• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
barabba73

barabba log file

2 posts in this topic

Hi,

I post my log file below, please check it and tell me what to do !

 

thanks in advance!!

 

 

 

 

Logfile of HijackThis v1.98.0

Scan saved at 19.52.29, on 20/07/2004

Platform: Windows 2000 SP3 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\csrss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\Programmi\Trend Micro\PC-cillin 2002\Tmntsrv.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\Programmi\Trend Micro\PC-cillin 2002\PCCPFW.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\carpserv.exe

C:\Programmi\Trend Micro\PC-cillin 2002\pccguide.exe

C:\Programmi\Trend Micro\PC-cillin 2002\PCCClient.exe

C:\Programmi\Trend Micro\PC-cillin 2002\Pop3trap.exe

C:\WINNT\system32\rundll32.exe

C:\WINNT\system32\internat.exe

C:\WINNT\wininet32.exe

C:\WINNT\runwin32.exe

C:\Programmi\StopDialers\StopDialer.exe

C:\Programmi\Trend Micro\PC-cillin 2002\WebTrap.EXE

C:\WINNT\system32\wuauclt.exe

C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe

C:\Programmi\WinRAR\WinRAR.exe

C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\Rar$EX00.938\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchmeup.com/search.php?aid=1057

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchmeup.com/search.php?aid=1057

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchmeup.com/search.php?aid=1057

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchmeup.com/search.php?aid=1057

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchmeup.com/search.php?aid=1057

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchmeup.com/search.php?aid=1057

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchmeup.com/search.php?aid=1057

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.searchmeup.com/search.php?aid=1057

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchmeup.com/search.php?aid=1057

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {2197F002-4390-4641-A12C-F3A42F8B77A6} - C:\WINNT\system32\nhekgaa.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [CARPService] carpserv.exe

O4 - HKLM\..\Run: [pccguide.exe] "C:\Programmi\Trend Micro\PC-cillin 2002\pccguide.exe"

O4 - HKLM\..\Run: [PCCClient.exe] "C:\Programmi\Trend Micro\PC-cillin 2002\PCCClient.exe"

O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Programmi\Trend Micro\PC-cillin 2002\Pop3trap.exe"

O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\StarModem\StarModem USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"

O4 - HKCU\..\Run: [internat.exe] internat.exe

O4 - HKCU\..\Run: [spySweeper] "C:\Programmi\Webroot\Spy Sweeper\SpySweeper.exe" /0

O4 - HKCU\..\Run: [runwin32] C:\WINNT\runwin32.exe

O4 - HKCU\..\Run: [wininet32] C:\WINNT\wininet32.exe

O4 - Startup: Stop Dialers.lnk = C:\Programmi\StopDialers\StopDialer.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Download with GetRight - C:\Programmi\GetRight\GRdownload.htm

O8 - Extra context menu item: Open with GetRight Browser - C:\Programmi\GetRight\GRbrowse.htm

Share this post


Link to post
Share on other sites

You have a CoolWebSearch infection.

 

Download and run http://www.spywareinfo.com/~merijn/files/CWShredder.exe from its own folder.

 

Click Fix and then Next, let it fix everything it asks about.

 

Then reboot.

 

Put Hijackthis in it's own permanent folder such as C:\HJT\, and post a new log.

 

(Please make sure you include the whole log, that one doesn't look complete)

Edited by expertec

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0