Welcome to the Dell forums. I don't see anything in your log file that would indicate the WinFixer problem. There ARE a couple of things that we can get rid of. After we clean these up, we can dig a little deeper, if we need to and go from there. Once we get everything cleaned up, I can give you some pointers on how to keep from being reinfected. Go to
www.trendmicro.com, then:
Save a copy of the report,:
Click "
Print the report", then
copy/paste to a
new Notepad file and save to a convenient location. Post results into the next reply if requested to do so.
Run
HiJackThis and click "
Scan", then check(tick) the following, if present:
O17 - HKLM\System\CCS\Services\Tcpip\..\{77646C9B-2ABF-4B97-B939-469C8AE8B473}: NameServer = 209.144.103.10,209.144.103.11 ...(
Verify that these ip addresses are for your isp's DNS Servers, if so, don't 'fix' these.)
SpotCheckBilly
932 Posts
0
December 8th, 2005 20:00
Welcome to the Dell forums. I don't see anything in your log file that would indicate the WinFixer problem. There ARE a couple of things that we can get rid of. After we clean these up, we can dig a little deeper, if we need to and go from there. Once we get everything cleaned up, I can give you some pointers on how to keep from being reinfected.
Go to www.trendmicro.com, then:
1. Click " Free Online Scan".
2. Click " Scan now, it's free".
Follow the screen prompts.
Save a copy of the report,:
Click " Print the report", then copy/paste to a new Notepad file and save to a convenient location. Post results into the next reply if requested to do so.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O3 - Toolbar: LexLink IE ToolBar - {CBAA6F21-985C-11D4-A02B-00B0D073E889} - C:\Program Files\LEXIS-NEXIS\CheckCite\llieobj.dll (file missing)
O8 - Extra context menu item: RemindU - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{77646C9B-2ABF-4B97-B939-469C8AE8B473}: NameServer = 209.144.103.10,209.144.103.11
...( Verify that these ip addresses are for your isp's DNS Servers, if so, don't 'fix' these.)
O23 - Service: SNMP Trap Service (SNMPTRAP) - Unknown owner - C:\WINDOWS\system32\snmptrap.exe (file missing)
With all windows closed except HiJackThis, click " Fix checked".
Post back a new log, along with the results from the online scan. :smileyhappy:
George a.k.a. SpotCheckBilly