For spyware I usually search in normal mode, but in the case I described, I certainly tried safemode before looking for different solutions.

Don't open email, or download attachments from unrecognized email addresses. 3. Then navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the Narrator key (C:\WINDOWS\System32\vciokr.exe) Next go to HKLM\Software\Microsoft\Active Setup\Installed Components\ and delete 54dd9b2f-c8a8-4b94-97b3-5823843401d8 Download KillBox (http://www.greyknight17.com/spy/KillBox.exe). All links to programs are in my signature. Save it to your desktop.

Scan all downloaded files with a reliable UP-TO-DATE antivirus program. If you search the web I'm sure you'll find info that is a little more precise that my drunken ramblings... Then navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the Narrator key (C:\WINDOWS\System32\vciokr.exe) Maybe this is the persistant problem. Windows Update: Keep your version of windows and Internet Explorer up to date and safer from attacks.

The BHO it installs changes your Internet Explorer home page and breeds innumerable popup ads. (BHO's are found at locations 49 and 50.) As for the "Narrator" key it appears every other reboot and is the spywares attempt to put it's files back in place.

When I rebooted I got question from spybot sd about five of these files about registry changes.I denied. I stopped the send as they didn't need to copy my whole computer in my estimation. Copy and paste each of the following into the top line (hitting the X button for each file - choose NO when it asks if you want to reboot): C:\Documents and Reboot in "normal mode", and "copy/paste" a new Hijack This!

Extension\MsgPlus.exe" O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [REGSHAVE] C:\Program Delete all of the following noted (in red) file(s)/FOLDER(s) you can find: c:\windows\etb <--- FOLDER c:\windows\msresearch.exe <--- file c:\windows\system32\cheez <--- FOLDER feqfq.exe <--- file msed32.exe <--- file msnrgd32.exe <--- file teskmangr.exe

Open hijackthis...click...config..misctools.

But neither of these programs found the CWS.HomeSearchAssistant. O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} Click the button Make a Log of what was Found Post that log. **Note** Only if you get an error after pressing Run Locate.com: Copy autoexec.nt from c:\windows\repair\ folder to c:\windows\system32\

Write down the name of the DLL file that's displayed! (If you see several values separated by commas or spaces, which is unlikely, use Windows Explorer to search for each one Files Found in system Folder............ ------------------------ C:\WINDOWS\system32\fastvideoplayer.dll: .aspack Files Found in all users startup Folder............ ------------------------ Logfile of HijackThis v1.99.0 Scan saved at 10:36:04 PM, on 1/27/2005 Platform: Windows XP SP1

Your RegLite instructions worked like a charme for me.

If anyone has a solution please let me know. Run the cleanup utility again..and then reboot when prompted. It runs in the background and checks in real time for possible hijacks.

Click the "Open Uninstall Manager" Button. If you have questions during the process, post them, and make sure you stay in this same thread.

Click file...export..and save a copy in case you make a mistake. Once you get to the last one click YES and it will reboot. Reboot in "safe" mode. Paste the following locations into KILL BOX one at a time.

Download Hijack This! It's a real nasty piece of software but I admire their ingenuity... Oohh, and for the best clean, boot into safemode and run your cleaning tools. Since I have done this I have had no furthernotification of windows update for the file listed above.

If it is, cut and paste it into a different folder i move mine to a folder called JUNK @ C:/JUNK, then try to delete it (You may or may not Close regedit. Then create FOLDERS with the names of the old files. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

The file did exist and was the Trojan itself.