Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
| Guest_golfer59_* |
Nov 13 2003, 07:45 PM
Post
#1
|
|
Guests |
Logfile of HijackThis v1.97.6 Scan saved at 7:44:43 PM, on 11/13/2003 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\EPOAgent\naimas32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\EPOAgent\naimag32.exe C:\Program Files\AIM\aim.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\WINNT\Profiles\Administrator\Local Settings\Temp\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.fastwebfinder.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fastwebfinder.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.fastwebfinder.com/sp.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fastwebfinder.com/hp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.fastwebfinder.com/sp.php O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\dnse.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NaimAgent_UI] C:\EPOAgent\naimag32.exe O4 - HKCU\..\Run: [ld] C:\WINNT\ld.exe O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: AIM (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O13 - WWW. Prefix: http:// O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7890.3579398148 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab |
|
|
|
Nov 13 2003, 08:13 PM
Post
#2
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 20 Joined: 28-June 03 Member No.: 116 |
Hi golfer59-
Close all browsers and rerun HJT. Check and click fix checked for all of the following- R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.fastwebfinder.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fastwebfinder.com/sp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.fastwebfinder.com/sp.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fastwebfinder.com/hp.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.fastwebfinder.com/sp.php O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\dnse.dll This one I'm not sure what it is. Maybe you do? O4 - HKCU\..\Run: [ld] C:\WINNT\ld.exe |
|
|
|
| Guest_Guest_* |
Nov 13 2003, 08:32 PM
Post
#3
|
|
Guests |
Hi OlTramp,
Thank you very much. I removed all of the entires and I believe IE is operating normally again. Thanks a lot, I really appreciate your help. golfer59 |
|
|
|
Nov 13 2003, 08:39 PM
Post
#4
|
|
![]() - ![]() ![]() ![]() ![]() Group: Visiting Staff Posts: 661 Joined: 10-May 03 Member No.: 4 |
You should be able to delete this file:
C:\WINNT\ld.exe now that you have fixed its O4 startup. |
|
|
|
| Guest_golfer59_* |
Nov 14 2003, 10:56 AM
Post
#5
|
|
Guests |
cnm,
Thanks. I have removed the file. golfer59 |
|
|
|
Nov 14 2003, 11:04 AM
Post
#6
|
|
![]() - ![]() ![]() ![]() ![]() Group: Visiting Staff Posts: 661 Joined: 10-May 03 Member No.: 4 |
Glad we could help.
If you need this topic reopened, please request this by sending Email to Zero or Email to cnm or Email to Coyote Choose only one of the above Include your post user name and detail why you need it reopened with a valid link to your post, any bad links or emails that are not from the original poster will be deleted without response. Others please start a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
8 | Kendo | 3,821 | 27th June 2003 - 11:54 PM Last post by: Galadriel |
|||
![]() |
3 | exposedone | 2,320 | 24th May 2005 - 07:19 PM Last post by: pskelley |
|||
![]() |
4 | burnt horns | 1,637 | 15th March 2005 - 07:46 AM Last post by: pskelley |
|||
![]() |
7 | chrose | 1,721 | 13th October 2006 - 02:11 PM Last post by: Micah_6:8 |
|||
![]() |
36 | DBuisson | 5,103 | 25th March 2005 - 04:59 PM Last post by: pskelley |
|||
|
Time is now: 19th May 2013 - 08:28 AM |