Frist all my icons,windows, and screens are getting smaller. C:\WINDOWS\Explorer.EXE C:\Program Files\Saitek\Software\Profiler.exe C:\Program Files\Saitek\Software\SaiMfd.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Robert

Thanks hijackthis! Any files you deleted in safe mode afterwards.4. Thanks...Phil Back to top #11 pskelley pskelley In Remembrance ..Rest in Peace Phil Trusted Malware Techs 1,767 posts Location:Clearwater, Florida Posted 22 February 2006 - 10:35 AM It appears these issues Join over 733,556 other people just like you! https://forums.techguy.org/threads/solved-new-hjt-log-need-help-in-cleaning.352390/

Inc. - C:\WINDOWS\system32\YPCSER~1.EXE O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe teapot0077, Apr 12, 2005 #1 Sponsor dvk01 Derek Moderator Malware Specialist Joined: Dec 14, 2002 Messages: 50,575 If you still want help, do this and in the posted order. 1) Move HJT from the Desktop for safety. When windows starts up it asks for a password.

Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra 'Tools' menuitem: Yahoo! If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Everyone else please begin a New Topic. Unknown Jun 2006 edited Jul 2006 in Spyware & Virus Removal Hi, this is my first time here, and I was wondering if I could get an opinion of my hjt

Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra fourth I can't see but one tab on my desk top prop. 5th system restore says it can't be restored . Restart the computer and post the ewido scan results, a new HJT log and any feedback you think I should have. http://www.techmonkeys.co.uk/forum/Thread-solved-hjt-log-3-icons-on-desktop-error-cleaner-privacy ONLY the bad entries that you removed / ticked off in HJT3.

Click here to Register a free account now! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra 'Tools' menuitem: Yahoo! But nowhere else. Inc. - C:\WINDOWS\system32\YPCSER~1.EXE teapot0077, Apr 21, 2005 #7 dvk01 Derek Moderator Malware Specialist Joined: Dec 14, 2002 Messages: 50,575 Download pocket killbox from http://www.thespykiller.co.uk/files/killbox.exe & put it on the desktop

If you do not have a firewall installed, please download and instal one of these excellent (and free) products: Zone Alarm or Sunbelt Kerio PF. http://newwikipost.org/topic/0F84oY8ifXDbbUNCnWVaEcTLCXJl1CHB/Solved-Struggling-to-clean-infection-please-help.html So I have that shut off. this means it may take a little longer to get here, but hopefully it'll be worth the wait securitywonks: I am already with you yaar:)I think, you had seen my email I'm currently amassing all the HJT files I've dealt with myself, but it seems that we can do this a heck of a lot quicker if we worked together as how

Read this: . check over here Sorry for the trouble. Invalid email address. Please re-enable javascript to access full functionality.

IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Yahoo! I realize that my suggestion/s are not narrowing down the specific problem file/program that is causing your rig to do what it's doing, but first thing's first, and that would be Cookies & Temp files were cleaned previously in Internet Options. http://blightysoftware.com/solved-new/solved-new-here.html Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\PDF Converter\IEShellExt.dll /100

wait until a text opens, post it in a reply to your thread. Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin I always recommend it!

I prefer C:\HJT\HijackThis.exe, if you need additional instructions use these: http://russelltexas....tehjtfolder.htm Please do this before you proceed. 2) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php The newest version of

second my computer runs real slow. Let me know how things are, and if we can mark this resolved? 0 OptionsEdit Bobstar Jul 2006 edited Jul 2006 Here is my latest hjt log, if it is ok, I am truly a Short Media convert. Click the Remove or Change/Remove button.

hijackThis Log--please help solve Non-StopSearch spyware Started by winigo , Dec 29 2004 02:37 PM This topic is locked 7 replies to this topic #1 winigo winigo Members 40 posts OFFLINE Its asking me for an activation key number. Logfile of HijackThis v1.99.1 Scan saved at 10:01:33 PM, on 4/12/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe http://blightysoftware.com/solved-new/solved-new-gig.html Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ

We got engaged on the night o… drasnor Hawthorne, CA 27 Feb Do you like bananas? regscrub). SourceForge Browse Enterprise Blog Deals Help Create Log In or Join Solution Centers Go Parallel Resources Newsletters Cloud Storage Providers Business VoIP Providers Internet Speed Test Call Center Providers Share Share I am using that for a browser nowdays.

Restart the computer and post the ewido scan results, a new HJT log and any feedback you think I should have. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Staff Online Now crjdriver Moderator Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Forums Recent And what else can I do. :help: Logfile of HijackThis v1.99.1 Scan saved at 7:41:14 PM, on 2/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running

hmaxos vs Lowest Rated 1 of 5 2 of 5 3 of 5 4 of 5 5 of 5 "No internet connection available" When trying to analyze an entry. Everyday is virus day. Thanks Back to top #8 mlt mlt New Member Members 6 posts Posted 18 February 2006 - 07:52 PM I've done everything you said. You seem to have CSS turned off.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:How did I get infected ? Uncheck Hide extensions for known filetypes and Hide protected operating system files.How to see hidden files in WindowsREBOOT into SafeMode by tapping F8 key repeatedly at bootup: Starting your computer in Locate and delete these items: C:\Windows\Prefetch\ >>> delete the contents (NOT THE FOLDER) Prefetch info: http://www.windowsne...refetch-XP.html If you don't have a good cleaner, use this one with these instuctions: Download CCleaner and post a fresh HJT log with the qoologic log file please dvk01, Apr 21, 2005 #8 teapot0077 Thread Starter Joined: Jul 21, 2004 Messages: 55 I did everything you

Run Spybot first, reboot then run Ad-aware.

