home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

hjt log, please advise

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1953
Discussions: 200,992, Posts: 2,379,903, Members: 246,360
Old June 27th, 2006, 01:28 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Aug 2004
Posts: 30
hjt log, please advise

Hey everyone, I ran HJT and got this log, checked on http://www.hijackthis.de/index.php?langselect=english then removed: R1, R3, O17 and O20. When I restarted I couldn't surf any webpages. I was able to get on ICQ but that was about it. I did a system restore to before I removed those files and I can surf again with no problem. Did I remove something I needed? Can someone check out this log and give me some advice?

Thanks a bunch
-Franky


Logfile of HijackThis v1.99.1
Scan saved at 11:57:21 AM, on 6/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\SuperAntiSpyware\SuperAntiSpyware.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [SuperAntiSpyware] C:\Program Files\SuperAntiSpyware\SuperAntiSpyware.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1136152253906
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D274334-BDB6-4029-BED0-05D9F2CA5D99}: NameServer = 85.255.116.153
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F128F8F-2759-4254-AC02-ABD5D97B6154}: NameServer = 85.255.116.153
O20 - AppInit_DLLs: C:\WINDOWS\system32\winspool.dll C:\WINDOWS\system32\winlogon.dll C:\WINDOWS\system32\notepad.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
xfrankyx is offline   Reply With Quote
Old June 28th, 2006, 08:51 AM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,860
Blog Entries: 15
http://www.techimo.com/forum/t137826.html
GroundZero3 is online now   Reply With Quote
Old July 5th, 2006, 04:16 AM     #3 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
You have an infection, not too bad but you may want to take care of it.

Copy your log here:

www.hijackthis.de and see what's lurking in the dark

This is what i can see:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
BluesMan1 is offline   Reply With Quote
Old July 5th, 2006, 04:19 AM     #4 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
You may also want to install Spyware Blaster:

http://www.javacoolsoftware.com/downloads.html

It will protect your computer against spyware installation, at least up to about 90%. Any protection that you have is like a condom, it is good to have it but not 100% proof

Better have protection than not
BluesMan1 is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Unable to log a user on "Security Log full" wingnuts Networking and Internet 7 August 31st, 2009 11:03 PM
Need advise asianrn Certification and Education 5 February 2nd, 2006 01:28 AM
Find It log and Hijack This Log (wayyyq.exe??) SunDizzle Security and Privacy Issues 20 March 3rd, 2005 03:00 AM
Can someone please help me with my HJT log? IDEAListic General Tech Discussion 7 October 18th, 2004 05:20 AM
spyware problem? I hope it's that easy. HJT dusrusg General Tech Discussion 0 October 7th, 2004 04:06 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3083)
Charges against non-tippers dropped.. (20)
Health Care Rationing (13)
Delete an OS (17)
Nvidia GTX 260 problem (10)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
windows vista security holes (19)
CPU fan stops spinning randomly (11)
Regular Build (11)
[F@H SPAM 11/16/09] ! 1/2 months to.. (41)
Point and Shoot Camera Suggestions. (8)
windows 7 problem (7)
Internet Lost (5)
Recent Discussions
[F@H SPAM 11/16/09] ! 1/2 months to r.. (41)
Print spooler problem (17)
Foxconn Blackops x48 MoBo (3)
Q9650 vs. Q9550 (2)
Desktop Calendar Application (2)
Looking for new motherboard (1)
soundmon.exe (8)
Jedi Academy Problem (3)
Can a page file be "too big".. (1)
Nvidia GTX 260 problem (10)
Point and Shoot Camera Suggestions. (8)
Size after cutting 700Mb file is 2.5 .. (0)
Delete an OS (17)
windows vista security holes (19)
updating BIOS via winflash, claims fi.. (1)
New Server Configuration Suggestions (0)
cheap gaming laptop? (12)
Unallocated Space (2)
help me pls laptop just stopped worki.. (1)
C# + LINQ Help (7)
Dynex DX E-402 (3)
EVGA 9800 gtx help with finding a goo.. (12)
Multiple Restarts Required at Boot (5)
cell phone won't work (0)
Is the PSU I received dead? (15)


All times are GMT -4. The time now is 09:51 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28