A toolbar she didn't recognize had appeard in ie and any attempt to visit her usual websites was redirected. I was unable to scan with SAS even in safe mode, but I managed to install and scan with a recent copy of MBAM (in safe mode), which I had on a USB drive. Her computer also kept freezing at apparently random times, and task manager did not work.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Kenny/facebook malware makes sense, considering her internet habits. Incidentally, my daughter doesn't actually 'have' Spybot. Viewpoint is also bundled with Adobe Atmosphere and hardware manufacturers pre-install some of these applications. Personally I wouldn't have it on my system, that is a choice for the user, but in mobile security. Reboot when installed and return to make sure there are no others.

  3. Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocxO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cabO16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cabO16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content

My recovery disc for my computer is not recognized when I reboot, although I am able to explore that disc and see the contents of it. My daughter's laptop (WinXP Media Center edition, SP3; 1.6 GHz, 1 GB RAM) has been infected with malware.

Make sure you are able to view system and hidden files/ folders. Her HJT log is attached. I just discovered I cannot do a defrag (I can get to the defrag screen, but I get an error message when I try to defrag C: that says "Disk Defragmenter could not start").

If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode". - Reboot. After rebooting, rescan with hijackthis and post back a new log. Other things that show up are either not confirmed safe yet, or are hijacked.

The service needs to be deleted from the Registry manually or with another tool.

If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it. O16 - ActiveX Objects (aka Downloaded Program Files). Run them both on a regular basis, following the manufacturer's recommendations. It is bundled with AOL, AIM, versions of Netscape, certain Adobe products and sometimes not mentioned in the license agreement.

Note that all previous restore points will be lost. If you have any more problems, post back. Thank you for any help you can offer! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:03:57 AM, on 6/29/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal. It found and removed a trojan downloader and a few lesser threats.

Wird eine Abweichung festgestellt, so wird diese in einem Protokoll (Logfile) angezeigt. Click Do a system scan and save a logfile. The hijackthis.log text file will appear on your desktop. Check the files on the log, then research if they are safe or malicious.

My girlfriend was using my computer and claimed she started seeing pop-ups and getting porn ads embedded into sites like the local news channel and other normally porn-free sites.

Clear your Temp folders. Clear out your Temporary internet files and other temp files.

Have HijackThis fix them. O14 - 'Reset Web Settings' hijack What it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.com What to do: If the URL is not the provider of your computer or your ISP, have HijackThis fix it. On the next page, click the System Restore Settings link on the left.

They rarely get hijacked, only Lop.com has been known to do this. Why does Google offer free fonts to use online?