If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

If normal mode still doesn't work, run BOTH tools from safe mode. Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it.O1 - Hostsfile redirectionsWhat it looks like:O1 - Hosts: - Hosts: If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it.

Do not change any settings unless otherwise told to do so.

  1. ByTiffanieMarie Feb 7, 2011 Page 1 of 2 1 2 Next > I am having serious issues with slow internet on my laptop and was wondering if you would be so
  2. I've exhausted many resources already and it seems like I need to just be able to figure out where the virus is hiding and delete it manually.
  3. Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {13143C48-BD13-4E54-840A-CD979952CD1f} - (no file)O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890}
  4. Here's the Answer Article Wireshark Network Protocol Analyzer Article What Are the Differences Between Adware and Spyware?
  5. The second part of the line is the owner of the file at the end, as seen in the file's properties.Note that fixing an O23 item will only stop the service
  6. The scan won't take long.
  7. It has done this 1 time(s). 2/12/2011 5:37:58 AM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly.

txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation) txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation) txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation) vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1

Cam Manager\CTLCMgr.exeC:\WINDOWS\SysWOW64\ctfmon.exeC:\Program Files (x86)\Adobe\Acrobat 6.0\Distillr\acrotray.exeC:\Program Files (x86)\WinZip\WZQKPICK.EXEC:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exeC:\WINDOWS\stsystra.exeC:\Program Files (x86)\Java\jre6\bin\jusched.exeC:\Program Files (x86)\ 3\program\soffice.exeC:\Documents and Settings\tloughlin\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exeC:\Program Files (x86)\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exeC:\Program Files (x86)\ 3\program\soffice.binC:\Program Files (x86)\Roxio\Roxio DVDMax Hijackthis Download Please post the contents of both OTL.txt and Extras.txt files in your next reply. Messenger Yahoo! Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account?

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Hijackthis Download Windows 7 Run Combofix from Safe Mode. 2. Here is a recent log in its entirety.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:10:21 PM, on 3/23/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16608)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Feb 12, 2011 #4 TiffanieMarie TS Rookie Topic Starter Posts: 46 Malwarebyte's Log Malwarebytes' Anti-Malware Database version: 5747 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/12/2011 6:01:14 AM

I have been having an issue where all of my google results links are getting redirected so I am dying to get this off my machine. Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves.

When finished, it will produce a report for you. If Combofix asks you to install Recovery Console, please allow it.

Have HijackThis fix them.O14 - 'Reset Web Settings' hijackWhat it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:If the URL is not the provider of your computer or your ISP, have It has done this 1 time(s). 2/12/2011 5:37:57 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly.

Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {13143C48-BD13-4E54-840A-CD979952CD1f} - (no file)O2 - BHO: Spybot-S&D IE Protection

If one of them won't run then download and try to run the other one.

Chat - - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - to do:If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis fix In the last case, have HijackThis fix it.O19 - User style sheet hijackWhat it looks like: O19 - User style sheet: c:\WINDOWS\Java\my.css What to do:In the case of a browser slowdown

Note Do not mouseclick combofix's window or do anything else on your pc while it's running. Feb 12, 2011 #12 TiffanieMarie TS Rookie Topic Starter Posts: 46 MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.

Logfile of HijackThis v1.98.2 Scan saved at 2:23:57 PM, on 1/4/2005 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA

htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If yours is not listed and you don't know how to disable it, please ask. I am somewhat tech savvy and have tried chkdsk and defragmenting but IE still runs slow.

That may cause the program/system to freeze/hang.