Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Sorry Dr Watson again


  • Please log in to reply

#16
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Run Hijack This, per previous instructions and put a check mark next to these.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.zllwopnfl...xpgfrmP8vV.html

O2 - BHO: (no name) - {9066C997-1184-E591-40A6-83D5ADB1E3E3} - C:\DOCUME~1\Kimmi\APPLIC~1\DEBUGLOG\jump beep.exe (file missing)

What are the following two files? If you don't know or don't need them, get rid of them.

O4 - HKLM\..\Run: [Army Ref Option Manager] C:\Documents and Settings\All Users\Application Data\Scrholdarmyref\draw setup.exe

O4 - HKCU\..\Run: [Grid Blah] C:\DOCUME~1\Barrie\APPLIC~1\STUPID~1\dupe file send.exe


O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

Reboot, and post a new log.
  • 0

Advertisements


#17
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Daughter's log

ninstall anything with webrebates and messenger plus 3. Run Hijack This and put a check mark next to these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://web.fmvfidsbm...AvXmUsEsqu.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yutgkjloo...E1sAKPzxbsE.htm

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file

What is this?
O2 - BHO: (no name) - {9066C997-1184-E591-40A6-83D5ADB1E3E3} - C:\DOCUME~1\Kimmi\APPLIC~1\DEBUGLOG\jump beep.exe

O4 - HKLM\..\Run: [Army Ref Option Manager] C:\Documents and Settings\All Users\Application Data\Scrholdarmyref\Playbat.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus1.exe" /WinStart

O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [Grid Blah] C:\DOCUME~1\Kimmi\APPLIC~1\STUPID~1\dupe file send.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZSzeb04650US
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

Reboot into safe mode and get rid of:

C:\DOCUME~1\Kimmi\APPLIC~1\DEBUGLOG\jump beep.exe
C:\Program Files\Web_Rebates\
C:\DOCUME~1\Kimmi\APPLIC~1\STUPID~1
C:\Program Files\Messenger Plus! 3

Clean out your temp. files and reboot.
  • 0

#18
Tylow

Tylow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Thx for replying again Coachwife,i take it first lot of instructions are for my account and second for daughters?,it'll be a couple of days till i get onto this i think (busy work schedule :mad: ).I'll keep you updated.............................
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP