I use NOD32 as my anti-virus and Comodo as my firewall. O7 - Regedit access restricted by Administrator What it looks like: O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 What to do: Always have HijackThis fix this, unless your system administrator has put this restriction into place. O8 - Extra

I just dont get it.. What is it ?R1 is for Internet Explorers Search functions and other characteristics. Ha heh. If we have ever helped you in the past, please consider helping us.

The cheapest router will do a fine job of filtering - just as well as the more costlier routers/firewalls. IPsec is more flexible, operating as it does at a lower level in the stack, since it can be used for protecting more traffic (ie, all those above layer 2), because Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value Ban 'em all!

Spybot Search & Destroy also has a memory-resident tool that traps attempts to change the Registry (a typical spyware or adware activity) and asks if you want to allow the changes. etc? Are these the same thing? It seems to belong to a user at the same ISP I use (a local company).

What is left? Please don't send help request via PM, unless I am already helping you. Updater (YahooAUService) - Yahoo! Both also received a thumbs-up from antivirus testing outfits ICSA Labs and Virus Bulletin.Beef Up the BrowserUntil recently, one browser was the same as the next.

E). Using the site is easy and fun. Probably this is the reason why it is not showing as a motherboard port. The F1 items are usually very old programs that are safe, so you should find some more info on the filename to see if it's good or bad.

It is unfortunate there is no router in front of the PC and behind the modem.

See http://www.pccitizen.com/threewayhandshake.htm

See http://www.pccitizen.com/threewayhandshake.htm Second event is: Server: resolver1.opendns.com Address: Name: us.mcafee.com Address: C:\Documents and Settings\SkyRider> O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console

This must be the source, no?Thanks for the effort by the way.Miguel oldsodAugust 27th, 2008, 08:26 PM

In order to find out what entries are nasty and what are installed by the user, you need some background information. A logfile is not so easy to analyze.

Sorry There was an error emailing this page. It is commonplace or not unusual for them. In the device manager - ports it only shows com1 com2 and the printer port.

Oh, and this comes after wmplayer.exe //ICWLaunchWhat's the significance of that if any ? · actions · 2005-Jul-3 9:46 pm · CajunTekInsane CajunPremium Memberjoin:2003-08-08Arlington, TX CajunTek Premium Member 2005-Jul-3 9:51 pm

In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this. Comodo shows 100% Traffic for this (ekrn.exe) every time when internet is connected.

