HyJinx
I can see by your log files this may be a company computer or one you use to connect to a company?
NOVELL network, Lotus Notes, Corporate Domain ?
Please let me know your type of connection is it VPN or SSL
just want to keep you safe and not have things broken...
This the one i want to know about O1 - Hosts: 172.17.226.89 HC1
General cleanup is needed and will hurt anything
Right Click on MyComputer icon and go to properties
Turn Off system restore
open IE and go to TOOLS OPTIONS delete temporary internet files and cookies
do a disk cleanup in your Start/accessories/system tools/ Menu
download
malwarebytes and install
BEFORE YOU DO THIS remember the connection O1 - Hosts: 172.17.226.89 HC1
run hijackthis and malwarebytes at the same time
select any files and or keys in the attachment I posted in hijackthis but on both maiwarebytes and hijackthis click fix at the same time.
then reboot immediatly.
if you forget to turn off system restore it will return no matter
You have the google redirecter also O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
MAKE sure you check all in Hijackthis
reboot once complete, run hijack this and post your log here again
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\dpmw32.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 172.17.226.89 HC1
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - AppInit_DLLs: girruy.dll
O20 - Winlogon Notify: geBuRIAT - geBuRIAT.dll (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe