Home > Please Help > Please Help Me And Look At My Highjackthis Log

Please Help Me And Look At My Highjackthis Log

Mark it as an accepted solution!I am not a Comcast employee. Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0527.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXEO14 - IERESET.INF: Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dllO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"O4 - Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.htmlO8 - Extra context menu item: RoboForm

my advice would be to boot into safe mode with networking, then download and run at least two of these tools, letting them clean anything they find. Could you maybe copy and paste the entries from my HijackThis logthat I should delete?Maybe that way I could find them easier. I also cannot find these entries in the registry usingregedit from the run box. by Grif Thomas Forum moderator / April 6, 2009 1:38 PM PDT In reply to: Please help me to analyse my hijackthis log In order to get your Hijackthis log interpreted,

FreewheelinFrank: There are 9 entries for wpclsp.dll which looks a bit odd. (That seems to be Vista parental control.) Try disabling that and see if that helps. If you like that program you can use Roboform instead which is free and has no spyware. So I called the HP tech support, you know they're in India.

or read our Welcome Guide to learn how to use this site. Microsoft Customer Support Microsoft Community Forums TechCenter   Sign in United States (English) Brasil (Português)Česká republika (Čeština)Deutschland (Deutsch)España (Español)France (Français)Indonesia (Bahasa)Italia (Italiano)România (Română)Türkiye (Türkçe)Россия (Русский)ישראל (עברית)المملكة العربية السعودية (العربية)ไทย (ไทย)대한민국 (한국어)中华人民共和国 (中文)台灣 This thread is now locked and can not be replied to. I deleted the following after saving the log file:R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)O4 - Startup: wwwpos32.exeThank you!Katy [email protected] Wednesday, January 27, 2010 7:26 PM Reply |

So when all was said and done I did system recovery to when this thing was brand new, luckily I did NOT lose ONE file. Mark it as an accepted solution!I am not a Comcast employee. I am not a Comcast employee, I am a paying customer just like you!I am an XFINITY Forum Expert and I am here to help. https://www.cnet.com/forums/discussions/please-help-me-to-analyse-my-hijackthis-log-337994/ Put your HijackThis.exe there, and double click to run it.

Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Skype add-on But I am not sure if I have virus's or anything nasty on my pc - if someone could be so kind as to inform me what my log means that I always use it when I clean one’s PC. I have posted my new log could you please have a look at it to see what I have done wrong and advise me how I can put back my original

Nothing is listed in there that match any of the entries you are saying to delete.Maybe I am not looking the right way or in the right spot?? I had to use my tab key or arrow keys. I also ran the malwarebytes free edition software and it found the Trojan.agent and it said it removed it just fine but still I get the pop up and can not Using the site is easy and fun.

Book your tickets now and visit Synology. Logfile of HijackThis v1.99.1 Scan saved at 4:44:12 PM, on 7/3/2005 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v5.50 (5.50.4134.0600) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\HPSYSDRV.EXE C:\PROGRAM I have posted my new log could you please have a look at it to see what I have done wrong and advise me how I can put back my original Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLLO3 - Toolbar: Starware - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\PROGRAM FILES\STARWARE\BIN\STARWARE.DLLO4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exeO4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -sO4 - HKLM\..\Run: [SystemTray]

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0527.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXEO9 - Extra Please try again now or at a later time. I am a paying customer just like you! To create a permanent folder: Click My Computer, then C:\ In the menu bar, File->New->Folder.

Now you have C:\HJT\ or C:\HijackThis\ folder. Privacy Policy Contact Us Back to Top Malwarebytes Community Software by Invision Power Services, Inc. × Existing user? Track this discussion and email me when there are updates If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and

Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast!

from whats already been run on there that should get rid of the rest of the infection. Back to top #13 lady_leila lady_leila Topic Starter Members 7 posts OFFLINE Local time:02:40 AM Posted 29 March 2005 - 04:56 AM Hiya I would just like to thank you For information on the program click here.We ask that you post publicly so people with similar questions may benefit from the conversation.Was your question answered? polonus: Hi Chelsjas,Another alternate solution could be: to change the network controller power management settings for both your controllers.

We tried system recover to an earlier date and it wouldn't let me. How I finally got it downloaded and run it was to log in as a guest and it seemed to work fine, I also did not update to IE8 as the all of these are portable which means they dont have to be installed, just download and double click and run "DrWebCureIT" http://www.freedrweb.com/cureit/?lng=en "Normans Malware Cleaner" http://norman.com/support/support_tools/58732/en-us "Kaspersky Virus Removal curlylad 23:09 05 May 05 Part 1 Logfile of HijackThis v1.99.1Scan saved at 23:01:39, on 05/05/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\WINDOWS\system32\ZONELABS\vsmon.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program

Always make sure you run HijackThis from the permanent folder. However I don't see anything in your log.. curlylad 23:12 05 May 05 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = click hereR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = click hereR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1O2 I physically deleted SecurityTool from both my start menu and desktop previouslybut could locate them using the run box today.

VoG II 21:42 05 May 05 Can you post another HJT log please? Accessing and setup of a Wireless Gateway Find everything you need to know about setting up your wireless gateway. Thanks! Disruptive posting: Flaming or offending other usersIllegal activities: Promote cracked software, or other illegal contentOffensive: Sexually explicit or offensive languageSpam: Advertisements or commercial links Submit report Cancel report Track this discussion

Showing results for  Search instead for  Did you mean:  5,596,191 members 18 online now 1,780,265 discussions Xfinity Help and Support Forums > Internet > Anti-Virus Software & Internet Security > Please However, due to bugs in the LSP software or deletion of the software, this chain can get broken, causing the Internet connection to become inaccessible.Download this free program from here: http://www.cexx.org/lspfix.zipIf Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.htmlO8 - Extra context menu item: RoboForm In regards to the redirect, although both of the items below may, or may not be present, please check for them..

That's why I ran the hijack this log thinking maybe something was hiding from me. If you find one, remove it as directed..