T_T » Thread Tools Show Printable Version Download Thread Search this Thread Advanced Search Similar Threads Thread Thread Starter Forum Replies Last Post Pls check my HJT log after cleaning Hi I really appreciate your help. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{0C03DEC4-B374-44DF-9B0D-38BD942080C4}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\ () CustomCLSID: HKU\S-1-5-21-2052111302-861567501-725345543-1004_Classes\CLSID\{7a434a49-f21e-5011-8f99-aa7578492b9c}\InprocServer32 -> C:\Documents and Settings\Lew\Local Settings\Application Data\DIRECTV Player\npPlayerPlugin.dll (NDS) ==================== Restore Points ========================= Log looks good Note: This will remove all previous Restore Points Turn off System Restore: On the Desktop, right-click My Computer.

Error: (01/25/2015 09:19:44 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module unknown, version, fault address 0x03840fef. You don't stop laughing when you get old; you get old when you stop laughing.A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)Malware Removal University Masters GraduateJoin The Fight Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\System32\drivers\svchost.exeO4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO9 Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Digital Line Detect.lnk = ?

MFDnNC, Sep 11, 2007 #2 tatersalad11 Thread Starter Joined: Sep 11, 2007 Messages: 87 Here are the two scans, plus the new High Jack This scan. Please contact your system administrator." ...when I try to adjust date/time. o Click the Close button to leave the control center screen. · On the main screen, under Scan for Harmful Software click Scan your computer. · On the left check C:\Fixed

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Scheduler;c:\program files\ACT\ACT for Windows\Act.Scheduler.exe [2007-05-16 90112] R4 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2008-07-21 20376] R4 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [2008-11-21 113152] R4 CAATT;AT&T Con App Svc;c:\program files\AT&T\Communication Manager\ConAppsSvc.exe [2008-11-21 125440] Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet I have followed the 5 steps for removing malware and I have run HJT and analysed while still in safe mode.

I was pretty happy with MS Security Essentials for a while, but I've seen too much obvious stuff slip by and have had to go back to Kaspersky for really effective Do not run any other tool until instructed to do so! Emergency Update.job 2015-03-01 22:36 - 2013-07-10 09:57 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-01 20:40 - 2014-01-03 10:34 - 00000464 _____ () C:\WINDOWS\Tasks\At2.job 2015-03-01 18:01 - 2013-12-09 16:46 - 00000281 _____ () If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop.

The file will not be moved unless listed separately.) R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation) R2 avast! Also in safe mode navigate to the C:\Windows\Temp folder. Symantec Endpoint Protection - That explains why whatever spyware is on your PC made it through. It's often worth reading through these instructions and printing them for ease of reference.

Ghoste Inactive Malware Help Topics 1 09-16-2005 09:01 AM Redvines HJT log Hi, im new here and not pc savvy but need some help. Pop up ads everywhere when browsing web. Windows XP : Double click on the icon to run it. Yes, my password is: Forgot your password?

I've tried running Norton, Ad-Aware, and Spybot and they are still happening! navigate here Ever since I installed Win XP SP2 I've had probs with adware. Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Installation is borked / not uninstalled properly You have both google and yahoo!

Please post the contents of log.txt. Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, Disinfecting a system which has been infected for an extended period of time relies on luck, skill, or very good software.

DO NOT attach the logs unless specifically instructed to do so.

Let me know if any of the links do not work or if any of the tools do not work.

