I'm constantly on the internet and have been for years never had a problem until recently. First I had the Microsoft Security Virus which completely locked up my computer. That was resolved with your software. Now I have an issue with google redirects. It doesn't seem to happen all the time but once it starts is seems like everything gets redirects to some random ads or sites. I updated software which I've been doing regularly now ran a full scan the other day and a quick scan today. NOTHING DETECTED! See reports below. I've been reading alot of the forum submissions and it sounds like there are a number of next steps but there are many warnings. I have no idea what I'm looking for or at and need some help PLEASE! Also when I start up my computer I seem to be receiving this message in my desktop notepad - opens 2 copies every time I turn on the computer. [.ShellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787 Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4885 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 10/19/2010 4:30:25 PM mbam-log-2010-10-19 (16-30-25).txt Scan type: Quick scan Objects scanned: 154750 Time elapsed: 11 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) __________________________________________ HERE is the most recent log that detected anything Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4817 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 10/14/2010 5:57:08 AM mbam-log-2010-10-14 (05-57-08).txt Scan type: Full scan (C:\|) Objects scanned: 273720 Time elapsed: 1 hour(s), 30 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\dldodrs32.dll (Trojan.Tracur) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{007adc0c-020b-45be-936d-9779ecce4b91} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{007adc0c-020b-45be-936d-9779ecce4b91} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{007adc0c-020b-45be-936d-9779ecce4b91} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Karen Galena\Application Data\SysWin (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\dldodrs32.dll (Trojan.Tracur) -> Delete on reboot. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP781\A0112847.exe (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Documents and Settings\Karen Galena\Application Data\asdsada.bat (Malware.Trace) -> Quarantined and deleted successfully. _____________________________________________________________________ Here is the log from the scan that removed the Microsoft Security Virus Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4791 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 10/10/2010 12:54:19 PM mbam-log-2010-10-10 (12-54-19).txt Scan type: Quick scan Objects scanned: 151164 Time elapsed: 13 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 4 Registry Values Infected: 2 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 38 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\bthserv32.dll (Trojan.Tracur) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c85eb5fa982 (Trojan.Tracur) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{a10c4948-b8b3-bcec-7870-ef688f177b89} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a10c4948-b8b3-bcec-7870-ef688f177b89} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a10c4948-b8b3-bcec-7870-ef688f177b89} (Trojan.Tracur) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Worm.Prolaco) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\bthserv32.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\bthserv32.dll -> Delete on reboot. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\bthserv32.dll (Trojan.Tracur) -> Delete on reboot. C:\WINDOWS\system32\AE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cryptdlg32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\F7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\11.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\118.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\12.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\125.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\137.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\145.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\14E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\160.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\194.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\19E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\1F2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\BB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\CddbFileTaggerRoxio32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dldocaps32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dldoinsb32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\B7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\BA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\27B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\2B9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\2D9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\2E3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\3CC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\3D0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\3DD.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\441.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4CB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\55.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\56A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\5E9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\69.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\6C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\A6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Documents and Settings\Karen Galena\Local Settings\Temp\19.tmp (Trojan.Tracur) -> Quarantined and deleted successfully. C:\Documents and Settings\Karen Galena\Application Data\SysWin\lsass.exe (Worm.Prolaco) -> Delete on reboot. ________________________________________________________