This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a copy of my log. I hope I did this right, and posted in the right section. This is my first time on here. So, If you see anything on my log that I need to take care of please let me know. Thanks so very much. (sigh…)



Logfile of HijackThis v1.99.1
Scan saved at 1:46:20 PM, on 2/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Greg\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS13
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O15 - Trusted Zone: *.af.mil
O16 - DPF: Yahoo! Graffiti -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
Hello annab, Welcome to TomCoyote forum. If you still need help please follow these directions.

1) HijackThis.exe is still in a Temp folder. It needs a permanent folder to save backups and logs. If you want to run it from Docs & Settings, go there and point your mouse at a blank spot and RIGHT click it. Make a NEW FOLDER, name it HJT and then move HJT.exe and any logs you see into that new folder. Once this is done you may delete everything in that Temp folder, NOT THE FOLDER just the contents.

2) You have no antivirus software running. WinXp SP2 does not provide this. I suggest you get something in place right away. Here are three free programs. I suggest AVG by Grisoft.
http://free.grisoft.com/freeweb.php
http://www.avast.com/eng/avast_4_home.html
http://store.ca.com/dr/v2/ec_main.entry25?…5715&CID;=179825

3) I see no firewall running, so please make sure you have the SP2 firewall activated. If you wish a link to free firewalls, please let me know.

4) This item shows up as adware, information is in the link, unless you wish to keep it, it will be removed.
http://www.trendmicro.com/vinfo/grayware/g…SNAME=ADW_POP.A
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab

5) You really have little showing in the log, I hate to take more :( but there are a few things that need to go. One of these items is in your 015 Trusted Zone: O15 - Trusted Zone: *.af.mil. I am not sure what it is, but I suggest you allow nothing in your Trusted Zone. These are hard to remove, so I will have you do the HJT fix in Safe Mode. Here are instructions for entering Safe Mode, make sure you follow the directions for your Operating System:
http://www.bleepingcomputer.com/forums/tutorial61.html

6) You will wish to print these instructions, you will not be able to see this page in Safe Mode.

7) Follow the instructions to start the computer in safe mode.
Scan with HijackThis and put a check in the box in front of these line items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
(If you do not want RoadRunner to be your start page, check the next item)
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O15 - Trusted Zone: *.af.mil
O16 - DPF: Yahoo! Graffiti -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab

Click on "Fix Checked", empty the recycle bin and restart the computer back to normal mode. Surf a little to see how you are running, then use ADD REPLY, stay in this thread and post a new log along with your comments. I will have some great information about free programs to keep you clean and safe online.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
No response since 3/3/05


If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI