From: ted s. on
Bubba Gump wrote:
>
> I hate when people post long log files, but I probably need to:
>
You don't need to post it here. There are plenty of forums where you can
get real help.


From: YoKenny on
Bubba Gump typed:
> "YoKenny" <YoKenny(a)noway.invalid> wrote in
> news:iFQRe.8800$884.817084(a)news20.bellglobal.com:
>
>> Please read:
>> http://www.tenebril.com/src/info.php?id=461193304
>> http://www.vitalsecurity.org/2005/07/winfixer-where-did-this-thing-come
>> .html http://geekstogo.com/forum/index.php?act=ST&f=37&t=56960
>> http://castlecops.com/t130077-WINFIXER.html
>
> Links to ads for more anti-spyware or people telling others about the
> existence of "WinFixer" is no help. :(
>
> I hate when people post long log files, but I probably need to:
>
> Logfile of HijackThis v1.97.3

The version of HijackThis you are running is very downlevel.
Update to the v1.99.1 version to delete the following nasties:
http://216.180.233.162/~merijn/files/HijackThis.exe

<snip>

> O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
> Files\Java\j2re1.4.2_04 \bin\jusched.exe

The SunJava application is WAY down level and has security exposures.
Un-instal ALL ols SunJava levels and install the latest v1.5.0
http://java.sun.com/j2se/1.5.0/download.jsp

Post your updated HijackThis log in a support forum:
http://boards.cexx.org/viewforum.php?f=1
--
YoKenny
Check for security application updates at least weekly:
http://www.dozleng.com/updates/index.php?&act=calendar
From: dak on
On Fri, 02 Sep 2005 19:03:40 -0000, Bubba Gump
<ambrosia_1(a)REMOVE.dslextreme.REMOVE.com> wrote:

>I hate when people post long log files, but I probably need to:
>
>Logfile of HijackThis v1.97.3
>Scan saved at 1:46:38 PM, on 9/2/2005
>Platform: Windows XP SP2 (WinNT 5.01.2600)
>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

YoKenny already gave you the URL for the current version of
HijackThis!, so here's my contribution:

TUTORIALS/HELP FILES:
<http://www.bleepingcomputer.com/forums/index.php?showtutorial=42>
<http://www.aumha.org/a/hjttutor.htm>

DO IT YOURSELF:
<http://www.help2go.com/modules.php?name=HJTDetective>
<http://www.hijackthis.de/en>
<http://hjt.iamnotageek.com/>

GET EXPERT HELP:
*NOTE: Registration is REQUIRED before posting a log*
*NOTE: Web sites NOT listed in any particular order*
<http://aumha.net/viewforum.php?f=30>
<http://www.bleepingcomputer.com/forums/forum22.html>
<http://www.dslreports.com/forum/security>
<http://castlecops.com/forum67.html>
<http://www.wilderssecurity.com/forumdisplay.php?f=24>
<http://www.cybertechhelp.com/forums/forumdisplay.php?f=25>
<http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html>
<http://gladiator-antivirus.com/forum/index.php?showforum=170>
<http://forum.iamnotageek.com/f-130.html>
<http://forums.maddoktor2.com/index.php?showforum=17>
<http://www.spywarewarrior.com/viewforum.php?f=5>
<http://forums.spywareinfo.com/index.php?showforum=18>
<http://forums.techguy.org/f54-s.html>
<http://forums.tomcoyote.org/index.php?showforum=27>
<http://forums.subratam.org/index.php?showforum=7>
<http://boards.cexx.org/viewforum.php?f=1>
<http://www.malwarebytes.biz/forums/index.php?showforum=5>

--
dak
My SpywareBlaster Custom Blocking List:
<http://customblockinglist.cjb.net/>
From: Marie Brown on

"Bubba Gump" <ambrosia_1(a)REMOVE.dslextreme.DELETE.com> wrote in message
news:Xns96C4DECBECE71abcom(a)216.168.3.50...
> Hopefully someone can solve this.
>
> Am I infected, or must I simply start using the Windows Firewall (I have
> XP
> Pro with sp2)?

I have the exact same popup and can't find it either. I use ZoneAlarm so a
firewall will not stop this "popup." It pops up with both Mozilla and I.E..

Very annoying. All of the tips on stopping this popup assume
> you are already infected. Since I never clicked OK and HiJack shows no
> files I don't recognize, is this just something that all I can do is bite
> the bullet and activate the firewall? What a pain! :(

Forget your firewall. It wont stop this popup.

> Please help.
> -*- Bubba -*-

Marie

From: Marie Brown on

"YoKenny" <YoKenny(a)noway.invalid> wrote in message
news:iFQRe.8800$884.817084(a)news20.bellglobal.com...
>
> Please read:
> http://www.tenebril.com/src/info.php?id=461193304

This one doesn't tell you how to get rid of it.

> http://www.vitalsecurity.org/2005/07/winfixer-where-did-this-thing-come.html

Nothing here about getting rid of it either. :o(

> http://geekstogo.com/forum/index.php?act=ST&f=37&t=56960

Nothing here either.......... I give up!

> http://castlecops.com/t130077-WINFIXER.html
> --
> YoKenny
> Check for security application updates at least weekly:
> http://www.dozleng.com/updates/index.php?&act=calendar

Marie