Select the first option to run Windows in Safe Mode hit enter. E] ads. bdx. br. ct2.#[Tenebril. - You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter". Click Tracks] Ad] www2. www3. www4. Ad][Sun Belt.

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new Hijack This log.

The report can also be found at the root of the system drive, usually at C:\Logfile of Trend Micro Hijack This v2.0.2 Scan saved at PM, on 8/07/2008 Platform: Windows XP SP2 (Win NT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\C:\WINDOWS\system32\C:\WINDOWS\system32\C:\WINDOWS\system32\C:\WINDOWS\system32\C:\WINDOWS\System32\C:\WINDOWS\system32\C:\Program Files\Intel\Wireless\Bin\Evt C:\WINDOWS\Explorer.

EXE C:\Program Files\Intel\Wireless\Bin\S24Ev C:\Program Files\Sygate\SPF\C:\WINDOWS\system32\C:\Program Files\Common Files\Apple\Mobile Device Support\bin\Apple Mobile Device C:\Program Files\WIDCOMM\Bluetooth Software\bin\C:\Program Files\Executive Software\Diskeeper\Dk C:\WINDOWS\System32\C:\Program Files\Common Files\Light Scribe\C:\Program Files\Eset\nod32C:\WINDOWS\system32\nvsvc32C:\Program Files\Intel\Wireless\Bin\Reg C:\WINDOWS\system32\C:\Program Files\Hewlett-Packard\Shared\C:\WINDOWS\system32\C:\WINDOWS\system32\C:\Program Files\hpq\HP Wireless Assistant\HP Wireless C:\Program Files\Java\jre1.6.0_05\bin\C:\Program Files\Synaptics\Syn TP\Syn C:\Program Files\HP\Quick Play\C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Qlb C:\Program Files\Eset\nod32C:\Program Files\Intel\Wireless\bin\ZCfg C:\Program Files\Intel\Wireless\Bin\C:\WINDOWS\system32\rundll32C:\Program Files\Common Files\Install Shield\Update Service\C:\Program Files\i Tunes\i Tunes C:\Program Files\Hp\HP Software Update\HPWu Schd2C:\WINDOWS\system32\C:\Program Files\Google\Google Toolbar Notifier\Google Toolbar C:\Program Files\Windows Media Player\C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_C:\WINDOWS\system32\C:\Program Files\Yahoo! Clickbank] publishers.#[] j. r. click2#[IE-Spy Ad] secure.click2127.0.0.1 service.click2127.0.0.1 Ad] #[Mc Afee.

\Widgets\Yahoo Widget C:\Program Files\i Pod\bin\i Pod C:\Program Files\Intel\Wireless\Bin\Dot1C:\Program Files\HP\Digital Imaging\bin\C:\Program Files\Yahoo! \Widgets\Yahoo Widget C:\Program Files\Internet Explorer\C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLogin C:\Program Files\Hijack This\Hijack R1 - HKCU\Software\Microsoft\Internet Explorer\Main, Search Assistant = Click DLoader] ssl. zzz.#[Ewido.

src=ssb O2 - BHO: Adobe PDF Reader Link Helper - - C:\Program Files\Adobe\Acrobat 7.0\Active X\Acro O2 - BHO: Spybot-S&D IE Protection - - C:\PROGRA~1\SPYBOT~1\O2 - BHO: SSVHelper Class - - C:\Program Files\Java\jre1.6.0_05\bin\O2 - BHO: Windows Live Sign-in Helper - - C:\Program Files\Common Files\Microsoft Shared\Windows Live\Windows Live O2 - BHO: Google Toolbar Helper - - c:\program files\google\googletoolbar2O2 - BHO: Google Toolbar Notifier BHO - - C:\Program Files\Google\Google Toolbar Notifier.0.1225.9868\O3 - Toolbar: &Google - - c:\program files\google\googletoolbar2O4 - HKLM\..\Run: [hp Wireless Assistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless O4 - HKLM\..\Run: [Sun Java Update Sched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Nv Cpl Daemon] RUNDLL32.

EXE C:\WINDOWS\system32\Nv Cpl.dll, Nv Startup O4 - HKLM\..\Run: [Nv Media Center] RUNDLL32. Tracking Cookie] ctix8.#[] abc.checkm8127.0.0.1 rmm1u.checkm8127.0.0.1 web.checkm8#[CHECKM8 AD TAGS] ads.checkm8za ads. #[] de ad.#[e Trust. Tracking Cookie] board.classifieds1000127.0.0.1 xp.classifieds1000127.0.0.1] #[Spamdexing] Ad] ads.#[e Trust.

EXE C:\WINDOWS\system32\Nv Mc Tray.dll, Nv Taskbar Init O4 - HKLM\..\Run: [nwiz] /installquiet /nodetect O4 - HKLM\..\Run: [Msmq Int Cert] regsvr32 /s O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAud Prop O4 - HKLM\..\Run: [Syn TPEnh] C:\Program Files\Synaptics\Syn TP\Syn O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\Quick Play\QPService.exe" O4 - HKLM\..\Run: [Qlb Ctrl] %Program Files%\Hewlett-Packard\HP Quick Launch Buttons\Qlb /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\O4 - HKLM\..\Run: [Rec Guard] C:\Windows\SMINST\Rec O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.

