oh my goodness! I think it's gone! no pop-ups as of yet!!!! YES!!!!!
Good thinking my man!
Here's the new HJT log
Edition\docs\jre\bin\java.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AIM\aim.exe
H:\Program Files\Shareaza\Shareaza.exe
H:\Program Files\Xfire\Xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\HSA KILL\hijackthis.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Shareaza] "H:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - Startup: Xfire.lnk = H:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: Maya 6 PLE Documentation Server (mple6docserver) - Unknown owner - E:\Program Files\Alias\Maya 6.0 Personal Learning Edition\docs\wrapper.exe" -s "E:\Program Files\Alias\Maya 6.0 Personal Learning Edition\docs\Wrapper.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Along with the log from apropos,
Log of AproposFix v1
************
Running from directory:
C:\Documents and Settings\Steven Sullivan\Desktop\aproposfix
************
Registry entries found:
[HKEY_LOCAL_MACHINE\Software\CoUQmABEMj82]
@="P6v2xp BCCBCCDCh0pxt.4BCCBREClXcSdlhCh934t\\IHCs2x6t23C2\\r34up4D393"
"Device"="\\\\.\\Spaient"
"DriverPath"="C:\\WINDOWS\\System32\\drivers\\rmcstfat.sys"
"DriverName"="Avgrial"
"HideUninstallerName"="C:\\Program Files\\Chanager\\npkdmoe2.exe"
"HDll"="C:\\WINDOWS\\System32\\filmagx5.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="
http://adchannel.con...onbranded.html""PartnerId"="CP.LAV"
"InstallationId"="{Xf809917-5f48-4c96-d148-d0a25358299e}"
"PageFiltering"=dword:00000001
"ClientName"="C:\\Program Files\\Chanager\\nxdocvw.exe"
"AutoUpdater"="C:\\WINDOWS\\System32\\offbexec.exe"
"Version"="2.0.131"
"CrMnTmt"=dword:0036ee80
************
Removing hidden service:
Service Avgrial removed.
Removing hidden folder:
Deletion of folder Chanager succeeded!
Deleting files:
Deletion of file C:\WINDOWS\System32\drivers\rmcstfat.sys succeeded!
Deletion of file C:\WINDOWS\System32\offbexec.exe succeeded!
Deletion of file C:\WINDOWS\System32\filmagx5.dll succeeded!
Backing up files:
Done!
Removing registry entries:
REGEDIT4
[-HKEY_CURRENT_USER\Software\CoUQmABEMj82]
[-HKEY_LOCAL_MACHINE\Software\CoUQmABEMj82]
Done!
Finished!
Yay!,
Steve