Home > Highjack This > Highjack This Logfile Help Feb 4 2005

Highjack This Logfile Help Feb 4 2005

Most people never use it and you can uninstall it if you do not. I shut off everything I could except cybersitter since that would involve an uninstall and resinstall Attached Files: hijacklog.txt File size: 4.8 KB Views: 7 rgkleidman, Feb 4, 2005 #5 have hidden files and folders set to show. You can donate using a credit card and PayPal. http://pcialliance.org/highjack-this/highjack-this-log-help-ty.html

Save good links for reference. We usually recommend FireFox user posted image.2. TheGoodLife Logfile of HijackThis v1.99.0 Scan saved at 8:31:42 AM, on 2/5/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\ibmpmsvc.exe Here is the next log file.

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged You never ran the online scanners. Learn More. Well telling me what to remove, please also feel free to point out anything I can remove that is AOL or Yahoo related (etc..) that does things like adds unneeded toolbars

Lot's of reading and studying to do. Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".4. Scan and when it finishes, put an X in the boxes, only next to these following items, then click fix checked.O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" –osboot <- not needed C and you too Blaine.

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dllO9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dllO9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dllO9 - Extra If so, that is OK, as I think we have killed the malware. Please use windows explorer to find the following Files and Folders in blueC:\Program Files\ CxtPls\cxtpls.dll<-Delete this folderC:\WINDOWS\System32\ uoje.dll<-Delete this fileC:\WINDOWS\System32\ mzesj.dll<-Delete this fileC:\WINDOWS\System32\ chtee.dll<-Delete this fileC:\Documents and Settings\Owner\Local Settings\Temp\ EV.dll<-Delete this https://www.bleepingcomputer.com/forums/t/11171/hijackthis-log-please-help-diagnose/ A couple of oddities.

Click Here http://windowsupdate.microsoft.com/ to make sure that you have the latest patches for Windows.These next two steps are optional, but will provide the greatest protection.1. Please help analyzing Hijackthis log. JeEnYuS, Feb 3, 2005 #8 JeEnYuS Joined: Dec 18, 2004 Messages: 52 Location: Alabama now i see this isn't supposed to be R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.stolenfilenetwork.com R0 - Back to top #7 chenzak chenzak Topic Starter Members 4 posts OFFLINE Local time:04:29 PM Posted 13 February 2005 - 01:59 PM Logfile of HijackThis v1.99.0Scan saved at 8:58:39 PM,

After that, choose "Search and Destroy" and click on "Check for problems". Make sure you do this for all of the top tabs. Attached Files: finditlog.txt File size: 6.5 KB Views: 2 hijackthis.txt File size: 5.5 KB Views: 3 rgkleidman, Feb 6, 2005 #15 chaslang MajorGeeks Admin - Master Malware Expert Staff Member Okay! Even for an advanced computer user.

You can just have HJT fix that entry and it will no longer load at Startup. his comment is here I also went to McAfee.com and ran their online scan and it found 3 different viruses where as it doesn't have a removal for them unless u purchase the software : One Unique Case Where IPX/SPX May Help Fix Network Problems - But Clean Up The Protocol S... Please help NJGUY, Feb 16, 2005 Replies: 3 Views: 2,429 RealBlackStuff Feb 17, 2005 Locked My hijackthis log..please end the pain diarrhea, Feb 16, 2005 Replies: 1 Views: 1,640 RealBlackStuff Feb

Although you weren't explicit I assume you wanted the same logs as last time. Thank you! Symptoms: IE will open (I usually use firefox) and take me to sites selling spyware removal tools and other advertisements. http://pcialliance.org/highjack-this/highjack-this-please.html Click HereQUOTEPrevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.Restrict the actions of potentially dangerous sites in Internet

Two other tutorials which I have used are:AOL / JRMC.Help2Go.There are three basic ways of checking out your HJT log, and all leverage the power of the web to disperse knowlege. What Is A NAT Router? That does not stop Quiktime from working.

I don't know the answer to the rest of your questions but I'd love to know how these guys become the major geeks they are...

Exit Browsers now before continuing First Step: Now run LSP-Fix. You can donate using a credit card and PayPal. Do you want me to re-run the on-line scanners? Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List

Press OK.A DOS window will open.Type the following and then press Enter after typing each one:attrib -h -s c:\recyclerdel c:\recyclerClose the window and REBOOT.Check if the Recycle Bin is OK. On boot-up norton auto-protect does not load. I appreciate your time and the link to that last article. http://pcialliance.org/highjack-this/highjack-this.html Run this pc through the Panda Scan Online virus scanner or Trend Micro Housecall Online virus scanner *************************************************** Next, reboot and post a fresh HijackThis log to this thread.

Please Wait! Edited by Daisuke, 06 March 2005 - 05:24 AM. Poker - http://download.games.yahoo.com/games/clients/y/pt0_x.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/038cd80fdc4252...ip/RdxIE601.cabO18 - Filter: text/html - {9FC573C1-6792-4003-9D1F-0B75394E6F57} - C:\WINDOWS\SYSTEM\GHPI.DLLThx! :lol: Logged EASTER ASAP Members Hero Member Offline Gender: Date Registered:December 05, 2004, 06:12:53 once again i tried to rid my self the 69.xx.xx.xx host's and they seem like they go away but if i scan 2x i get them right back.

After I ran the tool this time the same two files disappeared. JeEnYuS, Feb 3, 2005 #6 JeEnYuS Joined: Dec 18, 2004 Messages: 52 Location: Alabama i was told something about a lspfix..do you know where i can get that?? In Scanning Engine: Unload recognized processes during scanning Include info about ignored objects in logfile, if detected in scan Include basic Ad-aware settings in logfile Include additional Ad-aware settings in logfile Do you mean you turned your computer off?

Please attach that log later when the remaining steps are completed. Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it. Literati - http://download.games.yahoo.com/games/clients/y/tt0_x.cabO16 - DPF: Yahoo! A t-shirt purchase will be coming soon.

Open System Security Suite.B. Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear BleepingComputer.com If not, how did these get there and what are they?Click to expand... All of the fixes did not take We are going to do some steps over with some slight changes in options on Killbox.

Do you know where your recovery CDs are ?Did you create them yet ? Better to blame this than my poor writing style. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. We've got experienced members happy to help and advise on your questions.

Allow it to finish.Reboot your PC.Please run a free online [url=http://housecall.antivirus.com/]virus scan here.(tick the "Auto Clean" checkbox):Please run Ad-aware one more time If you would please, rescan with HijackThis and post Edited by SifuMike, 11 February 2005 - 02:47 AM.