Can you check my hjt log please

Status
Not open for further replies.
Your HJT program version is well past its sell-by date!

Go to this post here first, and follow the instructions EXACTLY, especially about UPDATING and HJT-location.
How to remove Begin2Search/Coolwebsearch and Other Nasties

Uninstall anything to do with:
C:\WINNT\system32\P2P Networking\P2P Networking.exe
C:\Program Files\Cas\Client\casmf.dll

Start with the junk underneath, when you come to the HJT-program section in that post.
C:\winnt\system32\ypklcv.exe
C:\WINNT\system32\P2P Networking\P2P Networking.exe
C:\WINNT\system32\accwiz.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\WINNT\system32\rpnjpr.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - blank (file missing)
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - blank (file missing)
O2 - BHO: (no name) - {E7EE1223-CDF2-7E24-A878-4E6328965B82} - blank (file missing)
O4 - HKLM\..\Run: [ypklcv] c:\winnt\system32\ypklcv.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\system32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\system32\rpnjpr.exe reg_run
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll

Then post a fresh log, see How to post your Hijackthis log-files as an attachment.
 
Status
Not open for further replies.
Back