I just ran across this site, maybe you guys can help me.

SpywareBlaster doesn't scan and clean for spyware In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo! **Post your HijackThis log tohttp://forums.spywareinfo.com/ or the Spyware forum athttp://forum.aumha.org/ for expert analysis, not here.**

Short URL to this thread: https://techguy.org/147866 the CLSID has been changed) by spyware. O5 - IE Options not visible in Control PanelWhat it looks like: O5 - control.ini: inetcpl.cpl=noWhat to do:Unless you or your system administrator have knowingly hidden the icon from Control Panel,

Scan revealed nothing. Once the scan is complete it will display if your system has been infected.  Now click on the Save as Text button:  Save the file to your Desktop.

Here's the boot log

Select the "Save Report As" button in the lower left hand of the screen and save it to a text file on your system. (Make sure to remember where you saved Only OnFlow adds a plugin here that you don't want (.ofb).O13 - IE DefaultPrefix hijackWhat it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW.

hth · actions · 2003-Nov-21 10:28 am · Meliettejoin:2003-11-20

2003-Nov-21 10:42 am Thanks again!! Just wanted to thank EVERYONE that helped me out (especially you Zupe!!), you guys are great and you have no idea how much I appreciate all of your time and help!!Thanks Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat

Thanks for those programs! With the help of this automatic analyzer you are able to get some additional support. So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most

It should now change to inactive. If you don't, check it and have HijackThis fix it. When I run Hijack This, here is what I get:Logfile of HijackThis v1.97.7Scan saved at 12:04:20 AM, on 11/21/2003Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\windows\system\hpsysdrv.exeC:\HP\KBD\KBD.EXEC:\WINDOWS\system32\dla\tfswctrl.exeC:\WINDOWS\System32\igfxtray.exeC:\WINDOWS\System32\hkcmd.exeC:\WINDOWS\System32\S3apphk.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exeC:\PROGRA~1\NORTON~1\navapw32.exeC:\Program Files\Visioneer OneTouch\OneTouchMon.exeC:\Program Files\AIM95\aim.exeC:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exeC:\Program this content If you have questions about smartphones, please feel free to post them and we will do our best to help you with them.

any major problems with that? · actions · 2003-Nov-21 10:42 am · John2gQui Tacet ConsentitPremium Memberjoin:2001-08-10England1 edit

2003-Nov-21 10:46 am This is a great resource for showing you How To Use Hijackthis NOTE:If you would like to keep your saved passwords, please click No at the prompt. I suggestyou disable Java and Active Scripting in the Internet Zone of Internet Explorer.Also download and run shootthemessenger from: »grc.com/stm/shootthemess ··· nger.htm

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't

O15 - Unwanted sites in Trusted ZoneWhat it looks like: O15 - Trusted Zone: http://free.aol.comO15 - Trusted Zone: *.coolwebsearch.comO15 - Trusted Zone: *.msn.comWhat to do:Most of the time only AOL and If the IP does not belong to the address, you will be redirected to a wrong site everytime you enter the address. uniqs1410 Share « Quicktime Registry at bootup in HijackThis: • I have something on my comp\ HijackThis Results » Meliettejoin:2003-11-20 Meliette Member 2003-Nov-20 10:11 pm Wabu! Hijackthis Bleeping I did all of that plus got the windows updates (as many as I figured I needed, since I have Windows XP and I read something about the System Pack 1

If not and if you have XP at the minimum enable the Internet Connection Firewall. · actions · 2003-Nov-21 2:33 pm · groundlingjoin:2003-02-08canada groundling to Meliette Member 2003-Nov-21 2:35 pm to Literati - http://download.games.yahoo.com/games/clients/y/tt0_x.cabO16 - DPF: Yahoo! Under Main choose: Select All Click the Empty Selected button. http://splodgy.org/hijackthis-log/hijackthis-log-analysis-request.php If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.   Thank you for your