Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exeO23 - Service: avast! Hannu Full Member Posts: 131 My Hijackthis log - advice needed « on: March 19, 2008, 06:48:48 PM » Could someone please check my HJT log:Logfile of Trend Micro HijackThis v2.0.2Scan Only OnFlow adds a plugin here that you don't want (.ofb).O13 - IE DefaultPrefix hijackWhat it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW.

If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it.O16 - ActiveX Objects (aka Downloaded Program Files)What it looks like: O16 - DPF: Yahoo! You can use it regularly. C:\WINDOWS\JGRMLFS.EXE <-- Find this file in Explorer, right-click on it, and choose "Properties" from the pop-up menu. Treat with extreme care.O22 - SharedTaskSchedulerWhat it looks like: O22 - SharedTaskScheduler: (no name) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c:\windows\system32\mtwirl32.dll What to do:This is an undocumented autorun for Windows NT/2000/XP only

O7 - Regedit access restricted by AdministratorWhat it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:Always have HijackThis fix this, unless your system administrator has put this restriction into place.O8 - Extra marj0 Aug 29, 2004 #5 RealBlackStuff TS Rookie Posts: 6,503 A small party-barrel would be more like it! MOS...this bug's for you Re: My Hijackthis log - advice needed « Reply #4 on: March 19, 2008, 10:01:22 PM » Yes some are gone. I don't like the looks of that one!

Before I :knock: the hard-disk (I have the data, so it's not a major issue) ---- is there any way to recover? Seems like a virus hit me too See ya! Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so. Compare it to having a burglar in your house.

I suceeded in getting in machine thru safe mode, making myself an admin (great security!!!!), and owning/grabbing all users My Docs to CD. InCd.exe is a software I have installed with my cd-dvd writer) windows-virus 3Contributors 7Replies 8Views 12 YearsDiscussion Span 12 Years Ago Last Post by DMR 0 DMR 152 12 Years Ago Yes, my password is:

Let it do its thing and when its done, even if it crashes.When its done run hijackthis again post a new log Lawrence AbramsFollow us on Twitter!Follow us on FacebookCircle BleepingComputer Once the program opens, choose the "Find..." option under the Edit menu to bring up the search window, paste one of CLSIDs from the suspect filenames into the search box, perform Looking around my C:\windows I found more of these files.

Then I rebooted in Normal Mode, checked all the malicious entries in HJT log,hit fix and then did a third reboot. Article How to View and Analyze Page Source in the Opera Web Browser List Top Malware Threats and How to Protect Yourself Get the Most From Your Tech With Our Daily Hijackthis Log Analyzer TechSpot Account Sign up for free, it takes 30 seconds. Hijackthis Trend Micro See if Hijackthis can fix the following: O2 - BHO: (no name) - SOFTWARE - (no file) O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINDOWS\mslagent\4b_1,0,1,0_mslagent.dll (file missing) O2 - BHO:

skotzghirl View Public Profile Send a private message to skotzghirl Find all posts by skotzghirl #2 14-08-06, 22:22 Noviciate HijackThis Helper Join Date: Oct 2004 Location: Numpty HQ Please re-enable javascript to access full functionality. The Windows partition should be set to: 2GB for W98 or ME, 4-5GB for W2K and 10GB for XP. support component PDVDSERV.EXE - Power DVD remote control support INCD.EXE - Nero CD writing support fileJGRMLFS.EXE - WTF??

Try What the Tech -- It's free! Aug 28, 2004 #2 marj0 TS Rookie Topic Starter Thanks for your reply. I went ahead and ran HijackThis. Although there are others, the help available will be less.

How can I make it available? 0 OPDiscussion Starter Perrom 12 Years Ago I tried another way. If there is some abnormality detected on your computer, HijackThis will save them into a logfile. Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htmO8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htmWhat to do:If you don't recognize the name of the

One of the best places to go is the official HijackThis forums at SpywareInfo.

Join the community here. This will delete all the tools you have downloaded plus itself. * Create a new restore pointYou must be logged on to an administrator account Go to Start - All Programs If you have any suggestions or observations about this log please post them. For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat

Logged Windows 7 Home premium 64-bit SP1 / Hitman Pro / Macrium Reflect free oldman Avast Evangelist Massive Poster Posts: 4165 Some days..... D/L and run www.lavasoft.de 's Adaware as well as Spybot S&D from http://www.safer-networking.org/en/index.html Run the web-updates first on both programs after you install them, then run them. The upside is that I guess my neighbour owes me a beer! Bold Text Here"May the Wombat of Happiness snuffle through your underbrush." Ancient Aborigine blessing 0 OPDiscussion Starter Perrom 12 Years Ago good idea finding out what jgrmlfs.exe is up to!

The SDFix Folder will be extracted to %systemdrive% \ (Drive that contains the Windows directory - typically 'C:\SDFix') Open the SDFix folder in Safe Mode then double click the RunThis.bat file MOS...this bug's for you Re: My Hijackthis log - advice needed « Reply #12 on: April 25, 2008, 03:00:45 PM » Let's have a look and see if all traces are Click on Config and then click on Miscellaneous Tools. Looking around my C:\windows I found more of these files.

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. Hijackthis log deciphering needed Jun 18, 2010 Advise needed Hijackthis Log Jun 25, 2005 HJT log advice needed Apr 11, 2006 Add New Comment You need to be a member to I've emptied my Temporary Internet Files, I've deleted files created around the date/time of infection, I've searched for Java Virtual Machine as advised in other virus support posts related to MS03-011, All of the above are free which is the best privce I can think of!

It's nothing but a resource hog anyway.