Home > My Hijack > My Hijack Log Please Help

My Hijack Log Please Help

When I deleted one of those files and restarted the computer it asked me to activate windows!! EDIT: Oh I just read that lavasoft site a little more thoroughly and saw that I was supposed to upload the actual file.. Staff Online Now crjdriver Moderator Drabdr Moderator Triple6 Moderator DaveA Trusted Advisor Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home And when I submit those files what am i supposed to put in the information part, because it wont let me submit without info. his comment is here

I deleted the oqlgqto.exe file Here is the latest log: Logfile of HijackThis v1.98.2 Scan saved at 6:54:23 PM, on 9/10/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 Preview post Submit post Cancel post You are reporting the following post: hijackthis log - Please help This post has been flagged and will be reviewed by our staff. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O8 - Extra context menu item: C:\WINDOWS\SYSTEM32\elitesav32.exe: FSG!

All Rights Reserved. Register now! Please print these directions and then proceed with the following steps in order.Step #1Download Cwshredder.exe and save it to a folder of its own. Privacy Policy & Cookies Legal Terms We use cookies to ensure that we give you the best experience on our website.

  • Exit Spy Sweeper.
  • Follow Us Facebook Twitter Help Community Forum Software by IP.BoardLicensed to: What the Tech Copyright © 2003- Geeks to Go, Inc.
  • tutorial: HJT Tutorial It is possible to restore things accidentally "fixed".
  • Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file) O9 - Extra 'Tools' menuitem:
  • Reboot when installed and return to make sure there are no others.
  • It's free.
  • and fix these items: R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O2 - BHO: jimmyhelp.CBrowserHelper - {E5EAB580-233E-466D-AA73-18F22978782D} - C:\WINNT\dolh.dll O4 - HKLM\..\Run: [uxiy] C:\WINNT\oqlgqto.exe O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D}
  • Quote Report Back to top Post a reply Unread posts or replies No unread posts or replies Unread Posts (Read Only Forum) No Unread Posts (Read Only Forum) Forum

Click on Sweep and allow it to fully scan your system. The Windows Advanced Options Menu appears. Download Hijack This! First, try going to: Start > Control Panel > Add/Remove Programs, then remove: WebHancer Reboot afterwards.

Try What the Tech -- It's free! Files Found in system Folder............ ------------------------ C:\WINDOWS\system32\AUNPS2.dll: UPX! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! We keep you safe and we keep it simple.

Several functions may not work. Be that as it may, but you should ensure that an adequate antivirus program is installed, set to automatically update and to perform continual background scanning. Toolbar", as it is checked by default during CCleaner Setup Download Free Trial of Spysweeper Install it using the Standard Install option. (You will be asked for your e-mail Everytime Derbiz installs itself I delete the desktop icon and either one of aforementioned files that I find in SYSTEM32.

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Free malware removal help and training has remained a constant. Already have an account? Log is attached in .txt format.

C:\WINDOWS\system32\elitersk32.exe: FSG! this content Please re-enable javascript to access full functionality. Download Hijack This! C:\WINDOWS\sideb.exe: UPX!

Ok. Want to help others? Logfile of HijackThis v1.97.7 Scan saved at 2:40:15 PM, on 1/20/04 Platform: Windows 98 Gold (Win9x 4.10.1998) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\EXPLORER.EXE weblink Back to top #8 packrunner packrunner New Member New Member 8 posts Posted 12 February 2006 - 02:20 PM Much better.

Here is my hijack logPlease help me get rid of these menaces.Thanks!Logfile of HijackThis v1.99.0Scan saved at 11:38:10 AM, on 1/19/2005Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ELSBLaunch.lnk I must have screwed something up in the process...

Discussions cover how to detect, fix, and remove viruses, spyware, adware, malware, and other vulnerabilities on Windows, Mac OS X, and Linux.Real-Time ActivityMy Tracked DiscussionsFAQsPoliciesModerators General discussion hijackthis log - Please

Run Pocket Killbox again and paste the full file path in the box and click on Delete on Reboot. Sign In Create Account Body Background skin color theme reset What the Tech Search Advanced Search section: Google This topic Forums Members Help Files Downloads Unreplied Topics View New Content Check your browser settings here: A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web. No, create an account now.

Clear out Cookies. Oct 28, 2006 #2 (You must log in or sign up to reply here.) Show Ignored Content Topic Status: Not open for further replies. C:\WINDOWS\usxhs.exe: UPX! Loading...

Below are the results from what you asked me to do earlier. Run Spysweeper: Click on "Options > Sweep Options" and check "Sweep all Folders on Selected drives". The computer then begins to start in Safe mode. Started by Daven81 , May 19 2005 05:02 AM Please log in to reply 1 reply to this topic #1 Daven81 Daven81 Members 23 posts OFFLINE Local time:10:50 PM Posted

Show Ignored Content Page 1 of 2 1 2 Next > As Seen On Welcome to Tech Support Guy! Click here to join today! SHOW ME NOW CNET © CBS Interactive Inc.  /  All Rights Reserved. WE'RE SURE THAT YOU'LL LOVE US!

Logfile of HijackThis v1.99.1Scan saved at 10:35:31 PM, on 5/17/2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exeC:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXEC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\Program Files\Norton Back to top #5 packrunner packrunner New Member New Member 8 posts Posted 11 February 2006 - 05:41 PM Again, Thanks a bunch! Follow safe Internet practices: 1. Rescan with HijackThis and post a new log here.

Next, after cleaning, let it Reboot Next go to Start- Search and scrolldown using the scroll bar on the right. If you wish to show your appreciation, then you may donate to help keep us online. C:\WINDOWS\system32\qvgbq.dat: UPX! Oh.

It seems like it reappears when the computer is shutdown for a long period of time (like over night) and Im almost sure it will come back, so after someone tells However, because of reading this thread I can see from the rkfiles scan that the elitedmz32.exe does exist along with alot of others but I just can't find them and Killbox Make sure you update it first though. Username Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy