Please Look At HJT Log And Advise. Thanks!

I have a copy of the registry key value saved in a .txt file. It removes it temporarily and then it comes right back. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. WindowsBBS.com is completely free, paid for by advertisers and donations. click for more info

Following is my HJT Log. Run the latest CWShredder, v1.59.1, then another HJ log. After fixing that entry, reboot and empty your temp folder, then the recycle bin. Logfile of HijackThis v1.99.1Scan saved at 11:31:10 PM, on 9/21/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEc:\program files\mcafee.com\agent\mcdetect.exec:\PROGRA~1\mcafee.com\vso\mcshield.exec:\PROGRA~1\mcafee.com\agent\mctskshd.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\svchost.exeC:\Program Files\McAfee.com\VSO\mcvsshld.exeC:\Program Files\McAfee.com\VSO\oasclnt.exec:\program files\mcafee.com\agent\mcagent.exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\WINDOWS\system32\S3tray2.exec:\progra~1\mcafee.com\vso\mcvsftsn.exeC:\Program Files\Messenger\msmsgs.exeC:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

  2. Please continue with MS tech support. -------------------- Please see the Important topics, located at the top of this section, and at the top of other sections of this forum.
  4. Oh, and I miswrote (again, sigh).
  6. Sorry I can't help you more but don't give up, one of the pros will take it from there.

Un and re install Internet Explorer 11.Unininstall: http://www.sevenforums.com/tutorials/31335...indows-7-a.html reboot when done.

Please visit Windows Update (follow this link: http://www.windowsupdate.com) to update Windows.

Stay logged in Sign up now! jjustjjo View Member Profile 5.01.2015 05:26 Post #14 Member Group: Members Posts: 10 Joined: 3.01.2015 Thank you so much! exited spybot and other stuff. I'll go do something else for awhile.Note some differences: The java script error is happening a little more frequently now -- it pops up quicker and less time between each occurrence.

Thanks again cryo for all

LD AdAwareSpybot HiJackThis-CWShredder LDTate, #15 2004/07/14 ksteele Inactive Thread Starter Joined: 2003/09/30 Messages: 41 Likes Received: 0 Trophy Points: 81 Computer Experience: beginner Ran cwshredder and rebooted. Hopefully i will be able to keep the nasties away, if not i will certainly be back for guidance. iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exeO23 - Service: avast! I thought Spybot and HJT were trusted tools.

Welcome.

No, create an account now. If you're not already familiar with forums, watch our Welcome Guide to get started. Bring up the taskmanager and click on the processes tab.

Logfile of HijackThis v1.98.2 Scan saved at 2:57:09 PM, on 14/12/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Mark it as an accepted solution!I am not a Comcast employee. For information on the program click here.We ask that you post publicly so people with similar questions may benefit from the conversation.Was your question answered?

I did do a restart after resetting IE.

Be sure to update first. I am still getting the recurrent popup javascript error. If any files are infected and uncleanable, click the report button then copy and paste it here. Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab O16 -

I am an XFINITY Forum Expert and I am here to help.We ask that you post publicly so people with similar questions may benefit.Was your question answered? Install Service Pack 1 and all critical Start here. After a time, it will go back to normal and everything works normally again.

However all attempts to shut it down permanently have failed. The link for the GSI file is http://www.getsysteminfo.com/read.php?file...f6cb2ef5af57795Attached are two images -- one of the java script error, one of value of the regkey.I got the javascript error 7 times while LD AdAwareSpybot HiJackThis-CWShredder LDTate, #12 2004/07/14 Newt Inactive Joined: 2002/01/07 Messages: 10,974 Likes Received: 2 Trophy Points: 608 Location: Concord, NC, USA Computer Experience: ***** Lonny Jones said: subratam's link is Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_1us.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/SysQuery.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{666AEB3C-E703-4060-AF06-8EF57E3E791A}: NameServer =

When it's done, select all and fix. Thanks a million :-) Regards,ParagLogfile of HijackThis v1.99.1Scan saved at 12:12:06 PM, on 8/31/2006Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\atiptaxx.exeC:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\ewido anti-spyware 4.0\ewido.exeC:\Program Files\Java\jre1.5.0_06\bin\jusched.exeC:\Program Files\Messenger\msmsgs.exeC:\Program jjustjjo View Member Profile 4.01.2015 06:18 Post #5 Member Group: Members Posts: 10 Joined: 3.01.2015 No. Everyday is virus day.