someone please read hijack this logfile and tell me what to delete

By fruto
Feb 12, 2006
  1. as the subject says

    the logfile is attached

    thanks in advance
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

  3. fruto

    fruto Banned Topic Starter

    I already did that
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Boot into safe mode.

    Turn off system restore.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system".

    Go to add remove programmes in your control panel, and uninstall anything to do with(if there).

    C:\Program Files\Daily Weather Forecast\weather.exe

    Close control panel.

    Open your task manager, by pressing the ctrl/alt/delete keys together.

    Click on the processes tab, and end process for(if there).


    Close task manager.

    Run HJT with no other programmes open, and have HJT fix the following, by placing a tick in the little box next to(if there).

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page ={SUB_CLCID}

    R3 - URLSearchHook: (no name) - {927927BB-CC52-B9F6-28E5-C79EFF3802C5} - C:\WINDOWS\system32\psq.dll

    O2 - BHO: (no name) - {927927BB-CC52-B9F6-28E5-C79EFF3802C5} - C:\WINDOWS\system32\psq.dll

    O4 - HKCU\..\Run: [Perfjcv] C:\WINDOWS\system32\m?config.exe

    O11 - Options group: [INTERNATIONAL] International*

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) -
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
    O16 - DPF: {9B8D3E79-A732-4EC0-AEEE-8AF8CDF10D8A} (PalmSourceInstallerX) -

    Now click on the fix checked button.

    Close HJT.

    Locate, and delete the following bold files(if there).

    C:\Program Files\Daily Weather Forecast\weather.exe

    Boot into normal mode, and turn system restore back on.

    Regards Howard :)
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...