Welcome to the forum gillj,Please use the Will let you know what happens and send the log files to you.

Open Microsoft AntiSpyware. Post that log in your next replyNote:Do not mouseclick combofix's window whilst it's running. HijackThis log « previous next » Print Pages: [1] 2 All Go Down Author Topic: Please help! Close any open browsers. 2.

If Ewido finds anything, it will pop up a notification. Select "I do not want to receive any type of information". (unless you want to receive such information) Click on Send Confirm registration, and continue by entering your user name and Reboot your computer in SAFE MODE" using the F8 method. Central 3] "C:\Program Files (x86)\Creative\Creative Live!

There is a yellow triangle with an exclaimation mark that appears constantly with different alerts. The fix will run then HijackThis will open, if it does not open automatically please open it manually. After you uncheck these, click on the Save button and close Microsoft AntiSpyware. Next you will see: Please type in the second filepath as instructed by the forum staff then press enter: At this point please type the following file path (make sure to

It should look like this VundoFix V2.15 by Atri By using VundoFix you agree that you are doing so at your own risk Press enter to continue.... navigate to this website In the left pane, click on Real-time Protection. TANSTAAFL!!I am not a Comcast employee, I am a paying customer just like you!I am an XFINITY Forum Expert and I am here to help. O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Should you decide to keep it, please don't use it until we have finished up here.

You might want to try Ewido to see if it can find anything.

Type Y to begin the cleanup process. Unless you bought and paid for it, please uninstall it and then run CKScanner. c:\program files\webmediaviewer c:\program files\webmediaviewer\browseu.exe c:\program files\webmediaviewer\myc.ico c:\program files\webmediaviewer\myd.ico c:\program files\webmediaviewer\mym.ico c:\program files\webmediaviewer\myp.ico c:\program files\webmediaviewer\myv.ico c:\program files\webmediaviewer\ot.ico c:\program files\webmediaviewer\qttask.exe c:\program files\webmediaviewer\qttasku.exe c:\program files\webmediaviewer\ts.ico c:\windows\winhelp.ini ----- BITS: Possible infected sites ----- hxxp://IL084SMSDHS6:80 hxxp://dhswsus02 GAC76 Guest Please help!

Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 4:36:59 PM, on 11/12/2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.18123) Boot mode: Normal Running processes: click site Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK: ComboFix /u -------------------------------------------------------------------- To help protect your computer in the future I

If you see a message in the titlebar saying "Not responding..." you can ignore it. From the main Ewido screen, click on "Update" in the left menu, then click the "Start update" button. 4. Anti Exploit Security Trend-net TEW-PS1U Wireless USB... It does not provide an option to clean/disinfect.

Pager] --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe R2 DriveHQ FileManagerFun;DriveHQ FileManagerFun;"C:\Program Files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe" [2007-07-11 21:30] R2 VenturiClient;Venturi Client;C:\Program Files\Netbooster Client\Client\ventc.exe [2007-02-05 16:53] R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC);C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2006-07-06 10:28] R3 USB28xxBGA;WinTV The time now is 01:50 PM. Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704] "DriveHQ FileManager"="C:\Program Files\DriveHQ\DriveHQ FileManager\DriveHQClient.exe" [2007-12-21 14:30 1974272] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-20 11:28 7581696] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-07-20 11:28 86016] "nwiz"="nwiz.exe" [2006-07-20 11:28 1519616 C:\WINDOWS\system32\nwiz.exe] "MsmqIntCert"="regsvr32 /s mqrt.dll" [] "MWLExe"="C:\Program Click here to join today!

HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\[email protected]? ????d??????`[email protected][email protected] HKCU\Software\Microsoft\Windows\CurrentVersion\Run QNPlus = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Post-it Software Don't close this window or go to another page while it is downloading.

Home > Please Help > Please Help! HijackThis Log 11/28

Page 1 of 2 1 2 Next > Advertisement rajrana007 Thread Starter Joined: Jan 31, 2008 Messages: 21 Hello Friends ! shut down your protection software now to avoid potential conflicts. Emergency Update" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40525C58-79C2-47A1-9AA2-F1D7FC4F0691}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40525C58-79C2-47A1-9AA2-F1D7FC4F0691}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{575815E5-190E-4262-9DD4-78B5EDFE9706}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows After you uncheck these, click on the Save button and close Microsoft AntiSpyware. news

HijackThis log « Reply #9 on: November 29, 2007, 02:24:06 PM » As requested, see the attached.[saving disk space - old attachment deleted by admin] Logged evilfantasy Malware Removal Specialist ModeratorGenius I would also recomend you switch to Avira Antivir for virus protect(free) or for paid ones Kaspersky/NOD32. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll R3 - URLSearchHook: ArchiBar toolbar - {24cc1362-11c6-4918-a2c0-b9ee5a563185} - C:\Program Files\ArchiBar\tbArch.dll O2 - BHO: Yahoo! Please then paste the contents of the text file to this thread.

But....when I tried to run the Kaspersky scanner it got to 100% for the updates; then it said connection to server failed. For information on the program click here.


