For example, aren't processes like these ones (Real and Quicktime) unnecessary and just memory hogs?O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeThanks.--------------------------------------------------------- ewido security Please click Stop to stop the service and change the Startup type to Disabled. Internet keeps on disconnecting 3 replies To whom it may concern. Select Yes at the prompt.Lastly, are there processes in my log file that I can delete?

If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode". - Reboot. =============== After rebooting, rescan with hijackthis and post back a new log. Remove the check by these: Enable the Microsoft Security Agents on startup. (recommended) Enable real-time spyware threat protection. (recommended) Click "Save".

Open MS Anti-Spyware and click on Options>Settings. Restart your computer into Safe Mode now. (Start tapping the F8 key at Startup, before the Windows logo screen). AVG makes an excellent free antivirus client, as do AntiVir and avast!. The Javascan is much quicker than Active-X ones as it doesn't have to download "the works".

Here are the results (and a new HijackThis log below that) Object "DyFuCA Spyware/Adware" found in File System! infected with a trojan ='( » Thread Tools Show Printable Version Download Thread Search this Thread Advanced Search Posting Rules You may not post new threads You may not post replies Best to get recommendations from a reliable site and always use originators site. You mentioned that Norton and McAfee are both trial versions.

I want to transfer my existing straight talk service. PLEASE HELP ME! Since Norton isnít running, thatís why itís not showing in your logs. http://www.spywareinfoforum.com/topic/48869-cant-get-rid-of-elitebar-and-other-spyware/ Disruptive posting: Flaming or offending other usersIllegal activities: Promote cracked software, or other illegal contentOffensive: Sexually explicit or offensive languageSpam: Advertisements or commercial links Submit report Cancel report Track this discussion

File C:\WINDOWS\System32\a_i_037.exe infected by "Trojan-Downloader.Win32.IstBar.iu" Virus! On Internet Explorerís menu bar, click View => Toolbars and then look for Google Toolbar. Terms of Service - Privacy Policy - Contact C:\Program Files\PartyPoker files...

I'm making my donation to the site this very minute. http://www.tomsguide.com/answers/id-3186019/rid-counterflix.html Last Post 1 Month Ago What does Google have from serving us with Google Fonts? Having both of them is not a bad thing, but please make sure to have real-time protection enabled on only one program. Thanks.Logfile of HijackThis v1.99.1Scan saved at 7:59:29 PM, on 5/28/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\System32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\Program Files\MSN Messenger\msnmsgr.exec:\progra~1\mcafee.com\vso\mcvsftsn.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\ewido\security suite\ewidoctrl.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\wuauclt.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\System32\wuauclt.exeC:\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

In the Add or Remove window, I still see uninstall options for "EliteBar Internet Explorer Toolbar" and "YourSiteBar" listed. Action Taken: No Action Taken. Action Taken: No Action Taken. Action Taken: No Action Taken.

Please let me know if my ordeal is over.Oh, the reason I have Norton and Mcafee is that I downloaded both trial versions recently when I found out I had virus Show Ignored Content As Seen On Welcome to Tech Support Guy! I reinstalled a new virus protector and that couldn't get rid of them it just says its at risk. Rebooted in safe mode and tried both spybot and mcafee - nothing found.Made a hijackthis log and obviously lots of trojan stuff on my pc.

I saw two additional folders on my PC:c:\program files\yoursitebarc:\program files\webrebatesC:\Program Files\SideFindYes, those folders are all malware. Elitebar removal Started by steve_1979 , Dec 16 2004 08:13 AM Please log in to reply 3 replies to this topic #1 steve_1979 steve_1979 Members 3 posts OFFLINE Local time:12:38 Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL".

Double-Click LQfix.exe and click Next > Next > Install.

solution SolvedPlease help me Forum Solvedplease help me with this Forum SolvedPlease help me! ASAP - Alliance of Security Analysis Professionals - Proud Member Since 2005 MS MVP 2007 Consumer Security Back to top #21 takepityonme takepityonme Member Full Member 57 posts Posted 29 May I searched Nortons website for any indication of reflive.exe and mathfragbold.exe but nothing came up. IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

It disappeared the day my PC was hijacked. Preview post Submit post Cancel post You are reporting the following post: Two viruses I was unaware of and can't find any information This post has been flagged and will be Tom’s guide in the world Germany France Italy Ireland UK About Us | Contact Us | Legal | Terms Of Use and Sale | Privacy | Copyright Policy | Purch Privacy Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab O16 - DPF:

I don't like the idea of using an online scan, I just have a bad feeling about it.