Please help! P.S. BLEEPINGCOMPUTER NEEDS YOUR HELP!

What do you think about these two? Problem is, I can't find explicit directions for how to do this on my system -- Win XP SP3.  You know of a link on this?

Head over to Henson's post for more details about that. If only your insulting comments were removed from all threads, much space could be freed up you know. DogRancher - Lets see, 4000 meters is 13,000 feet, and 9000 meters is 29500 feet. I used to have AVG a long time ago, but found it to be a memory hog and it didn't catch a nasty virus that almost wiped out my desktop.

Granted, this was written for Win 2000.  But, XP is similar, from what I understand.  I have a bunch of other reputable citations on this ALO-thing , voicing similar opinions. Can any one explain the activity?Anyway, that's part of the problem. Well I did get rid of the backdoor.inject.a, and I deleted the others that were in quarantine.

check for the virus using virus program and HJT also search the registry one more time.. And when updated, use them all from Safe Mode.

scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-781878022-3114317985-875658923-1006\Software\Microsoft\SystemCertificates\AddressBook*]@Allowed: (Read) (RestrictedCode)@Allowed: (Read) (RestrictedCode)[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4"[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}"[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".Completion time: 2010-09-25 10:40:24ComboFix-quarantined-files.txt 2010-09-25 15:40ComboFix2.txt 2010-09-25 03:05Pre-Run: 32,948,195,328 bytes freePost-Run: 32,931,811,328 bytes Red47 #happy Funny, I was going to say he said it better, too. Share this post Link to post Share on other sites ko57    Regular Member Topic Starter Honorary Members 71 posts Location: s/e Louisiana ID: 15   Posted September 27, 2010 I Message Edited by Floating_Red on 09-22-2009 06:07 PM Thursday, November 21, 2013: The THREATCON was changed to Level 1: Normal | Tue., Nov. 05, 2013: Zero-Day Vulnerability: Microsoft Security Advisory 2896666 |

Beyond that it is probably going to be down to Robby monitoring his system very closely for a while to make sure no other problems are apparent. Please REBOOT and repeat this process until there are no more updates to install!![*]Keep your other software up to date as wellSoftware does not need to be made by Microsoft to

Here is the combofix log:ComboFix 10-09-23.01 - Kerry Owen 09/25/2010 10:21:46.2.1 - x86Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2014.1377 [GMT -5:00]Running from: c:\documents and settings\Kerry Owen\Desktop\ComboFix.exeAV: avast! How can you be that ate up with the dummies Russell? Cletus B Neckbeard✓Vindicated They're giving thanks they aren't gullible? All rights reserved.

I went back to the 1.8 version, and I use Firefox or Opera, avoiding IE, even though I have IE7, I still do not like it. In the case any of them pops up a warning or a block, allow the changes, but I think it should go fine. Are you having any trouble on the C drive scanning within Spybot's archives or not?

You are really embarrassing yourself, and the really sad thing is that you don't realize it. Gimme a break. Thanks, again.

OWilson Al Gore was a fan of putting a brick in your toilet tank to save water per flush!

Secure] C:\Program Files\Easy Desk Utilities\PCSecure\Pcsecure.exe Silent O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Several functions may not work. Thanks for the link to castle cops.

Mail Scanner)SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! I'm glad that NIS was able to find the threat.

Create Account How it Works Javascript Disabled Detected You currently have javascript disabled. Secure = C:\Program Files\Easy Desk Utilities\PCSecure\Pcsecure.exe Silent -------------------------------------------------- Shell & screensaver key from C:\WINNT1\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from

Share this post Link to post Share on other sites ko57    Regular Member Topic Starter Honorary Members 71 posts Location: s/e Louisiana ID: 7   Posted September 25, 2010 Good

Some malware is designed to work within Windows and might be able to hide itself to a degree, but running a scan outside Windows might allow better chance of detection. It didn't scan.

The only reason I had AVG is that it found viruses that ZA did not.