Hijackthis Log Supplied. Please Help

I'm posting my current HijackThis log in case it is any help: Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 8:37:35 AM, on 5/19/2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) Windows automated pages says I have a virus or malware! At least it has for me. justkidzmom, Apr 16, 2004 #9 ~Candy~ Retired Administrator Joined: Jan 27, 2001 Messages: 103,706 Probably different, but have a look. ~Candy~, Apr 16, 2004 #10 justkidzmom Thread Starter Joined: Apr check over here

The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them

Advertisements do not imply our endorsement of that product or service. I I looked for the files in the location listed, including hidden files, and can't find them anywhere so I believe they have been removed by the scanners. button.

Attached is my HijackThis log: Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 9:02:19 AM, on 5/18/2015 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17801) FIREFOX: 37.0.2 m 0 l Can't find your answer ? I tried starting it in safe mode and it would go to the windows screen and freeze. In his role managing the content for a site that has over 600,000 page views per month and a weekly newsletter with 25,000 subscribers, Tony has learned how to talk to

Please Help Started by jackiron , Nov 07 2007 08:05 PM

I have to log off and play domestic goddess, but others may have other ideas for you, but in my opinion, that would be the first thing I'd check

In this panel click the Save list button. I've run the scans you instructed, the logs are as below. ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Saturday, December 08, 2007 8:27:26 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 justkidzmom, Apr 16, 2004 #11 ~Candy~ Retired Administrator Joined: Jan 27, 2001 Messages: 103,706 First off, are the cpus the same? More about : virus hijackthis log enclosed Lag May 18, 2015 6:13:04 AM You need to install a program called hitmanpro.

Thought I would supply the Hijack This log to see if anyone could find anything suspicious. Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8

If we have ever helped you in the past, please consider helping us. check my blog That will get us started. Please note that many features won't work unless you enable it. I restart the computer outside of safe mode again, and the browsers are STILL hijacked.

Several functions may not work. This morning it was all froze up again so I turned the thing off and re-booted. O20 - AppInit_DLLs: c:\programdata\flashbeat\flashbeat32.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - http://exomatik.net/hijackthis-log/hijackthis-log-aky.php Please help.

The only thing Hitman Pro comes up with consistently is YTdownloader, which gives two entries. Why is in a root directory called Empty? danoo94, Sep 1, 2016, in forum: Virus & Other Malware Removal Replies: 1 Views: 374 dbreeze Sep 3, 2016 New help with hijackthis logs markythesparky, Aug 17, 2016, in forum: Virus

I did not try HitmanPro yesterday, but I've downloaded it this morning and after I re-run MalwareBytes I'm going to follow up with HitmanPro for the "2nd opinion" they advertise it

I cant afford to buy another. I remove them, one needs to be rebooted for removal, and it shows up again. Tech Support Guy is completely free -- paid for by advertisers and donations. have a peek at these guys Dominoes - http://download.games.yahoo.com/games/clients/y/dot4_x.cab justkidzmom, Apr 15, 2004 #1 Sponsor Dingenium Joined: Apr 14, 2004 Messages: 105 The line: C:\EMPTY\AIM.EXE Shouldn't this be in the Program Files\AIM\ directory?

Shut it down and re-booted it about 30 (yes...30) times getting different messages every time. I stopped two processes on startup: YTdownloader and WindeskWinsearch. then Misc Tools if its open on the scan Window) Then click the Open Uninstall Manager... Pinochle - http://download.games.yahoo.com/games/clients/y/ut2_x.cab O16 - DPF: Yahoo!

adwcleaner seems to have taken care of it! In order to find out what entries are nasty and what are installed by the user, you need some background information.A logfile is not so easy to analyze. Got anti virus software?

Please remember...this is a real ssstttrrreeetttccchhh for me, touching the guts of this darn thing! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quietO4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Stay logged in Sign up now! Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More...

And as suggested, run it safe mode to ensure that you get rid of it all. Then I re-booted and it had to go through the scandisk process again...geeze...what a pain! Messenger (HKLM) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38020.777337963 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab O16 - From then it was ALL downhill.