Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Hijack this log

[Fixed] Hijackthis! Logs - [Resolved] Hijack this log posted in the Security & Safety forums; I'm looking for what is causing this toolbar to show up in IE, with a red x that says "remove toolbar", a search option, and a few drop down menus....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-20-2005
New Poster
 
Join Date: Dec 2005
Posts: 2
TheDwardler - See this Members User comments on their Profile page
Default [Resolved] Hijack this log

I'm looking for what is causing this toolbar to show up in IE, with a red x that says "remove toolbar", a search option, and a few drop down menus.
Attached Files
File Type: log hijackthis.log (9.0 KB, 2 views)


  #2  
Old 12-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Dwardler , welcome to PCHF.



Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner


Please download FixWareout from one of these sites:

http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, Hijack This will launch. Close Hijack This, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.

Then boot in safemode (hit f8 when booting up) and fix these with hjt:
(if still present)

O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\opssw.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\opssw.dll
O4 - HKLM\..\Run: [Testimonials] ATLIEHELPER.exe
O4 - HKLM\..\Run: [MONITER] clamav.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C8A39DA-4875-48E3-A846-5F1CA3EE7E99}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EA4426F-1528-4007-BFA4-5A89C07B1AFD}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F26BE47-E50C-40B1-9807-B36B8433F21B}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A914708-184F-48E6-81AE-17B6425EA1B8}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{B4C1B459-0043-420B-B191-B320E3B13266}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC560ED3-43FC-4909-B64F-F0F39AF5EE83}: NameServer = 85.255.113.147,85.255.112.23
O17 - HKLM\System\CS1\Services\Tcpip\..\{5C8A39DA-4875-48E3-A846-5F1CA3EE7E99}: NameServer = 85.255.113.147,85.255.112.23
Delete the file in bold , and run Ccleaner.


Finally, reboot and please post the contents of the logfile C:\fixwareout\report.txt and a new hjt log.




Also i see that you have the windows messenger service enebled , it is recommended to disable that:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state ? running or disabled ? that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.
And there is also a legit toolbar from comcast , if you dont want that one either then uninstall the Comcast Toolbar/support software in add/remove programs.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fixed] My Hijack and Ewido reports are ready tungvu [Fixed] Hijackthis! Logs 8 12-11-2005 10:33 PM
Re: WinAntiSpyware 2005 Hijack 4sarge Spyware / AdWare 1 09-18-2005 11:23 PM
[Answered] cant find help anywhere. can someone fix my msn/broser hijack problem? robstradamus Spyware / AdWare 1 08-31-2005 11:01 AM
HiJack This! Logs Go One Forum Up! Thank You! Spaceman3750 Spyware / AdWare 0 08-02-2005 08:53 PM

All times are GMT +1. The time now is 05:37 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top