Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [RESOLVED] HJT and ewido logs frustrating problem

[Fixed] Hijackthis! Logs - [RESOLVED] HJT and ewido logs frustrating problem posted in the Security & Safety forums; Hey we're the same age, :cool: kewl. LOL OK, that's great. Don't be embarrased, I'm impressed that you knew enough to try doing this on your own with HijackThis.de OK, ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 11-10-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,694
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey we're the same age, :cool: kewl. LOL

OK, that's great. Don't be embarrased, I'm impressed that you knew enough to try doing this on your own with HijackThis.de

OK, here is what I would like you to do. I would like you to do these in Safe Mode, so you should print out the instructions first.

Please download Spy Sweeper from my signature. Install it and update the program. Dowload RegSupremePro from my sig. Install it, exit out. Download but do not install Hoster, you will use that later.

Next please make sure that you have disabled the System Restore on your PC, and that you have all files and folders showing, refer to instructions in previous post.

Now please boot into Safe Mode, run CCleaner make sure that all options are checked including Advanced, click on OK to each warning. Click on Analyze, let it run. When it has finished, click on Run Cleaner. exit out of CCleaner when it has finished.

Next run Spy Sweeper, click on Options, Sweep Options, make sure all drives are selected, and all options are checked except Do Not Sweep System Restore Folders. Click on Sweep Now, and then the Start button. Let it run. When it has finished, allow it to quarantine everything that it locates.

Now unzip the Hoster file, Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.

Next run your ewido, noting any item it is unable to fix.

Now run HijackThis, fix the following if they are still there, delete the file in bold.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:7900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.un td.com;127.0.0.1;localhost;*microsoft.com;*windows update.com;*wustat.windows.com;*.pogo.com;*.worldw inner.com;*test-speed.com;liveupdate.symantecliveupdate.com;*syman tec.com;*.nai.com;*.networkassociates.com;*photosi te.com;*.dir.untd.com;<local>

O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\f60olgd3160.dll
Run CCleaner again, and then reboot back into normal mode. Now run RegSupremePro, it will want to make a back up of your registry, let it, naming for today's date. Once it has finished, click on Registry Cleaner, choose Aggressive and then click Start. Once it has finished, click on Select, and choose All, then click on Fix. Allow it to fix everything that it finds.

Now run another HJT log and post it back here.

Look forward to your reply.

TTFN

LGW


  #9  
Old 11-10-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 8
Darsus - See this Members User comments on their Profile page
Default My Lady,

Thank you for taking all this time. I will follow your instructions.


__________________
Pentium 4 Celeron 1.7GHZ
512 RAM
WIndows XP
  #10  
Old 11-10-2005
Bronze Member
 
Join Date: Nov 2005
Posts: 8
Darsus - See this Members User comments on their Profile page
Default

Lady,

Should I be using "Quarantine" and "Immunize" when I run adware SE and Spybot? AND should I be running these in safe mode? .....So much for my day off....


__________________
Pentium 4 Celeron 1.7GHZ
512 RAM
WIndows XP
  #11  
Old 11-10-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

@Darus Don't fix this entry with hjt:

O17 - HKLM\System\CCS\Services\Tcpip\..\{489E7FB5-7D42-4162-BDA4-B0AF737276A2}: NameServer = 64.136.28.120 64.136.20.120

I have removed it from the fix list.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #12  
Old 11-10-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,694
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Guys,

@Darsus, sorry about your day off sir, but think how well your computer will be running. If you also have Adaware and Spybot, by all means use them as well, make sure their updates are current before booting into safemode. I usually run them after ewido, before HJT.

@Joe, don't leave us hangning Joe, you know I bow down before your superior knowledge. Where did I make the mistake? The file didn't associate with NetZero, please tell us so we can learn. :kiss:

TTFN

LGW


  #13  
Old 11-10-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

http://samspade.org/t/lookat?a=64.136.28.120+


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #14  
Old 11-10-2005
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,694
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

OK, is Juno a provider for NetZero? The 017 entries always make me crazy.

Should I be looking at who is instead of googling an 017? Thanks Joe, you're knowledge and guidance is as always greatly appreciated.

TTFN

LGW



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 01:07 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Latin for Children
Memoria Press produces Latin, Logic & Rhetoric texts for children. Classical Education & Trivium Pursuit.

Cheap Loan
Cheap loan information from the experts at Ocean Finance.

Farm
Small farm community and resource center, farmers helping farmers farm better through collaborative efforts.