Hijack This review request

Status
Not open for further replies.

chipperh

Posts: 12   +0
Hello,
I've attached the .log file created by Hijack this for review. Request some feedback and guidance please.

I've been constantly redirected when clicking on google choices and would like to fix that problem.

Thank you in advance.
Chip
 
Chip - I suggest you do what dayslayer8. suggest, as you have a large number of infections
 
Thank you both.
I did as Dayslayer suggested and it appears that I no longer get re-directed when I click on a google link. I ran all three of the cleaner applications and they each found 'infections' and removed them.

Thanks again.

Chip
 
Some NOTES for your consideration:

1. Posting the HijackThis log only is not sufficient for a review. While one problem might have been resolved, it is almost certain that some malware is still on the system. While you have 'assumed' that simply running the cleaning programs has resolver all the malware problems, that is not the case.

2. You are running out-dated versions of Java and Adobe Reader. These are security risks
(Acrobat 7.0> s/b v9.01, jre1.6.0_07> s/b v6u13.

3. None of the scans can be relied on to be accurate because you are running 2 Real Time Protection programs: TeaTimer and Spysweeper. Per Step 3, these are suppose to be temporarily disabled while cleaning as they can interfere with the scans.
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

4. You have 4 Domains in the Trusted Zone which do not need to be there.
O15 - Trusted Zone: *.intuit.com
O15 - Trusted IP range: http://192.168.1.114
O15 - Trusted IP range: http://192.168.1.111
O15 - Trusted IP range: http://192.168.1.115

5. You are running the AskBar and Smiley Central, both known adware contributors:
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (file missing)

O8 - Extra context menu item: &Search - ?p=ZNfox000>>> SmileyCentralPFSetup2.3.50.19
File Behavior

SMILEYCENTRALPFSETUP2.3.50.22.ZNFOX000.EXE has been seen to perform the following behavior:
* This process creates other processes on disk
* Executes Processes stored in Temporary Folders
* This Process Deletes Other Processes From Disk
* Executes a Process
SMILEYCENTRALPFSETUP2.3.50.22.ZNFOX000.EXE has been the subject of the following behavior:
* Executed as a Process
* Created as a process on disk
* Deleted as a process from disk
* Has code inserted into its Virtual Memory space by other programs
* Executed by Internet Explorer[/B]

6. You have an entry in the log which is only displayed if it is malware:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe>> The F2 entry will only show in HijackThis if something unknown is found. This does not necessarily mean it is bad, but in most cases, it will be malware.

7. You have entries set for Global Startup which are incomplete. And Global means that they will start up no matter which user account is being used:
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Windows Home Server.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe

IF you would like to complete the cleaning properly, please follow the Steps HERE and attach all three logs for review when finished.

And one final comment: you are starting up with an excessive number of running processes, processes loading from programs on the Startup Menu and the Registry. you have an excessive number of Services set to Automatic.

My guess is that your startup and shutdown are slow and your surfing speed is slow because of the excessive processes.
 
Thank you Bobbye,
I've since run the 8 step cleaning process twice, but will run once more ensuring that I shut down Spysweeper and Spybot s&d Teatimer.

Thank you for the time you've spent anayzing the log file I've sent. I will get busy with what you've instructed me with and re-upload the three files when complete.

Again,
Thank you.

Chip
 
OK! I have some log files to post. I sincerely hope that one of you guys can provide some enlightenment to me. I've done the scans. When clicking on a google search item, the browser still takes me someplace else.
I disabled Teatimer and spysweeper for the scans. I was going to disable NAV autoprotect, but the autoprotect selection says "ERROR" and I cannot toggle it. I may have to re-install Norton System works.

I really appreciate you taking the time to help me.

THank you in advance.

Chip
 
And regarding the number of processes running , How do I safely shut down and prevent all the extra process from running?

Chip
 
Quick question - Have Spysweeper - Antivirus, and have you paid for Norton/Symantec ?
 
**Bump**
I've uploaded the three logs (a few posts back), hoping one of the experts here might be able to help?

Thank you!

Chip
 
Ok. Deactivate All programs from msconfig (except your security programs)

Look here how to:
http://netsquirrel.com/msconfig/

It will stop many processes.

If you afterwards get any errors/messages on Bootup, activate the program/s there give you the message.
 
FYI: Real Time Protection is still running:[/B]
3. None of the scans can be relied on to be accurate because you are running 2 Real Time Protection programs: TeaTimer and Spysweeper.
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

Remove bad HijackThis entries
Run HijackThis
• Click on the System Scan Only button
• Put a check beside all of the items listed below (if present):
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: (no name) - {9A065C65-4EE7-4DDD-9918-F129089A894A} - (no file)
O4 - HKLM\..\Run: [Ptipbmf] "C:\WINDOWS\system32\rundll32.exe" ptipbmf.dll,SetWriteCacheMode
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Windows Home Server.lnk = ?
O23 - Service: wnvirq32 Service (Wnvirq32Service) - Unknown owner - C:\WINDOWS\system32\wnvirq32.exe (file missing)

• Close all open windows and browsers/email, etc...
• Click on the "Fix Checked" button
• When completed, close the application.

Chip, you have a lot of processes running from National Instruments. Are you actively using that program? All parts of it? there are many processes starting up that don't need to be. I can help you with that.

Are you still getting redirected while using Firefox? If you are, I have a program specifically for this- let me know and 'll give you the info. We never dealt with the logs.
 
Thank you.
I have removed the recommended items after scanning with HJT.

I am using LabView fairly regularly, but only stand alone (No GPIB, DAQ, or external interface in use). In about two weeks, I will be done using it for a while (at least on this machine). If there are processes I can eliminate, I am all ears (eyes).

I just played around with FireFox, google searched. I did get redirected when selecting some of the search results. Some of them connected correctly.

Suggestions?
And thank you, seems your recommendations are making some difference.
Chip
 
Status
Not open for further replies.
Back