Thread: hjt log, please advise
-
June 27th, 2006, 12:28 PM #1Member
- Join Date
- Aug 2004
- Posts
- 30
hjt log, please advise
Hey everyone, I ran HJT and got this log, checked on http://www.hijackthis.de/index.php?langselect=english then removed: R1, R3, O17 and O20. When I restarted I couldn't surf any webpages. I was able to get on ICQ but that was about it. I did a system restore to before I removed those files and I can surf again with no problem. Did I remove something I needed? Can someone check out this log and give me some advice?
Thanks a bunch
-Franky
Logfile of HijackThis v1.99.1
Scan saved at 11:57:21 AM, on 6/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1136152253906
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D274334-BDB6-4029-BED0-05D9F2CA5D99}: NameServer = 85.255.116.153
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F128F8F-2759-4254-AC02-ABD5D97B6154}: NameServer = 85.255.116.153
O20 - AppInit_DLLs: C:\WINDOWS\system32\winspool.dll C:\WINDOWS\system32\winlogon.dll C:\WINDOWS\system32\notepad.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
-
June 28th, 2006, 07:51 AM #2
-
July 5th, 2006, 03:16 AM #3
You have an infection, not too bad but you may want to take care of it.
Copy your log here:
www.hijackthis.de and see what's lurking in the dark
This is what i can see:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
-
July 5th, 2006, 03:19 AM #4
You may also want to install Spyware Blaster:
http://www.javacoolsoftware.com/downloads.html
It will protect your computer against spyware installation, at least up to about 90%. Any protection that you have is like a condom, it is good to have it but not 100% proof
Better have protection than not
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Unable to log a user on "Security Log full"
By wingnuts in forum Networking and InternetReplies: 9Last Post: July 30th, 2011, 09:19 AM -
Need advise
By asianrn in forum Certification and EducationReplies: 5Last Post: February 2nd, 2006, 01:28 AM -
Find It log and Hijack This Log (wayyyq.exe??)
By SunDizzle in forum Security and Privacy IssuesReplies: 20Last Post: March 3rd, 2005, 03:00 AM -
Can someone please help me with my HJT log?
By IDEAListic in forum General Tech DiscussionReplies: 7Last Post: October 18th, 2004, 04:20 AM -
spyware problem? I hope it's that easy. HJT
By dusrusg in forum General Tech DiscussionReplies: 0Last Post: October 7th, 2004, 03:06 PM



LinkBack URL
About LinkBacks



Reply With Quote

Ugh, and I just got done doing an uninstall of one of Windows Botched updates from months ago, that seems to have affected many users for various programs, in my case, FRAPS doesn't record the...
nVidia GeForce 320.18 WHQL Driver...