Hijack This Log -MHTML.Redir.Exploit

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by eljulz, Dec 16, 2004.

  1. eljulz

    eljulz Private E-2

    Two days ago Norton said I had this, and that access to the file was denied. I deleted temporary internet files and cookies. I tried to quarantine the file, but it said it could not find the file, probably because it was in a temporary internet folder.

    Then Spyware Guard started saying my home change had been changed, searchbar had been changed etc, and asked whether I wanted to keep the new change or revert back to the old one. I clicked revert but the windows kept popping up.

    I rebooted into safe mode (System Restore I always keep disabled), and ran a scan with Norton AntiVirus but it found nothing. I did a scan with Adaware SE which found something called Alexandra which I deleted. I restarted back in normal mode but the spyware guard things still pop up so in the end I just crossed the window.

    I was wondering if someone could check my Hijack This log to see if anything is wrong. P.S I found a file called m00.exe which was created at the same time I got the thing, so I deleted it.



    Thanks.
     

    Attached Files:

    • hjt.txt
      File size:
      6.1 KB
      Views:
      1
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hijackthis is the last step not the first and with have guidelines about when to post them and where to install HJT and how to run it. Please read and follow the Sticky threads.

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    You should also uninstall Messenger Plus 3. It installs malware (including LOP) on to your PC.

    And it appears that you are using msconfig to control what starts up. Disable using msconfig and allow everything so we get a true picture of what is running on your PC.

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. eljulz

    eljulz Private E-2

    Ok I think Ive dealt with it.

    Thanks :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you have anymore problems, let us know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds