Home > Hijackthis Log > CouponAge Malware - HiJackThis Log - Help?

CouponAge Malware - HiJackThis Log - Help?


Check out the forums and get free advice from the experts. Thanks. You may have already taken a few of the steps, but it never hurts to take a quick look   1 -- Use an AntiVirus Software, and be sure you update It has to be a shell extension if the popup is opening ie while I'm using mozilla, right?   thanks again,   redjeep0 Share this post Link to post Share on

This utility will find legitimate files in addition to malware. Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show Any help would be greatly appreciated! Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blankR3 - Default URLSearchHook is missingO4 - HKLM\..\Run: [dnam] http://www.bleepingcomputer.com/forums/t/62461/hijack-this-log-plus-other-info-and-it-aint-pretty/

Hijackthis Log Analyzer

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL O9 - Extra button: Yahoo! If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their It is. You are currently using hijackthis from a temp directory.

Did we mention that it's free. Using the site is easy and fun. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin ---------------------- reboot normally rescan with hjt and post new log.......... Hijackthis Windows 10 C:\WINDOWS\SYSTEM\owprt400.dll C:\WINDOWS\SYSTEM\mpwstr10.dll C:\WINDOWS\SYSTEM\jjdw400.dll C:\WINDOWS\SYSTEM\rpgwizc.dll C:\WINDOWS\SYSTEM\wlashext.dll C:\WINDOWS\SYSTEM\co60pprt.dll C:\WINDOWS\SYSTEM\mtdamg9x.dll C:\WINDOWS\SYSTEM\mucd30.dll C:\WINDOWS\SYSTEM\wpploc.dll C:\WINDOWS\SYSTEM\hldci.dll C:\WINDOWS\SYSTEM\oedbse32.dll C:\WINDOWS\SYSTEM\mjawt.dll C:\WINDOWS\SYSTEM\wsaupd98.dll C:\WINDOWS\SYSTEM\nntos.dll C:\WINDOWS\SYSTEM\crmctl32.dll C:\WINDOWS\SYSTEM\cqm.dll C:\WINDOWS\SYSTEM\cw60dr32.dll C:\WINDOWS\SYSTEM\mwnsspc.dll C:\WINDOWS\SYSTEM\ekshared.dll C:\WINDOWS\SYSTEM\nncpl.dll C:\WINDOWS\SYSTEM\umbui.dll C:\WINDOWS\SYSTEM\nldd32.dll C:\WINDOWS\SYSTEM\nuarch32.dll C:\WINDOWS\SYSTEM\jrsh400.dll C:\WINDOWS\SYSTEM\mlihnd.dll C:\WINDOWS\SYSTEM\iisrmt.dll C:\WINDOWS\SYSTEM\prpndi.dll C:\WINDOWS\SYSTEM\vescript.dll C:\WINDOWS\SYSTEM\lpxlmtmp.dll C:\WINDOWS\SYSTEM\malocusr.dll C:\WINDOWS\SYSTEM\nq3400.dll

I tried 'reset settings' but it did not help. Hijackthis Download VMSS----file WSXSVC----file Reboot afterwards if the files are successfully deleted. End check for missing files..... Once the first scan has completed, it will ask you if you wish for about:Buster to scan once more.

Logfile of HijackThis v1.99.0 Scan saved at 7:40:46 PM, on 2/14/2005 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE Hijackthis Download Windows 7 Virus cleanup? Select calsp.dll and using the right-pointing 'arrows' move all instances of calsp.dll it mentions and -->nothing else<--to the Remove side but leave everything else (it might already be over there when VXD CheckREGEDIT4[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers]"VDD"=hex(7):43,3a,5c,50,52,4f,47,52,41,7e,31,5c,53,79,6d,61,6e,74,65,63,5c,53,\ 33,32,45,56,4e,54,31,2e,44,4c,4c,00,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,\ 6c,65,73,5c,41,6c,77,69,6c,20,53,6f,66,74,77,61,72,65,5c,41,76,61,73,74,34,\ 5c,61,73,77,4d,6f,6e,56,64,2e,64,6c,6c,00,00.....

Hijackthis Download

Thanks, Roger Greb49erMarch 17th, 2007, 05:12 AMHi ,the only thing I can think of is post a hijackthis log at one of the sites below. So this thread will be closed. Hijackthis Log Analyzer Any other suggestions? Hijackthis Trend Micro Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers.

please post this at the forumLogfile of HijackThis v1.99.1Scan saved at 3:32:09 AM, on 8/19/2006Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exeC:\Program Files\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Svchost.exe causing system to slow down Started by Kurkus54 , Jan 18 2017 09:16 PM Prev Page 2 of 2 1 2 Please log in to reply 17 replies to this Please re-enable javascript to access full functionality. Windows will scan. Hijackthis Windows 7

Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE O12 - Plugin for .pdf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\nppdf32.dll O15 - Trusted IP range: (HKLM) O16 Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXEO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dllO9 - Extra 'Tools' menuitem: Sun Java I have a feeling it is but I'm not positive.If you could let us know how all this turns out that would be great. I tried to fix this numerous times but to no avail.

Hope Back to top Related Topics Page 1 of 2 1 2 Next Back to Virus, Spyware & Malware Removal · Next Unread Topic → 1 user(s) are reading this How To Use Hijackthis Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast!

If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their

Let it scan your system for files to remove. Change the "Save As Type" to "All Files". With the help of this automatic analyzer you are able to get some additional support. Hijackthis Portable digitalgypsyMarch 17th, 2007, 08:01 AMHello, Should I post any response that I get from the links you sent me?

the latest hjt.log is: Logfile of HijackThis v1.99.0 Scan saved at 10:50:30 AM, on 2/18/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. My background has been changed also. Pages Reset...