TechSpot

hijack this logfile

By licid33
Feb 6, 2006
Topic Status:
Not open for further replies.
  1. this message is now at least 10 characters long
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 25,948   +19

  3. licid33

    licid33 TS Rookie Topic Starter

    HIJACKTHIS log

    this message is now more than 10 characters
     
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 25,948   +19

    Go back to this thread HERE and this time follow the instuctions.

    Only post a fresh HJT log when you`ve completed the above.

    Regards Howard :)
     
  5. licid33

    licid33 TS Rookie Topic Starter

    hijackthis log

    k i followed all of the instructions this time and removed a lot of files - heres what i got after a fresh hijackthis

    i still have winfixer 2006 on here - could you tell me how to remove that? thanks
     
  6. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 25,948   +19

    Boot into safe mode.

    Turn off system restore.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system".

    Click start/run and type regsvr32 /u C:\WINDOWS\system32\oppon.dll and press the enter key.

    Run HJT with no other programmes open, and have HJT fix the following by placing a tick in the little box next to(if there).

    O2 - BHO: MSEvents Object - {CE70731D-F28D-4D81-9D61-C8EE60378401} - C:\WINDOWS\system32\oppon.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll (file missing)

    O15 - Trusted IP range: 67.19.185.246

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab

    O20 - Winlogon Notify: oppon - C:\WINDOWS\system32\oppon.dll

    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)

    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)

    O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)

    O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)

    Now click on the fix checked button.

    Close HJT.

    Locate, and delete the following bold file(if there).

    C:\WINDOWS\system32\oppon.dll

    Click start/run and type services.msc into the run box, and press the enter key.

    When the window appears, maximise it.

    Locate the above 023 services. Double click on them, and select stop if they are running. Set the startup type to disabled.

    Click apply ok.

    Reboot into normal mode, and turn system restore back on.

    Regards Howard :)
     
  7. licid33

    licid33 TS Rookie Topic Starter

    Howard,
    i am unable to delete oppon.dll - says it is connected to current processes - but the only 3 processes that are running are taskmgr.exe explorer.exe winlogon.exe ( cant terminate) and csrss.exe ( cant terminate)
     
  8. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 25,948   +19

    Please post a fresh HJT log thanks.

    Regards Howard :)
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.