Computer just went bonkers Detective came up suspicious, pls check getting a error when i restart puter System setting protector Error help hijack this help hijack this Browser hijacker?

Have HijackThis fix them.O14 - 'Reset Web Settings' hijackWhat it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:If the URL is not the provider of your computer or your ISP, have HijackThis fix it.

The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those. b56649.cabO16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) - http://games.bigfishgames.com/en_zenerc ... 0.0.10.cabO16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://games.bigfishgames.com/en_dinerd ... 0.0.33.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game09.zylom.com/activex/zylomgamesplayer.cabO16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Be sure to reach Step 5 and post the requested logs in your next reply.

You have word wrap turned on, this is making your logs difficult to read Run notepad Goto Format and untick Word Wrap Now post a new HijackThis log, please.

FirstRunDisabled is set. Hijackthis Download Windows 7 Post the log file in your next reply.Reboot back to normal mode, go to start > run > and type msconfig, click on the Startup tab and untick the Creative MediaSource So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most It will start scanning your computer for files.

We ran hijackthis and deleted files but cannot create a new log...help? List 10 Free Programs for Finding the Largest Files on a Hard Drive Article Why keylogger software should be on your personal radar Get the Most From Your Tech With Our Hijackthis Log Analyzer Windows Internal Firewall is disabled. Hijackthis Windows 7 The HijackThis web site also has a comprehensive listing of sites and forums that can help you out.

The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'Ort'. this content Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htmO8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htmWhat to do:If you don't recognize the name of the Suspect Malware. Next time you reboot you will get a message window pop up asking if you want to revert to the state you were in before you made the changes... Hijackthis Trend Micro

CWS.

Prefix: http://ehttp.cc/?What to do:These are always bad. How To Use Hijackthis

O15 - Unwanted sites in Trusted ZoneWhat it looks like: O15 - Trusted Zone: http://free.aol.comO15 - Trusted Zone: *.coolwebsearch.comO15 - Trusted Zone: *.msn.comWhat to do:Most of the time only AOL and

Desktop icon advertising Hijackthis Log - Exp. If it asks if you would like to do a second pass, allow it to do so.

For the R3 items, always fix them unless it mentions a program you recognize, like Copernic.F0, F1, F2, F3 - Autoloading programs from INI filesWhat it looks like:F0 - system.ini: Shell=Explorer.exe This security permission can be modified using the Component Services administrative tool. -- End of Deckard's System Scanner: finished at 2008-05-10 17:49:31 ------------ Active Scan: ;*********************************************************************************************************************************************************************************** ANALYSIS: 2008-05-10 17:14:54 PROTECTIONS: 1

In the Toolbar List, 'X' means spyware and 'L' means safe.