December 8th, 2005 20:00

Hello mclojai,

Welcome to the Dell forums. I don't see anything in your log file that would indicate the WinFixer problem. There ARE a couple of things that we can get rid of. After we clean these up, we can dig a little deeper, if we need to and go from there. Once we get everything cleaned up, I can give you some pointers on how to keep from being reinfected.

Go to www.trendmicro.com, then:

1. Click " Free Online Scan".
2. Click " Scan now, it's free".

Follow the screen prompts.

Save a copy of the report,:
Click " Print the report", then copy/paste to a new Notepad file and save to a convenient location. Post results into the next reply if requested to do so.

Run HiJackThis and click " Scan", then check(tick) the following, if present:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O3 - Toolbar: LexLink IE ToolBar - {CBAA6F21-985C-11D4-A02B-00B0D073E889} - C:\Program Files\LEXIS-NEXIS\CheckCite\llieobj.dll (file missing)

O8 - Extra context menu item: RemindU - file://C:\Program Files\topMoxie\TEMP\upromise_script0.htm

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/20031218/akamai.info.apple.com/iTunes4/WW/win/019-0123.20031218.zes4d/iTunesSetup.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{77646C9B-2ABF-4B97-B939-469C8AE8B473}: NameServer = 209.144.103.10,209.144.103.11
...( Verify that these ip addresses are for your isp's DNS Servers, if so, don't 'fix' these.)

O23 - Service: SNMP Trap Service (SNMPTRAP) - Unknown owner - C:\WINDOWS\system32\snmptrap.exe (file missing)

With all windows closed except HiJackThis, click " Fix checked".

Post back a new log, along with the results from the online scan. :smileyhappy:

George a.k.a. SpotCheckBilly
No Events found!

Top