Absence of symptoms does not mean that everything is clear.If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer Advertisements do not imply our endorsement of that product or service. Each time I got an error message "service failed (5)" after the "C:\Program Files\Bonjour\mDNSResponder.exe" –remove command. Now, my request is, can anyone confirm if it is ok to have this service on (started & enabled condition)?

And have had no problems. I'll be restarting soon so I hope for the best! Also, EXPORT a key and its sub-keys, before deleting that key. I recently installed Apple Safari Browser too… As i read this post, I could not find this service doing anything harmful but would like to confirm from experts.

After reboot post new hijacthis log. ypager Yahoo Messenger>> Number 12,13, and 14 are certainly suspect. So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most

sZs Reply Mike says: September 1, 2013 at 00:08 run your command prompt "as administrator" or it won't have the rights to uninstall the service. I recently discovered a brilliant uninstaller that not only forces uninstall, but searches the whole system for traces of the program - and erases them.

I'm not sure of the changes it made to shell32.dll. For the purposes of boredom-abatement, this forum may be used to post topics of a general, non-help related nature. No, create an account now. Check This Out How lengthy have you been blogging for?

You definitely know how to bring an issue to light and make it important. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts. I am thrilled...Thank you so much...

when it says repair or remove click repair. Reply Frankie says: November 3, 2010 at 18:30 Hi Kyle, I suspect that when you deleted the Bonjour folder and files, you also deleted (within the files) a component In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this.

You can find all the links to referenced programs and sites on my website here:http://www.elephantboycomputers.com/page2.html#Removing_Malware1) Scan in Safe Mode with current version (not earlier than 2004) antivirus using updated definitions.Before you In regard to the Winsock2 entry it creates, as mentioned in a prior post, be VERY careful to adjust the Num_Catalog_Entries located at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5 The value shown for Num_Catalog_Entries should MATCH a3d92782 Sys3213. anyone else get this problem Reply HyJax says: May 24, 2008 at 00:03 I used the un-installer placed in windows control panel…seems to have eliminated this process without causing the issues

Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabWhat to do:If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis fix Reply Michelle says: September 2, 2008 at 05:06 My online security system, Embarq, picks up on Bonjour at least once a week. Rather, HijackThis looks for the tricks and methods used by malware to infect your system and redirect your browser.Not everything that shows up in the HijackThis logs is bad stuff and E.G.

But the folder and files remain in the program files folder. I'm sure its some dumb thing my daughter downloadedknowingly or knowingly.I've used msconfig to stop some programs from loading that I thoughtwould be the cause, but that didn't work.Any one have I tried to delete the Bonjour folder but was told that I can't delete mdnsNSP.dll because the file is open in another program. Reply Скачать says: December 27, 2012 at 11:16 A fascinating discussion is worth comment.