Tried "stuff to do before posting HijackThis Log" HELP!

Reply

Join Date: Nov 2004
Posts: 65
Reputation: geezer is an unknown quantity at this point 
Solved Threads: 1
geezer's Avatar
geezer geezer is offline Offline
Junior Poster in Training

Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #1
Dec 6th, 2004
Ay up fellows! I've tried AdAware, Spybot and finally after doing the tutorial on Hijack this I fixed the R1 line of the log. My home page is still going to some ad site (about blank) and even my email goes to this page when I log in. Its driving me up the wall and I'm thinking of restoring the system (with a lump hammer). You geezers have helped me fix a horrible problem with IE before so please give us a hand again. I know you can do it.I'll attach the HJT log...
Last edited by alc6379; Dec 6th, 2004 at 3:40 pm.
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 65
Reputation: geezer is an unknown quantity at this point 
Solved Threads: 1
geezer's Avatar
geezer geezer is offline Offline
Junior Poster in Training

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #2
Dec 6th, 2004
Originally Posted by geezer
Ay up fellows! I've tried AdAware, Spybot and finally after doing the tutorial on Hijack this I fixed the R1 line of the log. My home page is still going to some ***** ad site (about blank) and even my email goes to this page when I log in. Its driving me up the feckin wall and I'm thinking of restoring the system (with a lump hammer). You geezers have helped me fix a horrible problem with IE before so please give us a hand again. I know you can do it.I'll attach the HJT log...
Ay up, its me (Geezer) again... I know you're sick to death of Hijack this logs but I've done every thing I can think of to fix the problem myself... Ive gone over the log and what's left seems to be safe enough but I keep getting that bloody microsoft search page and I just dont want any viagra...
Logfile of HijackThis v1.97.7
Scan saved at 11:22:30, on 06/12/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\internet security suite\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/r...search&ap=b204
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1033\phdintl.dll/phdContext.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
Last edited by DMR; Dec 6th, 2004 at 6:02 pm. Reason: (another) profanity edit
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 2,414
Reputation: alc6379 has a spectacular aura about alc6379 has a spectacular aura about alc6379 has a spectacular aura about 
Solved Threads: 123
Team Colleague
alc6379's Avatar
alc6379 alc6379 is offline Offline
Cookie... That's it

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #3
Dec 6th, 2004
Had to edit this post for content due to language. Please have a look at the Forum Rules regarding use of profanity in the forums.

Thanks.
Alex Cavnar, aka alc6379
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #4
Dec 6th, 2004
Logfile of HijackThis v1.97.7
You are running an outdated version of HijackThis. Please get the latest version (1.98.2) and post the log that version generates.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 65
Reputation: geezer is an unknown quantity at this point 
Solved Threads: 1
geezer's Avatar
geezer geezer is offline Offline
Junior Poster in Training

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #5
Dec 6th, 2004
Originally Posted by DMR
You are running an outdated version of HijackThis. Please get the latest version (1.98.2) and post the log that version generates.
Nice one! I'm gonna have a go at that now... I'll try moderating my language too. Tricky when you're as flippin wound up as I am now rant rave snarl etc.... Ok!... well the ****in' websearch fo ***'in viagra etc is back. anyway before I get into more trouble with my vernacular here's my log file..

Logfile of HijackThis v1.98.2
Scan saved at 21:21:07, on 06/12/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\Program Files\internet security suite\new hijack this\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~2\Office\1033\phdintl.dll/phdContext.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

There's a few new ones in here allright. Earlier i tried Merijn's tutoial but I'm no techie and I've already done a bit of messing with the OS and seem to have gotten away with it... Anyone who isn't sick of checking over these logs will be forever in my favour. (hey! still no expletives!)
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #6
Dec 6th, 2004
Many of the processes listed in your log don't necessarily need to be running as startup items, but none of them are malicious as far as I can see.

1. Given that your log indicates no obvious "nasties", can you describe the pages/ads/pop-ups/whatever that you're getting in greater detail please?

2. Stop using Internet Explorer as your *$#$% web browser, ya foul-mouthed Geezer! :mrgreen:

Use Netscape, Firefox, or Opera instead; they're pretty much immune to the spyware/adware/etc. problems that plague IE

3. If you absolutely need to use Internet Exploder, at the very least download and install SpywareGuard and SpywareBlaster; they plug some of the security "loopholes" in IE. Links to those two programs are in my sig below.

4. Try Shoot the Messenger; it might stop some of the crud.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 65
Reputation: geezer is an unknown quantity at this point 
Solved Threads: 1
geezer's Avatar
geezer geezer is offline Offline
Junior Poster in Training

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #7
Dec 6th, 2004
Originally Posted by DMR
Many of the processes listed in your log don't necessarily need to be running as startup items, but none of them are malicious as far as I can see.

1. Given that your log indicates no obvious "nasties", can you describe the pages/ads/pop-ups/whatever that you're getting in greater detail please?

2. Stop using Internet Explorer as your *$#$% web browser, ya foul-mouthed Geezer! :mrgreen:

Use Netscape, Firefox, or Opera instead; they're pretty much immune to the spyware/adware/etc. problems that plague IE

3. If you absolutely need to use Internet Exploder, at the very least download and install SpywareGuard and SpywareBlaster; they plug some of the security "loopholes" in IE. Links to those two programs are in my sig below.

4. Try Shoot the Messenger; it might stop some of the crud.
Ay up! I've just been trying out major geeks "do this before posting HJT logs" advice. I couln't stop one RPC helper (options greyed out) and I'm starting to get worried about all this messing with my puter's mind... The home page I'm getting is about:blank with search the web all in *^%$*!! orange offering to search for all the usual***!!!%^$!. Oh no I'm off again... Its even hijacked my email opening page - as soon as I sign in There it *&^%$£!! is! How come there's no preposterously irate smilies? Thanks for helping my bloodpressure somewhat, I'll let you know how I'm getting on... Oh, does about:Buster do what it says on the tin?
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #8
Dec 6th, 2004
Originally Posted by geezer
How come there's no preposterously irate smilies?
But they're are, oh geezerly-one; you just need to know where to look:

http://www.stevewolfonline.com/Downl...ls/furious.gif http://www.stevewolfonline.com/Downl...isuals/grr.gif http://www.stevewolfonline.com/Downl.../possessed.gif http://www.stevewolfonline.com/Downl...suals/para.gif


well... you get the idea, yes?



Originally Posted by geezer
Oh, does about:Buster do what it says on the tin?
Yes- good catch; give AboutBuster a try; it's legit. MajorGeeks as a whole is a trusted and reputable site, so if you find something available for download there, it's pretty sure bet that the program has merit.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 353
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #9
Dec 6th, 2004
1. The about:blank home page setting is legit in one instance; it is what you'll get if you choose the "Use Blank" home page option in your Internet Options control Panel.

Can you change the home page setting to something other than about:blank via your Internet Options control Panel? If so, does that change persist, or does your home page keep reverting to about:blank?


2. Is the "Search the Web" stuff you describe an unwanted toolbar that appears in IE? If so, can you give us a screenshot of it? There are some particularly nasty variants/offshoots of the CoolWebSearch family that exhibit similar symptoms, and not even CWShredder can kill all of those. One such variant is the rather new-ish HSA (Home Search Assistant) infection; see the following link for more info on that:

http://www.short-media.com/forum/sho...d.php?p=172774
Last edited by DMR; Dec 6th, 2004 at 8:22 pm. Reason: crikey- my cat types more accurately than I do...
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Nov 2004
Posts: 65
Reputation: geezer is an unknown quantity at this point 
Solved Threads: 1
geezer's Avatar
geezer geezer is offline Offline
Junior Poster in Training

Re: Tried "stuff to do before posting HijackThis Log" HELP!

 
0
  #10
Dec 7th, 2004
Ay up magnanamous marsupial! I've since tried even more in depth stuff and still no joy. I've run all the antispy stuff including about:blaster and CWShredder and was going through the HJT log tutorial (bewildering for a novice like myself) when i found the "qttask.exe" thing with a lower case q - identified by castle cops as spyware. I'm not sure how to get rid of it though and I'm not sure about all the stuff from the "global startup" bits onward, especially the "o12" bits.
I'm trying all I can myself to avoid wasting the time of you good folks and your help and zen calming is very welcome.
by the way the red smiley is about right...
Oh yeah, the page that comes up (still) is a whole page full of advertising links not a toolbar extension.

Thanks for keeping in touch
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC