Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". Click the System Restore tab. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Put a check by these entries in Hijack This and click the "Fix Checked" button: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\hzhku.dll/sp.html#12345 R1 - Learn More. When you find it, double-click on it. To protect yourself further: IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. http://maddoktor2.com/forums/index.php?topic=1135.0;wap2

Put a check by these entries in Hijack This and click the "Fix Checked" button: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\hzhku.dll/sp.html#12345 R1 - To protect yourself further: IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system.

If you are not sure which version applies to your system download both of them and try to run them. You will be presented with a dialog asking you to pick a file.

They may have been changed by this CWS variant to allow ALL ActiveX!! You must follow these directions exactly and you cannot skip any part of it. Click Start > Run > and type in: services.msc Click OK.

This file contains binary data so it will look ugly in Notepad.

IMPORTANT! Logs to include with next post:Frst.txt Addition.txt checkup.txt

tried ad-aware, cwshredder & spybot... Double Click on FindnFix.exe and it will install the batch file in its own folder. 3. Start a full scan (all files) (!) by running mwavscan.com (directory c:\bases). STEP 5 run now first DELLATER.exe on your system.

O4 - Global Startup: ISDNWatch.lnk = C:\Programme\FRITZ!\IWatch.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show Reboot to normal mode, scan again with Hijack This and post a new log here.   13. Otherwise the backups made when items are fixed won't be secure.

Download DelDomains.inf from here: http://www.mvps.org/winhelp2002/DelDomains.inf Rightclick DelDomains.inf and choose install.

Could someone kindly take a look at my logfile and advise on what I need to do? My name is Satchfan and I would be glad to help you with your computer problem.Please read the following guidelines which will help to make cleaning your machine easier: please follow Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll (file missing) O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" Download FindnFix.exe. 2.

Absence of symptoms does not mean that everything is clear all logs/reports, etc.

In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. http://housecall.trendmicro.com/ http://www.pandasoftware.com/activescan/ http://www.ravantivirus.com/scan/ Allow them to clean/delete any viruses or trojans they may find. Check Turn off System Restore. Click *ok* and let it download and install the updates by clicking on *Finish* .This will return you to the main screen.

Turn off System Restore: On the Desktop, right-click My Computer. The program should start scanning. Make sure it's up to date. The home page is no longer being changed!!!!!!!!!!!! Logfile of HijackThis v1.98.2 Scan saved at 10:08:28 PM, on 8/20/2004 Platform: Windows 2000 SP2 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00

The link did not get the files and I was unable to find it anywhere else. The easiest way to accomplish this is to reinstall and delete any copies of HijackThis.zip you have saved.Please download the self-extracting version of HijackThis from here:HijackThis_sfx downloadSave HijackThis_sfx to your desktop.Double-click

close all open windows AND browsers and check these items for HJT to fix: O4 - HKLM\..\Run: [bullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe This item is considered to be resource hog Install Ad-Aware SE and Spybot S&D and check each of them in turn for updates. Am I clean? Restart and it will delete the peper files.