In fact, quite the opposite. Have HijackThis remove this line: ---> O4 - HKLM\..\Run: C:\WINDOWS\Config\pslib.exe 2. Reboot your computer into Normal Mode and run another HijackThis scan.

Please re-enable javascript to access full functionality. Enter these commands: attrib -h pslib.exe del pslib.exe 4.

Download the latest version here and then make sure you uninstall any older versions from Control Panel>Add/Remove:http://www.java.com/en/download/index.jsp « Last Edit: October 21, 2006, 11:59:19 AM by FreewheelinFrank » Logged Once I was rid of all that, I was still having the problem with certain webpages that I was visiting being redirected, thats when I realized it was DNS HiJacking. I DO have a firewall, I just had to disable it to get something ELSE working.

So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - (no file) O2 - BHO: CATLEvents SO i did that and here it is.Logfile of HijackThis v1.99.1Scan saved at 6:43:14 PM, on 10/20/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Unable to get Internet Explorer version!Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Lavasoft\Ad-Aware SE And I also followed the instructions I found on another forum to run SmitFraud.

Go to your user Temp folder: cd "\Documents and Settings\Kevin\Local Settings\Temp" b. Click the Remove or Change/Remove button. I may not be a computer expert like you guys, but I am by no means a beginner.

Rather, HijackThis looks for the tricks and methods used by malware to infect your system and redirect your browser.Not everything that shows up in the HijackThis logs is bad stuff and It appears you're in a hurry. Using the site is easy and fun. If that's clean I still have some final instructions for you to finalise this process of solving the problems you had.

Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours" 3.

Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours" 3. this content Run HijackThis, click Scan and checkmark the following entries:R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.zpecialoffer.com/indexie.htmlO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.*******************************************Download CCleaner and install it. (default location is best). If there is some abnormality detected on your computer HijackThis will save them into a logfile.

They are a little quirk in HijackThis. 0 Kudos Posted by Kevin247 ‎10-09-2004 05:05 AM Visitor View All Member Since: ‎10-06-2004 Posts: 28 Message 28 of 30 (187 Views) Re: internet Back to top #6 kev25v6 kev25v6 Topic Starter Members 227 posts OFFLINE Gender:Male Location:Clowne, Derbyshire Local time:11:57 PM Posted 27 July 2007 - 04:34 PM I normally run scans by Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't http://pcialliance.org/hijackthis-log/hijackthis-log-ryanair-internet-explorer-not-responding.html It looks like you still have your firewall disabled, please enable it a.s.a.p.

Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htmO8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htmWhat to do:If you don't recognize the name of the Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O3 - Toolbar: Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 -

Please follow these steps to remove older version Java components and update.

Go to Edit - Select All then copy/paste that log back here. Let them know that you have been to this forum and that no malware was found.When posting to any other forum, do not post a HijackThis log or the post will PLEASE HELP ASAP! When the fix completes, close HijackThis.

Javascript You have disabled Javascript in your browser. Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - a. check over here Reboot into normal mode and run another HijackThis scan. 0 Kudos Posted by Kevin247 ‎10-08-2004 09:27 AM Visitor View All Member Since: ‎10-06-2004 Posts: 28 Message 6 of 30 (187 Views)

This folder contained the "keywms.exe" file. Fix these items: ------------------------------------------------------- ---> O2 - BHO: CATLEvents Object - {FD8609EC-7D7C-4778-AB8F-0053245550EF} - C:\DOCUME~1\Kevin\LOCALS~1\Temp\bilsp.dat ---> O4 - HKLM\..\Run: C:\WINDOWS\Config\pslib.exe ---> O4 - HKLM\..\RunOnce: C:\WINDOWS\Config\pslib.exe rerun ------------------------------------------------------- 4. O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1.

I click to fix or delete them and run the scan again but its always the same. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts. Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat In normal mode.

If it asks you to reboot at the end, click NO. You can remove the Prefetch file. Back to top #13 PMS-ING PMS-ING Topic Starter Members 8 posts OFFLINE Local time:07:57 PM Posted 21 February 2007 - 06:04 PM Here's the latest HijackThis log. Thank you!

You might want to clean out files in that "Temp" folder altogether. Go to the folders containing the renamed files and use the del command to delete them. Problem Affecting My Employment As Well Started by PMS-ING , Feb 20 2007 02:05 AM Page 1 of 2 1 2 Next Please log in to reply 15 replies to this In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo!

Post the BitDefender log.Post the OTMoveIt log, the BitDefender log, a new Hijackthis log, and tell me how your computer is running. Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged Do not run it yet.5.