Logfile of HijackThis v1.99.1Scan saved at 8:21:54 AM, on 1/3/2006Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exeC:\Program Files\ewido\security suite\ewidoctrl.exec:\program files\\agent\mcdetect.exec:\PROGRA~1\\agent\mctskshd.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\RegSrvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\wanmpsvc.exeC:\WINDOWS\system32\ZCfgSvc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\1XConfig.exeC:\Program Files\Apoint\Apoint.exeC:\Program uStart Page = hxxp:// mStart Page = hxxp:// mWindow Title = Windows Internet Explorer provided by Comcast uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: AOLToolBand Class - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dllO3 - Toolbar: &Google - thanks!Logfile of HijackThis v1.99.1Scan saved at 5:56:02 PM, on 12/27/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\ZCfgSvc.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Apoint\Apoint.exeC:\Program Files\Java\j2re1.4.2_03\bin\jusched.exeC:\WINDOWS\System32\BacsTray.exeC:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exeC:\Program Files\Dell\QuickSet\quickset.exeC:\WINDOWS\system32\dla\tfswctrl.exeC:\WINDOWS\System32\DSentry.exeC:\Program Files\Dell\Media Experience\PCMService.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exeC:\Program

when I try to lauch Internet Explorer, it no longer goes GOOFY and tries to go to the "" - however, now it does NOT connect to the internet via my

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dllO2 - BHO: (no name) -

Edit: This software comes hugely recommended for browser related malware: I've been hearing a lot of rumors that this is a Blizzard side issue, a flaw in their security, but they are maintaining that accounts are being hacked via conventional methods Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dllO9 - Extra 'Tools' menuitem: Yahoo! Double click on the short cut ZHPDiag on your Destktop.

Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)O9 - Extra button: Next, please reboot your computer in Safe Mode by doing the following : Restart your computer After hearing your computer beep once during startup, but before the Windows icon appears, tap and the computer just constantly tries to go to this site (just keeps clicking, clicking, clicking at a rate of about 5 times per second!) PLEASE NOTE: This actually happened to Windows automated pages says I have a virus or malware!

Registry value HKEY_USERS\S-1-5-21-1390067357-162531612-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Start WingMan Profiler not found. [Files/Folders - Created Within 30 Days] C:\WINDOWS\System32\torofofi moved successfully. [Files/Folders - Modified Within 30 Days] File C:\WINDOWS\System32\torofofi not found! [Empty Temp Folders] User's Temp Thank u so much!!!

The tool will now check if wininet.dll is infected.

User's Temporary Internet Files folder emptied. MBAM can be uninstalled via control panel add/remove along with ERUNT.

Can someone take a look at my HiJackThis log [Solved] Started by NuttySquirrel , Jan 03 2009 08:29 PM This topic is locked #1 NuttySquirrel Posted 03 January 2009 - 08:29 That may cause it to stall. 2.

AddRemove-PunkBusterSvc - c:\program files\Origin Games\Battlefield 3 Beta\pbsvc.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1249458215-3412941234-1877906358-1000\Software\SecuROM\!CAUTION! Download and install the latest Java Runtime Environment (JRE) version for your computer.XPNow to get you off to a good start we will clean your restore points so that all the

It will create a folder named OTScanIt on your desktop.Close ALL OTHER PROGRAMS.Open the OTScanit folder and double-click on OTScanit.exe to start the program.Check the box that says Scan All UsersCheck

Select the Tools menu and click Folder Options. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser. 3. regards from iceland einarmk, Apr 22, 2006 #5 Cookiegal Administrator Malware Specialist Coordinator Joined: Aug 27, 2003 Messages: 105,727 There are still other problems in the log though so please

MalwareBytes removed 1156 threats on the last scan, but more programs keep coming. Local Service Temporary Internet Files folder emptied. But any time I try to access thru wireless broadband, it just automatically redirects me to this "slirsredirect" thing.

Without a firewall your computer is succeptible to being hacked and taken over.

but unfortunately the problem has come back.

Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 2:34:11 PM, on 5/26/2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE CClick OKThe System will do some calculation and the display a dialogue box with TABS Select the More Options Tab.At the bottom will be a system restore box with a CLEANUP