Have a great day, wng (Parts of all clean speech courtesy of Chris RLG) Edited by wng_z3r0, 31 October 2005 - 03:33 PM. This alone can save you a lot of trouble with malware in the future.

I am not sure that there is anything wrong but could do with someone taking a look at this log if poss? In a very basic sense, they are used to locate webpages. Please download VundoFix.exe to C:\ Double-click VundoFix.exe to run it.

For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves. Download it here.

Log looks good how are things? Be sure to visit the browser test link at the end of the article to really see how secure your system is!!

Am particularly curious about the entry 04 iuengine.exe. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts. O7 - Regedit access restricted by AdministratorWhat it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:Always have HijackThis fix this, unless your system administrator has put this restriction into place.O8 - Extra Please go to the windows update site to get the critical updates.

security.' Of course I deleted that, and made sure my Win updates were / are current, and rebooted for them to take effect. You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection.

See this link for a listing of some on line & their stand-alone anti virus programs: Computer Safety On line - List of free Anti virus programs Update your Anti Virus How To Analyze HijackThis Logs C:\WINDOWS\system32\jkhfdax.dll -> Adware.Duncan : Cleaned.

Repost it here, along with some information about the steps you have already taken to clean out the CWS infection. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [EPSON Stylus C44 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 C:\WINDOWS\system32\jkkjifc.dll -> Adware.Duncan : Cleaned.

To see how to set this up as well as more spybot features, see here Spybot can be downloaded at this location Download SpywareBlaster Spyware blaster is a program that stops activex controls are, see here You can download SpywareBlaster here here Download iespyad It puts many bad webpages on your restricted zones list.

Grinler offers an outstanding overview at Virus, Spyware, and Malware Protection and Removal Resources   2 -- To reduce re-infection potential for malware in the future, I strongly recommend installing three

C:\Documents and Settings\Richard Murphy\Cookies\richard [email protected][2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Richard Murphy\Cookies\richard [email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned. ::Report end =============== Logfile of HijackThis v1.99.1 Scan saved at 16:01:28, on 27/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer

If there is some abnormality detected on your computer HijackThis will save them into a logfile. To delete it, fix the line following line in Hijackthis: O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe   Once you have selected all the items for HJT to fix, and remember

