Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [ATIPTA] "D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" Basically, this prevents your coputer from connecting to those sites by redirecting them to which is your local computer

This .dll file can be injected to all running processes and can change or manipulate their behavior. Some of these pop ups include: WinAntiVirus Pro 2000 Drivecleaner Movietickets Amongst many other things which I can't remember off the top of my head. Because the uninstaller automatically creates a backup, there is no risk of anything going wrong.

Name the folder HJT 4. Please do a scan with ESET Online Scanner Note: The scan will only work with Internet Explorer Once you are on the ESET site, check the box "Yes, I accept the Select: * Delete on Reboot * then Click on the All Files button.*(or on the folders option)* * Please copy the file paths below to the clipboard by highlighting ALL of In the Applications Tab: Clean all (optionally, except cookies) in the Firefox/Mozilla section if you use it.

  1. It requires you to manually reboot to restore your normal windows desktop.
  2. Firefox now looks brand new.
  3. Taskbar virus Alert!!
  5. Without regular updates you WILL NOT be protected when new malicious programs are released.

Any help would be greatly appreciated. Please!! Click the Windows Start Button. I do however have all the other required attachments.

over 20. Description: PfuSsOrgOcrHook.dll is not essential for Windows and will often cause problems. By the way, when I ran spybot S&D it smitfraud kept coming up, as well as some Win32agent alert. Download, install and run Windows Defender, Ad-Aware, Spybot S&D and SpywareBlaster in Safe Mode available HERE .

We now suspect that a system is more prone to a Vundo infection when the Java application has not been updated: Please update your Java and Clear the Java Cache

We use cookies to ensure that we give you the best experience on our website. More about the author Boot into Safe Mode How to use the F8 method to Start Your Computer in Safe Mode*Restart the computer. *as soon as BIOS is loaded begin tapping the F8 key until If you have additional information about this file, please leave a comment or a suggestion for other users. Right click in an empty space on your desktop. 2.

Click the SCAN button to produce a log. Now, run the program and post a fresh HJT log for review. Bookmarks and saved passwords are retained, but all browser extensions and their related data are deleted [1]. http://nuvisiongraphx.com/pls-help/pls-help-with-hijack-log-file.html Logfile of HijackThis v1.99.1 Scan saved at 7:48:38 PM, on 9/3/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\csrss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\Ati2evxx.exe

BHOs are often used by adware and spyware. REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "huhzjak.dll"=- "DllRunning"=- [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcc] [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe] [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhoo32] [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxyyayx] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Hidden"=dword:00000001 "SuperHidden"=dword:00000001 "ShowSuperHidden"=dword:00000001 "HideFileExt"=dword:00000000Click to expand... A tutorial on installing & using this product can be found here: Using SpywareBlaster to protect your computer from Spyware and Malware Update all these programs regularly - Make sure you

Reboot Your System Finally, RUN Hijackthis again and produce a new HJT log.

Then after it deletes the files click the Exit (Save Settings) button. Now attach new logs for: * GetRunKey * ShowNew * HJT TimW, Feb 22, 2007 #3 D Lo Private E-2 Update: I did exactly as you posted though when I This is especially effective when it comes to older computers that have accumulated vast quantities of "garbage data" as the result of many software installs and uninstalls. news Copy about:support into your Firefox browser's address bar.

tryed in save mode cant delete dll tryed VirtumundoBeGone and VundoFix still there please help doing my head in.. close the program Download and install: http://www.filehippo.com/download_ccleaner/ For a basic version of CCleaner with no Yahoo Toolbar, select the second or third install option as follows: Even if you selected Option to remove C:\Program Files\VSAdd-in I couldn't find it, so I just opened up C:|Program Files and deleted it myself. For Technical Support, double-click the e-mail address located at the bottom of each menu. 3.

Always remember to perform periodic backups, or at least to set restore points. U Guys Are The Best.....Thank You SOOOOO MUCH!!!!!!!!!!!!!!!! Why not be the first to write a short comment? This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.

thanks for the help!! just downloaded ZeroSpyware will try that any idears?? TimW, Feb 23, 2007 #7 D Lo Private E-2 Ok, when I tried to use Your Installer! Thank you so very much for the help!

Logs as follows - Vundofixlog: VundoFix V4.2.69 Running as SYSTEM from c:\windows\system32\VundoFix.exe Checking Java version...