Malwarebytes.com Malwarebytes Remove all the files and sub-folders from the below TEMP Folders: C:\Documents and Settings\ \Local Settings\Temp C:\temp C:\windows\temp The TIF ( Temporary Internet Files) can also be emptied via: Internet Explorer--Tools--Internet Open hijackthis, click on open misc tools section, click on open uninstall manager, click on save list and save it.

The combofix icon will look like this when it has downloaded to your desktop. ByFukurou Apr 24, 2006 My Girlfriend's computr she claims has been running slow, I warned her about Warez but... Full Review Samsung Magician 5.0 Reviewed by AlphaC I don't know why Samsung would ever do this, but they made an application that has fewer features just for a more Remove formatting × Your link has been automatically embedded.

Boot into safe mode. HijackThis logfile to look at. If it finds anything that it cannot clean have it delete it or make a note of the file location so you can delete it yourself. I put it on my desktop but just relized that (unless im confused with ANOTHER program) I should be in it's own location under the C Drive.

Anyway, please tell us what looks bad from our Hijackthis log to get rid of: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 7:42:25 PM, on 11/24/2012 Platform: Windows XP Your cache administrator is webmaster. Once these two steps have been completed, double-click on the ComboFix icon found on your desktop. An example of this can be seen below.

C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s C:\DOCUME~1\Owner\LOCALS~1\Temp\2005810205444_mcinfo.exe /insfin ShowWnd.exe C:\Program Files\NewDotNet\newdotnet7_22.dll Reboot into normal mode and turn system restore back on. Mail Scanner - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe O23 - Service: avast! Maybe I could persuade her to junk it and just sign into the website like I do. WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn . - - End Of File -

I went ahead and got a Hijackthis log: Quote: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:30:09 PM, on 1/11/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer I removed it Via Add/Remove Programs. Most things are harmless and needed so don't make any changes. Download and Run ComboFix If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Also rerun hijackthis and place checks next to the following entries. More about the author uStart Page = hxxp://search.babylon.com/?affID=114066&tt=3612_6&babsrc=HP_ss&mntrId=94c8a1c6000000000000000f1f475c0c uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 TCP: DhcpNameServer = DPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF} - hxxp://admin-dev.mhi.aol.com/netagent/objects/custappx2.CAB DPF: {AFDD01B0-7ABB-11D9-9669-0800200C9A66} - hxxp://c.ancestry.com/MFInstall/MFInstall.cab FF - ProfilePath - c:\documents and settings\*******\Application Data\Mozilla\Firefox\Profiles\se21gico.default\ FF - prefs.js: browser.search.selectedEngine Antivirus - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe O23 - Service: avast! Save the file to your windows desktop.

Last edited: Nov 27, 2012 Methos' Morals, Nov 27, 2012 #6 Methos' Morals New Member Messages: 37 Okay: ComboFix: ComboFix 12-11-26.02 - ******* 11/26/2012 22:44:05.1.1 - x86 Microsoft Windows XP Home Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended. Make sure you click the "Fix" button Next Download Ad-Aware SE Use the: "Check for Updates Now" option and download the latest reference files Use the Start button, and on the check my blog Generated Wed, 25 Jan 2017 01:59:08 GMT by s_wx1077 (squid/3.5.23)

Yes, my password is: Forgot your password? Contents of the 'Scheduled Tasks' folder . 2012-11-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-24 15:43] . 2012-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-05-27 02:38] . 2012-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-05-27 We'd like to nip the problem in the bud here.

Methos' Morals, Nov 25, 2012 #1 Methos' Morals New Member Messages: 37 I should also add that we had some sort of email virus(?) that got us kicked off of numerous

Slots Special Edition Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 You may also... Mojo I'm no pro with HijackThis, but I don't see anything abnormal up there. Apr 25, 2006 #11 (You must log in or sign up to reply here.) Show Ignored Content Topic Status: Not open for further replies.

Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users. This procedure can take some time, so please be patient. Regards Howard Apr 25, 2006 #8 Fukurou TS Rookie Topic Starter Posts: 51 Last question before I leave, Does it matter where I placed Hijackthis? http://exomatik.net/hjt-log/hjt-log-from-slower-computer.php Sorry.