Are these instructions dodgy???...please advise

  • Thread starter Thread starter alpha
  • Start date Start date
A

alpha

Hello, i have just been told to check the following tick boxes and fix
the following hijackthis log file entries.....do these instructions
look malicious or are they safe to proceed.....thought it best to
double check and get a second opinion from those with more experience.

many thanks in advance if you can quickly look it over.....A

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
= http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet
Explorer\Search,Default_Search_URL = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=

R3 - URLSearchHook: HyperSearchHook -
{92394A67-A587-48ED-9AB0-C3DA76EA257E} - C:\Program Files\Common
Files\Hyperbar\HyperbarSS3.dll

O3 - Toolbar: GuruNet - {E8893D9E-169E-4a05-B0B6-FC5809D1AA77} -
C:\PROGRA~1\GURUNET\Toolbar\GuruNetToolbar.dll (file missing)
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} -
(no file)

O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class)
- http://www2.incredimail.com/contents/setup...er/imloader.cab
 
alpha said:
Hello, i have just been told to check the following tick boxes and fix
the following hijackthis log file entries.....do these instructions
look malicious or are they safe to proceed.....thought it best to
double check and get a second opinion from those with more experience.


No they are not dodgy. U need to stay away from the gay goat sites:)
 
second opinion

HijackThis log file analysis & repair
http://hijackthis.de/index.php?langselect=english
HijackThis is a program used by experienced users in order to detect
browser hijackers. It allows you to identify any sort of spyware and
malware (as well as some trojan horses and worms). This is achieved
by scanning special zones of the registry as well as the hard disk
drive, the results being listed in a structured window. Another
feature of HijackThis is the creation of a log file, which can be
saved as a simple text file and opened by any text editor (notepad
as default). Until now, inexperienced users, who could not analyze
the log file by themselves, had no other choice than posting it in a
specialized forum and to hope that a more experienced user takes some
time to analyze it. The script presented on this page is a way to
analyze your log without help from the outside: simply copy/paste
the content of the log file in the textbox below and hit the analyze
button.

* Posted via http://www.sixfiles.com/forum
 
alpha said:
Hello, i have just been told to check the following tick boxes and fix
the following hijackthis log file entries.....do these instructions
look malicious or are they safe to proceed.....thought it best to
double check and get a second opinion from those with more experience.

many thanks in advance if you can quickly look it over.....A

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
= http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://minisearch.startnow.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.startnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant
= about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch
= http://minisearch.startnow.com
R1 - HKLM\Software\Microsoft\Internet
Explorer\Search,Default_Search_URL = http://minisearch.startnow.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=

R3 - URLSearchHook: HyperSearchHook -
{92394A67-A587-48ED-9AB0-C3DA76EA257E} - C:\Program Files\Common
Files\Hyperbar\HyperbarSS3.dll

O3 - Toolbar: GuruNet - {E8893D9E-169E-4a05-B0B6-FC5809D1AA77} -
C:\PROGRA~1\GURUNET\Toolbar\GuruNetToolbar.dll (file missing)
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E}
- (no file)

O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class)
- http://www2.incredimail.com/contents/setup...er/imloader.cab


Who told you? Yep trash them.

HJT will also show BHO's. Here is a nice free proggie:

http://www.definitivesolutions.com/bhodemon.htm

--
He released government from the restraint of law.
____Lord Acton on Niccolo Machiavelli (1469-1527), George W. Bush, and
the Straussian neocons

Ellis_Jay
 
Back
Top