
Hey Guys,
I am not seeing anything particularly nasty, but there are some oddities the
HJT is showing that may be relevant to what is going on.
First of all you can fix these with
HJT;
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :0
O4 - Global Startup: Logitech SetPoint.lnk = ?
Also, please download Shoot the Messenger from my signature, and run it, (very simple, one button), this will disable your Windows Messenger, which is an unnecessary utility that is leaving you vulnerable to PopUp attacks.
OK, now on to the oddities. Merlin and Gar, you will know better than I if this is an issue, but I have not seen it before in a log.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
As you can see, his ATI utilities are running double on one and triple on the other. This doesn't look like the regular configuration for ATI to me. I would completely uninstall the graphics card completely, and get a clean download and reinstall.
Also located this information,
ClickSpring Masking as Legit,
Will be back to finish later.
TTFN
LGW
That's all that showed up in the
HJT. NightJ, if you could please attach the ewido log as well that could prove enlightening.