When you are nameing the file to save on the desktop make sure you use the quotes just like I did else the file won't run rightREGEIDT4[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]"SystemManager"=-[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"appinit_dlls"=-

O4 - Global Startup: KeenValue.lnk = C:\Program Files\Common Files\KeenValue\keenvalue.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

Your pop-up killer is actually a home page hijacker. Also, when I try to uninstall Kazaa it says "Error in C:\WINDOWS\System32\cd_clint.dll Missing Entry: ServiceRunDll"

DoubleClick on the "FIX.bat" file.

Value "AppInit_DLLs" in key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" has different lengths (1 vs 32)

KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files\Google\Update\\GoogleCrashHandler.exe (Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe () C:\Program Files\SupTab\HpUI.exe () C:\Program Files\SupTab\Loader32.exe (Avira Operations GmbH & How To Use Hijackthis Here's how to and why you mist place hijackthis into a folder of its own.. Close the windowClean your Cache and Cookies in IE:Go to Control Panel > Internet Options > General tab.Click the "Delete Cookies" button and then the "Delete Files" button next to it.When C:\WINDOWS\SYSTEM32\ msxslab.dll Mon Aug 23 2004 9:48:32p ..SHR 0 0.00 K bridge.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K jac.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = click hereR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = click hereR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by PC

Thank you...I had a feeling it would be bad. http://splodgy.org/hijackthis-download/hijack-log-someone-help-please.php MINIMAL REQUIREMENTS INCLUDE: _________XP HOME/PRO; SP1; IE6/SP1 _________2K/SP4; IE6/SP1 ________________________________________________________________________________ »»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»» -----END------ Fri 26 Nov 04 14:59:19 0 Kudos Posted by CajunTek ‎11-27-2004 01:15 PM Security Expert View All Power SNiF 1.34 - The Ultimate File Snifferdog. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. Hijackthis Trend Micro

Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. In addition to scan and remove capabilities, HijackThis comes with several useful tools to manually remove malware from your computer. Click here to join today! weblink INTERNET\DIALBTYAHOO.EXEC:\PROGRAM FILES\YAHOO!\BROWSER\YBROWSER.EXEC:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXEC:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXEC:\WINDOWS\DESKTOP\ANTI VIRUS PROGS\HIJACKTHIS.EXER0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = click hereR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = click hereR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by PC

Umandlg Dll 35,840 . . . . Hijackthis Alternative No matches found. Error: (10/14/2014 02:05:31 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY) Description: 0x8000002a28\??\C:\Users\jody\ntuser.dat Error: (10/14/2014 02:03:58 PM) (Source: DCOM) (EventID: 10010) (User: جودي) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (09/30/2014 01:05:55 AM)

Double click the icon.

Error: (10/21/2014 01:58:32 AM) (Source: DCOM) (EventID: 10016) (User: جودي) Description: application-specificLocalActivation{B77C4C36-0154-4C52-AB49-FAA03837E47F}{EA022610-0748-4C24-B229-6C507EBDFDBB}

Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response. Please don't fill out this field.

Please don't fill out this field. Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_2_3_0.DLLO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

MS-DOS Version 5.00.500 *command.com test passed! Please copy and paste the contents of both in your reply Thank you.

combofix created a quarantine folder...what should i do with it? Feclient Dll 21,504 . . . . Loading... d l 000011D0:l adin h vk UDeviceNotSelectedTimeout 00001210: 1 5 P 9 0 vk ' zGDIProce 00001250:ssHandleQuota" vk Spooler2 y e s _ 00001290: h 0 ` vk 5swapdisk vk 000012D0:

Youhaveto hate me. ClickOKon theScan completescreen, thenOKon theAddition.txtpop up screen. 2 Notepad documents should now be open on your desktop. I am a paying customer just like you! KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [37352 2014-09-24] (Avira Operations GmbH & Co.

C:\WINDOWS\SYSTEM32\ msxslab.dll Mon Aug 23 2004 9:48:32p ..SHR 0 0.00 K bridge.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K jac.dll Mon Aug 23 2004 9:48:34p ..SHR 0 0.00 K Total of file sizes: 0 bytes 0.00 K »»»»» (*4*) »»»»»......... KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-10-21 01:27 - 2014-09-24 12:44 - 00037352 _____ (Avira Operations GmbH & Co.