has been identified as safe. I am sure that Windows Updates needs to work on the main disk where Windows is...but, uninstalling games or large programs and installing over on the new drive would help you I have the MBR.dat file if that helps.. Click the Start button to begin the cleaning process and let it run uninterrupted to completion. have a peek here

Checks for updates for RealPlayer C:\Program Files\Avast\AvastUI.exe Safe (4.54 / 5.00) C:\Program Files\Windows Sidebar\sidebar.exe Very safe This entry was classified from our visitors as good. That should fix that problem. Click OK.

Choose one that actually installs the files on your PC. I keep getting "host" errors. It's better to be sure and safe than sorry.Please reply to this thread. ST3500630AS ATA Device.

I have spent the past week and hours on the phone with our antivirus technical support (Trend), and microsoft technical support, and all to no avail. ... Now move all instances of the file that we determined was bad in the previous steps into the remove section by clicking on the button that points to the right (>>). http://www.hijackthis.de/en Good luck. O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll The entry OneNote Lin&ked Notes has been identified as safe.

Many variants of CWS parasite uses this method.

Example of 013 entries from HijackThis logs

O13 - DefaultPrefix: http://ehttp.cc/? somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Some versions of Lop.com use this method, together with huge list of cryptic domains.

Example of 017 entries from HijackThis logs O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ao.lop.com O17 - HKLM\System\CCS\Services\Tcpip\..\{665F2FE6-9364-453A-AD28-9DDF4773B522}: Domain All Rights ReservedAd Choices The information on Computing.Net is the opinions of its users.

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Very safe This entry was classified from our visitors as good. navigate here I started noticing little quirks in IE 8 (x86) yesterday.Little flickers here and there. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing This page has been identified as safe. If a shortcut doesn't exist O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" Very safe Java von Sun O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Safe Safe (4 / 5.00)

Check if you know this process and arrange a viruscheck where required. Make sure all other windows are closed and to let it run uninterrupted.Select All UsersUnder the Custom Scan box paste this in netsvcs %SYSTEMDRIVE%\*.exe /md5start explorer.exe winlogon.exe /md5stop %systemroot%\*. /mp /s n7gmo46c.exe) and allow the gmer.sys driver to load if asked.Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe. Check This Out Put a checkmark in the I know what I'm doing checkbox.

Download ComboFix from one of these locations:Link 1Link 2* IMPORTANT !!!

If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it.

O16 - ActiveX Objects (aka Downloaded Program Files) In this section HijackThis tags the items

Important!

To do so click on the gray "Reply to Thread" button or "Go Advanced" and click on the "Manage Attachments" button. Is there a way to tweak this and get rid of all the components I have no use for? Let it run uninterrupted to completion.Once it's finished it should reboot your machine. Please save it to a convenient location.

Logfile of HijackThis v1.97.7 Scan saved at 4:36:54 PM, on 3/3/2005 Platform: Windows 2000 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\LEXBCES.EXE C:\WINNT\system32\spoolsv.exe