This seems to have started after updating from AGV 6 to 7. Edited by Demon, 08 November 2004 - 12:04 AM. Only OnFlow adds a plugin here that you don't want (.ofb).O13 - IE DefaultPrefix hijackWhat it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW. The same goes for the 'SearchList' entries.

Boot into safe mode and use Windows Explorer to delete: C:\Program Files\ClockSync <--- the whole folder If you get an error when deleting a file. In order to find out what entries are nasty and what are installed by the user, you need some background information.A logfile is not so easy to analyze. Tried to read as much as I could before doing this. Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabWhat to do:If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis fix

I've followed a bunch of different instructions but still can't get it out. Always fix this item, or have CWShredder repair it automatically.O2 - Browser Helper ObjectsWhat it looks like:O2 - BHO: Yahoo! Wait again until ready. So obviously I'm getting random popups every few minutes which is death when your playing an FPS.

the CLSID has been changed) by spyware. Make sure you follow the directions on installing it and running it. Ask a question and give support. Thanks!!

Empty all internet temp folders, and cookies. Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't

How to post your Hijackthis log-file as an ATTACHMENT. Yes, my password is: Forgot your password? As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged Here's my log:Logfile of HijackThis v1.97.7Scan saved at 8:38:17 PM, on 11/7/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXEC:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exeC:\Program Files\RealVNC\VNC4\WinVNC4.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program

In the Toolbar List, 'X' means spyware and 'L' means safe. Similar Topics Need help destroying websearchtv popups - HJT log attached Dec 29, 2005 Need to remove "websearchtv" Jan 7, 2006 Need help with Websearchtv Jan 14, 2006 Angels & Demons You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection. However nothing seems to rid me of Dealhelper, whatever that is.

