I have run the scanner twice and the same thing seems to happen. C:\Program Files (x86)\SearchProtect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot. C:\Users\Eda\AppData\Roaming\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\Eda\AppData\Roaming\SearchProtect\bin\msvcr100.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot. check over here

Run defrag at your convenience. It will scan and the log should open in notepad. When the scan is finished, the "Scan" button will change into a "Save Log" button.

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Kit\PC Health Kit.lnk (Rogue.PCHealthKit) -> Quarantined and deleted successfully. C:\Program Files (x86)\PC Health Kit\CookiesException.txt (Rogue.PCHealthKit) -> Quarantined and deleted successfully. So I guess thats the only issue resulting from the infection I see so far. Attached Files: hijackthis.log File size: 6.7 KB Views: 1 mbam-log-2010-03-20 (00-38-47).txt File size: 1.3 KB Views: 1 SUPERAntiSpyware Scan Log - 03-20-2010 - 01-15-53.log File size: 621 bytes Views: 1 Mar

C:\Users\Eda\Local Settings\Temporary Internet Files\Content.IE5\1FRT5MLP\DefaultTabSetup_20130903[1].exe (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully. PST with CNET how-to video link and Updated Oct. 18, 2010, at 2:19 p.m. Close any open browsers. You Suspect That Some Of Your Computers Have Been Hijacked And Are Being Used To Perform HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.

That scan is taking a while so I figured I would show everything else to you. Computer Hijacked Ransom To end a process (program) that won't terminate any other way, use Advanced Process Termination (freeware): www.diamondcs.com.au/index.php?page=products9. Find it through the Start menu among the "Programs" under "Accessories." Then you must try to locate the virus file. Submit the suspected malware to AV and AT vendors.

C:\Users\Eda\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll (PUP.Optional.SearchProtect.A) -> Delete on reboot. Bleeping Computer The items not listed in red should not be touched at this time.3.2 Ad-aware (free version available): Download it here: www.lavasoftusa.com/software/adaware/majorgeeks.coma) Download and install the latest version of Ad-Aware. C:\Users\Eda\AppData\Roaming\SearchProtect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. This has only been happening for about a day.

When you post your reply, use the button instead. When running the scan, record exactly the details of any problems turned up. (Tracking cookies are easily cleaned up by deleting them, so don't bother recording them.)

It has done this 1 time(s). My system is running alot better now. Once complete, if you continue to have problems with a particular user account, repeat the scans in steps 2 and 3 using that user account. (On Windows XP, you will need http://splodgy.org/computer-hijacked/hijack-log-virus-or-trojan-infecting-computer.php Click on View Scan Report. 8.

C:\Program Files (x86)\SearchProtect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. Malwarebytes How do I get help? C:\Program Files (x86)\WhiteSmoke_New\GottenAppsContextMenu.xml (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.

C:\Program Files (x86)\WhiteSmoke_New\ldrtbWhit.dll (PUP.Optional.WhiteSmoke.A) -> Quarantined and deleted successfully.

Report the crime.Reports of individual incidents help law enforcement prioritize their actions. C:\Users\Eda\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. Run tools that look for viruses, worms and well-known trojans3. There is more on this in step 6.

When the downloads have finished, click on Settings. 5. Click Yes to do this. 7. Login now. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review. **Note: Do not mouseclick combofix's window while it's running.

If applicable, report identity theft, cancel credit cards and change passwords.

Please be patient as this can take some time. When the scan completes, click List Threats. Click Export, and save the file to your desktop using a unique name, such as ESETScan.

Under the System Protection tab, find Available Disks. Vista/Windows 7/8 users right-click and select Run As Administrator. Click on the Scan button. AdwCleaner will begin...be patient as the scan may take some time to complete. After the scan has finished, click on Run tools that allow for examination of some security and system settings that might be changed by a hacker to allow remote control of the system.