Home > Hjt Log > HJT Log - Fixing GF's Laptop

HJT Log - Fixing GF's Laptop

I am at her place now and once I got on her laptop I saw that Symantec was running crazy and eating all the CPU up. I know the details are not great, but I went ahead and had her run HJT and send me the log. the program does work on the other laptop????? Verify that you have access to this location and try again.

Brian Cooley found it for you at CES 2017 in Las Vegas and the North American International Auto Show in Detroit. Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean. Did you research any of these entries?Bob Flag Permalink This was helpful (0) Collapse - No Computer Skills by v120778 / June 5, 2011 9:41 PM PDT In reply to: Ouch. Thanks!The fixes and advice in this thread are for this machine only. https://forums.techguy.org/threads/hjt-log-fixing-gfs-laptop.917181/

If you're not already familiar with forums, watch our Welcome Guide to get started. If the IP does not belong to the address, you will be redirected to a wrong site everytime you enter the address. Once the scanner is installed and the definitions downloaded, click Next. can i try running this from normal mode instead of safe?

Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat that's right i said it... Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List O5 - IE Options not visible in Control PanelWhat it looks like: O5 - control.ini: inetcpl.cpl=noWhat to do:Unless you or your system administrator have knowingly hidden the icon from Control Panel,

If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). One of the best places to go is the official HijackThis forums at SpywareInfo. Upon running it again, they are gone so thats good.I have read and re-read all of your logs and still having some issues. He installed tons of Pokemon programs or something similar on it.

Take a deep breath "TCP Query User{4070073F-A3EA-49B6-A836-76D301FEFFAF}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent"UDP Query User{A185E90A-6CB4-464F-A3A3-CE2B7870F216}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent"TCP Query User{6558277D-18F6-4BA1-A786-884AD3657731}C:\\program files\\bittorrent_dna\\dna.exe"= UDP:C:\program files\bittorrent_dna\dna.exe:dna"UDP Query User{36F11B42-C206-4E92-8626-3EC5B4CB31E9}C:\\program files\\bittorrent_dna\\dna.exe"= TCP:C:\program files\bittorrent_dna\dna.exe:dna"{BDF33702-AA8F-4C51-BD9E-0C233A42D7F4}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour"{A612F9F5-15A5-495D-9462-6E98786C0C79}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Save the file to your desktop. Jump to content Resolved Malware Removal Logs Existing user? Please include a link to this thread with your request.

It's been detected a couple of times and quarantined but never completely removed. http://www.techsupportforum.com/forums/f10/trying-to-fix-my-gfs-01-xp-dell-laptop-161960.html I'll be waiting for your reply Microsoft MVP Consumer Security 2008 2009 2010 2011 2012 2013 UNITE member since 2006 I don't help with logs thru PM so don't bother to Extract the contents of the zipped file to desktop.Right click on GMER.exe and select "Run as Administrator" to run the program. Are you looking for the solution to your computer problem?

No, create an account now. Read every reply you receive carefully and thoroughly before carrying out the instructions. Proffitt Forum moderator / June 5, 2011 2:09 PM PDT In reply to: Log Files I have to wonder if you posted in forums that read those log files?Btw.R3 - URLSearchHook: For MalWarebytes AntiMalware, I changed the setup.exe to sri.exe and it installed fine, however, it won't let me run it.Thanks Share this post Link to post Share on other sites AdvancedSetup

Have HijackThis fix them.O14 - 'Reset Web Settings' hijackWhat it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:If the URL is not the provider of your computer or your ISP, have All of you could be getting paid to do this, yet you do it for free. Advertisements do not imply our endorsement of that product or service. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 8:30:11 PM, on 4/12/2011 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.19019) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe

IAT/EATDrives/Partition other than Systemdrive (typically C:\)Show All (don't miss this one)Then click the Scan button & wait for it to finish.Once done click on the [Save..] button, and in the File That may cause it to stall* * * * * * ADDITIONAL DOWNLOADS * * * * * * * * * * * * * *Download & install CleanUp.exe (not Please re-enable javascript to access full functionality.

Prefix: http://ehttp.cc/?What to do:These are always bad.

I just went in to msconfig and disabled everything symantec for the most part. Please use "Reply to this topic" -button while replying. Provided removal instructions are meant to be used in the correspondent user's case only. Provided removal instructions are meant to be used in the correspondent user's case only.

dotty999 replied Feb 10, 2017 at 5:56 PM 4 Word Story continued (#6) dotty999 replied Feb 10, 2017 at 5:54 PM Windows 2000 Pro L Henry replied Feb 10, 2017 at This is only a short scan.Once the short scan has finished, mark the drives that you want to scan.Select all drives. Select the option to run Windows in Safe Mode.* * * * * * UN-INSTALLING PROGRAMS * * * * * * * * * * * * * * Go Please refer to our CNET Forums policies for details.

Advertisement matty200 Thread Starter Joined: Jul 7, 2005 Messages: 36 Looking for some help if anyone has time, havent been to the site in a while but would appreciate the help! Please re-enable javascript to access full functionality. Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing. after running that, drwin would (and other programs) would not run at all did everything else in the process though.

scanning hidden autostart entries ...scanning hidden files ... Flag Permalink This was helpful (0) Collapse - No need to buy a new computer at all. scan completed successfullyhidden files: 0**************************************************************************.------------------------ Other Running Processes ------------------------.C:\Windows\System32\audiodg.exeC:\Windows\System32\wlanext.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exeC:\Windows\System32\drivers\XAudio.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exeC:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exeC:\Windows\System32\dllhost.exe.**************************************************************************.Completion time: 2008-05-03 18:22:52 - Please re-enable javascript to access full functionality.

it's already night and day with how far ive come along, but then new things started popping up.. The scan will take a while so be patient and let it run. Then OK, again. If you have problems create a thread in the forum, please.Don't post your log into other user's topic, create a new one.

Have a great vacation Member of ASAP and UNITEProud Graduate of the WTT Classroom Back to top #9 JonTom JonTom Trusted Malware Tech Trusted Malware Techs 3,009 posts Gender:Male Location:UK Posted I will direct her to this thread so she can start. It did not work. Anyone have any other suggesstions.

Treat with care.O23 - NT ServicesWhat it looks like: O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exeWhat to do:This is the listing of non-Microsoft services. geos74 Resolved HJT Threads 32 02-05-2007 05:57 PM I read all your stickys, please look at my hijack this file.