My computers been acting "weird" for awhile.
I ran a few programs and here are my results...
Considering I don't know much about this I am kindly asking for help.:cheesy:
--- What is the "weird" behavior?
--- What makes you think there is a rootkit on your machine?
--- Note that EWIDO was bought by Grisoft and is now AVG Anti-spyware.
For our purposes, your current version should be OK. Just update the definitions before scanning.Anyhoo, here we go:
You might wish to relocate HijackThis to a safer location. Most Forum volunteers expect to find it at C:\Program Files\HijackThis or C:\HijackThis.
NOW, on to the fix:
You may want to print out these instructions for reference, since you will have to restart your computer during the fix. Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
Save it to your desktop and run it.
Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. When your system reboots, follow the prompts. Afterwards, HijackThis will launch (If Hijackthis does not launch then please start it yourself).
Please Scan with HJT, and check the boxes for the following items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:4001 ---> If this is the desired setting, then leave it alone
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [LanzarL2007]"C:\DOCUME~1\BRITTN~1\LOCALS~1\Temp\
{C9B6AD6F-64FA-4DE7-AB02-B27C92CB780B}\{D1DA2BA7-2592-4036-
9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe"/SETUP:"/l0x0009"
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
Fix all of these 018s that relate to Logitech Desktop Messenger. I suggest removing it completely...
O18 - Protocol: bw+0 - {E847C0A4-7FB1-4848-93D2-CD6F3744A18B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
Be sure All Browser Windows are Closed and then Click Fix Checked.
NEXT:
Click Start > Run > type CMD > Enter
Type or Copy&Paste: ipconfig /flushdns > Press Enter
(Be sure to leave the space between the g and the / )
THEN:
Please Update your Java here ---> http://www.java.com/en
Then, look in Add/Remove Programs and Remove ALL traces of any older Java versions!
If you do not uninstall ALL older versions, you may remain at risk for a number of baddies.
NEXT:
Download ATF-Cleaner.exe by Atribune to your Desktop.
-- Click on ATF-Cleaner to run it
-- Where it says Select Files To Delete, Check the Select All Option (if you don’t want it to clean cookies, set it accordingly)
-- Click Empty Selected > OK > EXIT
This will flush TEMP files, etc... as well as clean the Java Cache.
THEN:
Please Online Update your EWIDO and do a Complete System Scan. Let it fix what it finds and save the scanlog for me.
LASTLY: Please locate c:\fixwareout\report.txt and post it here along with Fresh HijackThis Scanlog and the EWIDO Log and we'll go from there.
Best Luck :)
PP