Home > General > W32>desktophijack


Right click on the file and extract it to it's own folder on the desktop. Open My Computer. Do NOT run a scan yet. Click the Start button. Check This Out

My computer is slow---My Blog---Follow me on Twitter. Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum. I don't know why it didn't change back. HELP!

At that time, it had cleaned 4 infections. Before attacking an adware/spyware problem with hijackthis make sure you have already run the following tools. The tool creates a log of the fix which will appear in the folder.

Please respond to this thread one more time so we can mark this thread as resolved. __________________ We Are The BORG Spyware KILLER and Adware Destroyer! 08-01-2005, 01:41 AM here's my new HJT log. Yes, my password is: Forgot your password? I am currently trying to get a copy of WININET.dll from another computer to put on to m infected computer.

HELP! This site is completely free -- paid for by advertisers and donations. Save the log file when it asks and then click Finish. Join over 733,556 other people just like you!

THE ANTI-SPYWARE TUTORIAL MAKING INTERNET EXPLORER SAFER Please stay safe out there and take the helpful advice thatís been given. I've merged both of your posts into this one thread. The only problem with this is I am unsure of what file size you had b4, so again, there is no certainty in this.What do you think. Retired Staff 12,739 posts What OS does that other system have?

Thanks, Excal 0 #43 Richie_CUFC31 Posted 08 August 2005 - 04:31 PM Richie_CUFC31 Member Topic Starter Member 23 posts Ok, ive got a copy of the file from a friend who Thread Status: Not open for further replies. Thanks, Excal 0 #45 Richie_CUFC31 Posted 08 August 2005 - 05:08 PM Richie_CUFC31 Member Topic Starter Member 23 posts Hi again, I will post a fresh HiJack This log below:Logfile of Open add/remove programs and remove the following IF listed.

It infected a file called wininet.dll. I updated my virus definitions and now the virus is called w32.desktophijack. My computer is slow---My Blog---Follow me on Twitter. But my internet is still acting funny.

Logfile of HijackThis v1.99.1 Scan saved at 509 AM, on 7/31/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Double Click the System icon Performance tab option. No, create an account now. Get the one that's specified for your Operating System.

It was the same way in Safe Mode, but I'm not in Safe Mode anymore. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: HomepageBHO - {893fad3a-931e-4e53-b515-b1426d63799b} - D:\WINDOWS\system32\hp9700.tmp (file missing) O3 - Toolbar: Stay logged in Sign up now!

IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.

All rights reserved. When it's finished it will reboot your machine to finish the cleaning process. To remove these you need to flush/disable System Restore, reboot and enable it again. Let me see a fresh HiJackthis log to verify everything is allright.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup <--delete all the files in the AOL backup folder (Leave the folder!) Reboot into C:\WINDOWS\SYSTEM32\psis80ex.ax C:\WINDOWS\GatorPdpSetup.log C:\WINDOWS\smdat32a.sys C:\ms32.tmp Once back to normal windows...run another Panda scan and post it's log along with a new hijackthis log and let me know about your desktop issue. __________________ It found two new viruses called Trojan.desktophijack.C and Download.Trojan. Select the Tools menu and click Folder Options.

Your Desktop issue....you will need to reset the XP theme as one of the hijackers you had really messes it up.