Sep 29, 2006 Is my PC clean? Go to Start > Control Panel double-click on the Software icon > add/remove programs. Lucian Bara 16.02.2007 18:02 if that log is continually getting modified then there's a way to find out who writes in it, you can use "filemon" http://www.microsoft.com/technet/sysintern...sk/Filemon.mspxopen it and under include Daniel D 16.02.2007 17:23 QUOTE(lucianbara @ 16.02.2007 15:42)it does n't look like it's created by the system, but from what i see those are all only titles of the windows are

Please do NOT run a scan yet! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO2 - BHO: (no name) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C:\PROGRAM FILES\POPUP ELIMINATOR\AUTODISPLAY401.DLL (file missing)O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLLWhat to do:If In the Toolbar List, 'X' means spyware and 'L' means safe. O5 - IE Options not visible in Control PanelWhat it looks like: O5 - control.ini: inetcpl.cpl=noWhat to do:Unless you or your system administrator have knowingly hidden the icon from Control Panel,

it removed the ShowWnd.exe from my WINDOWS folder but it didn't remove the svchost.exe..

http://www.bleepingcomputer.com/forums/tutorial62.html Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

They rarely get hijacked, only Lop.com has been known to do this.

Using the site is easy and fun. Always fix this item, or have CWShredder repair it automatically.O2 - Browser Helper ObjectsWhat it looks like:O2 - BHO: Yahoo! PowerReg Scheduler.exe Scheduler.exe You will need to search your system for the above files.

The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those. Everything looks pretty clean to me except for O16 the CLSID has been changed) by spyware.

If the IP does not belong to the address, you will be redirected to a wrong site everytime you enter the address. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts.

Removal of infections and prevention protection should be installed on ALL User Account IDS.Download and install WinPatrol.http://www.winpatrol.comBrowser settings for increased security:http://bshagnasty.home.att.net/browsersettings.htmInstall IE-SPYAD then run the install.bat in the ie-spyad folder and Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone. Join our site today to ask your question.

O7 - Regedit access restricted by AdministratorWhat it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:Always have HijackThis fix this, unless your system administrator has put this restriction into place.O8 - Extra