Possible Trojan Horse.Here's Hijackthis Scan.Please Help!

What do I do?

Please read ComboFix's Disclaimer. Should I rescan and post the new one?

How do I get help? Save it to your desktop.Double click on the icon on your desktop.Check Click the button.Accept any security warnings from your browser.Under scan settings, check and check Remove found threats Click Advanced roblem with certain keys not working Question: Will help2go update firewall/antivrus list? Right-click on the file, choose Properties and examine the General and Version tabs.Lets investigate your system further.

Please describe any problem(s) in detail as they could provide a clue as to whether your issues are malware related or not. If an application does not behave as it should then discard the changes and restart the process with a new mirror file. ComboFix 11-11-27.02 - Administrator 11/27/2011 20:09:26.1.2 - x86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1216 [GMT -6:00]Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exeAV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\documents and settings\Administrator\g2ax_customer_downloadhelper_win32_x86.exec:\documents The free version is limited to basic on-demand scanning and malware removal.

  1. This article aims to give you a general overview on how a trojan infects you as well as hints and techniques on manually removing a trojan infection.
  2. IMPORTANT NOTE: I do not recommend the routine use of registry cleaners/optimizers for several reasons: • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning
  3. Place a check against each of the following:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.htmlR0 -

We need a deeper look. One of SUPERAntiSpyware's strongest selling points is its high level of compatibility with other protection tools like Avira, Kaspersky, Symantec, and McAfee.

You can use msconfig and manage startup items to do so.

I installed and ran Spybot to see if that would help, no luck. Try to find the nomenclature various antivirus products use to refer to the type of infection you have on your computer. Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... More about the author It will save you a lot of trouble: Update the antivirus to the latest version, and update the virus signature database.

If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members. How are things running now? The Anti-Malware installation includes another application from Malwarebytes called FileASSASSIN—a helpful tool for deleting files locked by Windows.HijackThis (Windows, Freeware) HijackThis stands alone in this Hive Five as being the least

However, it then places itself in a different location (folder) than where the legitimate file resides and runs from there.

HijackThis does not delete them. Is AVG missing something? Turn it back on.

Before you go and disable software it is important to find out exactly what it does first. Discussion in 'Virus & Other Malware Removal' started by Scrolly21, Dec 7, 2004. There are a number of them available but they do not all work entirely the same way.

They are volunteers who will help you out as soon as possible. Start a full scan with this software, it'll detect the Trojan and remove it. Best Malware Removal Tool? Some services are harder to disable then others.

Use your arrow keys to move to "Safe Mode" and press your Enter key.* Start HijackThis, close all open windows leaving only HijackThis running.

Back to top #4 howlymowly howlymowly Topic Starter Members 10 posts OFFLINE Local time:03:53 AM Posted 14 January 2007 - 05:05 PM [combofix log continued](((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. A rootkit scan is required2007-01-14 12:08 -------- d-------- C:\Program Files\mozilla firefox2007-01-13 18:22 -------- d-------- C:\Program Files\quicktime2007-01-13 04:01 -------- d-------- C:\Program Files\Common Files\wise installation wizard2007-01-13 03:29 -------- d-------- C:\Program Files\web photo etc The utility prompts the user to select an action to apply to suspicious objects (Skip, by default).