Over 1 million tech questions and answers.

uh-oh - laptop was in checked baggage and now.....

Q: uh-oh - laptop was in checked baggage and now.....

Absolutely helpless laptop owner here. Hi and thanks for your help. In a recent business trip, I didn't realize I would have to take a puddle-jumper. There was no time to re-pack and grab my laptop before the airline grabbed my roll-on bag and tossed it in the cargo bay.

When I got home, the wireless icon and the wireless antenna seem to stayed on the plane. I'm stuck tethered to a USB connection to my router. HELP!

The antenna used to toggle off and on using the blue Fn key + the F2 key. Won't toggle anymore, but will the antenna indicator will occasionally light up as if the antenna was on.

The wireless antenna icon used to be found grouped with other icons under the Network Connections - LAN/High-Speed Internet. It's missing most of the time now.

The system tray will (rarely) show the message "Wireless Network Connection (Wireless)" connected. On the rare chance I fumble my way to Network Connections fast enough, the wireless network icon is there. When I unplug the USB connector, the wireless connection disappears in under 30 seconds. Most of the time the system tray message is "1394 Connection connected."

The laptop has to be connected via USB or Ethernet cable to get wireless on the road.

I'm uploading a word doc w/ a couple screenshots. It's the best I could cobble together! Any ideas? Is my goose cooked?

System info:
Tech Support Guy System Info Utility version 1.0.0.1
OS Version: Microsoft Windows XP Professional, Service Pack 3, 32 bit
Processor: Genuine Intel(R) CPU T2250 @ 1.73GHz, x86 Family 6 Model 14 Stepping 8
Processor Count: 2
RAM: 1014 Mb
Graphics Card: Mobile Intel(R) 945GM Express Chipset Family, 224 Mb
Hard Drives: C: Total - 109427 MB, Free - 21956 MB;
Motherboard: Dell Inc., 0FF049, , .3V7YQB1.CN1296167S7539.
Antivirus: Norton Internet Security, Updated: Yes, On-Demand Scanner: Enabled

RELEVANCY SCORE 200
Preferred Solution: uh-oh - laptop was in checked baggage and now.....

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: uh-oh - laptop was in checked baggage and now.....

If you go into device manager, is there any yellow marks beside anything?
vicks

Read other 1 answers
RELEVANCY SCORE 97.6

Last week before I came to Korea, I put my laptop in one of my bags thinking it is the carry on one I have. I didn't notice that it was not in there until I went through TSA. Now after a few days, I finally found it in one of my bags and luckily, there was no damage on the outside of the laptop. Do you guys think that it is fine in the inside since the outside is not damaged too, or will I have to turn it on and find out? I will have to get an adapter for the outlet since it is a different shape, but the AC adapter supports 100-240V.

A:Accidently left laptop in checked baggage

It should be fine, those baggage handlers are very gentle, ya right. I hope it`s ok

Read other 9 answers
RELEVANCY SCORE 49.2

I am having a similar infection to another recent poster, however I am having a lot of other problems with it. Pop-ups, tray icons.

I'm running Windows XP Pro with SP2. It is fully updated.

My AVG scans have also been turning up goldun.nu for months. Anyway, a big thank you for your help. Here is the HijackThis log. I also have the panda report to if needed.

HijackThis log

Deckard's System Scanner v20071014.68
Run by Colin on 2007-10-25 16:18:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 3 Restore Point(s) --
3: 2007-10-25 23:18:12 UTC - RP4 - Deckard's System Scanner Restore Point
2: 2007-10-25 01:56:31 UTC - RP3 - System Checkpoint
1: 2007-10-23 2151 UTC - RP2 - Removed Ad-Aware 2007


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 16.89 GiB (less than 15%) free.


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-10-25 16:20:56
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.5730.13)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS... Read more

A:Live Safety Center and Other infectious baggage

72 hour BUMP.

Read other 4 answers
RELEVANCY SCORE 48.8
RELEVANCY SCORE 48.8

+1 833_228-2161 Spirit Airlines Flight Baggage Fee



Spirit baggage fees





Baggage category

Fee

Max Weight



Gate check baggage fee

$65





First checked bag

$21-$50

40lbs



Second checked bag

$31-$60

40lbs



Third - fifth checked bag

$76-$100

40lbs





Do you have to pay for carry on with spirit?





When you fly Spirit Airlines, you can bring on a personal
item up to 18 x 14 x 8 inches on board for free while a full-sized carry-on will cost you $37 to $65, depending on when and where you purchase the right to bring the bag on board.
(Prices slightly less for $9 Fare Club members.)

Read other answers
RELEVANCY SCORE 47.6

My question did not match the board options but surely my warranty should start from the date of purchase

A:Bought new laptop Jan 2017. Checked warranty, . Expired 18/1...

Hi,Contact HP directly to rectify this: http://www8.hp.com/us/en/contact-hp/ww-phone-assist.htmlhttp://www8.hp.com/us/en/contact-hp/ww-contact-us.htmlIt's not that difficult.Scan your Invoice/Bill of purchase of this laptop, send to HP when asked.RegardsVisruth

Read other 1 answers
RELEVANCY SCORE 47.6

I wonder if someone out there has techy info for me regarding a problem I have with my home computer. To explain what happened. I have a PC with windows xp which contracted a virus. Worried that I wouldn?t get complete rid of the virus and to get the files from my harddrive I bought an external box, took out the harddrive and fitted into the external box. I then installed a new harddrive and done an XP system restore which worked fine. Here is where my problem is. I checked the external harddrive (my old harddrive) on my VISTA laptop which I was pleased I was able to see the files I clicked on one file which it then asked me about permissions and clicked and continued to click through them to see the files, which seemed fine. Then when I connected the external harddrive to the XP PC to pull over these files I can?t open them at all I assume because I?ve done a permissions thing on Vista. I?ve tried putting them on a pen drive which doesn?t work, even trying to email them as an attachment. Do you know how I can get them to open on my XP pc so I can pull them over? Do I have to change some permission?s on the folder file on the Vista laptop before I can then open them on the XP PC? After this I want to uninstall Vista on the laptop and install a version of XP, so I don?t have this problem again, it?s a nightmare any advice would be appreciated.

A:files from External HDD to XP PC having checked the folders on a Vista laptop

With this post does anybody know how I can fix this problem . All I've done really was take a HDD out of XP PC put into external box checked the files are theer on vista laptop although did open a file by doing the security tab and taking ownership. So now I go to get the files back of the external drive onto the new HDD i've put in the XP pc and the particular file I took ownership in Vista won't open on the XP. How do I fix this??????? HELPP

Read other 1 answers
RELEVANCY SCORE 47.6

Hi frnds,
My Laptop cant detect any wifi connections.I have already tried Updating Network Adapters,its all Up-to-Date.
My Problem in brief - Few days ago I downloaded a Nvidia gfx update for my Card (Geforce GT 720M 2GB) with Win8.1(updated using a update previously downloaded from Win8 to 8.1). After Installing Nvidia driver update all my Games was unable to run,so i searched for it, I found that my Intel drivers are out of date as i was using latest Nvidia drivers,so I tried to download Intel drivers but the installation says that these drivers r not compatible with my device(i dont know wtf happened), Then I shutdown my Laptop.

Next Day I started my pc, I shows a blue screen just before the Login page of WIndows, Its Says..."Your PC ran into a problem and needs to restart.We're just collecting some error info,and then we'll restart for you. (100% completed)"
under which error was given - VIDEO_TDR_FAILURE (igdkmd64.sys)".
I waited for 15min but the blue sceen was stilll there. I restarted and it was again blue...I started using f8, recovery etc...login to system somehow...then got its solution by something to do with memory sump setting.and now its all gone...

But my games were still not running and so many programs stopped working showing "BEX" as error and after few days I wasnt able to connect/identify to my wifi hotspot. even newly installed games wasn't running...

now I installed a Fresh copy of win8 and also installed a... Read more

A:Laptop cant detect wifi Win8,already checked drivers

The fresh copy - did you reformat the drive and re-install
Or
was it a repair install?

How did you do the fresh install
from the harddrive - from a USB drive or DVDs?

lets see a device manager screen shot to start

------------------------------------------------------------------------
Device Manager

Please Post back the results in device manager as requested below

You will now need to take a screen shot and copy that back to the working PC.
Save the file to a USB flash drive or other removable media. Plug it into the working computer with internet access and copy the screen shot and attach the screen shot in a reply on the forum here.
If you do not have another PC - do you have a phone connected to the internet - can you photograph the result and post the image in a reply

how to access device manager for different windows versions

http://www.computerhope.com/issues/ch000833.htm

Hold the Windows key and press Pause key, should now open to allow device manager to be seen, see the menu on the left hand side

on a laptop you may need to use Hold the Windows key and press FN key + the pause key

If the above does not work then
For Windows 8 or Windows 10

If you happen to be using a keyboard with Windows 8, the quickest way to open Device Manager is via its shortcut on the Power User Menu, accessible by pressing the WINDOW key and the X key together.
If on a touch screen - have a read here http://pcsupport.about.com/od/windows-8/a/device-manager-windows-8.htm
̴... Read more

Read other 1 answers
RELEVANCY SCORE 47.2

I checked the box under "Wireless network properties" to "Connect automatically when this network is in range" but somehow it un-checks itself and then won't connect to my network until I re-check it again. The "un-checking" usually happens after
I put the laptop to sleep and then wake it back up. It also un-checks it when I restart my laptop. Any idea what is causing this to happen since it is very annoying. This doesn't happen with Windows XP...



A:Box won't stay checked for my laptop to automatically connect to my wireless network.

Hi,
 
First, please try to update the network adapter driver to latest version to check the result.

Meanwhile, when trying to connect the Wireless network, please check the ?Start the connection automatically? option. Then, when you trying to connect certain Wireless network next time,
it should connect to the Wireless network automatically.
 
Hope this helps.

Vincent Wang
TechNet Community Support

Read other 3 answers
RELEVANCY SCORE 43.2

Good Evening;

noticed an abrupt slow-down on a usually fast dsl connect. Persisted long enough that I poked around and having performed a netscan, noticed a name or two unfamiliar to me-

would someone be good enough to take a look at a current HIJACK SCAN and comment on anything unusual?

Thanks in advance for the assist!
webz

to follow.....SCAN________________________________

Logfile of HijackThis v1.97.2
Scan saved at 7:36:01 PM, on 11/25/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijk\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra... Read more

A:spoting strange"baggage" on my netstat....

Its the cleanest shortest log ive ever seen.

 

Read other 3 answers
RELEVANCY SCORE 35.6

Can this get checked for me please ... Thanks in advance, Lu

Logfile of HijackThis v1.93.0
Scan saved at 7:40:24 PM, on 8/8/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.google.ca/search?q=APOD&ie=UTF-8&oe=UTF-8&hl=en&btnG=Google+Search&meta=
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to ... Read more

A:Can the HJL be checked, please

Read other 7 answers
RELEVANCY SCORE 35.6

Logfile of HijackThis v1.99.1
Scan saved at 8:11:59 PM, on 8/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:... Read more

A:New log to be checked

It all looks fine to me.Are you having problems ?.

Read other 2 answers
RELEVANCY SCORE 35.6

Logfile of HijackThis v1.99.0
Scan saved at 10:51:30 a.m., on 29/09/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\NVSVC.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\ZONELABS\ISAFE.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\E_S4I3V1.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\MAILFRONTIER\MANTISPM.EXE
C:\PROGRAM FILES\DVD REGION+CSS FREE\DVDREGIONFREE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\MY DOCUMENTS\HIJACKTHIS ANALYZER\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vodafone.co.nz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} ... Read more

A:just want to get this hjt checked

I don't see anything that needs addressed. IF you want..you can fix that entry in hijackthis and it will take it out of your startup. It's really not needed anyway..as you can launch the utility manually.

O4 - HKLM\..\Run: [OWCCardbusTray] ocbtray.exe


C:\WINDOWS\SYSTEM\E_S4I3V1.EXE <--check this file properties and confirm it's an Epson file please.

Read other 4 answers
RELEVANCY SCORE 35.6

Quote:




Logfile of HijackThis v1.99.1
Scan saved at 22:02:41, on 17.09.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\F-Secure Anti-Virus\fswsclds.exe
C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Prog... Read more

A:Can I have this log checked please?

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually.

Download LSPFix http://www.greyknight17.com/spy/LSPFix.exe and run it. Click on xfire_lsp_10650.dll on the left window and click on the arrow pointing to the right. Click Finish and follow the prompts.

Download CleanUp! ht... Read more

Read other 7 answers
RELEVANCY SCORE 35.6

Just accquired this laptop and could use a look at the log i just did---i already no i did it on the desktop--if there is any fixes i will then move my log to a separate file---thank you for checking it out----

Logfile of HijackThis v1.99.1
Scan saved at 11:34:44 PM, on 10/20/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\PROGRAM FILES\NETGEAR\WG511V2\WLANCFG5.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
O2 - BHO: AcroIEHlpr... Read more

A:Need HJT log checked.........

Looks fine to me.
 

Read other 1 answers
RELEVANCY SCORE 35.6

After some unexpected popups appeared, I'd like to get my HJT logs checkedThanks in Advance for your helpLogfile of HijackThis v1.94.0Scan saved at 11:46:10, on 21/08/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=file:///E:/Stef/page%20Web/Page%20d%E9marrage.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet ExplorerR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htmR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htmR3 - Default URLSearchHook is missingO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {3BD8317F-E365-5990-8723-64557FA67B4F} - C:\WINDOWS\System32\ebzpfmn.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBarO4 - HKLM\..\Run: [WebCam Go Plus Sti Service Application] WcgopsvcO4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXEO4 - HKLM\..\Run: [LogitechGalleryRep... Read more

A:HJT Log to be checked

Where did you download your version of HJT? I wasn't aware 1.94 was out Put a checkmark next to the following entries in HijackThis. Make sure all other windows and browsers are closed before clicking on ?Fix Checked?.R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=file:///E:/Stef/page%20Web/Page%20d%E9marrage.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title=Microsoft Internet ExplorerR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htmR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htmR3 - Default URLSearchHook is missingO16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\cqjvlbms.exeO16 - DPF: {11111111-1111-1111-1111-111111111111} - file://c:\info6.cabO16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exeO16 - DPF: {11111111-1111-1111-1111-111111111732} - file://c:\progra~1\pl.exe *********************************************************************** Empty your recycle bin. Then reboot and post a new log. :D

Read other 10 answers
RELEVANCY SCORE 35.6

I've been manually checking my computer for unrecognizeable files / folders and I found a lot. My computer is running SO slow that it is keeping me from getting my work done. I've installed ad-aware and its not picking up anything. I don't have a lot of space on my computer and when I say not alot I mean like...none. So I need to get this cleaned up fast, without a lot of installations. The sooner the better. I need all the help I can get. THANK YOU!!!Logfile of HijackThis v1.99.1Scan saved at 3:23:23 AM, on 7/5/2006Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\SYSTEM32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\MWW32\MANAGER\MWMDMSVC.EXEC:\WINNT\MWW32\MANAGER\MWSSW32.EXEC:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exeC:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\WINNT\System32... Read more

A:I Need This To Be Checked As Soon As Possible!

Hi there and welcome to Bleeping Computer !As you may have noticed already, the forums are very busy at the moment and i have noticed your log has gone unanswered so far!We look at the oldest logs first, and we were wondering that if you still need help, please start by posting a new HijackThis log in this topic and i will then be able to take a look!Thanks very much David

Read other 1 answers
RELEVANCY SCORE 35.6

Hello All,This is my 1st post here [looks like a good place to get answers]. Having browser problems [Firefox/3.0.5], slow to load or not at all. Ccleaner, spybot,sdfix,adware,avg show no problems...however I don't think this belongs on my machine "O17 - HKLM\System\CCS\Services\Tcpip\..\{925E2FB6-3D3D-413D-AAAA-82727E2B8519}: NameServer = 64.136.173.4 64.136.164.76". Does log look ok?Thanks for looking!!------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:57:25 PM, on 5/13/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\LSI SoftModem\agrsmsvc.exeC:\PROGRA~1\AVG\AVG8\avgwdsvc.exeC:\WINDOWS\system32\cisvc.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WIND... Read more

A:HJT Log; needs checked out

Hello and welcome to Bleeping Computer.My name is km2357 and I will be helping you to remove any infection(s) that you may have.I will be giving you a series of instructions that need to be followed in the order in which I give them to you.If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.Please do not start another thread or topic, I will assist you at this thread until we solve your problems.Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.Sorry for the delay in replying, the forum is very busy. If you still need help, please post a fresh HiJackThis Log

Read other 3 answers
RELEVANCY SCORE 35.6

Logfile of HijackThis v1.98.2
Scan saved at 23:11:57, on 2004/12/13
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\System32\wdfmgr.exe
G:\Program Files\Vexira Antivirus\VAGUARD.EXE
G:\Program Files\Vexira Antivirus\VAWUPSRV.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
G:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
G:\Program Files\Vexira Antivirus\VASched32.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.ex... Read more

A:i need log checked

Hi


Make sure you have already run Adaware, Spybot S & D(check for updates) as these will do a preliminary clean first.Some files below may not be present after running the above programs.

Then....
Turn off your System Restore SEE HERE Reinstate it when your log is cleaned and then create a new restore point.Close your browser window and run hjt in safe mode... HOW TO RUN SAFE MODE and have "Hijack This" fix all the following items by placing a check in the appropriate boxes and selecting "fix checked".
Folders that have been highlighted RED in the log will need to be uninstalled.Check first as some folders maybe uninstalled via the Add/Remove program. Files highlighted in BLACK in the log will need to be removed from your hard drive. Make sure to have your system set to show hidden files and folders.. HOW TO SHOW FILES ..Please reboot and post a new log when finished...


O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - Startup: PowerReg Scheduler V3.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/...ive/HS_live.cab
O16 - DPF: {9A19966F-AE0E-4699-8CCE-9B6F5F1C352C} (NPKXSite Control) - http://211.172.247... Read more

Read other 1 answers
RELEVANCY SCORE 35.6

I recently was having a lot of issues with popus, mainly from tracking.101.com and avsystemcare.com. I believe through my personal efforts found the files associated with my issues and have since deleted them and set a new restore point. However, not having the true ability to analize this log, could someome see if theres anything left suspisios. I currently am not having any issues. The only process that I still had concern on that i havent completly deleted is :

O4 - HKLM\..\Run: [udhvdfwba] c:\windows\system32\udhvdfwba.exe udhvdfwba

Here is the HJT log. Thanks for your time.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:27:12 PM, on 9/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Digital Media Reader\... Read more

A:Just having this checked

Swadowolffff , Hi

Still problem free ?

You can fix that leftover 04 item
Start Hijackthis Scan and place a check next to these items If there.

O4 - HKLM\..\Run: [udhvdfwba] c:\windows\system32\udhvdfwba.exe udhvdfwba

====================================
Hit fix checked and close Hijackthis.
Restart the PC

Read other 6 answers
RELEVANCY SCORE 35.6

I'm working on my daughter's laptop, which has been taken over. I ran an ad-aware scan in safe mode, but the problems keep coming back. Tried CWshredder-seems like whenevr I reboot, the issue comes back. Here is my log:
Logfile of HijackThis v1.99.1
Scan saved at 6:49:48 PM, on 2/25/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\EXECUTIVE SOFTWARE\DISKEEPERLITE\DKSERVICE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\PRPCUI.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.02.3000.1001\EN-US\MSNAPPAU.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\S... Read more

A:BHO-Need HJT log checked

Read other 13 answers
RELEVANCY SCORE 35.6

I have had that problem with the blue screen and cannot get rid of it. So I searched and found that using HijackThis could work. Here is a copy of my log file using the latest version of the program:

I used HijackThis analyzer to get my 'new" log

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05

***Security Programs Detected***

O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 3:29:43 PM, on 28/09/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\System32\combo.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\System32\paytime.exe
C:\Program Files\Bonjour\mDNSResponder.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://195.95.218.1... Read more

A:Could I please get my HJT log checked

Hi and Welcome to TSF!

Please subscribe to this thread to be notified of fixes as soon as they are posted by our Team. To do this, please click the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread".

Before you begin, take a read through the instructions and download the programs that I've advised. Save the below instructions in notepad or wordpad, because you also have to work in safe mode without networking support, so this page wouldn't be available then. You should not have any browsers on.

Please allow yourself a few spare hours. Below are instructions for a virus scan that can take longer then 2 hours. If you want, you may leave Ewido running while you go about your business. It's not essential that you sit and monitor it's progress.

If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below.

It is also important you don't miss a step and perform everything in the right order!!. .

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download these additional files/programs. Do not run them unless instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.

Place a shortcut to Panda ActiveScan on your desktop.

Download smitRem.exe and save... Read more

Read other 1 answers
RELEVANCY SCORE 35.6

When I play my favorite game, 5 card Slingo Millenium during the game advertisements slide down over my screen. THIS IS VERY ANNOYING!

Please help me to idenitfy the problems and get rid of them.

StartupList report, 5/22/2008, 1:35:19 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18000)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Secunia\PSI (RC1)\psi.exe
C:\Program Files\C... Read more

Read other answers
RELEVANCY SCORE 35.6

Logfile of HijackThis v1.98.0
Scan saved at 11:54:25 a.m., on 27/07/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vodafone.co.nz/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\PROGRAM FILES\REGETDX\IEBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\... Read more

A:hjt to b checked

Make sure to update Windows at http://windowsupdate.microsoft.com.

End the following processes (Ctrl+Alt+Del keys):

DSSAGENT.EXE

Uninstall the following via the Add/Remove Program’s Window if they exist:

ReGet <- possible spyware, suggest removing

Make sure to close any open browsers you have. Check and fix the following in HijackThis (make sure not to miss any) – if you didn’t uninstall ReGet, you may ignore all the ReGet entries to fix:

O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\PROGRAM FILES\REGETDX\IEBAR.DLL
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
O8 - Extra context menu item: Download A&ll by ReGet Deluxe - C:\PROGRAM FILES\COMMON FILES\REGET SHARED\CC_All.htm
O8 - Extra context menu item: Do&wnload by ReGet Deluxe - C:\PROGRAM FILES\COMMON FILES\REGET SHARED\CC_Link.htm

Did you set this to be your homepage, if not fix it:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vodafone.co.nz/

Reboot into Safe Mode (hit F8 key until menu shows up). Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

C:\PROGRAM FILES\REGETDX\ - only delete this if you uninstalled ReGet
C:\PROGRAM FILES\COMMON FILES\REGET SHARED\ - only delete this if you uninstalled ReGet
C:\WINDOWS\BBSTORE\DSS\

Reboot and post a new HJT log file so ... Read more

Read other 1 answers
RELEVANCY SCORE 35.6

Please could someone check this log for me.Thanks,SMALogfile of HijackThis v1.97.7Scan saved at 8:37:28 AM, on 5/22/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exeC:\HP\KBD\KBD.EXEC:\windows\system\hpsysdrv.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Hewlett-Packard\PhotoSmart\Digital Imaging\Unload\hpqcmon.exeC:\WINDOWS\Downloaded Program Files\winhlp32.exeC:\WINDOWS\wt\updater\wcmdmgr.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnf.exeC:\WINDOWS\Downloaded Program Files\winhlp32.exeC:\WINDOWS\Downloaded Program Files\win... Read more

A:hjt log needs checked please

I want you to fix some of those entries. Please do the following:Please make sure that you can view all hidden files. Instructions on how to do this can be found here:How to see hidden files in WindowsPlease put a checkmark in the box for each of these entries, close all other windows, and click the fix button:O4 - HKLM\..\Run: [system check] C:\WINDOWS\Downloaded Program Files\updater.exeO4 - HKLM\..\Run: [winhlp32.exe] C:\WINDOWS\Downloaded Program Files\winhlp32.exeReboot your computer into Safe Mode.Then delete these files or directoriesc:\WINDOWS\Downloaded Program Files\winhlp32.exeC:\WINDOWS\Downloaded Program Files\updater.exeDisable System Restore. You can find instructions on how to enable and reenable system restore here:Managing Windows Millenium System RestoreorWindows XP System Restore GuideRenable system restore with instructions from tutorial aboveReboot your computer to go back to normal mode and post a new log.

Read other 2 answers
RELEVANCY SCORE 35.6

If some one could please look over the Hijack This log to make sure my computer is clean? Thanks!

Logfile of HijackThis v1.97.7
Scan saved at 2:03:23 AM, on 12/6/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\00THotkey.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\zone alarm\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hIJACK!\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dial
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dakilube.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU\Softwa... Read more

A:Just need to have this checked

Read other 7 answers
RELEVANCY SCORE 35.6

Hi...have copied my log to have someone look over. My system is really acting strange and do not know what could be the cause. Thank you for checking this out for me, very appreciated...parrotplayLogfile of HijackThis v1.99.1Scan saved at 6:11:49 PM, on 10/8/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\Explorer.EXEC:\Program Files\UPHClean\uphclean.exeC:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Alwil Software\Avast4\ashDisp.exeC:\Program Files\AnalogX\MaxMem\maxmem.exeC:\Program Files\SpywareGuard\sgmain.exeC:\Program Files\SpywareGuard\sgbhp.exeC:\Program Files\Yahoo!\Messenger\YPager.exeC... Read more

A:need to have log checked

Looks clean to me

Read other 11 answers
RELEVANCY SCORE 35.6

Can someone please take a look at this and tell me if there is anything wrong. I have performed all prior steps required and removed a bunch of problems with all programs. The PC was BSOD ing and search page appeared to be hijacked Logfile of HijackThis v1.99.1Scan saved at 3:41:12 PM, on 7/4/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16473)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exec:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Intel Application Accelerator\iaantmon.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Dell Support Center\bin\s... Read more

A:Can This Be Checked Please

Hi Navcomm,Our apologies for the delay. If you still need help, please post a new log so I can see if anything has changed.A new version of HijackThis has now been released, so before you repost your log please download and install the new version by following the instructions in Step 9 of the Preparation Guide For Use Before Posting A Hijackthis Log. Note that it is unnecessary to uninstall the old version because the new one will be copied to a different folder.

Read other 1 answers
RELEVANCY SCORE 35.6

Logfile of HijackThis v1.98.2
Scan saved at 22:43:55, on 2004/12/13
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\documents and settings\administrator\local settings\temp\AfV.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\system32\BSHARELITE.EXE
C:\WINNT\system32\Internat.exe
C:\Program Files\AIM95\AIM.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\imejpmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Outlook Express\msimn.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\... Read more

A:I need LOG checked

you've got a few suspect processes running there, before we get started, I'd recommend doing the following things to clean up the easy stuff.

Download the following programs from this website http://www.greyknight17.com/download.htm

AdAware SE
Spybot Search and Destroy
CWSShredder

Then run them in this order and have them fix whatever they find:
CWSShredder
AdAware SE
Spybot Search and Destroy

If you have a broadband connection then go to housecall.trendmicro.com and run a scan.

After you've done the above, post a new hijack this log and we'll take it from there.

Good Luck!

Read other 2 answers
RELEVANCY SCORE 35.2

Hello.

REcenlt my vista pc shows some errors.

While opening, after loading windows, it says "disk have to be checked, press any key in 10 seconds to cancel."

But mostly i cant hit any button because my keyboard are not working at that time. 3-4 times i could press but after that, my pc restarted.

chkdsk comes %40 normally 2/3, but then it goes into infinite loop. It writes like that.



G?zdenge?irme olurken %40a kadar iyi geliyor, sonra sonsuz d?ng?ye giriyor,

deleting identify 9 index #sdh array with 2 identify

deleting identify 9 index #sdh array with 3 identify

deleting identify 9 index #sdh array with 4 identify

It goes until 10000s. I couldnot translate exactly, sorry.

I am waiting for 1.5 hours now and it is now writing in loop that:


xx index changing with security 11
xx index changing with security 12



What can i do? I cant go into desktop. PRoblem is in windows or harddisk?Please help.

A:Disk have to be checked?

You will need to wait until it has finished there has been some problem either corruption to the operating system or hard drive and it is trying to correct it or at least make the machine bootable,this may take some hours to complete.

Read other 6 answers
RELEVANCY SCORE 35.2

I'm not familiar with what poses a threat with the HJT log, but i was hoping there is nothing wrong with my pc without me knowing. Nothing seems to be running incorrectly or funny. but i'd just like to be sure. Also maybe suggestions on clearing up any clutter?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:34 AM, on 1/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\... Read more

A:Just wondering if my HJT log can be checked.

Read other 7 answers
RELEVANCY SCORE 35.2

Hello,

My WoW-account information was recently stolen and of course I thought it was another trojan (I had one 6 months ago which did this). I scanned my computer with Spybot S&D and Norton Internet Security 2009, found nothing. Then I downloaded Ad-Aware and tried Kaspersky online scanner, found nothing with those either.

So, I would appreciate if someone could take a look on this HjT-log (I only had Norton Internet Security running while doing this):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:08:25, on 2009-05-03
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program\Delade filer\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\Program\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WIND... Read more

Read other answers
RELEVANCY SCORE 35.2

Can anybody i did all the things posted in this topic [Proxy keeps getting checked] here is the log from Hijackthis

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 9:15:58 AM, on 28/3/2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
CHROME: 33.0.1750.154
FIREFOX: 27.0.1 (en-US)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Users\cireailemor\AppData\Local\ATI Technologies\atiedxx.exe
C:\Users\cireailemor\AppData\Local\Apps\2.0\GE1V6QY4.5NO\MGHAV8N7.2E8\zedg..tion_4cd56dcfd1799009_0001.0002_ea3f01849f5e16c3\ZedgeTonesync.exe
C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\MultiMedia Keyboard\KBLED.exe
C:\Program Files (x86)\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe
C:\Windows\V0640Mon.exe
C:\Program Files (x86)\... Read more

A:Proxy keeps getting checked

Read other 15 answers
RELEVANCY SCORE 35.2

I'd like to have someone check my logs before I set a new restore point. Any help would be greatly appreciated. ThanksLogfile of Trend Micro HijackThis v2.0.2Scan saved at 9:52:49 PM, on 2/12/2008Platform: Windows Vista (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16575)Boot mode: NormalRunning processes:C:\Windows\System32\smss.exeC:\Windows\system32\csrss.exeC:\Windows\system32\wininit.exeC:\Windows\system32\csrss.exeC:\Windows\system32\services.exeC:\Windows\system32\lsass.exeC:\Windows\system32\lsm.exeC:\Windows\system32\winlogon.exeC:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\System32\svchost.exeC:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\system32\SLsvc.exeC:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Creative\SBLive\AudioHQ\AHQTbU.exeC:\Windows\System32\CtHelper.exeC:\Program Files\Logitech\SetPoint\SetPoint.exeC:\Program Files\Common Files\Apple ... Read more

A:Need Log Checked Before Restore

Topic closed.

Read other 1 answers
RELEVANCY SCORE 35.2

Hi All,
I got a strange one this afternoon when I turned on my computer.
Instead of booting to windows, it tells me
?One of your drives needs to be checked for consistency?
It started to run a program, I guess it was chkdsk, but I am not sure about that. I then went to answer my phone, so I don?t know what happened after that. When I came back, windows was up and running. I can see nothing wrong with windows.
Anyone know what is this all about?
Thanks
Sven

A:checked for consistency

Apparently Windows found an issue with one of your drives and ran chkdsk to fix the problem. Are you dual booting Windows 7 and 8 by any chance?

Read other 9 answers
RELEVANCY SCORE 35.2

Had a customer come in with a infected computer ran malwarebytes it found a rootkit and removed it. customer took the system home. when she got home there was a letter from her cable company in the mail about mass mailing coming from her system afew days ago. she called them and let them know that she had taken it in and had it cleaned but they said that combofix was the only software that would remove this. so she brought it back to me i ran it and now need the log looked at. Plz!

A:Combofix log i need checked out.

Hello,Please post the log here by creating a new topic,http://www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/Let me know if that went OK.

Read other 3 answers
RELEVANCY SCORE 35.2

Log for a friend. I don't have any specific problem other than the system seems much more slugging than it was in the past.

I really appreciate your time.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:26:17 PM, on 9/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\eEye Digital Security\Blink\blinksvc.exe
C:\Program Files\DigitalPersona\Bin\DPWinLct.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\GEEK SQUAD POWER MANAGEMENT\ppped.exe
C:\Program Files\Retrospect\Retrospect Express HD 2.0\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\DigitalPersona\Bin\DPFUSMgr.exe
C:\Program Files\Common Files\eEye Digital Security\Application Bus\eeyeevnt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\umonit.exe
C:\WINDOWS\STMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eEye Digi... Read more

Read other answers
RELEVANCY SCORE 35.2

Thank you for whoever will take the time to check this.
Log was analyzed using HijackThis Analyzer - Updated on 12/17/04
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Logfile of HijackThis v1.99.0
Scan saved at 2:55:24 PM, on 12/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Program Files\Propel Accelerator\propelac.exe
C:\HJT\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us5.hpwis.com/
R0 -... Read more

A:Would very much like my Hijackthis.log to be checked

Are you having any problems now? I don't see anything wrong here.

Just one note about this though:
Market Browser's End User Agreement - We may use third party network advertisers such as DoubleClick to deliver ads to you on our behalf. We may also use third-party service providers to contact you on our behalf, or facilitate some aspects of our Web site services or fulfill your purchase requests. These network advertisers and service providers may be supplied with or have access to your personally identifiable information solely for the purpose of providing these services to us or on our behalf. Except as specifically set forth in this Privacy Policy, we will not share your personally identifiable information outside of LMT or MarketBrowser sponsors, unless you opt in to having your personally identifiable information shared with a company that is not affiliated with us.

Read other 2 answers
RELEVANCY SCORE 35.2

When we start up the computer, a white line goes across the monitor and then the statement
checking file systeam C the type of file systeam is NTFS one of your disks needs to be checked for consisteny.
This keeps coming up until any key is pressed and then it cancels.
Also since this has been happening, we can not restore the computer and the computer seems to be running slower.

(Error Message)

System Type: Desktop / Tower

System Manufacturer: Dell

Operating System: Windows XP

Processor Type: Pentium 4

Ammount of RAM: 256 MB

Hard Drive Capacity: 40 GB

Internet Connection Speed: Cable

Monitor Size: 17"

Printer Manufacturer: Hewelet Packard

Printer Type: Ink Jet

CD-ROM: 48x
 

A:checked for consisteny

Read other 8 answers
RELEVANCY SCORE 35.2

AVG is teling me I have a possible virus MPH can someone please check my HJT log
thanks

Logfile of HijackThis v1.99.1
Scan saved at 18:43:26, on 17/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\BTopenworld NetHelp\bin\mpbtn.exe
C:\WINDOWS\System32\wpabaln.exe
C:\Documents and Settings\JR.JAMES\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/...b/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/cust... Read more

A:MPH virus Can HJT Log be checked

Read other 7 answers
RELEVANCY SCORE 35.2

Someone hijacked my email and sent out messages. Not sure if any of the stuff hijack this found is responsible, any help would be greatly appreciated.

Thanks
-collated

A:Not sure what needs to be checked and removed

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explanation about the tool. No input is needed, the scan is running.Notepad will open with the results.Follo... Read more

Read other 2 answers
RELEVANCY SCORE 35.2

https://www.grc.com/x/ne.dll?bh0bkyd2

A:have you checked you security lately

I guess I'm OK. File sharing tests:





Quote:
Your Internet port 139 does not appear to exist!
One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.
Unable to connect with NetBIOS to your computer.
All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.


Testing the ports shows this for every port:





Quote:
Stealth. There is NO EVIDENCE WHATSOEVER that a port (or even any computer) exists at this IP address!


Kari

Read other 9 answers
RELEVANCY SCORE 35.2

Hi everyone
Haven't been on here in a while but would still appreciate someone checking my hjt log for me.
I am running WinME on a Compaq Deskpro EN with a pentium lll processor, was told because of it only being a lll I can't upgrade to XP but that's ok, I do fine with the ME.
I have AVG aniti-virus, ZoneAlarm firewall, windows media player and real player. I also have spybot S&D and Ad-aware, all of which I update and run frequently.My internet provider is Verizon/Yahoo DSL. I also empty my temp internet files and cookies regularly, just wondering if there is anything here on my log that I could still get rid of.
Thank you for your time
Kim34

Logfile of HijackThis v1.99.1
Scan saved at 7:11:34 PM, on 9/25/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HKCMD.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR... Read more

A:haven't had my hjt log checked in a while...

Looks fine
 

Read other 3 answers
RELEVANCY SCORE 35.2

I feel like i have something slowing down my internet but nothing is coming up on any scans. So here are the logs from the files that you guys request. Tell me what you think.

Hijackthis file

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:08:38 AM, on 1/29/2011
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\James Hall\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\James Hall\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Norton 360 Premier Edition\Engine\3.8.0.41\ccSvcHst.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program File... Read more

A:Need my Logs to be checked

Here is one other file, the attach.txt. I think it goes along with a file named DSS.txt. there was nothing on the ark.txt so i didn't paste that log.
 

Read other 1 answers
RELEVANCY SCORE 35.2

My computer locks now and then, but my NOD32 can't find any vira, and i've tried a couples but ain't working :(, some help sorting out the files would be great.
My log looks following:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:46:26, on 02-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\iFinger\iFinger.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SER... Read more

A:Need help getting my log checked - got virus

Welcome to TSF

You have a trojan zlob infection.


Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
http://siri.geekstogo.com/SmitfraudFix.exeDouble-click on SmitfraudFix.exe



Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
In your next reply, please post the contents of rapport.txt.

Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "Risk Tool". Its not a virus, but a program used to stop system precesses. Antivirus programs cannot distinguish between "good" and malicious" use of the such programs, therefore they may alert the user.
http://www.beyondlogic.org/consultin...rocessutil.htm

Read other 3 answers
RELEVANCY SCORE 35.2

Need to know if this has any spyware in it.

----------------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:41:15 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program F... Read more

A:Need a HijackThis Log to be checked

Read other 8 answers