Edited by IndiGenus, 15 April 2009 - 09:17 AM. please find attached the combofix file, and here is the contents of the HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:54:48, on 16/04/2009 Platform: Windows XP SP2

uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyServer = proxyss.wits.ac.za:80 uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://www.google.com/search?q=%s LSP: imon.dll FF - ProfilePath - c:\documents and settings\Tegan\Application Data\Mozilla\Firefox\Profiles\5of98r9v.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1371996&SearchSource=3&q= c:\documents and settings\Tegan\Application Data\.# c:\documents and settings\Tegan\Application Data\.#\[email protected]@B241F8.### c:\documents and settings\Tegan\Application Data\.#\[email protected]@B24228.### c:\documents and settings\Tegan\Application Data\.#\[email protected]@B24248.### c:\documents and settings\Tegan\Application Data\.#\[email protected]@B24258.### c:\documents and settings\Tegan\Application Data\.#\[email protected]@B241C8.### c:\documents and settings\Tegan\Application Data\.#\[email protected]@B241F8.### c:\documents and settings\Tegan\Application

Once the license has been accepted, reset to 100%.) Or use Firefox with IE-Tab plugin https://addons.mozil...efox/addon/1419 In your next reply post: Kaspersky log New HJT log taken after the above scan When the scan is complete, click OK, then Show Results to view the results.

In order to find out what entries are nasty and what are installed by the user, you need some background information.A logfile is not so easy to analyze. You enjoy a clean, safe computer. Back to top #5 IndiGenus IndiGenus Teacher Emeritus Authentic Member 5,251 posts Interests:Computer Security, Music, Sports Posted 15 April 2009 - 09:17 AM could you possibly let me know what was

Below is her hijack this log, plz help.Logfile of HijackThis v1.98.0Scan saved at 1:18:46 PM, on 29/08/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Sophos\Remote Update\cachemgr.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Sophos

Just press new topic, fill in the needed details and just give a link to your post here & then press the browse button and then navigate to & select the If you need to know how, click Format, un-check Word Wrap.

Animated tutorial http://i275.photobuc...ng/KAS/KAS9.gif (Note.. Even for an advanced computer user.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

The malware was preventing explorer.exe from running at startup. Once the scan is complete, click on View scan report To obtain the report: Click on: Save Report As Next, in the Save as prompt, Save in area, select: Desktop In

If this is an issue or makes it difficult for you -- please tell your helper. 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below.

No items were processed. 3/6/2009 7:55:09 AM:906 Scan Started Scan Type - Intelli-Scan 3/6/2009 8:01:55 AM:312 Scan Finished Scan Type - Intelli-Scan Items Processed - 217767 Threats Detected - 0 Infections Save the above as CFScript.txt 4.

They may otherwise interfere with our tools. Let SCars do it for you. here is the combofix.txt, minus the wordwrap...

If you need help working with these tools, here are some helpful tutorials.Spybot TutorialAdaware Tutorial **********************************************************************Please use one of these free online scans. Thanks in advanced Logfile of HijackThis v1.99.1 Scan saved at 12:58:40 PM, on 5/1/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe