Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Please help with this hijack log  (Read 11673 times)

0 Members and 1 Guest are viewing this topic.

dl65

  • R.I.P.


  • Prodigy

    Thanked: 18
    Re: Please help with this hijack log
    « Reply #15 on: September 09, 2005, 11:16:09 PM »
    majakdragon..... Is you system restore turned off ? If it isn't please turn it off . Now go into safe mode again and go to this location
    C:\WINDOWS\System32\Perfhmon.exe   ........ find the file and delete it .

    reboot back into normal ....run your hijack this again and if it is still there mark it for removal again .

    dl65  ::)
    If you don't know the answer, it isn't a dumb question.

    majakdragon

    • Guest
    Re: Please help with this hijack log
    « Reply #16 on: September 10, 2005, 08:48:24 AM »
    System Restore IS and HAS been turned off since I started this repair operation. Everything is being removed through the HIJACK program. I have checked everything you have requested checked and removed this way.

    This is a very stuborned file that refuses to leave.

    dl65

    • R.I.P.


    • Prodigy

      Thanked: 18
      Re: Please help with this hijack log
      « Reply #17 on: September 10, 2005, 12:05:23 PM »
       majakdragon.......Have you actually gone into the Windows folder....... System32  and located Perfhmon.exe   and tried to delete it ?

      This one seems to change its name ......
      O2 - BHO: (no name) - {6E28339B-7A2A-47B6-AEB2-46BA53782373} - (no file)File Missing

      When a file is missing, you should always have HijackThis fix the item.

      Mark that one for removal then reboot and see if it comes back.

      let us know

      dl65  ::)
      « Last Edit: September 10, 2005, 12:17:19 PM by dl65 »
      If you don't know the answer, it isn't a dumb question.

      majakdragon

      • Guest
      Re: Please help with this hijack log
      « Reply #18 on: September 10, 2005, 08:40:12 PM »
      Both files have been removed.
      The Perfhmon entry was removed using cmd.

      here is the new log:

      Logfile of HijackThis v1.99.1
      Scan saved at 9:38:23 PM, on 9/10/2005
      Platform: Windows XP  (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\Program Files\ewido\security suite\ewidoguard.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\hijackthis\hijackthis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} -
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe



      dl65

      • R.I.P.


      • Prodigy

        Thanked: 18
        Re: Please help with this hijack log
        « Reply #19 on: September 10, 2005, 09:18:54 PM »
        majakdragon.........Eureeka ....it appears you have done it ....... Don't forget to D/L sp2 and Ms Antispyware Beta .
        How is the pc working ?

        dl65  ::)
        If you don't know the answer, it isn't a dumb question.

        majakdragon

        • Guest
        Re: Please help with this hijack log
        « Reply #20 on: September 10, 2005, 10:03:44 PM »
        Computer seems to be working fine. Loads pages much faster. The only thing I can find different is that SOMETIMES the monitor looks weird. Sortof like a rainbow effect. Wasn't doing this before the repairs. I don't know if it is the monitor I am using or if something is interfering with the display.