Zone and Neopets lock up when I click anywhere. That log looks clean (and much better without all those toolbars.. N2 corresponds to the Netscape 6's Startup Page and default search page. N3 corresponds to Netscape 7' Startup Page and default search page. have a peek at this web-site

An example of a legitimate program that you may find here is the Google Toolbar. In the box that opens type in remservice.bat for the file name. Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 So I can't even "Run" to get to edit registry, which I have read in a few links.

The default program for this key is C:\windows\system32\userinit.exe.

Unlike the RunServices keys, when a program is launched from the RunServicesOnce key its entry will be removed from the Registry so it does not run again on subsequent logons. When Internet Explorer is started, these programs will be loaded as well to provide extra functionality. List 10 Free Programs for Finding the Largest Files on a Hard Drive Article Why keylogger software should be on your personal radar Get the Most From Your Tech With Our Hijackthis Windows 10 Click on Edit and then Copy, which will copy all the selected text into your clipboard.

If you need to remove this file, it is recommended that you reboot into safe mode and delete the file there. Hijackthis Download If not please perform the following steps below so we can have a look at the current condition of your machine. If it's a desktop Too much junk on it. check it out When something is obfuscated that means that it is being made difficult to perceive or understand.

AssertNull here. Hijackthis Windows 7 When you fix these types of entries, HijackThis will not delete the offending file listed. If the Hosts file is located in a location that is not the default for your operating system, see table above, then you should have HijackThis fix this as it is Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exeO9 - Extra 'Tools' menuitem: Yahoo!

This will make both programs launch when you log in and is a common place for trojans, hijackers, and spyware to launch from. We advise this because the other user's processes may conflict with the fixes we are having the user run. Hijackthis Log Analyzer This location, for the newer versions of Windows, are C:\Documents and Settings\All Users\Start Menu\Programs\Startup or under C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup in Vista. Hijackthis Trend Micro Also ran PCDoctor just in case.

The CLSID in the listing refer to registry entries that contain information about the Browser Helper Objects or Toolbars. Check This Out Temp/Temporary folders are just that- Temporary. There is only one set of entries in your log which need to be fixed, but they won't be cause of the problems you describe. My name is fireman4it and I will be helping you with your Malware problem. Hijackthis Download Windows 7

Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:15:38, on 01/03/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running

You can update more if you wish to use a customized hosts file, but if you do not want to "lose" time updating and checking your Hosts file on a daily You can generally delete these entries, but you should consult Google and the sites listed below. These are the toolbars that are underneath your navigation bar and menu in Internet Explorer. Hijackthis Portable HiJack spotted the problem (with the 015 errors), but could not fix it (I think it wants to edit the key values, not insert the keys).

You can read a tutorial on how to use CWShredder here: How to remove CoolWebSearch with CoolWeb Shredder If CWShredder does not find and fix the problem, you should always let remove all the toolbars you have.. This would have a value of http=4 and any future IP addresses added to the restricted sites will be placed in that key. have a peek here In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo!

News: Home Help Search Login Register The Comodo Forum > Learn about Computer Security and Interact with Security Experts > Virus/Malware Removal Assistance > Hijack Log help please Print Pages: [1] Logfile of HijackThis v1.99.0 You are using an older version of HJT. HijackThis has a built in tool that will allow you to do this.