Hello again Alex
Please follow all instructions and in which order they come,if you have any questions,please ask before proceeding.
======================================================
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs :
AdwareAlert 1.9.0 AdwareAlert was listed on this page because of concerns with false positives and the lack of information about the company and its privacy practices. In late fall of 2005, a new version of AdwareAlert was released, followed by new definitions. Testing with this new version indicates that the problems with earlier versions have been satisfactorily resolved. Thus, we can no longer consider AdwareAlert to be "rogue/suspect" anti-spyware.
http://www.spywarewarrior.com/rogue_...adw-alert_note
========================================================
Reg Fix
Go to Start->Run and type in regedit and hit OK.Go to HKEY_LOCAL_MACHINE and click on it>then right-click on HKEY_LOCAL_MACHINE and select export.
Save the registry somewhere as a backup. Close the Registry Editor now.
Open notepad and copy/paste the text in the quotebox below:
(don't forget to copy and paste REGEDIT4)
Quote:
REGEDIT4
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
|
Save the file as "Fix.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:
Double click on the Fix.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.
=====================================================
Open notepad and copy/paste the text in the quotebox below into it:
Quote:
KillAll::
File::
C:\WINDOWS\system32\uuuxpqva.ini
C:\WINDOWS\system32\mcrh.tmp
C:\Install
C:\Program Files\folder.js
C:\Documents and Settings\Incomplete\downloads.dat
C:\Documents and Settings\Incomplete\T-15872-nik color efex.exe
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
Folder::
C:\VundoFix Backups
C:\Program Files\AdwareAlert
C:\Documents and Settings\Hank\Application Data\AdwareAlert
C:\Program Files\E404 Helper
C:\Program Files\Tfbbwtah
C:\Program Files\rcxcdsxg
C:\Documents and Settings\Hank\Application Data\SpyGuardPro
C:\WINDOWS\SGFuaw
DirLook::
C:\Temp\PALM
C:\Temp\2577
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4574ECBE-7799-48C7-A514-C499EAB88AD8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4F42E612-4210-4896-BEEF-D2E484659561}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50A3D411-02D2-4AA8-9EF8-953C513AF631}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineak32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hank^Start Menu^Programs^Startup^Virtual Bouncer.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\antiware]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Open Site]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperFreeEdition]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
|
Save this as
CFscript
Refering to the picture above, drag CFscript into ComboFix.exe
Follow the prompts, and post the resulting log,
C:\ComboFix.txt
Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
====================================================
Clear IE6 cookies
*Open IE and click
Tools
*Click on
Internet Options
*Click on
General Tab
*Click on
Delte Temp Files &
Cookies buttons.
====================================================
Perform an online scan with Internet Explorer with
Panda ActiveScan- Click on
located at the bottom of the page.
- A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
- Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting

- If it finds any malware, it will offer you a report.
- Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
- Click on
then click 
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Paste the Panda Scan report into your next reply.
====================================================
Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.
=======================================================
Logs Required
C:\Combofix.txt
Panda scan report
Hijackthis log
An update on how your system is behaving,thanks.