Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dllO4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exeO4 - HKLM\..\Run: [Track-It! Logfile of HijackThis v1.99.0 Scan saved at 9:08:23 PM, on 1/4/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}

Next press the Apply button and then the OK to exit the Internet Properties page. This does not necessarily mean it is bad, but in most cases, it will be malware. Then delete these files or directories (Do not be concerned if they do not exist) C:\WINDOWS\system32\sduvg.dll C:\WINDOWS\system32\sysfn.dll C:\WINDOWS\system32\ieph32.exe C:\WINDOWS\System32\tibs5.exe C:\WINDOWS\addyo32.exe C:\Program Files\Internet Explorer\wgfqrmqk.exe C:\WINDOWS\sdkel32.exe Run a full scan with Adaware. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine.

So you can always have HijackThis fix this. -------------------------------------------------------------------------- O12 - IE plugins What it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O12 - Plugin for .PDF: C:\Program

The second part of the line is the owner of the file at the end, as seen in the file's properties. When the scan is finished, look at the bottom of the screen and click the Save report button. If anybody can help me, please, please reply! What to do: Usually the Netscape and Mozilla homepage and search page are safe.

I do not recommend that you have more than one anti virus product installed and running on your computer at a time. It will take a few minutes and is checking your file system because of the Bad Shutdown we caused. Learn More. http://splodgy.org/hijackthis-log/hijackthis-log-attached.php SmitFraud infections commonly use this method to embed messages, pictures, or web pages directly on to a user's Active Desktop to display fake security warnings as the Desktop background.

Did all the stuff you said but once i ran hijackthis again some of the lines had changed so i didn't get rid of anything. Perform an ActiveSCan: http://www.pandasoftware.com/activescan/ Save the report to the desktop. I can't open task manager or add/remove programs. by Grif Thomas Forum moderator / May 15, 2007 3:41 AM PDT In reply to: ICON.EXE - Hijack this log attached - HELP PLS !!

Your Java is out of date. What to do: F0 entries - Any program listed after the shell statement will be loaded when Windows starts, and act as the default shell. Post the vundofix.txt file from the vundofix folder into as well. Symantec anti-virus is a real pig.

The same goes for the 'SearchList' entries. I'm at work at the moment but will copy and Uninstall Log and a new HijackThis log when I get home and will post it here. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Say hello!

The fix will tell you to shutdown using the Power button. First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.