C:\Program Files\Windows AdStatus\Click the "Delete File" button which looks like a stop sign.

I hope you had a wonderful weekend also =) Do you know what type of problem those programs could have been? (e.g. General questions, technical, sales and product-related issues submitted through this form will not be answered. On the previous saturday (04/13/08) when I ran the exact same HiJack This! Riceorony, I'm not surprised that HijackThis had problems removing those O23 entries, as this is not uncommon.

And would they have still affected my computer if I didn't disable the services?) Thanks again for the help. log, i've noticed 4 unknown files with O23 (startup) that have their files missing. If you have run any malware removal software (Ad-aware, AVG Antispyware, SuperAntiSpyware…), please reboot before scanning.

  • This looked like a legit window (vs a spyware fake).
  • I have a download link that we can use for the show hidden files step.
  • When it's finished it will reboot your machine to finish the cleaning process.
  • I'm hoping someone can work their magic again.Adware (about:blank, only the best, et al) have taken over my operating system Windows XP.
I have them gone to Control Panel --> Administrative Functions --> Event viewer And found that the 4 programs tried loading on 04/13/2008 but were unable to because "service was an Back to top #13 daveai daveai Members 266 posts OFFLINE Local time:05:54 AM Posted 08 February 2005 - 12:32 AM Okay...stand by...we are discussing the case now daveai "Applying computer

I've been talking this over with a colleague, and we believe you need to replace your explorer.exe file. On startup and logging on, my desktop remains empty, and I can only access programs/files through Windows Task Manager. Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\PGPserv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Mixer.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\RUNDLL32.exe C:\WINDOWS\SM1BG.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Kodak\Kodak http://www.bleepingcomputer.com/forums/t/10649/hijack-this-logaboutblank-etc/page-1 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1097619029609 O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildt...lim/install.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab27513.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v5.cab O16

I'll be away from my infected computer most of today, but will check this forum and PM's periodically. I ran Spybot and spyware before running this log. If you're receiving help online, hijackthis.log contains the info that's required to receive analysis and assistance.

Any more problems? As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged oldsodApril 20th, 2008, 04:26 PMYou are welcome Guru chiaz.

I'll repost the fix with any changes I see. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: Please provide your comments to help us improve this solution.

Thanks. It says 'Safe Mode' in each corner and ' Windows XP' across the top, but there are no desktop icons or startup menu. here's a fresh log. Regarding those entries that you highlighted, Those are definitely 'bad' entries.

Check these three boxes and then press ok to remove: Temporary Files, Temporary Internet Files, Recycle Bin.7 -- This is the step where we will use About:Buster that you had downloaded I try to remove them (2 times) with HiJack This! Open My Computer.Select the Tools menu and click Folder Options.

Trained experts helpers at the HJT forums are always needed. I've have taken a look at your newest HijackThis log, and everything appears to be clean to me. Using the site is easy and fun. Let's do this.

Click on the cwshredder.exe then click "Fix" (Not "Scan only") and let it do it's thing. * Go to Control Panel > Internet Options. TrendMicro uses the data you submit to improve their products. It gave me a notice that it finished. Click the Generate StartupList log button.

Some items are perfectly fine. Apple's Epic Design Fail. The video did not play properly. log riceoronyApril 16th, 2008, 12:52 AMGood morning to all.

Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Computer problem? I look forward to any further advice,Mike[quote]Okay...I'm going to get some other Helpers looking at this problem with me. keyloggers or trojans? That task is certainly part of the infection, but ending it alone will not cure it, since there are other pieces still active.

Now unzip the SpSeHjfix109.zip file to the SpSeHjfix folder you created. To search for a file, click on the Start button..."[quote]Here is a suggestion from ne of the others here:[quote] In Task Manager, have him go to File | New Task (Run...) When it is finished restart your computer. Normally there should be only one.

Every time I went into MSIE, the about:blank would still be there, and a subsequent ad-aware scan would show that CoolWebSearch returned. Best regards. If an entry isn't common, it does NOT mean it's bad. Sorry if there was any confusion.But I have posted a new Hijack This log v1.99, as you requested.I'll be anxiously awaiting your response, to see if we can fix these infections.thanks!tiedyetriguy