Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I began having problems withe my IE 6 opening new windows slowly so I started to troubleshoot. My original antivirus is Symantec Enterprise ver. 9.0.1.1000 which shows no virus. I ran Microsoft Malicious software program and it shows a backdoor:Win32/Zonebac.gen!B virus that it cannot remove. I followed Symantec's instructions of turning off MS Restore ansd it still does not dtect the virus.I have tried running both antivirus's in safe mode along tried AVG by Grisoft, Spybot Search and Destroy, Adaware, Super Antispyware, and a few others with no success. Does anyone have any suggestions short of killdisk?

We will need to run a few scans to try to locate the baddies.
Please download SmitFraudFix from this link http://siri.urz.free.fr/Fix/Smitfra... Then extract the contents to your desktop.
!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!
Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.Please download and install the latest version of HijackThis v2.0.2:
Download the HijackThis Installer from this link: HijackThis
1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Here are the results from Smithfraudfix:
SmitFraudFix v2.240
Scan done at 16:52:57.33, Fri 10/12/2007
Run from D:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode»»»»»»»»»»»»»»»»»»»»»»»» Process
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
D:\WINDOWS\Explorer.exe
D:\WINDOWS\system32\RUNDLL32.exe
D:\Program Files\ISP50\bin\bartshel.exe
D:\Program Files\QuickTime\bak\qttask.exe
D:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\WINDOWS\system32\devldr32.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
F:\SUPERAntiSpyware.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\PROGRA~1\LEXMAR~1\bak\AcBtnMgr_X73.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\Program Files\WinZip\WZQKPICK.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\spider.exe
D:\Program Files\Microsoft Office\Office\WINWORD.exe
D:\Program Files\Orbitdownloader\orbitdm.exe
D:\Program Files\Orbitdownloader\orbitnet.exe
D:\WINDOWS\system32\cmd.exe»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» D:\
»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Administrator
»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Administrator\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\ADMINI~1\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="http://i4.ebayimg.com/01/i/03/a3/b9/78_1_b.JPG"
"SubscribedURL"="http://i4.ebayimg.com/01/i/03/a3/b9/78_1_b.JPG"
"FriendlyName"=""
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: VIA PCI 10/100Mb Fast Ethernet Adapter - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1
DNS Server Search Order: 192.168.1.1HKLM\SYSTEM\CCS\Services\Tcpip\..\{7A8D84DC-C740-45A4-BE47-7E64A48A6AFE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7A8D84DC-C740-45A4-BE47-7E64A48A6AFE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{7A8D84DC-C740-45A4-BE47-7E64A48A6AFE}: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» EndHere are the log contents of Hijack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:00:18 PM, on 10/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: NormalRunning processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
D:\WINDOWS\Explorer.exe
D:\WINDOWS\system32\RUNDLL32.exe
D:\Program Files\ISP50\bin\bartshel.exe
D:\Program Files\QuickTime\bak\qttask.exe
D:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\WINDOWS\system32\devldr32.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
F:\SUPERAntiSpyware.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\PROGRA~1\LEXMAR~1\bak\AcBtnMgr_X73.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\Program Files\WinZip\WZQKPICK.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Microsoft Office\Office\WINWORD.exe
D:\Program Files\Orbitdownloader\orbitdm.exe
D:\Program Files\Orbitdownloader\orbitnet.exe
D:\WINDOWS\notepad.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "D:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Bart Station] D:\Program Files\ISP50\hta\station.sbrt
O4 - HKLM\..\Run: [LogitechGalleryRepair] D:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] D:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] D:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] D:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "D:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aim6] "D:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bitwisesystems.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartAc...
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yah...
O20 - Winlogon Notify: !SASWinLogon - F:\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - D:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.exe
O23 - Service: LVCOMSer - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - D:\WINDOWS\SYSTEM32\LxrSG20s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - D:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - D:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://i4.ebayimg.com/01/i/03/a3/b9...--
End of file - 10342 bytes

I see 015 whataboutadog.com in Hijackthis. I will wait for your suggeastions before trying to remove this.

Please download FindAWL from this link FindAWF
Double-click on the FindAWF.exe file to run it. It will open a command prompt and ask you to "Press any key to continue". You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT
Press 1 then press Enter. Copy and paste the contents of the AWF.txt file in your next reply.

Here is a copy of the second AWF log from option 1:
Find AWF report by noahdfear ©2006
Version 1.40The current date is: Fri 10/12/2007
The current time is: 18:06:22.93
bak folders found
~~~~~~~~~~~
Directory of D:\PROGRA~1\AIM6\BAK04/27/2007 04:17 PM 50,736 aim6.exe
1 File(s) 50,736 bytesDirectory of D:\PROGRA~1\ISP50\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\LEXMAR~1\BAK
05/11/2001 05:57 PM 53,248 AcBtnMgr_X73.exe
05/11/2001 11:39 AM 53,248 ACMonitor_X73.exe
2 File(s) 106,496 bytesDirectory of D:\PROGRA~1\MSNMES~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\QUICKT~1\BAK
03/12/2006 07:22 PM 155,648 qttask.exe
1 File(s) 155,648 bytesDirectory of D:\PROGRA~1\SYMANT~1\BAK
08/02/2004 08:36 PM 124,232 VPTray.exe
1 File(s) 124,232 bytesDirectory of D:\PROGRA~1\COMMON~1\SYMANT~1\BAK
06/09/2004 09:31 PM 66,680 ccApp.exe
1 File(s) 66,680 bytesDirectory of D:\PROGRA~1\ELABOR~1\CLONECD\BAK
11/02/2002 01:33 AM 45,056 ElbyCheck.exe
1 File(s) 45,056 bytesDirectory of D:\PROGRA~1\GOOGLE\GOOGLE~2\BAK
06/13/2007 06:28 PM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytesDirectory of D:\PROGRA~1\ISP50\HTA\BAK
10/17/2003 05:40 PM 14,369 station.sbrt
1 File(s) 14,369 bytesDirectory of D:\PROGRA~1\LOGITECH\QUICKCAM\BAK
07/25/2007 04:06 PM 2,027,792 Quickcam.exe
1 File(s) 2,027,792 bytesDirectory of D:\PROGRA~1\LOGITECH\VIDEO\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\YAHOO!\MESSEN~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
05/11/2007 03:06 AM 40,048 Reader_sl.exe
1 File(s) 40,048 bytesDirectory of D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK
09/11/2006 05:40 AM 218,032 ISUSPM.exe
1 File(s) 218,032 bytesDirectory of D:\PROGRA~1\COMMON~1\LOGISHRD\LCOMMGR\BAK
07/25/2007 04:02 PM 563,984 Communications_Helper.exe
1 File(s) 563,984 bytesDirectory of D:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK
09/28/2004 09:26 PM 32,881 jusched.exe
1 File(s) 32,881 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK
05/14/2001 09:04 AM 36,352 printray.exe
1 File(s) 36,352 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK
11/15/2001 12:00 PM 196,608 hpztsb04.exe
1 File(s) 196,608 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~28172 Oct 3 2007 "D:\Program Files\AIM6\aim6.exe"
50736 Apr 27 2007 "D:\Program Files\AIM6\bak\aim6.exe"
28172 Oct 3 2007 "D:\Program Files\LexmarkX73\AcBtnMgr_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\AcBtnMgr_X73.exe"
28172 Oct 3 2007 "D:\Program Files\LexmarkX73\ACMonitor_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\ACMonitor_X73.exe"
28172 Oct 3 2007 "D:\Program Files\QuickTime\qttask.exe"
155648 Mar 12 2006 "D:\Program Files\QuickTime\bak\qttask.exe"
28172 Oct 3 2007 "D:\Program Files\Symantec AntiVirus\VPTray.exe"
124232 Aug 2 2004 "D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
28172 Oct 3 2007 "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
66680 Jun 9 2004 "D:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
54296 Dec 2 2003 "E:\Program Files\Common Files\Symantec Shared\CCAPP.exe"
28172 Oct 3 2007 "D:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
45056 Nov 2 2002 "D:\Program Files\Elaborate Bytes\CloneCD\bak\ElbyCheck.exe"
45056 Nov 2 2002 "E:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
52272 Jan 27 2007 "D:\Program Files\Google\googletoolbar3user.exe"
61440 Sep 14 2006 "D:\Program Files\Google\Google Earth\googleearth.exe"
28172 Oct 3 2007 "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
14405024 Oct 19 2006 "D:\Documents and Settings\Administrator\My Documents\downloads\GoogleEarthWin.exe"
559784 Jul 21 2006 "D:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138168 Jan 27 2007 "D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 13 2007 "D:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
28172 Oct 3 2007 "D:\Program Files\ISP50\hta\station.sbrt"
14369 Oct 17 2003 "D:\Program Files\ISP50\hta\bak\station.sbrt"
28172 Oct 3 2007 "D:\Program Files\Logitech\QuickCam\Quickcam.exe"
2027792 Jul 25 2007 "D:\Program Files\Logitech\QuickCam\bak\Quickcam.exe"
28172 Oct 3 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
40048 May 11 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
28172 Oct 3 2007 "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
218032 Sep 11 2006 "D:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
28172 Oct 3 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
563984 Jul 25 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\bak\Communications_Helper.exe"
28172 Oct 3 2007 "D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe"
32881 Sep 28 2004 "D:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
28172 Oct 3 2007 "D:\WINDOWS\system32\spool\drivers\w32x86\2\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x7328e0\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\2\bak\printray.exe"
28172 Oct 3 2007 "D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
196608 Nov 15 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe"
end of report

Double-click the FindAWF icon once again
If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak foldersA text file opens called: files.txt
Click below the line and paste the following list of files to be restored:
"D:\Program Files\AIM6\bak\aim6.exe"
"D:\Program Files\LexmarkX73\bak\AcBtnMgr_X73.exe"
"D:\Program Files\LexmarkX73\bak\ACMonitor_X73.exe"
"D:\Program Files\QuickTime\bak\qttask.exe"
"D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
"D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
"D:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
"D:\Program Files\Elaborate Bytes\CloneCD\bak\ElbyCheck.exe"
"D:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"D:\Program Files\ISP50\hta\bak\station.sbrt"
"D:\Program Files\Logitech\QuickCam\bak\Quickcam.exe"
"D:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
"D:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
"D:\Program Files\Common Files\LogiShrd\LComMgr\bak\Communications_Helper.exe"
"D:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
"D:\WINDOWS\system32\spool\drivers\w32x86\2\bak\printray.exe"
"D:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe"
Next, close and click Yes to save the changes.
Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folderWhen done with the above, it automatically runs a new scan and opens a new log.
Please post the new FindAWF log in your reply.

Here is the copy of the FindAWF log after restoring the files:
Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfullyThe current date is: Sat 10/13/2007
The current time is: 12:23:45.42
bak folders found
~~~~~~~~~~~
Directory of D:\PROGRA~1\AIM6\BAK04/27/2007 04:17 PM 50,736 aim6.exe
1 File(s) 50,736 bytesDirectory of D:\PROGRA~1\ISP50\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\LEXMAR~1\BAK
05/11/2001 05:57 PM 53,248 AcBtnMgr_X73.exe
05/11/2001 11:39 AM 53,248 ACMonitor_X73.exe
2 File(s) 106,496 bytesDirectory of D:\PROGRA~1\MSNMES~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\QUICKT~1\BAK
03/12/2006 07:22 PM 155,648 qttask.exe
1 File(s) 155,648 bytesDirectory of D:\PROGRA~1\SYMANT~1\BAK
08/02/2004 08:36 PM 124,232 VPTray.exe
1 File(s) 124,232 bytesDirectory of D:\PROGRA~1\COMMON~1\SYMANT~1\BAK
06/09/2004 09:31 PM 66,680 ccApp.exe
1 File(s) 66,680 bytesDirectory of D:\PROGRA~1\ELABOR~1\CLONECD\BAK
11/02/2002 01:33 AM 45,056 ElbyCheck.exe
1 File(s) 45,056 bytesDirectory of D:\PROGRA~1\GOOGLE\GOOGLE~2\BAK
06/13/2007 06:28 PM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytesDirectory of D:\PROGRA~1\ISP50\HTA\BAK
10/17/2003 05:40 PM 14,369 station.sbrt
1 File(s) 14,369 bytesDirectory of D:\PROGRA~1\LOGITECH\QUICKCAM\BAK
07/25/2007 04:06 PM 2,027,792 Quickcam.exe
1 File(s) 2,027,792 bytesDirectory of D:\PROGRA~1\LOGITECH\VIDEO\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\YAHOO!\MESSEN~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
05/11/2007 03:06 AM 40,048 Reader_sl.exe
1 File(s) 40,048 bytesDirectory of D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK
09/11/2006 05:40 AM 218,032 ISUSPM.exe
1 File(s) 218,032 bytesDirectory of D:\PROGRA~1\COMMON~1\LOGISHRD\LCOMMGR\BAK
07/25/2007 04:02 PM 563,984 Communications_Helper.exe
1 File(s) 563,984 bytesDirectory of D:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK
09/28/2004 09:26 PM 32,881 jusched.exe
1 File(s) 32,881 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK
05/14/2001 09:04 AM 36,352 printray.exe
1 File(s) 36,352 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK
11/15/2001 12:00 PM 196,608 hpztsb04.exe
1 File(s) 196,608 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~50736 Apr 27 2007 "D:\Program Files\AIM6\aim6.exe"
50736 Apr 27 2007 "D:\Program Files\AIM6\bak\aim6.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\AcBtnMgr_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\AcBtnMgr_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\ACMonitor_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\ACMonitor_X73.exe"
155648 Mar 12 2006 "D:\Program Files\QuickTime\qttask.exe"
155648 Mar 12 2006 "D:\Program Files\QuickTime\bak\qttask.exe"
124232 Aug 2 2004 "D:\Program Files\Symantec AntiVirus\VPTray.exe"
124232 Aug 2 2004 "D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
66680 Jun 9 2004 "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
66680 Jun 9 2004 "D:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
54296 Dec 2 2003 "E:\Program Files\Common Files\Symantec Shared\CCAPP.exe"
45056 Nov 2 2002 "D:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
45056 Nov 2 2002 "D:\Program Files\Elaborate Bytes\CloneCD\bak\ElbyCheck.exe"
45056 Nov 2 2002 "E:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
52272 Jan 27 2007 "D:\Program Files\Google\googletoolbar3user.exe"
61440 Sep 14 2006 "D:\Program Files\Google\Google Earth\googleearth.exe"
68856 Jun 13 2007 "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
14405024 Oct 19 2006 "D:\Documents and Settings\Administrator\My Documents\downloads\GoogleEarthWin.exe"
559784 Jul 21 2006 "D:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138168 Jan 27 2007 "D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 13 2007 "D:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
14369 Oct 17 2003 "D:\Program Files\ISP50\hta\station.sbrt"
14369 Oct 17 2003 "D:\Program Files\ISP50\hta\bak\station.sbrt"
2027792 Jul 25 2007 "D:\Program Files\Logitech\QuickCam\Quickcam.exe"
2027792 Jul 25 2007 "D:\Program Files\Logitech\QuickCam\bak\Quickcam.exe"
40048 May 11 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
40048 May 11 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
218032 Sep 11 2006 "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
218032 Sep 11 2006 "D:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
563984 Jul 25 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
563984 Jul 25 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\bak\Communications_Helper.exe"
32881 Sep 28 2004 "D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe"
32881 Sep 28 2004 "D:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\2\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x7328e0\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\2\bak\printray.exe"
196608 Nov 15 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
196608 Nov 15 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe"
end of report

Thank you jabuck for taking the time and effort to help me. The last FindAWF seems to have removed the virus. Since it was a backdoor Trojan only time will tell for sure. I will check back for any more suggestions you may have.
Kep up the good work.

We are not finished yet, but it is looking better.
Option 3:
Double-click the FindAWF icon once againIf a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 3 then Enter to remove bak foldersA text file opens called: folders.txt
Click below the line and paste the following list of folders to be removed:"D:\Program Files\AIM6\bak\aim6.exe"
"D:\Program Files\LexmarkX73\bak\AcBtnMgr_X73.exe"
"D:\Program Files\LexmarkX73\bak\ACMonitor_X73.exe"
"D:\Program Files\QuickTime\bak\qttask.exe"
"D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
"D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
"D:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
"D:\Program Files\Elaborate Bytes\CloneCD\bak\ElbyCheck.exe"
"D:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"D:\Program Files\ISP50\hta\bak\station.sbrt"
"D:\Program Files\Logitech\QuickCam\bak\Quickcam.exe"
"D:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
"D:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
"D:\Program Files\Common Files\LogiShrd\LComMgr\bak\Communications_Helper.exe"
"D:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
"D:\WINDOWS\system32\spool\drivers\w32x86\2\bak\printray.exe"
"D:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe"Next, close and click Yes to save the changes.
Once folders.txt is saved, FindAWF does the following:
-It deletes the contents of the bak folders
-Removes the bak foldersWhen done with the above, it automatically runs a new scan and opens a new log.
Please provide the new FindAWF log in your reply.
Next Option 4.
Option 4:
Double-click the FindAWF icon once againIf a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 4 then Enter to reset domain zonesThis removes all entries from the domain zones.
When the program returns to the main menu, use the following option:
Press E then Enter to EXITNext,Open notepad (Start Menu > Run > Type notepad and press "ok".
Copy and paste everything into notepad between the x's making regedit4 the top line.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Then, disconnect from the Internet!
Next, on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.
Optional if the following programs are in your computer.
Note that since the Domains are deleted SpywareBlaster protection must be re-enabled. Spybot's Immunize feature must be used again, also you have to re-install IE-SpyAd if installed.
Delete the fixme.reg file just created as we will be creating another one.Open notepad (Start Menu > Run > Type notepad and press "ok".
Copy and paste everything into notepad between the x's making regedit4 the top line.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL][HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXGo to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it Fix.reg then save it to your desktop.
Double click Fix.reg (or right click and choose Merge) and it will ask if you want to merge the contents into the registry, choose Yes.
Restart the computer.
Post a new Hijack This log please.

rajbsn. Please start a new thread and state the problem. Please do not post a log until you are requested to do so as it is the forum rules, not my idea, but the forum rules never the less.

Log after running step 3:
Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfullyThe current date is: Tue 10/16/2007
The current time is: 9:54:01.31
bak folders found
~~~~~~~~~~~
Directory of D:\PROGRA~1\AIM6\BAK04/27/2007 04:17 PM 50,736 aim6.exe
1 File(s) 50,736 bytesDirectory of D:\PROGRA~1\ISP50\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\LEXMAR~1\BAK
05/11/2001 05:57 PM 53,248 AcBtnMgr_X73.exe
05/11/2001 11:39 AM 53,248 ACMonitor_X73.exe
2 File(s) 106,496 bytesDirectory of D:\PROGRA~1\MSNMES~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\QUICKT~1\BAK
03/12/2006 07:22 PM 155,648 qttask.exe
1 File(s) 155,648 bytesDirectory of D:\PROGRA~1\SYMANT~1\BAK
08/02/2004 08:36 PM 124,232 VPTray.exe
1 File(s) 124,232 bytesDirectory of D:\PROGRA~1\COMMON~1\SYMANT~1\BAK
06/09/2004 09:31 PM 66,680 ccApp.exe
1 File(s) 66,680 bytesDirectory of D:\PROGRA~1\ELABOR~1\CLONECD\BAK
11/02/2002 01:33 AM 45,056 ElbyCheck.exe
1 File(s) 45,056 bytesDirectory of D:\PROGRA~1\GOOGLE\GOOGLE~2\BAK
06/13/2007 06:28 PM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytesDirectory of D:\PROGRA~1\ISP50\HTA\BAK
10/17/2003 05:40 PM 14,369 station.sbrt
1 File(s) 14,369 bytesDirectory of D:\PROGRA~1\LOGITECH\QUICKCAM\BAK
07/25/2007 04:06 PM 2,027,792 Quickcam.exe
1 File(s) 2,027,792 bytesDirectory of D:\PROGRA~1\LOGITECH\VIDEO\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\YAHOO!\MESSEN~1\BAK
0 File(s) 0 bytes
Directory of D:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
05/11/2007 03:06 AM 40,048 Reader_sl.exe
1 File(s) 40,048 bytesDirectory of D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK
09/11/2006 05:40 AM 218,032 ISUSPM.exe
1 File(s) 218,032 bytesDirectory of D:\PROGRA~1\COMMON~1\LOGISHRD\LCOMMGR\BAK
07/25/2007 04:02 PM 563,984 Communications_Helper.exe
1 File(s) 563,984 bytesDirectory of D:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK
09/28/2004 09:26 PM 32,881 jusched.exe
1 File(s) 32,881 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK
05/14/2001 09:04 AM 36,352 printray.exe
1 File(s) 36,352 bytesDirectory of D:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK
11/15/2001 12:00 PM 196,608 hpztsb04.exe
1 File(s) 196,608 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~50736 Apr 27 2007 "D:\Program Files\AIM6\aim6.exe"
50736 Apr 27 2007 "D:\Program Files\AIM6\bak\aim6.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\AcBtnMgr_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\AcBtnMgr_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\ACMonitor_X73.exe"
53248 May 11 2001 "D:\Program Files\LexmarkX73\bak\ACMonitor_X73.exe"
155648 Mar 12 2006 "D:\Program Files\QuickTime\qttask.exe"
155648 Mar 12 2006 "D:\Program Files\QuickTime\bak\qttask.exe"
124232 Aug 2 2004 "D:\Program Files\Symantec AntiVirus\VPTray.exe"
124232 Aug 2 2004 "D:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
66680 Jun 9 2004 "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
66680 Jun 9 2004 "D:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
54296 Dec 2 2003 "E:\Program Files\Common Files\Symantec Shared\CCAPP.exe"
45056 Nov 2 2002 "D:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
45056 Nov 2 2002 "D:\Program Files\Elaborate Bytes\CloneCD\bak\ElbyCheck.exe"
45056 Nov 2 2002 "E:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe"
52272 Jan 27 2007 "D:\Program Files\Google\googletoolbar3user.exe"
61440 Sep 14 2006 "D:\Program Files\Google\Google Earth\googleearth.exe"
68856 Jun 13 2007 "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
14405024 Oct 19 2006 "D:\Documents and Settings\Administrator\My Documents\downloads\GoogleEarthWin.exe"
559784 Jul 21 2006 "D:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138168 Jan 27 2007 "D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 13 2007 "D:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
14369 Oct 17 2003 "D:\Program Files\ISP50\hta\station.sbrt"
14369 Oct 17 2003 "D:\Program Files\ISP50\hta\bak\station.sbrt"
2027792 Jul 25 2007 "D:\Program Files\Logitech\QuickCam\Quickcam.exe"
2027792 Jul 25 2007 "D:\Program Files\Logitech\QuickCam\bak\Quickcam.exe"
40048 May 11 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
40048 May 11 2007 "D:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
218032 Sep 11 2006 "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
218032 Sep 11 2006 "D:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
563984 Jul 25 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
563984 Jul 25 2007 "D:\Program Files\Common Files\LogiShrd\LComMgr\bak\Communications_Helper.exe"
32881 Sep 28 2004 "D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe"
32881 Sep 28 2004 "D:\Program Files\Java\j2re1.4.2_06\bin\bak\jusched.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\2\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x7328e0\printray.exe"
36352 May 14 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\2\bak\printray.exe"
196608 Nov 15 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
196608 Nov 15 2001 "D:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe"
end of report

I should have mentioned I got through opyion 4 of the FindAWF procedure. Here is the new log from Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:32:28 PM, on 10/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: NormalRunning processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\LEXBCES.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.exe
D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
D:\WINDOWS\system32\RUNDLL32.exe
D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\SYMANT~1\VPTray.exe
D:\Program Files\ISP50\bin\bartshel.exe
D:\Program Files\QuickTime\bak\qttask.exe
D:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
D:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
D:\Program Files\Logitech\QuickCam\Quickcam.exe
D:\WINDOWS\system32\devldr32.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\AIM6\aim6.exe
F:\SUPERAntiSpyware.exe
D:\Program Files\AIM6\aolsoftware.exe
D:\PROGRA~1\ISP50\bin\ppshared.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
D:\Program Files\WinZip\WZQKPICK.exe
D:\WINDOWS\system32\spider.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "D:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Bart Station] D:\Program Files\ISP50\hta\station.sbrt
O4 - HKLM\..\Run: [LogitechGalleryRepair] D:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] D:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] D:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] D:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "D:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "D:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aim6] "D:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - D:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bitwisesystems.com
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartAc...
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yah...
O20 - Winlogon Notify: !SASWinLogon - F:\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - D:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.exe
O23 - Service: LVCOMSer - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - D:\WINDOWS\SYSTEM32\LxrSG20s.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - D:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - D:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://i4.ebayimg.com/01/i/03/a3/b9...--
End of file - 10398 bytes

Ok, you killed the virus, the 015 is gone from Hijack This.
Run Hijack This, close all windows and browsers except Hijack This, place a check to the left of the following items and press"fix checked":
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
Exit Hijack This
Your java is out of date and can be exploited.
Download the latest version of http://java.sun.com/javase/downloads/index.jsp
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement". The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the "coffee cup" icon next to it.
Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed
. Then from your desktop double-click on jre-1_6_3-windowsi586-p.exe to install the newest version.
You should add "Spywareblaster" to your arsenol of antispyware tools, just do a google search for spywareblaster, download it,install it, and update it. Its free and runs in the background, so you don't actually run it, and re-writes malicious script before it can install on your computer. Look for updates weekly as there is no auto-update on the free version.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |