Copy everything in the Quote box below, and paste it in the box that opens: Files to delete: C:\WINDOWS\system32\rlkakhm.dll C:\WINDOWS\system32\actskn45.ocx C:\WINDOWS\system32\pmkhh.dll C:\WINDOWS\system32\wvusqqo.dll C:\WINDOWS\system32\opqss.ini C:\WINDOWS\system32\opqss.bak1 C:\WINDOWS\system32\rnoojdsi.dll C:\WINDOWS\system32\bbeeg.bak1 C:\WINDOWS\system32\bccdd.bak1 C:\WINDOWS\system32\bccdd.bak2 C:\WINDOWS\system32\cfhkj.bak1 C:\WINDOWS\system32\dccdd.bak1 C:\WINDOWS\system32\egjlm.bak1 Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested?

So when you see that Panda has found only cookies, that is not really a threat.THANK YOU SO MUCH!!!! http://www.lavasofts...p?showtopic=357

http://www.javacools...areblaster.html

I used all the basic tools at first to try to remove them including SmitRem, CWShredder, SmitFraudFix, Lop Uninstaller, Look2Me Uninstallers, VundoFix, etc. The darn Zedo window keeps poppin up though.

Hijack Log: Help! I unfortunately haven't been keeping up on the latest antivirus/antispyware news.

Choose clean, then put a check next to Perform action on all infections in the left corner of the box so you don't have to sit and watch Ewido the whole Close HiJackThis. Yep.. But the last I checked, antivirus programs such as Avast and Kapersky didn't necessarily protect you from spyware and adware such as this.

When the scan finishes, click on "Save Report". Say hello! Alternate download for Smitrem is here: http://www.downloads.subratam.org/smitRem.exe 3a.

You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created If you are running Windows XP or Windows ME, do the below: go back to step 8 of the

O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program We will also need the log from Smitrem: The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating Get a free online AV scan at Panda's ActiveScan and when it finishes save the log at the end to post back here.

C:\WINDOWS\SYSTEM32\oqqsuvw.ini C:\WINDOWS\SYSTEM32\oqqsuvw.ini2 C:\WINDOWS\SYSTEM32\oqqsuvw.bak C:\WINDOWS\SYSTEM32\oqqsuvw.bak1 C:\WINDOWS\SYSTEM32\oqqsuvw.bak2 C:\WINDOWS\SYSTEM32\oqqsuvw.tmp C:\WINDOWS\system32\wvusqqo.dll C:\WINDOWS\SYSTEM32\yycdd.ini C:\WINDOWS\SYSTEM32\yycdd.ini2 C:\WINDOWS\SYSTEM32\yycdd.bak C:\WINDOWS\SYSTEM32\yycdd.bak1 C:\WINDOWS\SYSTEM32\yycdd.bak2 C:\WINDOWS\SYSTEM32\yycdd.tmp C:\WINDOWS\system32\ddcyy.dll If Killbox does not reboot or you get a Pending Operations type error message just reboot your

Then reboot into >>>safe mode<<< Click Here for instructions 4.

Download SDFix and save it to your desktop.(either one

checking for PSGuard.com key PSGuard.com key not present! Sorry bubbarox for the confusion. P.S. Check This Out Reboot.

Look for the *New Topic* Button near the top right when viewing the forums. O2 - BHO: Helper Class - {3670A914-63C2-4E67-8C9B-370AE1922143} - C:\Program Files\BChanger\bchanger.dll HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe (since it's not doing a very good job) Reboot into Safe Mode.

It will create a folder named WinPFind35u on your desktop.Note: You must be logged on to the system with an account that has Administrator privileges to run this program.Close ALL OTHER I consider myself a pretty good spyware removal expert, but I ALMOST was stumped the other day when a customer's computer was infected with these strange "Powered by Zedo" ad popups.

