Make sure your Internet Explorer is closed when you click Fix Checked! Extract all the files to your Destop.

I didn't get anything back yet. Agree with above; also remove the following if you can't identify them. Style Default Style Contact Us Help Home Top RSS Terms and Rules Copyright © TechGuy, Inc. Kind of a big mess.Any help would be greatly appreciate.Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\TGTSoft\StyleXP\StyleXPService.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\DRIVERS\dcfssvc.exeC:\mysql\bin\mysqld-nt.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\wdfmgr.exeC:\WINDOWS\System32\MsPMSPSv.exeC:\WINDOWS\System32\svchost.exeC:\syswin32.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\System32\alg.exeC:\Program Files\lctt\pesr.exeC:\WINDOWS\seeve.exeC:\WINDOWS\system32\nsvsvc\nsvsvc.exec:\windows\system32\bkqsma.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\explorer.exeC:\unzipped\hijackthis[1]\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/gmailR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = - URLSearchHook:

But not giving up. if a movie is packaged in a .exe file, NEVER open itif the file was an .avi or .mkv, ect you shouldn`t of had a problem.maybe try a disk cleanup and then disk defrag just to see if it helps.my suggestion if you`re going to download movies, find a

Login on your usual account. Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.

C:\Documents and Settings\Navid\Desktop\test folder\PCOVXL0T\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Navid\Desktop\test folder\Local Settings\Temporary Internet Files\Content.IE5\SXQ70TIV\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).

Logfile of Trend Micro HijackThis v2.0.4Scan saved at 16:59:54, on 05/08/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\Program Files\Intel\Wireless\Bin\WLKeeper.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir Desktop\sched.exeC:\Program Files\Common Files\Apple\Mobile Device
C:\Documents and Settings\Navid\Desktop\test folder\Temporary Internet Files\Content.IE5\PCOVXL0T\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
Wait until you see the Update succesfull message.
Click on the Programs tab then click the Reset Web Settings button.

