CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]Need Help Removing Bad things!
Goto page Previous  1, 2, 3
 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
mark350

Trooper
Trooper


Joined: May 26, 2008
Posts: 18
Location: USA

PostPosted: Mon Jun 23, 2008 12:34 am    Post subject:
Reply with quote

Ok, ill do that now... thanks again for your help. This level of free help and time was very surprising to me to find - great forum!

Back to top
View users profile Send private message
sjpritch25

1st Responder
Premium Member

Joined: Mar 31, 2005
Posts: 5163
Location: West Coast of Florida, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Responders

PostPosted: Mon Jun 23, 2008 2:04 am    Post subject:
Reply with quote

Your Welcome!!!! Smile

Thumbs Up


_________________
Microsoft Valuable Professional--Consumer Security 2007-2009 image
image
http://geekfox26.blogspot.com/
Back to top
View users profile Send private message Visit posters website
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2938

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Mon Jun 23, 2008 2:37 am    Post subject:
Reply with quote

Greetings,

Pardon me for intruding, but I just wanted to post a tip for displaying the entries in Teatimer's log.

1) Open Spybot Search & Destroy;
2) Expand SS&D to fill your computer's screen;
3) From the menus, click Mode > Advanced Mode and choose Yes to the Warning pop-up;
4) On the left-hand side, click Tools > Resident.

This will show the log of allowed and denied entries.

Scroll down to see the most recent entries.

Tapping End will take you to the end of the line of whatever entry you're on. Home will take you to the start of the line.

Mark350, you should be able to locate which entry was blocked if you know the date/time it occurred.

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
mark350

Trooper
Trooper


Joined: May 26, 2008
Posts: 18
Location: USA

PostPosted: Mon Jun 23, 2008 1:43 pm    Post subject:
Reply with quote

Thanks... found the information.

*My system has been running good these last few days so I assume it's clean - thanks again!

For reference, here are the logs:

6/20/2008 10:19:32 AM Denied (based on user decision) value "Start Page" (new data: "http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome") changed in Browser page!

6/20/2008 10:19:36 AM Denied (based on user decision) value "Search Page" (new data: "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch") added in Browser page!

6/20/2008 10:19:38 AM Denied (based on user decision) value "Default_Page_URL" (new data: "http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome") added in Browser page!

6/20/2008 10:19:38 AM Denied (based on user decision) value "Default_Search_URL" (new data: "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch") added in Browser page!

Back to top
View users profile Send private message
sjpritch25

1st Responder
Premium Member

Joined: Mar 31, 2005
Posts: 5163
Location: West Coast of Florida, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Responders

PostPosted: Tue Jun 24, 2008 1:04 am    Post subject:
Reply with quote

looks good

And thanks Dragan_Glas


_________________
Microsoft Valuable Professional--Consumer Security 2007-2009 image
image
http://geekfox26.blogspot.com/
Back to top
View users profile Send private message Visit posters website
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2938

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Tue Jun 24, 2008 1:25 am    Post subject:
Reply with quote

Greetings,

sjpritch25
You're welcome! Thumbs Up

I think it's a case that since IE is the default browser, Microsoft is trying to encourage Mark350 to add MSN and Live Search to IE - preferably as default.

Once they're added as options only - not the default(s) - they should be alright.

Of course, there's no onus on Mark350 adding these at all. Wink

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Goto page Previous  1, 2, 3
Page 3 of 3

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer