Okay some new minor Q's

I did a scan with the Avast virus cleaner…Lately I got a minor annoyance where something changed my start page and was prompting me to download some “anti-tracking” proggy…of course i didnt! I just simpy used a HJT and fixed it up…followed by spybot and Avast…all good…but today i did another scan just incase and it said it couldnt scan the following files…just wondering why:

C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Messenger*myemail*@hotmail.com\SharingMetadata\Working\database_AAAC_7014_AC6F_D8F9\dfsr.db
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Messenger*myemail*@hotmail.com\SharingMetadata\Working\database_AAAC_7014_AC6F_D8F9\fsr.log
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Messenger*myemail*@hotmail.com\SharingMetadata\Working\database_AAAC_7014_AC6F_D8F9\fsrtmp.log
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Messenger*myemail*hotmail.com\SharingMetadata\Working\database_AAAC_7014_AC6F_D8F9\tmp.edb
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp~DF843C.tmp
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp~DF844A.tmp
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp~DF8A7F.tmp
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp~DF8A8D.tmp
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chandir.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\chn.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\D0000000.FCS
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\L0000002.FCS
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_die.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_dnd.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_ext.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\prs_rcv.idx
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.dat
C:\Program Files\Compaq Connections\5577497\Users\Default\Data\storydb.idx

here is a fresh HJT log to check out:

Logfile of HijackThis v1.99.1
Scan saved at 2:56:42 PM, on 19/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Owner\Desktop\useless crap\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM..\Run: [HPBootOp] “C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe” /run
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra ‘Tools’ menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://siameseluver.spaces.live.com//PhotoUpload/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Just wondering (we didnt cover this in IT school…maybe we did and i wasnt paying attention…hehe) but how do you stop or block ALL downloads and installations besides the google toolbar (which I have)…Thank you all so very much!!!

Your log loks clean, to resist bad downloads you should install spywareblaster from Javacool http://www.javacoolsoftware.com/spywareblaster.html and although spybot s&d is good it is getting a bit long in the tooth, so I would consider replacing it with a programme that I have recently started using and find to be quite effective http://www.superantispyware.com/?tag=SUPERANTISPYWARE this is a free version and I find that a weekly or even monthly scan should suffice

EDIT Just to ensure you are totally clean you could download and run this small progrgamme to check yoursself out. It can be deleted after use http://www.malwarebytes.org/rogueremover.php

:slight_smile: Hi :

 According to your HJT log, your Sun Java is 5 Updates behind & is therefore a serious security
 risk ; I recommend you uninstall it ASAP, then go to www.majorgeeks.com/download4648.html
 to get the latest version .

 AND I would NOT have the "Google Toolbar" on my computer; there are increasing concerns
 about it jeopardizing User's privacy .

Okay thanks…done and got rid of the google toolbar…it was kind of annoying anyways :D…thank you!