Hijack This log - please review (computer VERY slow now) Discussion in 'Virus & Other Malware Removal' started by Lori713, Oct 14, 2003.

Thank you for signing up.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't or read our Welcome Guide to learn how to use this site. Yes, my password is: Forgot your password? It is important to exercise caution and avoid making changes to your computer settings, unless you have expert knowledge.

Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! Towers 2.0 - http://download.games.yahoo.com/gam...ts/y/ywt0_x.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs5b.instantservice.com/jars...erxsigned33.cab Then restart. When it is finished close CCleaner.Step #6Reboot normally and run at least 2 of the following on-line virus scans:Bitdefender <<(22) Invalid argument The remote host or network may be down.

Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone.

Essential piece of software. How to Analyze Your Logfiles No internet connection available? I'm above average with tech, but Hijack This is above my level of knowledge.

However, since only Coolwebsearch does this, it's better to use CWShredder to fix it.O20 - AppInit_DLLs Registry value autorunWhat it looks like: O20 - AppInit_DLLs: msconfd.dll What to do:This Registry value

Once reported, our staff will be notified and the comment will be reviewed. the yahoo things are so when yahoo games are played, the main files don't have to be re-downloaded..

Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: Yahoo! Close Report Offensive Content If you believe this comment is offensive or violates the CNET's Site Terms of Use, you can report it below (this will not automatically remove the comment). Sent to None. check over here Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLLO2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLLO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

It works quickly to generate reports and presents them in an organized fashion, so you can sift through them to find items that may be trying to harm your system. Hijackthis Alternative Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra button: Real.com (HKLM) O9 - Extra button: MoneySide (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O16 - Increasingly worse issues « Reply #3 on: July 05, 2011, 06:30:28 PM » Are you haveing any redirection problems etc?Are you usuing Comodo firewall?Please download aswMBR from here http://public.avast.com/~gmerek/aswMBR.htm1)Double click the

Thank You for Submitting a Reply, ! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO2 - BHO: (no name) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C:\PROGRAM FILES\POPUP ELIMINATOR\AUTODISPLAY401.DLL (file missing)O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLLWhat to do:If Here's the logs. Hijackthis 2016 So far only CWS.Smartfinder uses it.

Reboot your computer normally, start HijackThis and perform a new scan. Advertisement Lori713 Thread Starter Joined: Sep 8, 2003 Messages: 50 My computer has become increasingly slow, so slow that it takes a full minute to open up a browser window. Re: Please review Hijack This log. http://splodgy.org/hijackthis-log/hijackthis-log-for-review-thanks.php Please enter a valid email address.

Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs5b.instantservice.com/jars/customerxsigned33.cab O16 - DPF: Thanks again fellas. if you goto start menu -> programs -> accessories -> system tools -> disk cleanup that will clean your computer of any temporary files that are present on you hard drive. Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing.

HiJackThis Web Site Features Lists the contents of key areas of the Registry and hard driveGenerate reports and presents them in an organized fashionDoes not target specific programs and URLsDetects only

Logfile of HijackThis v1.97.3 Scan saved at 8:31:29 PM, on 10/14/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Have you cleaned out your internet files lately? Please don't fill out this field. Article How to View and Analyze Page Source in the Opera Web Browser List Top Malware Threats and How to Protect Yourself Get the Most From Your Tech With Our Daily

so what else will they do? Then if you run HJT! Bottom Line Trend Micro HijackThis is a good tool for experienced users who need to eliminate malware that's dug in deep. For the R3 items, always fix them unless it mentions a program you recognize, like Copernic.F0, F1, F2, F3 - Autoloading programs from INI filesWhat it looks like:F0 - system.ini: Shell=Explorer.exe

