Please welcome our newest member, hhhhh22222. Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). And then I can't access yahoo at all. Copy and Paste that log into your next reply, along with fresh hijacktis log and tell how things are running ?.

Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:27:24 AM, on 11/4/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe And let vundofix do it`s stuff. Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). Join the ClassRoom and learn how.

Oct 20, 2006 #6 ssr2115 TS Rookie Topic Starter sorry for my poor abilities I am sorry but i was tired of this set up and i was ready to throw If there is some abnormality detected on your computer HijackThis will save them into a logfile. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. Oct 21, 2006 #9 howard_hopkinso TS Rookie Posts: 24,177 +19 Download Vundofix from HERE.

Have HJT fix the following, by placing a tick in the little box next to(if there). press the Delete File button (looks like a red circle with a white X). So I did some reasearch and downloaded Spybot and AVG to do some cleaning. C:\Documents and Settings\All Users\Application Data\System Doctor Free (Rogue.SystemDoctor) -> Quarantined and deleted successfully.

Please don`t post your own virus/spyware problems in this thread. If you're not already familiar with forums, watch our Welcome Guide to get started. Reboot your computer normally, start HijackThis and perform a new scan. C:\WINDOWS\System32\wvusr.dll C:\WINDOWS\System32\ldlehth.dll C:\WINDOWS\System32\iwgtff.dll Once your system has rebooted, turn system restore back on and rehide your protected OS files.

Have HJT fix the following, by placing a tick in the little box next to(if there). Close HJT. Please print these directions and then proceed with the following steps in order.Step #1Download CCleaner and install it but do not run it yet.Download Cwshredder.exe and save it to a folder Have HJT fix these inactive entries.

or read our Welcome Guide to learn how to use this site. Look for the following items and click in the checkbox in front of each item to select it:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acjmn.dll/sp.html#28129R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acjmn.dll/sp.html#28129R1 - Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" O4 - HKLM\..\Run: Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Another thing i wanted to ask if maybe I should use Zone Alarm. All other webstes seem to work fine.

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll R3 - URLSearchHook: (no name) - {38E77F06-89FC-44f5-B3AB-11DDEB791947} - C:\Program Files\FrontierSH\SrchHelp\frSrcAs.dll F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: Yahoo!

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Sorry about the delay in responding If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Follow all the instructions exactly. It's 100% free.

C:\Documents and Settings\LEVI\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully. The problem is that I can't use any search engine.