I have had some problems lately with programs closing themselves, found a littler bugger named PDSched.exe which i removed but I still have a feeling my computer still could be infected somehow. I hope somebody could look through the Hijack this log and tell me what should be safe to remove.
Logfile of HijackThis v1.97.7 Scan saved at 02:02:45, on 26.09.2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Remove - Messenger Plus!- From add remove programs, in controlpanel. Or just delete: C:\Program Files\Messenger Plus! 3\MsgPlus.exe<<< Messenger Plus Folder. And you will get rid of a lot of Spyware
Take one of the first seven links, activate all, in settings
Download Spybot Search and Destroy here : http://www.safer-networking.org/index.php?page=mirrors if it is not already installed on your computer Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the Immunize "Scan System" button. When the Check is over, fix all marked with red
Open adaware and Click the "Check for updates now" line on the main screen. Click the "Connect" button on the webupdate screen.
If an update is available download it and install it. Click the "Finish" button to go back to the main screen.
Click on the Settings button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes
Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "Customize". This will open the Scan Settings Page. Make sure all of the following are On with a "green" checkmark:
Scan within archives Scan active processes Scan Registry Deep-scan Registry Scan my IE Favorites for banned URLs Scan my Hosts File
Then Click the Advanced Button – if running- on the left side to open the Advanced Settings screen. Make sure the following is on with a "green" checkmark:
Others are optional to be checked or unchecked.
Then click on the "Tweak" Button to open up the tweak settings.
Open up the Scanning Engine section and make sure ll of the following are On with a "green" checkmark:
Scan registry for all users instead of current user only
Make sure the following is unchecked with a "red" X:
Unload recognized processes & modules during scan.
Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:
Always try to unload modules before deletion During Removal, unload Explorer and IE if necessary Let Windows remove files in use at next reboot.
Click the "Proceed" button to save settings.
Click the "Next" button to start the scan.
When a scan is completed the Performing System Scan screen will change name to "Scan Complete".
Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.
To fix all the bad critical objects do the following:
Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries.
When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.
Close Ad-Aware SE build 1.05 and Ad-Watch (if running) Install the VX2 Cleaner Start Ad-Aware SE build 1.05 Go to “Plug-ins” Select the VX2 Cleaner plug-in and click “Run Plugin” If your computer isn’t infected, click “Close”.
If your computer is infected:
Select “Clean System” Reboot your computer Scan your computer with Ad-Aware Remove any VX2 objects detected Reboot your computer again Run a second scan to make sure the files have been removed from your computer
Ok, I have removed those items from the system, but I was wondering if Messenger Plus still innstalls spyware when u tell the innstaller to not innstall the extra program? Somehow I feel we users have less and less control about whats innstalled on our computers, I have even found a couple of "extra programs" innstalled with Creative's SoundBlaster Azs card.
Indeed you are correct, I found some C2 Media libraries hidden on my hd which was removed when I got rid of msn +. I have now removed everything you told me to, and they doesnt appear again when using hijack this.
Currently it is Thursday, November 20, 2008 10:30 PM (GMT +1) There are a total of 63.948 posts in 15.824 threads. In the last 3 days there were 34 new threads and 164 reply posts. View Active Threads
Who's Online
This forum has 27181 registered members. Please welcome our newest member, DilbertCube. 44 Guest(s), 2 Registered Member(s) are currently online. Details bmullenix, gio