Completion time: 2008-05-31 14:46:31 ComboFix-quarantined-files.txt 2008-05-31 21:46:17 Pre-Run: 9,212,153,856 bytes free Post-Run: 9,516,204,032 bytes free 369 --- E O F --- 2008-04-09 10:15:11 dan_plus_o, May 31, 2008 #5 cohen New If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it. In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo! Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.7. http://www.hijackthis.de/

Hijackthis Log Analyzer

Sorry it toke me so long to get the log posted up but here it is.. ---------------------------------------------- ComboFix 08-05-21.3 - Dano 2008-05-31 14:44:05.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2274 [GMT C:\WINDOWS\system32\tmp76.tmp C:\WINDOWS\system32\tmp77.tmp . ((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-31 ))))))))))))))))))))))))))))))) . 2008-05-28 18:09 . 2008-05-31 14:45 3,152,160 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-05-28 18:09 . 2008-05-31 14:45 22,304 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-05-28 18:09 . I suggest AVG or Trend Micro RootkitBuster.6.

Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it.O1 - Hostsfile redirectionsWhat it looks like:O1 - Hosts: auto.search.msn.comO1 - Hosts: In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this. Spyware removal software such as Adaware or Spybot S&D do a good job of detecting and removing most spyware programs, but some spyware and browser hijackers are too insidious for even Hijackthis Windows 10 We recommend Gmail.   The notifications won't even be in your Spam folder - they just go down a black hole.

dan_plus_o, May 31, 2008 #7 ceewi1 VIP Member Messages: 5,427 His system is likely infected, it would be a good idea for him to post a log here. Hijackthis Download Sign in to follow this Followers 0 Go To Topic Listing Resolved or inactive Malware Removal All Activity Home Spyware, thiefware, browser hijackers, and other advertising parasites Malware Removal Resolved or O15 - Unwanted sites in Trusted ZoneWhat it looks like: O15 - Trusted Zone: http://free.aol.comO15 - Trusted Zone: *.coolwebsearch.comO15 - Trusted Zone: *.msn.comWhat to do:Most of the time only AOL and so just be careful!

Hijackthis Download

Windows firewall is better than none!ComodoComodo ™ Free Firewall Software DownloadZoneAlarmDownload ZoneAlarm Free 7.0.462.0 from filehippo.com Lisandro: Besides what have already been suggested, why don't you try?1.

Stay informed with Comcast Alerts Alerts are an easy, quick way to manage your account and get information - like payment confirmations and your current balance. http://splodgy.org/hijackthis-download/hijack-log-someone-help-please.php Here is the Malwarebytes' Anti-Malware log: -------------------------------------------- Malwarebytes' Anti-Malware 1.14 Database version: 812 4:10:58 PM 01/06/2008 mbam-log-6-1-2008 (16-10-58).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 369681 Time elapsed: 1 hour(s), 18 O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files (x86)\Megaupload\Mega Manager\mm_file.htm O8 - Extra context menu item: Google Sidewiki - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - If you have questions about smartphones, please feel free to post them and we will do our best to help you with them. Hijackthis Windows 7

Other things that show up are either not confirmed safe yet, or are hijacked (i.e. Also when I updated to SP3 I had a custom login background (Used Logon Studio) however I have change it back to the default to see if that would help the Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllF3 - REG:win.ini: load=C:\WINDOWS\system32\sstqo.exeO1 - Hosts: www.winmx.comO3 - Toolbar: Yahoo! check over here Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast!

Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat How To Use Hijackthis For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat Be sure that everything is checked, and click Remove Selected.

Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

Here's the Answer Article Wireshark Network Protocol Analyzer Article What Are the Differences Between Adware and Spyware? or read our Welcome Guide to learn how to use this site. The same goes for the 'SearchList' entries. Hijackthis Portable At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware then click Finish.

The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those. i have ever accepted crap like that..... scanning hidden autostart entries ... this content Once the program has loaded, select Perform full scan, then click Scan.

Please first disable any CD emulation programs using the steps found in this topic:Why we request you disable CD Emulation when receiving Malware Removal AdviceThen create another GMER log and post The HijackThis web site also has a comprehensive listing of sites and forums that can help you out. dan_plus_o New Member Messages: 129 Hello one of my friends on msn keeps sending me a link and a right after. It is not rocket science, but you should definitely not do it without some expert guidance unless you really know what you are doing.Once you install HijackThis and run it to