Chaslang: Reformat - new hijackthis log

Discussion in 'Malware Help (A Specialist Will Reply)' started by KM1, Jun 21, 2005.

  1. KM1

    KM1 Private First Class

    Chaslang,

    I have done the reformat of my smaller computer and updated all of my software. Ran these updated scans all in normal mode first:

    Mcafee Viruscan
    Panda free online virus & spyware scan
    Adaware se
    Adaware VX2 addin
    Microsoft Antispyware Beta1
    Xcleaner
    CWshredder
    CCleaner
    Spyware Blaster - Loaded & Enabled all
    Spybot S&D - immunized & scanned

    No threats were found with any of these scans

    Included is a hijackthis log (run with hidden files, extensions, and protected system files unchecked). There are two BHO items I have never seen before with no name. Have no idea what they are? Do you and should they be removed? Is there anything else that needs removal or indicates the need for some other type of scan? Any help would be appreciated.
     

    Attached Files:

  2. Brandon

    Brandon controlmind

  3. KM1

    KM1 Private First Class

    Yes I have read this many times. This hijackthis log is something I had discussed in a much earlier post to chaslang several weeks ago. I did not reference that post because of the time laps. If it necessary, I will repost this in that old post, if I can find it. Just let me know.

    KM1
     
  4. KM1

    KM1 Private First Class

    Am pretty sure that this:

    BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    Is for Microsoft Money which I do have on my machine but have yet to run. Found this exact listing at Castle Cops BHO listings.

    However, this:

    BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

    has been much more difficult to find. Was some reference to it in the broadband security forums to it being something associated with Adobe Reader which I did update from version 7.00 to 7.01 then to 7.02. Still not sure though.

    Chaslang, anything on the above and on my new hijackthis log would be appreciated.

    KM1
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log is basically clean as expected. Some people would recommend dumping the dell4me items since they are relatives of MyWay and noone wants to see them. In addition, very few people leave their default pages set as the manufacturer ships them.

    Yes this FDD3B846-8D59-4ffb-8758-209B6AD74ACC is from MS Money but it is not properly installed if the file is missing.

    The other item could be something from a hijacker. I have no specific info on it. It does show up a lot with no file. Fix it, but it may not remain fixed. This does happen quite often with BHO's. You could also search the registry for it to see if any other additional info can be determined about it.
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
     
  6. KM1

    KM1 Private First Class

    OK, great info.

    If I want my machine to be as clean as possible from the begining then would you recomend I remove all of these, including the my way from dell. If so what exactly are the procedures so I don't mess anything up.

    KM1

    PS - you know my original hijackthis log from this machine before the reformat did not contain either of those BHO's and the software is identical Here is the old post:

    http://forums.majorgeeks.com/showthread.php?t=63632&page=1

    Post #3 contains the log for this computer before the reformat.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's up to you! Do you want the dell stuff or not?
     
  8. KM1

    KM1 Private First Class

    I have switched my main page like most so I do not need the myway from dell. Also, want to eliminate those BHO's. Do I just run hijackthis in normal mode / check the appropriate boxes and click fix or are there other steps I need to take before and/or after to try and eliminate these item?

    If a legitimate program needs the two no name BHO's latter will it recreate them when I try to run the program?

    Your help is appreciated
    KM1
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but make sure NO browsers are running before clicking Fix.

    But be aware that sometimes, there are problems trying to get BHO lines to go away even though the files are already missing. We have seen this many times.

    Probably not! You may or may not even need them (like the MS Money BHO). It may depend on what features and things you use.
     
  10. KM1

    KM1 Private First Class

    Ok, BHO's appear to be gone. I have done a restart and a cold start and then did run hijackthis. The log is attached. Decided that dell4.com/myway was not hurting anything as is so I did leave it alone. If these BHO's have not come back after restarting is it unlikely they will come back on their own???

    KM1

    PS - Will be back in a couple weeks with the log from my larger computer once I reformat this. This machine came with problems right out of the box so I do not think that it will be as clean as the log from this computer. Thanks for all your help so far.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually please only comeback to post logs if you are having malware issues. And obviously only post logs after running the READ ME FIRST and getting approval. We do not really have time to check logs users doing new installs just for the heck of it. If you have software issues (not malware issues), those should be discussed in the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds