Webmaster Forum

Ezilon Directory   Keyword Research Tool   V7N Directory
Go Back   Webmaster Forum > The Webmaster Forums > Forum Lobby > Computers & Internet
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Computers & Internet For all those computer related discussions.

Reply
 
LinkBack Thread Tools Display Modes
Old 01-31-2006, 01:48 PM   #1 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 15,994
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
Smile Post Your HijackThis logs here

Cool Hi Jack This For Dummies

Computer running slow? Something just not feel right? Problems with pop-ups?

Well your in luck! We're here to help ya fix whats ailing ya!

How to use Hi Jack This

1. Download HJT - I have a Mirror download available HERE

2. Unzip HiJackThis - If you don't have winzip or winrar Download it HERE

3. Do a system scan and save a logfile - This is the first option at the very top of the page that opens (see screen shot below)

4. Start a new thread with HJT in the title - (and attach your logfile as an attachment) * Your log file is the notepad file that opens up simply go to file ==> Save As (blablabla.txt) then use the forums attach a file / manage attachments feature to attach your logfile to your new thread. (New threads make it easier to handle each problem separately and expedite the procedure time)

5. Wait for a response from someone here that has an IT background or understands HJT well! Never delete anything unless YOU feel safe doing so!

Tutorial kindly supplied by neo1seo

Thanks dude -

Please keep in mind that if you are posting HiJackThis logs, you must post them as attachments (so that they are not crawled by the SE's)and not just 'cut & paste' them -
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.

Last edited by G10 : 02-05-2006 at 04:09 AM. Reason: HijackThis Tutorial placed in
G10 is offline  
Add Post to del.icio.us
Reply With Quote
Sponsored Links
SEO Hosting by HostGator  Advertise Here  Buy Blog Links
Old 01-31-2006, 06:04 PM   #2 (permalink)
v7n Mentor
 
Sketch's Avatar
 
Join Date: 05-06-04
Location: London, UK
Posts: 1,452
iTrader: 0 / 0%
Latest Blog:
None

Sketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web pro
I'll be the first to post my log.

I have no idea what it means, but I don't think I have anything wrong with my machine ATM.
Attached Files
File Type: txt hijackthis.txt (10.4 KB, 204 views)
Sketch is offline  
Add Post to del.icio.us
Reply With Quote
Old 01-31-2006, 07:07 PM   #3 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,882
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
You can remove the following entries since the files are missing anyway...
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)


And, you can remove the following entry if you don't use quick time a lot...
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


You have a lot of stuff loading at boot time, but nothing I could see that was dangerous. (Unless you count Windows)


And, I would suggest all future posts should go in their own thread. If you are posting a hijackthis log for the first time here, please start a new thread so that each spyware event is self contained.
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 01-31-2006, 07:59 PM   #4 (permalink)
v7n Mentor
 
Sketch's Avatar
 
Join Date: 05-06-04
Location: London, UK
Posts: 1,452
iTrader: 0 / 0%
Latest Blog:
None

Sketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web pro
Done got rid of those, as well as the real player start up thing. Goddamn I hate Real Player it just takes over it should be counted as spyware!

[edit]
Sorry, I think I miss read both posts (ccole and G10) I should have made a new topic, I thought G10 was asking people to post their HijackThis log in this thread.

Sorry Guys.
[/edit]
Sketch is offline  
Add Post to del.icio.us
Reply With Quote
Old 01-31-2006, 08:24 PM   #5 (permalink)
DOS
Senior Member
 
DOS's Avatar
 
Join Date: 08-03-04
Posts: 1,077
iTrader: 0 / 0%
Latest Blog:
None

DOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to beholdDOS is a splendid one to behold
If you mess with the options, Real Player's not that bad. I use it to play my music actually, you can set it up to go straight to your music when you launch it and get rid of those things that pop up from it.
DOS is offline  
Add Post to del.icio.us
Reply With Quote
Old 01-31-2006, 08:41 PM   #6 (permalink)
v7n Mentor
 
Sketch's Avatar
 
Join Date: 05-06-04
Location: London, UK
Posts: 1,452
iTrader: 0 / 0%
Latest Blog:
None

Sketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web proSketch is a highly respected web pro
I still prefer Winamp and Windows Media Player, I only use Real Player to play Real Player Files. It's just one of those programs I have never really liked, I hate it when you install a program and it just steals all your file extensions and that's what Real does.
Sketch is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 01:22 AM   #7 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 15,994
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
I am not too hot on the 'HijackThis' side of things so I have also posted mine up to see if any improvements can be made
Attached Files
File Type: txt hijackthis.txt (9.6 KB, 138 views)
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
G10 is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 06:20 AM   #8 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,882
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
Clean as a whistle, my friend.

You might want to get rid of this...
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
It is a "something" that points to nothing.

You can get rid of this too if you don't use Quicktime a lot...
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


And, if you don't use MSN Messenger and really don't want it, I have a utility that kills it.
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 06:32 AM   #9 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 15,994
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
Thanks dude -

I appreciate your advice.
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
G10 is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 09:41 AM   #10 (permalink)
Contributing Member
 
intruth's Avatar
 
Join Date: 01-16-06
Posts: 548
iTrader: 0 / 0%
Latest Blog:
None

intruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to beholdintruth is a splendid one to behold
Great Thread and idea the other HijackThis forums are over loaded...

This will help alot of people who need to post their HijackThis log to get a faster responce...I should have thought of this 1st... lol Nice Job as a Super Moderator G10...
intruth is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 10:15 AM   #11 (permalink)
G10
Super Moderator
 
G10's Avatar
 
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 15,994
iTrader: 0 / 0%
Latest Blog:
None

G10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster materialG10 is supreme webmaster material
Thanks intruth but there were a whole lot of people who made this happen.

We got people like ccole1968 & joecoolfreak who I take my hat off to as they have some great I.T. knowledge and without members like that we wouldn't be able to make the "Computers & Internet" subforum work.

JS for taking the gamble, creating this subforum and allowing us techies the chance to do our stuff.

You got a point about the other HijackThis forums being overloaded and once people realise that it is also being done here, that should bring them over

Very early days still and we hope to bring in more stuff here
__________________

.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
G10 is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-01-2006, 11:33 AM   #12 (permalink)
Zap
Human Tripod
 
Zap's Avatar
 
Join Date: 01-15-06
Location: WEBTALKFORUMS.COM
Posts: 9,882
iTrader: 0 / 0%
Zap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster materialZap is supreme webmaster material
I got knowledge??? Hmmm. News to me!
__________________
BIG Gaming Forum

Toronto Forum
Zap is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-04-2006, 01:05 PM   #13 (permalink)
NeO
Contributing Member
 
NeO's Avatar
 
Join Date: 01-07-06
Location: 127.0.0.1
Posts: 928
iTrader: 0 / 0%
NeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest order
G10

I usually only like to see two BHO's on my log files... and those are Google & Adobe (And Adobe is only there cause every time I have to open a .pdf I get hassles if I've deleted it )

Of course that's just my personal prefrence... *knock on wood* I've yet to have a problem with a single pop up or virus in 5+ yrs

Here's something fun that will make everyone want to run a hijack this log file right after visiting the site (I guarantee that it's clean!) Check it out LOL... anyone not running SP2?

NeO
__________________
I can levitate birds....No one cares...

Top SEO Consultants | Beginning SEO Podcast
NeO is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-04-2006, 06:49 PM   #14 (permalink)
Inactive
 
Michael Allison's Avatar
 
Join Date: 12-08-05
Location: Spokane, WA
Posts: 1,961
iTrader: 0 / 0%
Latest Blog:
None

Michael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web proMichael Allison is a highly respected web pro
Send a message via MSN to Michael Allison Send a message via Yahoo to Michael Allison Send a message via Skype™ to Michael Allison
So, how am I doing?

Please have a look and see if there's anything that needs attention.

Thanks!
Attached Files
File Type: txt hijackthis.txt (6.9 KB, 110 views)
Michael Allison is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-05-2006, 10:53 AM   #15 (permalink)
NeO
Contributing Member
 
NeO's Avatar
 
Join Date: 01-07-06
Location: 127.0.0.1
Posts: 928
iTrader: 0 / 0%
NeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest order
Pretty clean Michael...

You have some missing files that when deleted should speed you up a bit

IMO all of these can go:
Quote:
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
Also your SunJava needs to be updated Should be on version JRE 1.5.0_06 instead of _02

nothing big but should help things out a bit... you did mention that your pc was running a little slow? what kind of RAM are you using? and did you recently put a new proggy on your system?

NeO
__________________
I can levitate birds....No one cares...

Top SEO Consultants | Beginning SEO Podcast
NeO is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-10-2006, 12:05 AM   #16 (permalink)
CEO, V7 Inc
 
John Scott's Avatar
 
Join Date: 09-27-03
Location: Japan, mostly
Posts: 42,097
iTrader: 2 / 100%
John Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster materialJohn Scott is supreme webmaster material
Send a message via AIM to John Scott Send a message via Yahoo to John Scott
I don't know if running Norton did anything, but not getting the browser hijacks ATM.
Attached Files
File Type: txt toshiba.txt (12.3 KB, 108 views)
__________________
Buy Permanent Contextual Links - V7N Web Directory

Questions? Call V7 toll free @ 1.888.876.8762
John Scott is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-10-2006, 12:33 AM   #17 (permalink)
NeO
Contributing Member
 
NeO's Avatar
 
Join Date: 01-07-06
Location: 127.0.0.1
Posts: 928
iTrader: 0 / 0%
NeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest orderNeO is a web professional of the highest order
Ok John... you have a ton of start up running... which will take a bit to figure all out but to start with I want you to get rid of these... anything else Ccole will probably find before I wake up

Quote:
Originally Posted by please remove
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINDOWS\system32\AlxTB1.dll (file missing)
*not sure about this one but I don't like the look of it -C:\WINDOWS\System32\TCtrlIOHook.exe hook is a bad file name...
don't like this one either... O4 - HKLM\..\Run: [TCtryIOHook] c:\WINDOWS\System32\TCtrlIOHook.exe
don't like this one either... O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
Garbage definately delete these...
For right now... I'd guess that you could get rid of all of those... Ccole needs to look at it and I'll do a bit more research tomorrow... I have meetings for most of the day so may be right when your getting back on

I can tell you this much I'm a hellovaLot betta than Norton

Now all your base are belong to us!

Just re run the HJT... this time only do a system scan... and click the boxes that I've posted to you... click "fix scanned" and do a quick restart run it once more... double check they are gone... and ya should be good to go...

Aight I'm off like a dirty prom dress!

Night M8's

NeO
__________________
I can levitate birds....No one cares...

Top SEO Consultants | Beginning SEO Podcast
NeO is offline  
Add Post to del.icio.us
Reply With Quote
Old 02-10-2006, 12:36 AM   #18 (permalink)