Home > Hijackthis Log > Hijackthis Log. Any Help Would Be A Help

Hijackthis Log. Any Help Would Be A Help

Yes, my password is: Forgot your password? Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe O4 - HKLM\..\Run: Help & Tips CableNut Tcp/Ip Analyzer TCPOptimizer Malware Removal Guide Dr Tweak Reply With Quote 11-26-08,12:36 PM #5 char View Profile View Forum Posts View Blog Entries Junior Member Join Date Tell me the location of the file when Autoruns finds it. (eg: C:\Windows\system32\logonui.exe) Best Regards cdavfrew, Aug 5, 2008 #2 rdrake Member Joined: Oct 11, 2006 Messages: 10 Likes Received: have a peek here

I think I may have some sort of embedded program from another download. Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program radrake rdrake, Aug 5, 2008 #3 2oldGeek Active member Joined: Jun 16, 2005 Messages: 3,682 Likes Received: 34 Trophy Points: 78 I hope cdavfrew forgives me but that file cannot Next run msautoruns and again check for anything odd usually not showing a publisher or a looks like this "jaleiwa.exe" etc you get the idea.

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dllO3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0311.0\msneshellx.dllO3 - Toolbar: AOL Radio Toolbar BleepingComputer is being sued by Enigma Software because of a negative post of SpyHunter. Service & Support HijackThis.de Supportforum Deutsch | English Forospyware.com (Spanish) www.forospyware.com Malwarecrypt.com www.malwarecrypt.com Computerhilfen www.computerhilfen.com Log file Show the visitors ratings © 2004 - 2017 The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you letting us know.

Will check it again. A case like this could easily cost hundreds of thousands of dollars. Hijackthis log. Save the file as gmer.log.Click the Copy button and paste the results into your next reply.Exit GMER and re-enable all active protection when done.-- If you encounter any problems, try running

I know this is frustrating, but it may save you a re-format / re-install.. 2OG 2oldGeek, Aug 6, 2008 #6 rdrake Member Joined: Oct 11, 2006 Messages: 10 Likes Received: Started by Kacie , Apr 05 2010 05:54 PM This topic is locked 2 replies to this topic #1 Kacie Kacie Members 1 posts OFFLINE Local time:07:11 PM Posted 05 tried it for a second time and it didn't seem to fix anything. KG) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-11-14] (Wacom Technology, Corp.) S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X] S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe"

BLEEPINGCOMPUTER NEEDS YOUR HELP! Any help would be a help! If there is some abnormality detected on your computer HijackThis will save them into a logfile. Privacy Policy & Cookies Legal Terms We use cookies to ensure that we give you the best experience on our website.

Since my last post I've realized that this goes beyond just the "LogonUI" error message. Stay logged in Sign up now! If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy

i had to run cmd as administrator. navigate here Ask a question and give support. Macboatmaster replied Jan 24, 2017 at 5:40 PM Loading... Try to do the EXPAND logonui.ex_ again as Administrator and see if it works.. 2oldGeek, Aug 6, 2008 #9 rdrake Member Joined: Oct 11, 2006 Messages: 10 Likes Received: 0

Join our site today to ask your question. Load CCleaner (no need to install this, its portable!) and select everything to clean! - http://www.majorgeeks.com/CCleaner_Portable_d5735.html Load/update Avast Home - http://www.avast.com Load/update superantispyware - http://www.superantispyware.com Load/update Malwarebytes - MalwareBytes (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) Load/update I think your friend would be better off backing up his important data, and doing a complete format, and reinstall. Check This Out This works with XP and I see no reason it will not with Vista.

That way, if it don’t work, you can always step back.. MM Member ASAP Quote Report Back to top Post a reply Unread posts or replies No unread posts or replies Unread Posts (Read Only Forum) No Unread Posts (Read It's at least good to know I'm not obviously infected Reply With Quote August 16th, 2006,03:39 AM #5 westin View Profile View Forum Posts Gonzo District BOFH Join Date Jan 2006

Next run msautoruns and again check for anything odd usually not showing a publisher or a looks like this "jaleiwa.exe" etc you get the idea.

oader5.cabO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... Run MalwareBytes and remove whatever it finds. You also may need admin priv. You can always install them again later so don't worry about it. 2nd thing is to TURN OFF System Restore!!! 3rd go to Start,Run, and type in msconfig and uncheck anything

If you use this mirror, please extract the zip file to your desktop.Disconnect from the Internet and close all running programs.Temporarily disable any real-time active protection so your security programs will Please reply using the Add/Reply button in the lower right hand corner of your screen. Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... this contact form Javascript You have disabled Javascript in your browser.

Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 212.71.0.33 212.71.8.10 Tcpip\..\Interfaces\{7E0F8103-88B7-4BE2-904B-2BA3AF5E6770}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{996D2D4A-789A-4FC3-A409-F9FAD853C3F6}: [NameServer] 82.163.143.169,82.163.142.171 Tcpip\..\Interfaces\{996D2D4A-789A-4FC3-A409-F9FAD853C3F6}: [DhcpNameServer] 212.71.0.33 212.71.8.10 Tcpip\..\Interfaces\{EB4E96BB-2B8E-4310-A94D-B1E923084011}: [NameServer] 82.163.143.169,82.163.142.171 FireFox: ======== FF ProfilePath: C:\Users\marina\AppData\Roaming\Mozilla\Firefox\Profiles\9ju69sia.default FF Homepage: hxxp://google.fr I had antivirus 2009 popping up and knocking me off of sites and another one too but I forget the name. I tried getting rid of it and thought I had but it was still there.