malware

That is Windows Live Messenger related, it’s ok. More info here.

Thanks, you have to wonder why they are so obscure in the naming of it.
As Shortiehi5 was running an old version of HJT that may be why it shows the (no file) as it used to report similar issues with avast. This is also why I said to check against the next run of HJT.

I have a WinPatrol Hijack log which also doesn’t give any info, just O2 - BHO: - {7E853D72-626A-48EC-A868-BA8D5E23E045}.

I guess Micro$oft doesn’t really bother with names :stuck_out_tongue:

Yes, but it doesn’t give the (no file) suffix, which was a common problem with the old 1.99 version of HJT. Not so much of a problem with HJT 2.0 and usually if that reports (No file) it is a redundant entry.

;D Here is a big Grin as i am happy i have attached it !!lol ''but 2 times lol ok i now know how…So i work in the morning ''just friday mornings so i’ll have to go and get some ZZZZZEEeeeZZ for now ’ i’ll be back on friday night 'i hope unless the dog eats my connection, while i am gone…no she sleeps as she pouts when i leave her lol >>… But hey you all have been simply amazing!! i wish i could do some thing for all of you!!! ty so very much!!! And i will do what you all have so sweetly asked me to do !!and get back with it !!tyty…Shortie :slight_smile:

Hi i am back and i am hoping this was done right! lol please feel free to let me know thank you ever so much!! I never thought i could do this you are all amazing with being so helpful!!tyty Shortie

Shortiehi5 close all browser windows then select the following then Fixed checked

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 <== make the home page Google as it loads a lot faster
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Do NOT delete this one! It’s Windows Live Messenger related, see 7-8 posts above :wink:

But why delete all the other stuff? The default pages and stuff in IE that is.

PiCo
I went to the posts labeled reply 7 and 8 on page 1
what exactly are you referring to?

No, I ment in this page :slight_smile:
That would be reply number 20!

Going to sleep now, have a good night!

??? hello every one ’ gee i am sorry i read your posts and i don’t understand… do i have malware? and if i click on checked fixed , will this delete all? could you tell me what ones i delete ? maybe i just don’t ''get it yet …please & thanks sorry i’am soo slow to get things !!Shortie…

gee i am sorry i read your posts and i don't understand.... do i have malware?
It looks like your system does not have malware.

It looks like you have not installed Service Pack 3 ( SP3 ) yet.

In IE go to Tools then Windows Update then run Windows update to download and install SP3.

The entries to be removed by HijackThis are mainly cosmetic and not urgently needed to be removed.

ok thank you this is me ;D very happy !! i will install the pack!! wishing you all the best !!and soooo nice of you to help us all here!! i will drop in to say a good hello now and then!!!Shortie!!

thanks Shortone

after you get SP3 then the Secunia Advisor and get everything up to date especially java and adobe
system running well generally?

more ram?

Hi and thank you Yes more ram !! i need it… but i got one more spot of trouble !! i got a warning about this one (and please do not touch it or Dl it ok…warning its bad am sure i had to get rid of this i put it in chest is this ok? ((( IRC: malware-gen )))) i never heard of this …i have been on the puter for 6 yrs and this is the 2nd time i have aprob so i figure its not too bad… any info on this please my friend’s son wanted to see this site and hence the malware… :-[ shortie was it ok to put the name on here? i hope it was don’t wanna make a mess ty

If you break down the malware name given, the IRC part, something that would come through Internet Relay Chat, the ‘Malware’ is unspecified (trojan/spyware/adware, etc.) as it is detected by a generic (-gen) signature.

The generic signature (the -gen at the end of the malware name), so that is trying to catch multiple variants of the same type of malware.

Since it is a -gen it may be a hit or a false positive

do the upload to virus total thing and also send to avast

good on ya shortie

:)ok i thank you !! glad to be here and lov all the help you so wonderfuly give out!! Very helpful place!!! tyty Shortie… i put the malware name as i thought it might be helpful to others !!