https://netfiles.uiuc.edu/ehowes/www/resource.htm prevX a new tool, looks like a good one http://www.prevx.com/prevxhome.asp Use spybot's immunize button and use spywareblaster' enable protection once you update it. It has shields for Chrome, Firefox, IE, Opera and Java but anything else you have to buy the paid version.Malwarebytes now have their own rootkit removal sofftware to be used if necessary.

Search in Windows Explorer is disabled. Going into safe mode and running thorough scans of everything found nothing.

Most of what it finds will be harmless or even required. Start HijackThis Fix. Open Hijack This and click on Scan. If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Certain pages will not load while online and others load with incorrect images that shouldn't be there. This is a critical point in removing the malware or virus.

Please note that many features won't work unless you enable it. However, if the above is too complex for you, Hispasec lab's free multi-engine single file scan and submission tool www.virustotal.com is much simpler to use.

You can proceed through most of the steps without having to wait for guidance from someone in the forum.This FAQ is long, but that is because the instructions are step-by-step. Questions regarding that should be directed to the appropriate browser support forums.I would suggest checking if all Microsoft Updates are installed and working OK.

Here is the log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 6:59:04 PM, on 6/21/2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16446) Boot mode: Normal. I was able to clean or delete a few problems but I have an uncleanable file that is in use and can't be deleted. Troj sdown.a is the virus.

Is your computer trying to call out or send emails? Quarantine then cure (repair, rename or delete) any malware found.

Update and run the defensive tools already on your computer.

hgfe.exe trojan virus..need help...Hijack this LOG included. I am running on an XP computer.

Thanks in advance!

Note that Norton had not found this trojan. If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Someone will be along to tell you what steps to take after you post the contents of the scan results. Several functions may not work. If you removed any malware, reboot and repeat the scans that revealed it earlier. This is to make sure that the malware has not managed to reinstall itself. With the help of this automatic analyzer you are able to get some additional support.

You might also want to try RootkitRemover by McAfee listed above.MalwareBytes Anti-Ransomware Beta. Place ComboFix.exe on your Desktop. Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. I have MSE, MBAM, SuperAntiSpyware, and a few other programs (all compatible as far as I can tell) installed on my computer (XPS 17 with 64 bit Windows 7 OS). Had to manually delete the registry edit, to ensure it didnt reinstall itself.

If you do you will end up with the wrong version.https://www.malwarebytes.org/mwb-download/thankyou/ or the direct download link at BleepingComputer: http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/?1Support Forum: Malwarebytes Community. Report the crime.

Thanksskulkhere is my hijack this log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:10:04 PM, on 9/4/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16705)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exeC:\Program Even scanning in safe mode had no results.