Sounds as though you account doesn't have Administrative privledges. Is the account a Limited User account?
Well, a bit of digging convinced me that the DllRegisterServer function is not the path we want to explore. :rolleyes: Let's try this. Execute the...
Good news .... all infected files are in quarantine by ComboFix and Norton, and located in System Restore points. Nothing active! :) Lets...
You had an AWF infection that replaced legitmate files on your system with rogue copies and placed the originals in a different location. Lets get...
Great! HijackThis is properly installed. Scan again and place a check next to the following entry, close all other windows, then click Fix...
That's great news, James. You're very welocme. Glad I could help! :) I'll mark this topic resolved after the weekend then, unless I hear...
You can bet he didn't forget ...... just very busy I'm sure. Been quite busy myself. I'll try to do a bit more research on the above tonight and...
Tyler, I've had a very long day and am now exhausted, so it will be tomorrow evening before I have further cleanup instructions (and it's needed)....
Odd that it wasn't found. :confused: Never hurts to run an online virus scan. Instructions are here for a couple different ones if you're...
Welcome to WindowsBBS rgkj3 :) When you refer to saving your password, do you mean the encryption key for a secure network? If so, on either...
First step would remove only the registry's path to the file, not the file itself. Just paste this into the Run dialog and hit enter, then delete...
Welcome to WindowsBBS Don :) I only see 1 thing in you log that needs removed, but I can't be certain that you have HijackThis properly...
Welcome to WindowsBBS tylerho :) Download ComboFix by sUBs from here, saving the file to your desktop. It's best disable realtime...
Scan again with HijackThis, place a check next to the following entry, then click Fix Checked. O4 - HKLM\..\Policies\Explorer\Run: [some]...
Highlight and copy the contents of the code box below to a blank notepad. Save it to the desktop as; Filename: fix.reg Save as type: All Files...
It's just a wallpaper hijack, and likely not infected. What is the user name on the account you use? eg; I need the name of your user account...
Looks pretty good. Delete the following file. C:\WINDOWS\Downloaded Program Files\webinst.dll Now open your Symantec antivirus interface...
Great! Lets do yet another. Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop...
ccApp is a Norton component, and it's not unusual for it to be a bit slow about closing at shutdown. See if the deleted 0 registry key was...
Scan again with HijackThis and place a check next to the following entries, close all other windows then click Fix Checked. O2 - BHO: (no name)...
Separate names with a comma.