Hi-jack this log - as requested

  1. #11
    Neal is offline Dedicated Member

    Re: Hi-jack this log - as requested

    Well, didn't see what I was wanting to see, strange.



    Download CCleaner from here:
    http://www.majorgeeks.com/download4191.html
    or here:
    http://www.filehippo.com/download_ccleaner.html

    don't run the tool just yet please.
    Install it. The windows tab should be opened in the upper left of the program. Click analyze and then click run cleaner. Just use the windows tab that is up front by default.

    1.Uncheck "Cookies" under "Internet Explorer".

    2.If you are running Firefox: ,then click on the "Applications" tab and uncheck "Cookies" under "Firefox".


    Download both these uninstallers to your desktop and run them.

    http://lop.com/new_uninstall.exe

    http://lop.com/toolbar_uninstall.exe


    Save to your desktop and then run them.


    Go here to learn how to show hidden files/folders:

    http://www.xtra.co.nz/help/0,,4155-1916458,00.html#5


    Download Clean.bat to your desktop(Save page as or Save as): for later use to clean out your TEMPORARY and PREFETCH files.
    http://www.thatcomputerguy.us/downloads/clean.bat


    Scan with HJT again and put a check next to these items, making sure all browser windows are closed includeing this one so print this or create a new text document on desktop by right clicking an open area select new text document and save it to what ever you like. Now put a check next to these:

    O4 - HKLM\..\RunOnce: [MessengerPlusUninstall] C:\WINNT\system32\cmd.exe /C "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MsgPlusUninst. b at"

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm



    Again make sure all browser windows are closed and click FIX


    Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.


    Hunt for and delete if present:

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MsgPlusUninst.b at < file


    Now run that clean batch file you created earlier, type in 'Y' a couple of times and press enter at the prompts.


    Now run CCleaner useing windows tab only please.

    Then reboot normal mode and re-scan with Panda and let's see if that LOP infection is still there. Thanks.

  2. #12
    merched4 is offline Junior Member
    thanks v much for the info - had to go away again suddenly for work hence delay. will try and sort it out this weekend. really appreciate the help.

  3. #13
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    OK thanks,


    Run both of these uninstallers

    Download both these uninstallers to your desktop and run them.


    http://lop.com/new_uninstall.exe

    http://lop.com/toolbar_uninstall.exe


    Then post a new hijackthis log please.

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2