Home > Please Help > Please Help Shdoc.dll Problem (HJT And CWS Log Included)

Please Help Shdoc.dll Problem (HJT And CWS Log Included)

Poker - http://download.games.yahoo.com/game...ts/y/pt0_x.cab O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...6/mcinsctl.cab O16 - DPF: {59D04288-805E-4D43-BE09-83B1083E9E1E} (IUpdateAutoLaunch Control) - http://idenphones.motorola.com/idenu...AutoLaunch.ocx O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Kozierok. Press enter. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged weblink

If it shows any errors removing any files delete them manually. HJT log included Thank you very much for your help. One who conquers himself is greater than another who conquers a thousand times a thousand on the battlefield". Phil Reply With Quote 08-19-2004,01:33 AM #10 shanmuga View Profile View Forum Posts View Blog Entries Visit Homepage View Articles Indian Master Geek Join Date Nov 2001 Location ^~^In my mind^~^

Empty the Recycle Bin. Also delete the file that you noted in the "Path to executable" field in the Network Security Services. For Windows XP, copy it to c:\windows\system32\.

Uncheck "Cookies" under "Internet Explorer". Yes, my password is: Forgot your password? If you have trouble deleting a key. All rights reserved.

Click the "Tweaks" button. Delete those keys then download, update and run CWShredder Click Fix, don't just scan. No Multi IP for Residential Cox users [Cox] by xymox1589. Attempting to delete C:\WINDOWS\system32\ehkmp.ini C:\WINDOWS\system32\ehkmp.ini Has been deleted!

Thread Status: Not open for further replies. Advertisement Recent Posts Which Monitor is Better for Gaming? Then post another log.


__________________ KangarooPoo View Public Profile Send a private message to KangarooPoo Find all posts by KangarooPoo Page 1 of 2 1 2 > Bookmarks Install an anti-virus.

  • Forums → Software and Operating Systems → Security → HJT Log uniqs1578 Share « Just a curious question about firewalls, • NAV 2005 not bootable in safe mode » samper13join:2004-02-03Naperville, IL
  • Click the System Restore tab.
  • UnZip the file and press "Restore Original Hosts" and press "OK".
  • Fios down in Tampa [FrontierCommunications] by tarp0n352.
  • Check the box labelled 'Turn off System restore'.
  • Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
  • Then click on everyone and put a checkmark in "full control".
  • Or, you can get Opera which in my opinion, is better still.
  • It allows unauthorised remote access to the infected computer via IRC channels.W32/Rbot-SV is a worm which attempts to spread to remote network shares.
  • Go here and download SDHelper.dll.

Additionally that computer needs to be secured properly as the method of infection is through network shares and weak passwords.What I can finish up with is the following, however, I suggest Scan again with HijackThis and post a new log (edit:alongwith with aboutbuster report) here. Finally go to Control Panel > Internet Options. I figure that file was the culprit.


jdshopping View Public Profile Send a private message to jdshopping Find all posts by jdshopping #6 17-07-04, 08:03 jdshopping

They may have been changed by this CWS variant to allow ALL ActiveX!! have a peek at these guys Click on the "Processes" tab. AdAware found 11 CWS and "possible hijack" items which I had AdAware fix. Here's what I did: Fixed the items in HJT, rebooted into safe mode.

HJT log included I'm stumped. I deleted those. The service will always start with __NS_Service. check over here Make sure that it is updated regularly and have it scan your system often.

Should he use Mozilla instead of IE? Is there another site for downloading control.exe? Run them both on a regular basis, following the manufacturer's recommendations.

Visa/MC/Paypal accepted. If this is your first visit, be sure to check out the FAQ by clicking the link above.

Additionally, I strongly recommend installing two fine freeware SpywareGuard and SpywareBlaster by JavaCool. Then press apply and ok and attempt to delete the key again. Read the all-new, FREE 200-page online guide: How to Build Your Own PC! NOTE: Using robot software to mass-download the site degrades the server and is prohibited. Unfortunately...

One of the HJT expert will be along to help. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Register Here now... http://nuvisiongraphx.com/please-help/please-help-me-log-included.html HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_*00BDO.#*017E*201A*201E*0081*00F5*00D8* 00C2*00B4*001E*00E2 It includes the "O.#´" in a "0000" folder in the services line.

Here are my hijack this logs -- before and after my first boot back: Logfile of HijackThis v1.98.0 Scan saved at 3:16:32 PM, on 7/17/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) Please check the HJT log below. Scroll down and find the service called "Network Security Service". Download FireFox and give it a run.

Articles Blogs Advanced Search Forum PC Operating System and Software Troubleshooting and Assistance Internet Security and Malware Help Another hijacking - HJT log included Custom Search Join the PC homebuilding revolution! before you tried the fix? Download the following zip file and unzip it to your desktop.http://www.mvps.org/winhelp2002/DelDomains.infRight-click on the deldomains.inf file and select 'Install'from the drop down menu (this will get rid of the *bad* items I R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fulpg.dll/sp.html#96676 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\fulpg.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\fulpg.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\fulpg.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search

Error #52 (Bad file name or number) in Sub GetLongPath(?.exe). Go to Start>Run and type msconfig. Now I still beleive something is bogging this thing down still, and need advice from a pro. I also did NOT spot the NS_Service keys in my registry.

Buddha, Siddhartha Gautama Reply With Quote 08-19-2004,02:21 AM #11 glyphic View Profile View Forum Posts View Blog Entries View Articles Geek Adept Join Date May 2004 Posts 67 Great. Western Australia. Poker - http://download.games.yahoo.com/game...ts/y/pt0_x.cab O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://www.support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...6/mcinsctl.cab O16 - DPF: {59D04288-805E-4D43-BE09-83B1083E9E1E} (IUpdateAutoLaunch Control) - http://idenphones.motorola.com/idenu...AutoLaunch.ocx O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Say hello!

Pages Reset... The time now is 07:56.

-- Default Style ---- Alt Blue Theme ---- Alt Grey Theme Contact Us - Web User - Archive - Privacy Statement - Top Also look here for tips on avoiding malware Last edited by shanmuga; 08-18-2004 at 06:24 AM. ......_=_ ....q(-_-)p .....'_) (_` ../__/ \ __\ .._ (<_ / )_.. (__\_\_|_/__) "Our life is i also can't open outlook express without it freezing up.

As I am following your advice I am a little perplexed with the recycle bin now. Are you looking for the solution to your computer problem? Something like "After trojan/spyware cleanup". Post back here with a fresh HijackThis log when you're done.


__________________ KangarooPoo View Public Profile Send a private message to KangarooPoo Find all posts by KangarooPoo