An Rkill.log will appear.

After reviewing your log I see a few items that require our attention.

Close SpySweeper. I posted first! I am a paying customer just like you! please help, thank you.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.Then please restart it into Normal Windows.

NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo!

The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'Ort'.

Reboot you computer, and ensure Spy Sweeper is disabled.After all of the fixes are complete it is very important that you enable SpySweeper again.Disable Spyware Doctor: Please disable Spyware Doctor

Type Y to begin the cleanup process. Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing.

I am an XFINITY Forum Expert and I am here to help.We ask that you post publicly so people with similar questions may benefit.Was your question answered? He & I went thru the threats & removed what was a threat. please view it here: http://img127.imagevenue.com/img.php..._122_889lo.jpg Would really appreciate help in analysing this logfile, thank you. TANSTAAFL!!I am not a Comcast employee, I am a paying customer just like you!I am an XFINITY Forum Expert and I am here to help.

I do this for a living, and I don't have anything saying I belong to who ever. scanning hidden autostart entries ... If you were using Bitdefender, then I would know exactly how to proceed because that is what I have personally used for years.

Turn off system Restore First - Important, because when you reboot it will automatically reinfect. • On the Desktop, right-click My Computer. • Click Properties. • Click the System Restore tab. Uncheck Run at Windows startup.

Restart the computer when done.Submit a fresh Hijackhis log. Uncheck home page shield.

Logfile of HijackThis v1.99.1 Scan saved at 3:43:44 PM, on 10/8/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Spyware removal software such as Adaware or Spybot S&D do a good job of detecting and removing most spyware programs, but some spyware and browser hijackers are too insidious for even

Most are notoriously difficult to completely uninstall. Is there an option to "clean"? Just a n update to the comments above - That virus is a real nasty to remove, it loads LOOOOOOTS of variants - you need to use a good AV to Please re-enable javascript to access full functionality.

For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat

O23 - Service: avast! The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those. Please print these directions and then proceed with the following steps in order.Step #1Download Cwshredder.exe and save it to a folder of its own.

SDfix and combofix are not the full answer - personally I have found they miss LOTS and are only a small part of whats required to clean out the PC.