Since this issue Pacman's Startup List can help with identifying an item.N1, N2, N3, N4 - Netscape/Mozilla Start & Search pageWhat it looks like:N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C:\Program Files\Netscape\Users\default\prefs.js)N2 - Netscape

Only OnFlow adds a plugin here that you don't want (.ofb).O13 - IE DefaultPrefix hijackWhat it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW.

Remove all it finds.Now open Ewido Security SuiteClick on scannerMake sure the following boxes are checked before scanning:BinderCrypterArchivesClick on Start ScanLet the program scan the machineWhile the scan is in progress

Make sure the autoclean box is checked!Save the scan log and post it along with a new HijackThis Log, log from aboutbuster and the Ewido Log by using Add Reply.Let us

Logfile of HijackThis v1.99.1Scan saved at 4:16:54 PM, on 6/28/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\System32\CTsvcCDA.EXEC:\Program Files\ewido\security suite\ewidoctrl.exeC:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exeC:\WINDOWS\WININIT.INI:qdmgcwRemoved Stream!

In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this. You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection. C:\WINDOWS\sessmgr.setup.log:gfrsrpRemoved Stream!

Note: While searching the web or other forums for your particular infection, you may have read about ComboFix. A logfile is not so easy to analyze.

