Home > Please Help > Please Help Winfixer

Please Help Winfixer

This applies only to the original topic starter.Everyone else please begin a New Topic. Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Had Norton 2004, can't find now..Logfile of HijackThis v1.99.1Scan saved at 8:06:20 AM, on 8/17/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\rundll32.exeC:\Program Files\AIM\aim.exeC:\Program Files\Microsoft AntiSpyware\gcasDtServ.exeC:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\wuauclt.exeC:\Documents Backing Up: C:\WINDOWS\system32\faamebuf.dll 1 file(s) copied. his comment is here

We only require a report from it. Backing Up: C:\WINDOWS\system32\dpcprop2.dll 1 file(s) copied. If we have ever helped you in the past, please consider helping us. Backing Up: C:\WINDOWS\system32\dimsrpcn.dll 1 file(s) copied.

So please, someone look at this HJT log file and tell me what I can do. Next you will see: Please Type in the filepath as instructed by the forum staff and then press enter: At this point please type the following file path (make sure to Do NOT be alarmed by what you see in the report.

Most of what it finds will be harmless or even required. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged If we have ever helped you in the past, please consider helping us. Please refer to our CNET Forums policies for details.

Backing Up: C:\WINDOWS\system32\ic41_qc.dll 1 file(s) copied. Sorry. Register now! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exeO23 - Service: avast!

Backing Up: C:\WINDOWS\system32\kjdca.dll 1 file(s) copied. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exeO23

sveldtgrazer, Apr 4, 2006 #1 Cheeseball81 Moderator Joined: Mar 3, 2004 Messages: 84,310 Welcome to TSG SysProtect, WinFixer, Blackworm, Vundo - The most common installation methods involve system or security exploitation, Once the license is accepted, reset to 100%.Post that log in addition to a fresh HijackThis log. PAGER] "C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE" -QUIET O4 - HKCU\..\RUN: [MSMSGS] "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /BACKGROUND O4 - HKCU\..\RUN: [MYWEBSEARCH EMAIL PLUGIN] C:\PROGRA~1\MYWEBS~1\BAR\A.BIN\MWSOEMON.EXE O4 - HKCU\..\RUN: [WINFIXER2005] C:\PROGRAM FILES\WINFIXER2005\UWFX5.EXE /SCAN O4 - STARTUP: MYWEBSEARCH EMAIL PLUGIN.LNK Look here: http://securityresponse.symantec.com/avcenter/venc/data/winfixer.htmlHope some of that helps,Steve Flag Permalink This was helpful (0) Collapse - Hi Mike, please follow Steve's advise and by roddy32 / December 15, 2005 7:17 AM PST

Backing Up: C:\WINDOWS\system32\dzband.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\tzolhelp.dll 1 file(s) copied. If not, can you just let me know what it found and if something could not be fixed. Box, we would prefer that method for a donation.For security reasons I cannot give out that information..

Backing Up: C:\WINDOWS\system32\lpexpand.dll 1 file(s) copied. Backing Up: C:\WINDOWS\system32\fzifs.dll 1 file(s) copied. Later, GeekChick Back to top #5 horus horus Topic Starter Members 3 posts OFFLINE Local time:02:20 AM Posted 07 October 2005 - 08:26 PM Thanks, will do. Create Account How it Works Javascript Disabled Detected You currently have javascript disabled.

Backing Up: C:\WINDOWS\system32\ifxrip.dll 1 file(s) copied. However, if you have a P.O. So after 2 long hours of trying that method twice, I was in dismay once I rebooted, and there you go, the thing reinstalled itself once again.

Back to top #10 screen317 screen317 Malware Response Team 236 posts OFFLINE Gender:Male Location:Los Angeles Local time:11:20 PM Posted 09 July 2008 - 11:05 PM Well except, I installed Kerio

A tutorial on it can be found here.4) Download and install IE-Spyad, which will place over 5000 'bad' sites on your Internet Explorer Restricted List. Backing Up: C:\WINDOWS\system32\mzimtf.dll 1 file(s) copied. unfortunately the only method accepted is Paypal. Backing Up: C:\WINDOWS\system32\kc1394.dll 1 file(s) copied.

Backing Up: C:\WINDOWS\system32\diser.dll 1 file(s) copied. Are you looking for the solution to your computer problem? successful Restoring Windows Update Certificates.: deleting local copy: alsldpc.dll deleting local copy: alsldpc.dll deleting local copy: cyyptdll.dll deleting local copy: cyyptdll.dll deleting local copy: denet.dll deleting local copy: denet.dll deleting local By default it will install to C:\Program Files\Hijack This.