When download is complete, click on Local Disks to start the scan.

Click on the Scan button. Here's my Hijackthis log :Logfile of HijackThis v1.99.1Scan saved at 9:47:14 AM, on 6/5/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16441)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully. Do you think I should go with AVG for virus protection instead of Avast!?

It should look like this: Double-click on it and when it asks you if you want to merge the contents to the registry, click Yes/OK. Any help would be appreciated. C:\Program Files\rhcp87j0e74v\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.

Press "Restore Microsofts Original Hosts File" 4. C:\Documents and Settings\Austin\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button.

I thought it was totally fixed.. about.blank hijack Discussion in 'Virus & Other Malware Removal' started by efbailey, Nov 9, 2004. Web Companion is usually rather good at preventing browser hijackers as Omniboxes.

C:\Documents and Settings\Dad.AUSTIN-N-BAILEY\Application Data\rhcp87j0e74v\Quarantine\Autorun\StartMenuCurr entUser (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{70f6a776-579a-4c95-ba88-134253907752} (Trojan.BHO) -> Quarantined and deleted successfully.

I'm not getting the 100% cpu at start up now. My computers been so slow lately.. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL

C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Click on OK. File name Size Date Time MD5 Hash ________________________________________________________________________ KBDL.333 57344 06-12-104 10:25 c185b36f9969d3a6d2122ba7cbc02249 CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk C:\FINDNFIX\JUNKXXX KBDL.333 : crc16=3138 crc32=D5C9FB2E File: CRC-32 : D5C9FB2E MD5 Total of file sizes: 8,192 bytes 8.00 K

These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.If your computer was used for online banking or has credit

C:\Program Files\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. The filters provided and registry scan should match the corresponding file(s) listed.

Please let me know what to clean out to get me going.

What do you make of it? Status: Deleted Cookies detected c:\documents and settings\banks\cookies\[email protected][1].txt CoolOnlineOffers.ScreenSaver Adware Bundler more information... and click on the CleanUp!

It will take around an hour to do, and I don't want to spend an hour doing something wrong. KBDL.DLL .....57344 12.06.2004

HKEY_CLASSES_ROOT\Interface\{2da07fee-0ffd-4a5b-aa82-4a94500ab7bc} (Trojan.BHO) -> Quarantined and deleted successfully.