Home > Hijackthis Log > Hijackthis Log (virtual Bouncer?)

Hijackthis Log (virtual Bouncer?)

Here is a logLogfile of HijackThis v1.97.7Scan saved at 12:14:36 AM, on 5/26/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exec:\Program Files\Common Files\Symantec Shared\ccSetMgr.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exec:\Program Files\Norton Everyone else please begin a New Topic. Sorry marcs41.You were faster on the keyboard than I was. All links to programs are in my signature. check over here

Reboot back to normal mode and post the contents of both the log.txt and log1.txt in your next post. **Note**Also try running that findit's tool in safe mode and see if Thanks again Attached Files rkflog.txt (899 Bytes, 23 views) remlog.txt (671 Bytes, 21 views) 04-30-2005, 11:15 AM #7 greyknight17 TSF Team, Emeritus Join Date: Jul 2004 Location: We are going to run this in 2 steps. Register now while it's still free! https://www.bleepingcomputer.com/forums/t/15368/derbiz-virtual-bouncer-etc-etc/

Poor printing by HP LaserJet 1020 Scammer took control of laptop Same exact laptops, Different... 'Captcha verification' didn't show... So I ran HJT, fixed the 02 line with nail and the line with bolger. Join your peers on the Internet's largest technical computer professional community.It's easy to join and it's free. RE: Hijackthis Log, Plz Advise Pop-up Problem cmeagan656 (TechnicalUser) 15 Jan 04 20:24 Oops.

Talk With Other Members Be Notified Of ResponsesTo Your Posts Keyword Search One-Click Access To YourFavorite Forums Automated SignaturesOn Your Posts Best Of All, It's Free! I will take a look at it. « Help!!! - Searchweb2 Hijack | Another Poor Guy Getting The WIN MIN » Thread Tools Show Printable Version Download Thread Search Modems' have short term memory [CharterSpectrum] by ssgcallen300. Router as access point; does speed of CPU matter much? [WirelessNetworking] by cpufrost265.

Ran Thread Tools Search this Thread 08-25-2004, 09:42 PM #1 jag6913 Registered Member Join Date: Aug 2004 Posts: 2 OS: xp I am at a lost been Then I ran HJt and here is the log. Both Very Highly Recommended Finally, go to Windows Update and ensure that ALL Critical updates are installed. -- Please respond in the same thread. http://newwikipost.org/topic/eGTfokNiNfw45MEjwA8rRmW9OVmGWE6o/vitrual-bouncer-and-others.html Unzip/extract the files inside to a folder on your desktop. 2.

Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List Put a check mark in front of the following lines if they still show:R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blankR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =R1 - HKCU\Software\Microsoft\Internet Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra You might want go to this page at Jim Eshelman's site, here: http://aumha.org/a/noads.htm or here: http://inetexplorer.mvps.org/parasite.htm and wait a little bit (be patient), while an analysis of a number of possible

log.Cheers. read this article The time now is 03:42 PM. -- Mobile_Default -- TSF - v2.0 -- TSF - v1.0 Contact Us - Tech Support Forum - Site Map - Community Rules - Terms of My log...virtual bouncer, redirect to other websites This is a discussion on My log...virtual bouncer, redirect to other websites within the Resolved HJT Threads forums, part of the Tech Support Forum Zazeen TV freezing on start.ca ISP [CanadianBroadband] by jackie999© DSLReports · Est.1999feedback · terms · Mobile mode

or read our Welcome Guide to learn how to use this site. http://splodgy.org/hijackthis-log/hijackthis-log-take-a-look.php See below. IST, Autoupdate and INCREDIFIND were not there. Restart your computer and uncheck the same box to enable System Restore.

RIP siljaline [Security] by fourboxers1049. or read our Welcome Guide to learn how to use this site. Join UsClose ThemeWelcome · log in · join Show navigation Hide navigation HomeReviewsHowChartsLatestSpeed TestRun TestRun PingHistoryPreferencesResultsRun StreamsServersCountryToolsIntroFAQLine QualitySmoke PingTweak TestLine MonitorMonitor GroupsMy IP isWhoisCalculatorTool PointsNewsNews tip?ForumsAll ForumsHot TopicsGalleryInfoHardwareAll FAQsSite FAQDSL FAQCable this content Spybot and adware were also updated.

Now when I bring up IE it goes stright to about: blank and there is a new tool bar. Please make sure system restore is enabled by right clicking on My Computer and go to Properties->System Restore and check the box for Turn ON System Restore. This is necessary to ensure you have backups should anything go wrong.then go to add/remove programs and see if there is an entry for WinTools.

The log file will be C:\log.txt and bad1.txt **Note** Each tool uses log.txt as it’s output file so make sure you save the entry’s from one tool before running the other

If they don't fix it then start here: Download HijackThis, free, here: http://209.133.47.200/~merijn/files/HijackThis.exe (Always download a new fresh copy of HijackThis [and CWShredder also] - It's UPDATED frequently.) You may also Post whatever questions you may have in the forum and we will take a look at it when we get to it. Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? Derfram ~~~~~~ Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear

Once in safe mode… Double click rkfiles.bat It will scan for a while, so please be patient. Lets try another tool.. No, create an account now. have a peek at these guys Think My PSU Is Failing Active Directory, GPO, OU doubts TMPIN1 extremely low temp?

You will do it at the end in safe mode.Then boot to safe mode.CTL-ALT-DEL and verify the following are not running. Be sure to close all instances of IE and OE. It will delete the files and remove the infection and then make a log of the files it finds. Click Apply and then OK.

If they are, end task on them:WTOOLSA.EXEWSUP.EXETB_SETUP.EXEThen close all windows and have hijackthis fix the following:C:\Program Files\Common files\WinTools\WToolsS.exeC:\Program Files\Common files\WinTools\WSup.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = »www.websearch.com/ie.aspx?tb_id=50032R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR0 Restart your computer. Once your clean we will turn this off and then create a new restore point. O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged You may also get it here if that link is blocked: http://www.zerosrealm.com/downloads/CWShredder.zip BE SURE that you get v.158 or later! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra button: IC 3.0 - {bba9a1cb-c90a-4912-8f01-dfa51a2b4102} - C:\Program Files\Aladdin Systems\Internet Cleanup\ic3hlpr.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll O9 Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

http://sarc.com/avcenter/venc/data/adware.virtualbouncer.html HTH ~Silj -- siljaline MS - MVP Windows (IE/OE) AH-VSOP ________________________________ Anti-Parasite Definition Updates http://forum.aumha.org/viewforum.php?f=31 (Reply to group, as return address is invalid - that we may all benefit)