Ive tried everything -- and I can't get rid of this wierd virus. its a "Fake virus popup" it opens on the bottom right of the screen and says asks me to update and "click here" and when I do it directs me to a spyquake website with a referral id... http://www.spywarequake.com/?aff=247 Here's my logs: RAPPORT SmitFraudFix v2.67 Scan done at 21:51:47.09, Wed 07/05/2006 Run from C:\Documents and Settings\mohamed\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}" »»»»»»»»»»»»»»»»»»»»»»»» End ________________________________ Ewindo --------------------------------------------------------- ewido anti-spyware - Scan Report --------------------------------------------------------- + Created at: 10:41:30 PM 7/5/2006 + Scan result: :mozilla.10:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.12:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.13:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.14:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.15:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.166:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.167:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.16:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.17:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.18:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.268:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.279:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.6:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.9:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.399:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.72:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.79:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.300:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.80:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.53:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.54:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.55:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.411:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.340:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.341:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.342:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.345:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.346:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.176:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.36:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.37:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.38:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.39:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.188:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.189:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.190:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.197:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.207:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.208:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.209:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.210:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.222:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Spylog : Cleaned. :mozilla.223:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.224:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.225:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.226:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.227:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.228:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.229:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.230:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.231:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.232:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.233:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.234:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.235:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.242:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.243:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.244:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.327:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.254:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.255:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.258:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.192:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.193:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.194:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.195:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.196:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.287:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.288:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.297:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.298:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.299:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.292:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.293:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.294:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. ::Report end ___________________________ HIJACK THIS Logfile of HijackThis v1.99.1 Scan saved at 11:56:26 PM, on 7/5/2006 Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Creative\Launcher\CTLauncher.exe C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\WINDOWS\CTHELPER.EXE C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe F:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\TechniSat DVB\bin\Server4PC.exe C:\WINDOWS\system32\wuauclt.exe F:\Program Files\iPod\bin\iPodService.exe C:\tqrecv\tqrecv.exe C:\tqrecv\tqrecv.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Opera\Opera.exe C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9202;https=127.0.0.1:9202;socks=127.0.0.1:9203 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [DAEMON Tools] "F:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [updateMgr] "F:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 O4 - HKCU\..\Run: [SoonR] "F:\Program Files\SoonR\SoonR Desktop Client\SoonrClient.exe" -boot O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe O4 - Startup: Registration Prince of Persia Warrior Within.LNK = D:\Program Files\Ubisoft\Prince of Persia Warrior Within\Support\Register\RegistrationReminder.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe O4 - Global Startup: palstart.exe O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{54856F5D-1FFD-439F-AA7B-2E328EB98B5F}: NameServer = 194.126.53.34 194.126.43.34 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} - C:\WINDOWS\system32\vpxnk.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kaspersky Anti-Virus Service (kavsvc) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
alright first of all, if a virus is putting pop ups that say "Uninstall" DO NOT TOUCH IT Try a program like Spyboy Search & Destroy and if that does not work, you may have to wipe the drive (meaning reinstalling your Operating System, this erases everything on your drive and reinstalling whatever your OS has on it, all viruses should be gone then