This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Not In Control

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't understand whats going on with my computer. All the settings from the registry to personal display are not by me. this is my home private laptop, not in any network where there is an administrator who can set permissions and rights to control my actions. . .but strangely enough actually ..there is. I have been not been able to rid myself of this matter. and when I've tried,I've only done more damage to myself and computer,and have had to format and reload orig. op system disk that came with computer, which I think has been written on or changed somehow(everyone tells me thats not possible)and just reloads the same problems. I need help to clarify whether or not I should be institutionalized or can I catch the rat. I went ahead and got hijack and ran scan and log since that seemed to be a common request from most I've seen.I will paste it below,and if I been presumptuous or offended and screwed up my dabue please except my apology and correct my actions on how to use this site correctly.
Thanks so much-whatthehey. Logfile of HijackThis v1.99.1
Scan saved at 10:34:46 AM, on 5/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS1\System32\smss.exe
D:\WINDOWS1\system32\winlogon.exe
D:\WINDOWS1\system32\services.exe
D:\WINDOWS1\system32\lsass.exe
D:\WINDOWS1\system32\svchost.exe
D:\WINDOWS1\system32\svchost.exe
D:\WINDOWS1\system32\svchost.exe
D:\WINDOWS1\system32\spoolsv.exe
D:\WINDOWS1\Explorer.EXE
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\Program Files\Common Files\AOL\1179921097\ee\aolsoftware.exe
d:\program files\common files\aol\1179921097\ee\aim6.exe
D:\WINDOWS1\System32\winhlp32.exe
D:\WINDOWS1\winhlp32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKCU\..\Run: [Aim6] "D:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - -{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - -{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - -{9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\WINDOWS1\system32\shdocvw.dll
O12 - Plugin for .pdf: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: -{4CCA4E80-9259-11D9-AC6E-444553544200} - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_5.cab
O16 - DPF: -{AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1174935581109
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1174935777171
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - AppInit_DLLs:
O20 - Winlogon Notify: docddr - docddr.dll (file missing)
whatthehey,

Welcome to the forum. I need to see an entire HJT log before I can really evaluate it, so do a couple of things for me.

Right click on the HJT Icon, (looks like a red stick of dynamite with a plunger) and rename it to Scanner.exe.
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use [external image: Posted Image] and not [external image: Posted Image]
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI