your computer" button.
Check "Perform Complete Scan" and then next.
Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
Make sure that they all have a check next to them and press next.
Click finish and you will be taken back to the main interface.
Click "Preferences" and then click the "statistics/logs" tab. Click the dated log and press view log and a text file will appear.
2. Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall