bargains.exe wasn't running in safe mode, but when i booted up normal it was there. Nov 10, 2007 Hijackthis LOG FILE HELP ATTACHMENT Oct 23, 2005 You get NO help if you do NOT post HJT as an ATTACHMENT!!!!! Click here to Register a free account now! Attached Files: hijackthis3.txt File size: 6.6 KB Views: 2 champagne supernova, Oct 12, 2004 #14 chaslang MajorGeeks Admin - Master Malware Expert Staff Member champagne supernova said: sorry...

The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. Now click on File and then Save As. champagne supernova, Oct 15, 2004 #46 champagne supernova Private E-2 hey.. chaslang, Oct 16, 2004 #48 champagne supernova Private E-2 ok...

i'll tell you what i did. In Windows Explorer, turn on "Show all files and folders, including hidden and system".

And where it says "Lower Pane View" make sure DLL's is checked. Also Webrebates is still there. did you want me to go back and do one of the things you said + those instructions? Also, I can't promise you we can repair all the damage it caused...

I did, however, find them in Windows Explorer, but it would not let me delete it. O4 - HKLM\..\Run: [sp2update] C:\windows\sp2update00.exe O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be

You can now attach your HJT log without having to rename it as a .txt file. If it is not running, keep Task Manager open and open an Internet Explorer session or Windows Explorer session (whatever is necessary to make it appear in Task Manager). Sometimes it's for the best to backup valued documents, format the machine, and start over.

Make sure you keep track of what happens here we must be sure these files get deleted. Attached Files ComboFix.txt (18.4 KB, 13 views) 01-28-2009, 05:15 PM #12 tetonbob Management Team, Security Center & TSF Academy Expert Analyst, Moderator, Security Team Rangemaster, Moderator, TSF Academy scanning hidden files ... I noticed there were a few more things that you needed to know in order to help.

champagne supernova, Oct 15, 2004 #43 chaslang MajorGeeks Admin - Master Malware Expert Staff Member champagne supernova said: ok... chaslang, Oct 12, 2004 #15 champagne supernova Private E-2 Yes, i checked for it, and somthing sililar, but couldn't find anything champagne supernova, Oct 12, 2004 #16 chaslang MajorGeeks Admin For now we will leave the folder you previously created (C:\Program Files\QoologicFinder ) and we will make a new one. chaslang, Mar 31, 2005 #15 PhilliePhan Guest chaslang said: Hmmm!

O16 - DPF: {FDF6378C-7B5D-4ABF-BA1F-92748305FFAC} (DownloadManagerInstall Control) - http://beta.byteswarm.com/agent/

Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. Any copy-and-pasted logs will be IGNORED and/or REMOVED, as they make for too much clutter in the thread. Have HJT fix the following, by placing a tick in the little box next to(if there).

chaslang, Oct 12, 2004 #21 champagne supernova Private E-2 I ran all the commands, and they succeeded just fine.

Double click on RSIT.exe to run RSIT. i deleted the stuff you told me to and bargains.exe isn't running now, though i'll restart and check again.

bargains.exe is still friggin running and i'm starting to think there's no hope! but since then programs like 'exdl1.exe' and 'bargains.exe' have tried to acces the internet. Here goes. Don't forget to give me all the results.

If a dialog box confirming this action appears, click OK.

Since this is not my laptop, and the owner does not have the install cd's for it. Click on the processes tab and end process for(if there). If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). by checking your notebook's original configuration with your Service Tag (it's actually a packing list of the shipment): http://support.dell.com/support/topi...n&lnki=0&s=gen Service Tag can be found on the bottom panel of your notebook

If there is no firewall or anti-virus and the OP does not have a serious infection. This is why we ask for feedback. Pls. Ask a question and give support.

C:\Program Files\HJT, NOT in Temp and NOT on your Desktop!

Click the "Processes" tab, and then end ALL instances of iexplore.exe and then explorer.exe.

I recommend you ask on forums like BleepingComputer.