Nope :D
It consists of a registry file that places many known bad sites into the restricted zone. It is often recommended by myself and others here to...
Save this to text where you can access it in safe mode. Some of your security settings have been changed in the registry by the virus. Download...
Looks good. Re-enable System Restore and create a manual restore point. Also recommend you download Spybot Version 1.3 from my signature and...
Sorry about the typo above. :rolleyes: Scan again with HJT and fix the following. O3 - Toolbar: (no name) -...
Fix the following with HJT. O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binari...ESS_1057_XP.cab Open...
Remove the entry. ;) Getting late, so I will respond to the rest hopefully tomorrow evening. Hang in there! :)
Save this to text where you can access it in safe mode. First, create a new folder named HJT in My Documents, then move HijackThis.exe to it....
Thanks for the kind words, and welcome to WindowsBBS David :) Save this to text where you can access it in safe mode. Download...
New one on me too. :confused: Try using Reglite. Select properties if available and you will get a permissions key.
I now see signs of another ugly (new) infection. Please print this out and/or save it to text where you can access it in safe mode. Go here to...
HeHe, you may be right Tony. I figured the cookie.exe is the Cookie Wall program, and I think I've been seeing too much of the Instant Access...
Welcome to WindowsBBS abnewallo:) Download "Registry Search Tool" (RegSrch.vbs) from here http://www.billsway.com/vbspage/ start it and...
Save this to text where you can access it in safe mode. You have HijackThis.exe located in a Temp folder and still unzipped. Both are bad....
Download "Registry Search Tool" (RegSrch.vbs) from here http://www.billsway.com/vbspage/ start it and paste in hxciqpknuz, wait, hit ok. Then...
This one doesn't look good to me. INSTAN~1.EXE 2952 Please download the List Installed Programs script from here, run it and post it's log.
Fix these. R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file) R3 - URLSearchHook: (no name) -...
Hi Martin! :) Suspicious activity and very odd CPU numbers. Lets have a closer look at your processes. Download Process Explorer, unzip and...
Great! Scan again with HJT, close all other windows and fix the following. O4 - HKLM\..\Run: [Preview AdService] C:\Program Files\Preview...
Hold off on any more fixing , please, until you have posted another log from within Windows. It can and may make a big difference.
Separate names with a comma.