Finally...please help w/ these logs!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by kav, Jun 1, 2006.

  1. kav

    kav Private E-2

    I could not do anything in safe mode. Everytime I booted in safe mode, the keyboard became disabled, and if I tried to use the keyboard, the comp. would just freeze up. So I finally got all these scans run, it took me a while cause I'm doing this for someone else, and I had to do it on my time. This computer is running extremely slow, so I hope someone can help with these logs. I done everything on the "read and run me first page"
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no major malware issues to fix. Just a few minor things. The problem with this PC is probably the same thing I have seen in the past with people who installed all this stuff from their ISP. It brings the PCs to its knees. Here is what I'm talking about in the below quote box. Look at all the stuff from Charter High-Speed Security
    My opinion is that all this stuff should be uninstalled and you you should just use a few items that we would recommend.
    Okay while you are thinking about all that. Let's fix the other items!

    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the winsflt.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move winsflt.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.


    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (file missing)
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  3. kav

    kav Private E-2

    I did look up alot of those running processes and they were all conected to charter security suite. Like I said, I am working on this problem on someone else's computer.....but on MY home computer, I use AVG and Zone Alarm, windows defender, lavasoft, and clean up! All free editions, and I've never had a problem. I will follow your instructions as soon as I make it over there today, and repost! Thank you, thank you, thank you!!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know they all belong to Charter. That was why I was pointing them out. It is way overboard. There is just too much stuff running and that is probably why the PC is slow.
     
  5. kav

    kav Private E-2

    Here is the new hijackthis log....I uninstalled charter security, and added zone alarm and avg. Thanks again for all your help, and let me know if this looks okay now....the computer is doing much better! Before, the printer wouldn't even work, or any thumb drives, but now, all is working well!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks fine! I knew it was not malware, but just excessive junk ware from another ISP. I see it all the time.

    Make sure your work thru the below with your friend, the educational points are important for them to know:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds