Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum

 
Closed TopicStart new topic
> Review Hijack Log, Hijack log from hijack this.
Guest_golfer59_*
post Nov 13 2003, 07:45 PM
Post #1





Guests






Can anyone assist me with identifying what to delete? Thanks in advance.

Logfile of HijackThis v1.97.6
Scan saved at 7:44:43 PM, on 11/13/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\EPOAgent\naimas32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\EPOAgent\naimag32.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\Profiles\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.fastwebfinder.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fastwebfinder.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.fastwebfinder.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fastwebfinder.com/hp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.fastwebfinder.com/sp.php
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\dnse.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NaimAgent_UI] C:\EPOAgent\naimag32.exe
O4 - HKCU\..\Run: [ld] C:\WINNT\ld.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O13 - WWW. Prefix: http://
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7890.3579398148
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Go to the top of the page
 
+Quote Post
OlTramp
post Nov 13 2003, 08:13 PM
Post #2


Authentic Member
**

Group: Authentic Member
Posts: 20
Joined: 28-June 03
Member No.: 116



Hi golfer59-
Close all browsers and rerun HJT. Check and click fix checked for all of the following-
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.fastwebfinder.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fastwebfinder.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.fastwebfinder.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fastwebfinder.com/hp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.fastwebfinder.com/sp.php
O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINNT\dnse.dll
This one I'm not sure what it is. Maybe you do?
O4 - HKCU\..\Run: [ld] C:\WINNT\ld.exe
Go to the top of the page
 
+Quote Post
Guest_Guest_*
post Nov 13 2003, 08:32 PM
Post #3





Guests






Hi OlTramp,

Thank you very much. I removed all of the entires and I believe IE is operating normally again.

Thanks a lot, I really appreciate your help.

golfer59
Go to the top of the page
 
+Quote Post
cnm
post Nov 13 2003, 08:39 PM
Post #4


-
****

Group: Visiting Staff
Posts: 661
Joined: 10-May 03
Member No.: 4



You should be able to delete this file:
C:\WINNT\ld.exe
now that you have fixed its O4 startup.
Go to the top of the page
 
+Quote Post
Guest_golfer59_*
post Nov 14 2003, 10:56 AM
Post #5





Guests






cnm,

Thanks. I have removed the file.

golfer59
Go to the top of the page
 
+Quote Post
cnm
post Nov 14 2003, 11:04 AM
Post #6


-
****

Group: Visiting Staff
Posts: 661
Joined: 10-May 03
Member No.: 4



Glad we could help. smile.gif

If you need this topic reopened, please request this by sending
Email to Zero or
Email to cnm or
Email to Coyote
Choose only one of the above
Include your post user name and detail why you need it reopened with a valid link to your post, any bad links or emails that are not from the original poster will be deleted without response.

Others please start a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts   8 Kendo 3,821 27th June 2003 - 11:54 PM
Last post by: Galadriel
No New Posts   3 exposedone 2,320 24th May 2005 - 07:19 PM
Last post by: pskelley
No New Posts   4 burnt horns 1,637 15th March 2005 - 07:46 AM
Last post by: pskelley
No New Posts   7 chrose 1,721 13th October 2006 - 02:11 PM
Last post by: Micah_6:8
No new   36 DBuisson 5,103 25th March 2005 - 04:59 PM
Last post by: pskelley

RSS Time is now: 19th May 2013 - 08:28 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy