Hi, I’ve been working on this problem for about 3 days and I feel that I still have an issue but cant figure it out. 3 days ago, a fake antivirus program showed up on my system anti-tray and gave me all these fake messages and I lost control of my pc. I couldnt run anything, and my norton virus kept indicating that various viruses were being blocked, 3 in total Cydoor, Trojan backdoor, and one other. My IE and firefox were hijacked and the only message that the website would give me were that the site was unsafe and to buy this fake antivirus program to make it go away. Fast forwarding a bit, I was able to get into safe mode, run task manager kill a whole bunch of processes and run a few scans. Norton told me there were no viruses present and only came back with a cookie but it was only partially resolved. Then I downloaded Microsoft Security essentials and that found an adware and was able to resolve it. Then i re-ran Norton and it came back with one cookie and said it was fully resolved. At that point I then downloaded the Malware bytes program and ran a full scan and it came back good with no virus results. I was feeling a lot better until a friend recommended that I also use Super AntiSpyware and it found 76 adware threats. I ran the scans in safe mode and it removed the items. However, I keep running the scans and after removing them continue to get the 3 following adware threats that keep coming back (even with the browser closed, running in safe mode, and then rebooting) : users/max/appdata/roaming/microsoft/windows/cookies/max@adecn(2).txt, @atdmt(2).txt, and @msnportal.112.207(1).txt. I’m not sure if I’m being paranoid, but I dont know if my pc is safe or compromised now. I did some research in the Norton’s window history and before al the attacks came it seems as if firefox was the issue. There was a low classification event about an hour before the attack that indicated that my registry had been modified and coincided with the timing of the Fake AntiVirus being displayed in my system tray. After that was the 3 attempts at installing the different virus all of which norton said was blocked. I changed back my internet settings on IE and firefox to not use the proxy settings and to automatically detect connections. I also contacted Norton support as I’m still a subscriber but didn’t understand everything the rep was saying and tried a session of Norton Power Eraser which came back without a virus and was unfortuntately disconnected with the rep. How do I know that my hosts file is not compromised? or that I have a virus and don’t even know it. Sorry to sound stupid, I’m just really confused as looking at the norton history there are a ton of messages Rule “Default block UPnP Discovery” stealthed (ip, Port ssdp(1900) ) Inbound UDP packet that I do not understand what they mean. I have downloaded PSI to help make sure all my other programs like Adobe are the most recent but I do not know what else to do. please help