Please Help "My HijackThis log"

By r_a_jewel
Mar 20, 2005
Topic Status:
Not open for further replies.
  1. Here is my HijackThis log. Now what do I do next guys?????????Before I blow up my computer and I don't have my xp cd to start over!!
    Thanks !!!!!!!!!
    :)Julie

    Attached Files:

  2. tbrunt3

    tbrunt3 Newcomer, in training Posts: 495

    Welcome to Techspot

    WHATTTTT no xp cd why????

    There is a few things you can do how to remove cool web can be found Here

    And how to post a Hijackthis log and what do I need can be found Here Read all the instructions there get all the programs it says ..

    Install hijackthis in its own folder yours is not install it to C/HJT also run all programs you find in above post and update them all and run them with all windows closed than repost your log here..
  3. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    Thank You!

    :giddy: Just making sure I am on the same page as you. I did save in c/programs ( by it self) ... And Everything that is on my log I should x to have hijack thi to remove it? Even if it includes sypbot and hijackthis programs? And by the way I'm sure I'm not the only one that doesn't have there cd..I moved, went though a divorce and have kids, blah, blah,blah.... ....things happen. Thank you you for your help..!! :)
    Julie
  4. tbrunt3

    tbrunt3 Newcomer, in training Posts: 495

    Hello

    Dont have Hijackthis remover anything yet .Hjackthis needs to be in its own folder C:/HJT not where yours is at now C:\WINDOWS\TEMP\Temporary Directory 2 for hijackthis.zip\HijackThis.exe Hijack this does not go in temp folder or docments and settings this is very important for back up.. Read the links I posted then if you have any questions ask...
  5. RealBlackStuff

    RealBlackStuff Newcomer, in training Posts: 8,165

    Move your Hijackthis file to e.g. C:\HJT\HijackThis.exe

    Boot in Safe Mode
    Run HJT on its own and put a 'tick'mark next to:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mybluelight.com/s/sp
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (disabled by BHODemon)
    O2 - BHO: (no name) - {4EDF390E-961C-50BE-820B-66557FF52C43} - C:\WINDOWS\system32\xabbb.dll
    O4 - Startup: .lnk.disabled
    O4 - Global Startup: .lnk.disabled
    O4 - Global Startup: Microsoft Office.lnk.disabled
    O4 - Global Startup: Verizon Online Support Center.lnk.disabled
    O4 - Global Startup: x.lnk.disabled
    O4 - Global Startup: xx.lnk.disabled
    O4 - Global Startup: xxx.lnk.disabled
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - (no file) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.mybluelight.com/s/sp
    O18 - Filter hijack: deflate - (no CLSID) - (no file)
    O18 - Filter hijack: gzip - (no CLSID) - (no file)
    O18 - Filter hijack: lzdhtml - (no CLSID) - (no file)
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O18 - Filter hijack: text/xml - (no CLSID) - (no file)
    O23 - Service: Windows Update Service (wuamgrd) - Unknown owner - C:\WINDOWS\System32\wuamgrd.exe (file missing)

    Then hit the button: Fix Checked.
    Delete this file: C:\WINDOWS\system32\xabbb.dll
    Reboot and see how it goes.
  6. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    Thank You!


    I thought i saved it in c/programs/hijackthis/
    here is my new log.. I made some corrections before I read your post. :knock:

    Thank you,
    Julie :wave:
  7. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    oops;forgot log

    :knock: to previous post!!!
    Here>>>
    Sorry :knock:
    Thanks,
    Julie
  8. tbrunt3

    tbrunt3 Newcomer, in training Posts: 495

    Boot in save mode place a check buy these have hijack this fix them...

    O18 - Filter hijack: deflate - (no CLSID) - (no file)
    O18 - Filter hijack: gzip - (no CLSID) - (no file)
    O18 - Filter hijack: lzdhtml - (no CLSID) - (no file)
    O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
    O18 - Filter hijack: text/xml - (no CLSID) - (no file)

    then repost than you should be clean than .Think about getting Firefox wich can be found here
  9. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    filter hijack?

    filter hifjack do not seem be fixed amd always comback. Now what boys? :knock:
  10. RealBlackStuff

    RealBlackStuff Newcomer, in training Posts: 8,165

    Click on Start/Run, type regedit and press OK.
    Then navigate to the following keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\deflate
    Right click on deflate and delete it.

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\gzip
    Right click on gzip and delete it.

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\lzdhtml
    Right click on lzdhtml and delete it.

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/webviewhtml
    Right click on text/webviewhtml and delete it.

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml
    Right click on text/xml and delete it.

    Reboot and then post a new log
  11. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    Hijackthis/thanks

    Hi! :wave:
    Here is my new log. Thanks for your help, I wish I had found your forum a long time ago!!! What do I do next? Also is it normal for windows xp to boot in to safe mode with no desktop, or start up programs?

    Thank You ,
    Julie:)
  12. tbrunt3

    tbrunt3 Newcomer, in training Posts: 495

    Your log pretty clear now..It not normal for it to boot to safe mode what other options do you have and do you have any errors?
  13. RealBlackStuff

    RealBlackStuff Newcomer, in training Posts: 8,165

    There is no need to have Spybot and HijackThis running each time the PC starts.

    Boot in Safe Mode, run HJT and let it 'fix':
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
    O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis.exe /startupscan
    O23 - Service: Windows Update Service (wuamgrd) - Unknown owner - C:\WINDOWS\System32\wuamgrd.exe (file missing)

    Reboot normal.
    Next, start Spybot and do a "Search for Updates" first.
    Then click on the red symbol with Immunize under it. If it does not say that all baddies have been blocked already, click on the green "+" sign and inoculate the lot, takes only a few seconds. Quit the program, you are done.

    I don't have XP so I cannot answer that question.
     
  14. Mictlantecuhtli

    Mictlantecuhtli TechSpot Evangelist Posts: 4,916   +9

    No. Sounds like Explorer won't start for some reason.

    Can you open Event Viewer and check if it lists any errors?
  15. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    Iyiyiyi..

    If that was only my problem... My biggest error is
    "A problem is preventing window from accuarately checking the licence for this computer. Error Code 0x8009001a.
    I can only access my xp in safe mode under Julie(which I am administrator)..I had x-bf who helped reistall who seems unavailable to with that amin. password acces...
    Happy easter or Happy Spring!!
    Julie
  16. tbrunt3

    tbrunt3 Newcomer, in training Posts: 495

    So your problem all set now or you still having problems??
  17. r_a_jewel

    r_a_jewel Newcomer, in training Topic Starter Posts: 20

    Thanks:)

    :haha: Of course not that was just to start. I can only boot in safe mode.
    Thanks,
    Julie :)
  18. Mictlantecuhtli

    Mictlantecuhtli TechSpot Evangelist Posts: 4,916   +9

    Try registering two dll files again:

    Go to Start - Run..., type

    regsvr32.exe regwizc.dll

    and

    regsvr32.exe licdll.dll
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.