Mail {5464D816-CF16-4784-B9F3-75C0DB52B499} = D:\PROGRA~1\Yahoo!\Common\ymmapi.dll HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a 2a9545d-a0c2-42b4-9708-a0b2badd77c8} Start Menu Pin = %SystemRoot%\system32\SHELL32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex \ContextMenuHandlers] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex \ContextMenuHandlers\WinRAR {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shel lex\ContextMenuHandlers] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shel lex\ContextMenuHandlers\EncryptionMenu {A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shel lex\ContextMenuHandlers\Offline Files {750fdf0e-2a26-11d1-a3ea-080036587f03} =

Rerun HJT,and put a checkmark beside these :- O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\jkhfg.dll (file missing) O4 - HKLM\..\Run: Download CCLEANER then run the scan under the windows tab. then DEFRAG your C:\ drive.

o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click

Use your up arrow key to highlight Safe Mode then hit enter.[*]Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat[*]You will first be presented with a warning. These are safe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run:

Trojan-conhook driving me nuts Please print these instructions out for use in Safe Mode.

Here's the Hijackthis log: (by the way im a noob with this program) ************************************************** ****** Logfile of HijackThis v1.99.1 Scan saved at 4:20:38 PM, on 8/24/2007 Platform: Unknown Windows (WinNT 6.00.1904) All submitted content is subject to our Terms of Use. Then press the red button with a white X in it. Restart in SAFE MODE From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan" This program will scan large amounts of files on your computer for known patterns so please be

Trojan-conhook driving me nuts can you post a HJT log generated in NORMAL MODE.

It may ask you to reboot at the end, click NO. weblink Page 1 of 2 1 2 > Thread Tools Search this Thread Display Modes #1 18-11-05, 05:11 Damon2 Newbie Join Date: Nov 2005 Posts: 6 Need help Click here to Register a free account now! I restarted but its still the same. 50%. 1 core used fully.

Click YES When it asks if you would like to Reboot now, click YES If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart

Logfile of HijackThis v1.99.1 Scan saved at 10:04:23 PM, on 17/11/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next by double-clicking the icon on your desktop (or from the Start > All Programs menu). his comment is here when HJT is run in safe mode it tells us nothing. __________________ PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Not a good idea telling us you've been using keygens to bypass paying for something. Trojan-conhook driving me nuts WARNING: not all files found by this scanner are bad. and i've never used one before...obviously since i'd know they gave u viruses:P lol. All Users[/list]Click OK Press the CleanUp!

This site is completely free -- paid for by advertisers and donations. Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Yahoo! http://www.bulletproofsoft.com/spy-download.html Styxx, Jul 5, 2004 #3 Flrman1 Joined: Jul 26, 2002 Messages: 46,329 These don't need to be fixed: O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHELPER.DLL O3 - Maybe i'll have to format and re-install windows... 25-08-2007,10:46 PM #9 apsattv View Profile View Forum Posts Private Message Senior Member Join Date Jan 2007 Posts 798 Re: Help With Hijackthis

I've got a E6850 @ 3.5Ghz so its not destroying my performace but it's driving me nuts and it can't be good for the cpu. Windows somethimes displays this message due to the high volume of disk I/O. To start viewing messages, select the forum that you want to visit from the selection below. click on "create new restore point" click on NEXT and follow the prompts. this is to ensure that if you have to do a system restore in the future that you

