We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Problems with redirection on itnernet

I have run HJT as instructed on the thread I hijacked and below is the results.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:11, on 31/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running proces

Message deleted Thanks for the advice
End of file - 10334 bytes
«13

Comments

  • GunJack
    GunJack Posts: 11,864 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ...some quick observations....

    1. you're only on windows Service Pack 2, should be on SP3

    2. your java's out-of-date, should be on v.11

    3. you stil have Microsoft Antispyware - this was replaced/updated to Windows Defender years ago !!

    4. O3 - Toolbar: (no name) - !!5F2AC0E5-139A-4A23-B14D-C112EE50F5BE} - (no file) fix this with HJT

    5. Can you download, update and run MAlwarebytes and post a log??
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • Conor_3
    Conor_3 Posts: 6,944 Forumite
    Can you open c:\windows\system32\drivers\etc\hosts (no extension) in notepad and post the contents in here? You may need to enable viewing hidden files and folders in Windows Explorer.
  • GunJack wrote: »
    ...some quick observations....

    1. you're only on windows Service Pack 2, should be on SP3

    2. your java's out-of-date, should be on v.11

    3. you stil have Microsoft Antispyware - this was replaced/updated to Windows Defender years ago !!

    4. O3 - Toolbar: (no name) - !!5F2AC0E5-139A-4A23-B14D-C112EE50F5BE} - (no file) fix this with HJT

    5. Can you download, update and run MAlwarebytes and post a log??

    I have tried to update to SP3 but it keeps aborting during instalation

    I updated java last week - will do it again as I run sytem restore since then

    Not sure about MS Antispyware - should I delete or upgrade this (If so How?)

    HJT is running just now and I have checked box and clicked fix checked.

    Was able to download mal last night but it would not run I had window popup saying "error loading database line: #0. (0)."

    Excuse my lack of knowledge I am not very PC literate.
  • Conor wrote: »
    Can you open c:\windows\system32\drivers\etc\hosts (no extension) in notepad and post the contents in here? You may need to enable viewing hidden files and folders in Windows Explorer.

    I could if you would please tell me how to:confused:
  • [quote=GunJack;17159985
    4. O3 - Toolbar: (no name) - !!5F2AC0E5-139A-4A23-B14D-C112EE50F5BE} - (no file) fix this with HJT

    [/quote]

    OK done this and it is now removed from the list
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Im concerned about this ~
    Unknown O2 - BHO: D - !!6CD58760-9B5B-36DF-9F4B-E9C01FF0CFA4} - C:\WINDOWS\system32\xel85030.dll
    Googled the dll, and its not even there at all! (Never a good sign)

    FIX these ~
    O3 - Toolbar: (no name) - !!5F2AC0E5-139A-4A23-B14D-C112EE50F5BE} - (no file)
    O9 - Extra button: Sky - !!08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
    O9 - Extra button: (no name) - !!6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.ht m (file missing)

    Uninstall the microsoft antispyware program
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Also. Ive no data on PC CHILLIN anti virus software. Im guessing its not too hot so you may want to consider changing it (Once weve sorted the problem out)
    :idea:
  • spud17
    spud17 Posts: 4,434 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Im concerned about this ~
    Unknown O2 - BHO: D - !!6CD58760-9B5B-36DF-9F4B-E9C01FF0CFA4} - C:\WINDOWS\system32\xel85030.dll
    Googled the dll, and its not even there at all! (Never a good sign)

    Did the same, there's now 1 instance - this post!

    Agree suspicious.
    Move along, nothing to see.
  • Right managed to run mbam look like my pc is gubbed :confused: I never use the desktop its normally the wife and kids, looks like its well infected. They tell me they have been ignoring updates because I tell them not to download anything without asking.

    Oh well hrer is my log from MBAM.

    Live in Hope

    BB

    alwarebytes' Anti-Malware 1.31
    Database version: 1456
    Windows 5.1.2600 Service Pack 2
    31/12/2008 15:10:59
    mbam-log-2008-12-31 (15-10-40).txt
    Scan type: Full Scan (C:\|)
    Objects scanned: 124840
    Time elapsed: 2 hour(s), 23 minute(s), 55 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 37
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 23
    Files Infected: 286
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)

    Message deleted Thanks for your help
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.