Home > Hijackthis Log > HiJackTHis Log Posted - Plz Help

HiJackTHis Log Posted - Plz Help

C: is not dirty. ***LOG1!*** Scanning for file(s) in System32... (1) (2) **File C:\FINDnFIX\LIST.TXT (3) No matches found. Please note that many features won't work unless you enable it. Contact Support. Lawrence Abrams Don't let BleepingComputer be silenced. have a peek here

Sign In Use Facebook Use Twitter Use Windows Live Register now! Password Register FAQ / Help Calendar Today's Posts Search Search Forums Show Threads Show Posts Tag Search Advanced Search Go to Page... Jump to content FacebookTwitter Geeks to Go Forum Security Virus, Spyware, Malware Removal Welcome to Geeks to Go - Register now for FREE Geeks To Go is a helpful hub, where All rights reserved.

ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.Windows update -> It is important that you visit Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Follow the prompts to install the program.

Back to top #26 Grinler Grinler Lawrence Abrams Admin 42,756 posts ONLINE Gender:Male Location:USA Local time:06:07 PM Posted 06 July 2004 - 01:24 PM Click on the link below to All your help is greatly appreciated! Click Yes to create a default host file.   Video Tutorial Rate this Solution Did this article help you? Thanks Back to top #4 Grinler Grinler Lawrence Abrams Admin 42,756 posts ONLINE Gender:Male Location:USA Local time:06:07 PM Posted 29 June 2004 - 11:18 AM What makes you think you

Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo! Sniffed -> C:\WINDOWS\SYSTEM32\COMCFK.DLL (*5*) **File C:\WINDOWS\SYSTEM32\DLLXXX.TXT Access denied ..................... Run the program from there going forward. Hang with us on LockerDomeCircle BleepingComputer on Google+!How to detect vulnerable programs using Secunia Personal Software Inspector Simple and easy ways to keep your computer safe and secure on the Internet

Adam ----------------------------------------------------------------------------------------------- *** freeatlast100.100free.com *** Microsoft Windows XP [Version 5.1.2600] IE build and last SP(s) 6.0.2800.1106 SP1-Q837009-Q832894-Q831167 The type of the file system is FAT32. The solution is hard to understand and follow. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Please User is a member of group BUILTIN\Users.

Post the contents of the ActiveScan reportIf kaspersky doesn't work. 0 #6 staticVoid Posted 15 August 2007 - 11:01 AM staticVoid Member Topic Starter Member 94 posts heres the report: Wednesday, Check out the forums and get free advice from the experts. Here's the log:-----------------------------------------------------------------------------------------------Logfile of HijackThis v1.97.7Scan saved at 11:02:15 AM, on 6/30/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\Program Plz help me.

this Topic has been closed. navigate here Please specify. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://mediasportal....5...;pn=0&pid=2O2 - BHO: MSVPS System - {47C54F02-1B28-45F1-AE46-B5CDFB6E7926} - C:\WINDOWS\duocore.dllO21 - SSODL: wmpenv - {71E27856-E835-4843-A19F-611C14699C97} - C:\WINDOWS\wmpenv.dllO21 - SSODL: wmpconf Power SNiF 1.34 - The Ultimate File Snifferdog.

We can not see the problem. Are there any other methods of removing CWS besides CWShredder, just wondering if there are any other possible methods for a permanent fix? Adam-----------------------------------------------------------------------------------------------Logfile of HijackThis v1.97.7Scan saved at 12:24:06 PM, on 7/2/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Microsoft Hardware\Mouse\point32.exeC:\Program Files\Roxio\WinOnCD\DirectCD\DirectCD.exeC:\WINDOWS\System32\ctfmon.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Common Check This Out Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window.On the right portion of the window

A case like this could easily cost hundreds of thousands of dollars. Help us fight Enigma Software's lawsuit! (Click on the above link to learn more) Become a BleepingComputer fan: FacebookFollow us on Twitter! Back to top #27 fivestar fivestar Topic Starter Members 22 posts OFFLINE Local time:06:07 PM Posted 06 July 2004 - 01:33 PM I think I was able to edit MOVEit.bat

Click here to Register a free account now!

I do not see anything in the log that coincides with these types of infections? You should then double click on cwshredder.exe again and click on the "FIX" button (not the "Scan only" button) and let it scan your computer.To get the best results it is It's highly reccomended to use programs that protect you from spyware infection. The video did not play properly.

Everyone else please begin a New Topic. 0 Back to Virus, Spyware, Malware Removal · Next Unread Topic → Similar Topics 0 user(s) are reading this topic 0 members, 0 guests, Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. A Notepad window will open with the contents of this log. this contact form Total of file sizes: 66,048 bytes 64.50 K --a-- W32i APP ENU 5.1.2600.0 shp 66,048 06-27-2004 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription

Help us fight Enigma Software's lawsuit! (Click on the above link to learn more) Become a BleepingComputer fan: FacebookFollow us on Twitter! You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".The tool may need to restart your computer to finish the cleaning process; General questions, technical, sales and product-related issues submitted through this form will not be answered. Then copy and paste the link to this topic into the body of the message and send the email.

If we have ever helped you in the past, please consider helping us. C:\WINDOWS\SYSTEM32\DLLCACHE\ notepad.exe Sun Jun 27 2004 8:35:26p A.... 66,048 64.50 K 1 item found: 1 file, 0 directories. Sniffed -> C:\JUNKXXX\COMCFK.222 **File C:\JUNKXXX\COMCFK.222 0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami 0000DED3: 63 65 53 65 74 Contacts About Web User Contact Us Advertising Info Top 10 Website - HitWise 2008 Follow Web User on Twitter Join the Web User Facebook group Watch the Web User Youtube channel

It is Forum Policy that we only help home users in the HJT Forum and your machine clearly comes from a corporate environment. Register now! Then try editing moveit.bathttp://www.bleepingcomputer.com/files/winfiles/notepad.zip Lawrence Abrams Don't let BleepingComputer be silenced. Plz help me Logfile of HijackThis v1.99.1 Scan saved at 8:36:20 PM, on 11/3/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe

A----- COMCFK .222 0000E000 20:35.40 27/06/2004 move C:\WINDOWS\System32\COMCFK.DLL C:\junkxxx\COMCFK.DLL --a-- W32i - - - - 57,344 06-27-2004 comcfk.222 A C:\junkxxx\COMCFK.222 File: CRC-32 : D5C9FB2E MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249 Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. I honestly have no clue how to solve this problem, so I posted here for help from the pros. Several functions may not work.

Thanks Back to top #6 Grinler Grinler Lawrence Abrams Admin 42,756 posts ONLINE Gender:Male Location:USA Local time:06:07 PM Posted 29 June 2004 - 01:19 PM Yes there are.