Thread: HijackThis Log
View Single Post
Old 10-30-2005, 03:36 PM   #3 (permalink)
Buzz1927
Slyware Assassin
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 6,050
Default

Run Hijackthis and select "Do a system scan only", place a check by the following entries.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY... on&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY... on&pf=desktop
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE


Close all open windows and browsers, and hit "Fix Checked".

Find and delete this file (its probably in the C:\Windows folder).

ALCXMNTR.EXE

Backweb is used by HP for updating. It used to be considered spyware, but they've cleaned up their act a bit now, most spyware programs don't flag it, it's up to you if you want to keep it.

Firewall_Anti is a trojan, althought there's no sign of it in the log. Check in the C:Windows folder for Firewall_Anti.exe.
__________________
The Grim Reaper - Son of Glyndwr
"To Hell or Connacht" may you burn in Hell tonight!
Buzz1927 is offline   Reply With Quote