Logfile of HijackThis v1.99.1 Scan saved at 02:30:04, on 18/07/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe

Yes No Sorry, something has gone wrong. Another one is name terminator.exe. Vide la quarantaine d a-squarred Free. That may cause it to stall. Post back with the log from ComboFix and a new HJT log please. __________________ PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST

Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection - Voir les règles du forum : http://www.malwarecomplaints.info/viewtopic.php?t=5 it's got to the point though where i desperately need help from an expert in anaylising hjt logs and advising what else i can try to shift this. La tienne = SmitFraud ; Vundo ; Lop ; Mywebsearch; HotBar ---> http://www.malwarecomplaints.info/viewforum.php?f=10 Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas Virus Cleaner Tool - version 1.0.211 UnicodeCreating log file: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\JTO8BLGJ\aswclnr[1].log9/23/2008, 6:29:00 PMMemory scanning started...No virus body found in memory.Memory scanning finished (74.1s).----------Files scanning started...C:\Documents and Settings\Owner\Local

hi firstly thanks for helping. I checked the url that you sent about hsperfdata_Owner. I really appreciate it. before iv'e had a chance to do anything though the egg timer starts going and it by passes and go's straight back into normal mode.

I do like their search engine and am always using it to look up computer related info. There are about 3 or 4 filenames from them picked up by scanners. Those are normalQuoteC:\Documents and Settings\Owner\Local Settings\Temp\hsperfdata_Owner\3716... There's a little arrow (dropdown-arrow) next to that field.

I have run a boot scan with Avast and it does not show anything, however when I ran a thorough scan including the archives, it showed up in the restore sector.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report * Click Save report *

On the question how to interpret Kaspersky's warning it has found RiskTool.Win32.PsKill.p please read this thread: SysInternals (Microsoft) PsKill. And Windows does not depend on "killwind.exe" or "pskill.exe" in order to function properly.

Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? Must say I'm a bit puzzled. where is it hiding if i quantine it, it reappears, as far as i know i have no need for it and the only part of my system that hasnt been this page file could not be scanned!C:\WINDOWS\system32\CatRoot2\tmp.edb...

Can anyone tell me what this is? I have place it in quarantine for now till i know it is safe to delete. Yep, Spywareblaster is installed and working.

J'ai téléchargé plusieurs anti spyware et fait plusieurs scan puis effacé des fichiers dangereux mais j'ai toujours le message qui apparait me disant qu'un "trojan32" à été détecté (message en anglais).

Accept that some days you are the pigeon and some days the statue. then :- run this ONLINE TROJANSCAN let me know if it finds anything. file could not be scanned!C:\WINDOWS\system32\CatRoot2\tmp.edb... If you carry out updates manually through HP's site then you can safely delete it.

Download CCleaner and clean out IE's Temporary Internet Files:http://www.ccleaner.com

