Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: help with program cant get rid of  (Read 3989 times)

0 Members and 1 Guest are viewing this topic.

marybeth

    Topic Starter


    Beginner

    help with program cant get rid of
    « on: February 21, 2009, 03:42:59 PM »
    Have no idea how but somehow a program which is supposed to be an anti virus has gotten on my computer, Its called anti virus 1 and i cant get rid of it. Its making me crazy. It did what it said was a scan of my computer and said i have 41 infections (honestly i think its 1 of them). but would have to register the program and pay some fee to do it. It also keeps popping up to register it.  I dont want this on my puter does anyone have a clue how to get rid of it. I tried looking in" my computer" to remove and its not there. And i tried to right click on the icon to delete  and it wont do nothing.
     thanks for your help
    marybeth

    kpac

    • Web moderator


    • Hacker

    • kpac®
    • Thanked: 184
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Computer: Specs
    • Experience: Expert
    • OS: Windows 7
    Re: help with program cant get rid of
    « Reply #1 on: February 21, 2009, 04:33:07 PM »
    Yes, the Antivirus program is actually the virus.

    Read here: http://www.computerhope.com/forum/index.php/topic,46313.0.html
    Post the three logs here when finished. :)

    marybeth

      Topic Starter


      Beginner

      Re: help with program cant get rid of
      « Reply #2 on: February 22, 2009, 05:14:16 AM »
      ok here is my 3 logs, it appears it is off now. can u tell from these logs where it may have originated.


      http://www.superantispyware.com

      Generated 02/21/2009 at 08:42 PM

      Application Version : 4.21.1004

      Core Rules Database Version : 3769
      Trace Rules Database Version: 1729

      Scan type       : Complete Scan
      Total Scan Time : 01:39:26

      Memory items scanned      : 486
      Memory threats detected   : 1
      Registry items scanned    : 5105
      Registry threats detected : 27
      File items scanned        : 92259
      File threats detected     : 6

      Rogue.Anti-Virus-1
         C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AV1\AV1.EXE
         C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AV1\AV1.EXE
         HKU\S-1-5-21-3516710294-2413042553-3426264863-1003\Software\AV1
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}\1.0
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}\1.0\0
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}\1.0\0\win32
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}\1.0\FLAGS
         HKCR\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}\1.0\HELPDIR
         HKCR\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}
         HKCR\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}\ProxyStubClsid
         HKCR\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}\ProxyStubClsid32
         HKCR\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}\TypeLib
         HKCR\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}\TypeLib#Version
         HKCR\AppId\QWProtect.DLL
         HKCR\AppId\QWProtect.DLL#AppID
         HKCR\AppId\{29256442-2C14-48CA-B756-3EE0F8BDC774}
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\InprocServer32
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\InprocServer32#ThreadingModel
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\ProgID
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\Programmable
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\TypeLib
         HKCR\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}\VersionIndependentProgID
         HKCR\QWProtect.QWProtectBHO
         HKCR\QWProtect.QWProtectBHO\CLSID
         HKCR\QWProtect.QWProtectBHO\CurVer
         HKCR\QWProtect.QWProtectBHO.1
         HKCR\QWProtect.QWProtectBHO.1\CLSID
         C:\Documents and Settings\All Users\Application Data\AV1\AV1.cab
         C:\Documents and Settings\All Users\Application Data\AV1\AV1i2.exe
         C:\Documents and Settings\All Users\Application Data\AV1
         C:\WINDOWS\Prefetch\AV1.EXE-1CE115EA.pf
         C:\WINDOWS\Prefetch\AV1I2.EXE-08C76101.pf

      Database version: 1075
      Windows 5.1.2600 Service Pack 2

      6:54:45 AM 2/22/2009
      mbam-log-02-22-2009 (06-54-45).txt

      Scan type: Quick Scan
      Objects scanned: 42932
      Time elapsed: 5 minute(s), 57 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)

      Scan saved at 7:07:13 AM, on 2/22/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\CDBurnerXP\NMSAccessU.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\Program Files\Digital Media Reader\shwiconem.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\AVG\AVG8\avgcsrvx.exe
      C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
      O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
      O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
      O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
      O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
      O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
      O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
      O1 - Hosts: 217.20.175.74 www.reviews.download.com
      O1 - Hosts: 217.20.175.74 reviews.download.com
      O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
      O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
      O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
      O1 - Hosts: 217.20.175.74 reviews.pcmag.com
      O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
      O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
      O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
      O1 - Hosts: 217.20.175.74 reviews.reevoo.com
      O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
      O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
      O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
      O1 - Hosts: 217.20.175.74 reviews.techradar.com
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: QWProtectBHO - {70FEAD04-A7FD-4B89-B814-8A8251C90EF7} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
      O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
      O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06b\BrStDvPt.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
      O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
      O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
      O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
      O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
      O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
      O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by139fd.bay139.hotmail.msn.com/activex/HMAtchmt.ocx
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      --
      End of file - 12200 bytes

      kpac

      • Web moderator


      • Hacker

      • kpac®
      • Thanked: 184
        • Yes
        • Yes
        • Yes
      • Certifications: List
      • Computer: Specs
      • Experience: Expert
      • OS: Windows 7
      Re: help with program cant get rid of
      « Reply #3 on: February 22, 2009, 05:57:56 AM »
      Unfortunately, only certain people on the forum are allowed help with malware removal. I'm not one of them. :(

      What you can do is....

      Download HostsXpert ( http://www.majorgeeks.com/Hoster_d4626.html ) and then follow the steps below:

      - Unzip HostsXpert.zip
      - It will create a folder named HostsXpert in whatever folder you extract it to.
      - Run HostsXpert.exe by double clicking on it.
      - click Restore MS Hosts File and then click OK.
      - Click the X to exit the program

      Restart computer.