Home > Is My > Is My HTJ Log Clean?

Is My HTJ Log Clean?

The files in System Restore are protected to prevent any programs from changing those files. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - Next, clean all temps, cookies, offline pages, etc. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Jump this contact form

Download it to your Desktop http://download.drwe... Advertisements do not imply our endorsement of that product or service. About Us Contact Us Donate Advertising Vendor Program Terms of Service API Newsletter Archive Community Forums Recent Articles Recommended Articles © 2002 - 2017 DaniWeb LLC 3825 Bell Blvd., Bayside, NY Do you know where your recovery CDs are ?Did you create them yet ? https://forums.techguy.org/threads/is-my-htj-log-clean.415452/

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do. I did cleanmgr and restarted. That's what the forums are here for. On the Tools menu in Windows Explorer, click Folder Options.B.

Name the folder 'HijackThis' or 'HJT'.* Unzip to or copy and paste HijackThis.exe to the new folder.Step #2Start HijackThis and click the Scan button to perform a scan. Choose No if asked to reboot your computer. They will add 1000's of sites to your resticted zone and block some hijacks from happening. Click the View tab.C.

Show Ignored Content As Seen On Welcome to Tech Support Guy! Move the arrow down to Custom CleanUp!. Right click the MS AntisSpyware icon in the system tray and choose Shutdown Microsoft Anti-Spyware. Run HijackThis!, press Scan, and put a check mark next to all these:O4 - HKLM\..\Run: [EBF244F3] C:\WINDOWS\system32\rxextpdl.exeO4 - HKLM\..\Run: [BD6D4CF6] C:\WINDOWS\system32\1agte.exeO4 - HKLM\..\Run: [836C14C3] C:\WINDOWS\system32\dvDLco.exeO4 - HKLM\..\Run: [E00791F3] C:\WINDOWS\system32\oxxvi.exeO4 - HKLM\..\Run:

When I clicked to run it came up with this: dss.exe has encountered a problem and needs to close. (do you want a copy of the error report?) I deleted and Style Default Style Contact Us Help Home Top RSS Terms and Rules Copyright © TechGuy, Inc. Let's try the simple way 1 more time and see if we can get rid of it.Start HijackThis and click the Scan button to perform a scan. Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003042...all/xscan53.cabO16 - DPF: {D6526FE0-E651-11CF-99CB-00C04FD64497}

TechSpot is a registered trademark. Do this immediately! If it is run from Temporary folders the backups and HijackThis itself could be accidentally deleted if the Temporary folders are cleaned.* Please open My Computer* Double-click on Local Disk (C:)* Advertisement aznxdarkrice Thread Starter Joined: Oct 7, 2005 Messages: 29 i've recently been getting popups and a few days ago my comp deleted a virus (that i thought i had gotten

Unzip it to your desktop.Install the program. weblink I did everything you asked and here is my new log.Logfile of HijackThis v1.99.0Scan saved at 7:24:04 PM, on 1/12/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [Share-to-Web Thanks a lot!Just in case it is useful to others: These malwares prevent combofix and malwarebytes from installing or running.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Forums Recent Posts Members Members Quick Links Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - navigate here As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged

Please use them so that others may benefit from your questions and the responses you receive.OldTimer Back to top #5 tschlaegel tschlaegel Topic Starter Members 5 posts OFFLINE Local time:02:37 Ask a question and give support. Start your computer in Safe Mode.

Sign In Sign Up Browse Back Browse Forums Guidelines Staff Online Users Members Activity Back Activity All Activity My Activity Streams Unread Content Content I Started Search Malwarebytes.com Back Malwarebytes.com Malwarebytes

Do you know where your recovery CDs are ?Did you create them yet ? Double-click VundoFix.exe. Your log is clean. What does ...

Press Enter once to continue. Click "Replace on Reboot" and check the "Use Dummy" box.Paste this file into the top "Full Path of File to Delete" box.C:\WINDOWS\system32\pcutmuth.exeClick the "Delete File" button which looks like a stop Back to top #3 akryte akryte Topic Starter Members 5 posts OFFLINE Local time:01:37 AM Posted 12 January 2005 - 10:28 PM First of all, Thank You for the help. his comment is here All Rights Reserved.

I put a copy on my "cruzer" and tried to load it on this computer and it said the exact same thing. Join the community here, it only takes a minute. Do you know where your recovery CDs are ?Did you create them yet ? I have run Ad-aware and Cw Shredder with no luck.

Post your new log file back here using the Add Reply button and I will review it when it comes in.OT I do not respond to PM's requesting help. What software do you recommend to help prevent this? Should I wipe it clean and start over from scratch? It downloaded great and installed fine.

TechSpot Account Sign up for free, it takes 30 seconds. Open System Security Suite.B. click okay. If you see the above line in the log again then reboot your computer into Safe Mode and repeat these steps.If either the line was gone after your first reboot or

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cabO16 - DPF: Yahoo! Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

Jump Join our site today to ask your question.

Then, go and read the Viruses/Spyware/Malware, preliminary removal instructions. They came over, replaced it with a Dlink and PRESTO!