HijackThis - Log Included - Details Below Started by WrathOfMe9 , Jul 02 2015 10:10 AM

kiervin001, Jan 18, 2017 at 4:34 AM, in forum: Virus & Other Malware Removal Replies: 13 Views: 288 kevinf80 Jan 24, 2017 at 3:22 PM In Progress Vosteran Chrome Hijack Help Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast!

Reboot into Safe Mode and delete the file if found.c:\windows\higeorge2.exe]O4 - HKLM\..\Run: [syshtray] c:\windows\higeorge2.exePost a fresh Hijack This! If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it.O16 - ActiveX Objects (aka Downloaded Program Files)What it looks like: O16 - DPF: Yahoo! If it's not on the list and the name seems a random string of characters and the file is in the 'Application Data' folder (like the last one in the examples

Scan suspect files before copying it onto your machine with Avast (simple, right-click, scan function). Check status of c:\eied_s7.cab at virustotal.com, whether it is legit.That is all for now, for the trojan downloader I suspect to be here, see: http://www.viruslist.com/en/viruses/encyclopedia?virusid=112169If so fix the according 016 entries by VinceGP / May 19, 2008 6:46 PM PDT In reply to: Help!

Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat

Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 Hijackthis Windows 10 Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program To make sure you have all the drivers you need (in case you don't have the resource cd's for all your stuff), go get the free Driver Collector v1.2 from www.majorgeeks.com Logged The best things in life are free.

HijackThis log included. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: &Yahoo!

thanks for your help! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetectO4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value

The second part of the line is the owner of the file at the end, as seen in the file's properties.Note that fixing an O23 item will only stop the service

I'm dealing with nasty virus! If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this

I'm dealing with nasty virus! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: &Yahoo!

Disabled and enabled the system files as requested and went to VirusTotal to upload the "higeorge" file, which i can't find anywhere within the C:\WINDOWS files...

