home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1810
Discussions: 188,470, Posts: 2,244,169, Members: 232,723
Old November 6th, 2006, 06:54 PM   Digg it!   #1 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
Hijackthis log

hey guys, my comp has been a little laggy so i thought i would run the program and have u guys check out anythin suspicious for me since i have no clue when it comes to that stuff. So heres my log please let me know if there is anythin malicious i should get rid of. thanx

Logfile of HijackThis v1.99.1
Scan saved at 5:54:22 PM, on 06/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\JMRaidTool.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
C:\Program Files\ASUS\ASUS DH Remote\AsDhRemote.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\program files\valve\steam\steam.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Rob\Local Settings\Temp\wzaf7a\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ai Quicker Help] "C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe"
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.0 RC 16\RivaTuner.exe" /S
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edg...ex-2.0.6.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{50275B52-86ED-41B5-8BD1-D5F7C2E73091}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{D75925A4-7CD8-4261-9B01-2BF1500E441B}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{E964512A-6B25-45DC-A124-C2F46A11885E}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
__________________
Core 2 E6600 @ 3.47Ghz
Asus P5W-DH
WD Caviar 250Gb
Maxtor 250Gb
Evga 7600GT KO (590/775)
Ultra 600W Xfinity
BenQ FP202W


Douce33 is offline   Reply With Quote
Old November 6th, 2006, 06:56 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5

GroundZero3 is offline   Reply With Quote
Old November 6th, 2006, 06:57 PM     #3 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
great, thanx GZ

Douce33 is offline   Reply With Quote
Old November 6th, 2006, 07:06 PM     #4 (permalink)
Ultimate Member
 
mjolnir1134's Avatar
 
Join Date: Jan 2005
Location: The Internet
Posts: 1,999
Try to uninstall the programs causing those bad processes. If the uninstalls were unsuccessful, heres what I do:

Start>Run>type in msconfig>go to "Startup" tab>find nasty process and disable it.>Reboot!

I won't say it can completely delete the folder or program that makes the nasty process, but it can help make it stop running and perhaps make it easier to uninstall.
__________________
Rationalrant.com - My website.
e6420—2GB RAM—8800GT—ASUS P5LD2—XP / EEE 1000H
mjolnir1134 is offline   Reply With Quote
Old November 6th, 2006, 07:26 PM     #5 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,228
Wow that very nasty things on those. Best is format and install fresh window xp.

Ok go to run and type msconfig then look at start up tab and read the words.
Here info that say if have virus on msconfig http://www.sysinfo.org/startuplist.php?filter=
__________________
sorry for my bad grammar!
Milwaukee is offline   Reply With Quote
Old November 6th, 2006, 10:05 PM     #6 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
What nasty things are you talking about?
GroundZero3 is offline   Reply With Quote
Old November 6th, 2006, 10:17 PM     #7 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,228
My mistake it have problem with registry files on those. Did you try Crap cleaner?

Did you have Adware se personal and firewall? Is there another problem like pop errors or get bsod? how old those is? Just ask question.
Milwaukee is offline   Reply With Quote
Old November 7th, 2006, 07:24 AM     #8 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
You may have a little infection.

There is some tools that you can use to try to do something with it:

Ad Aware: http://www.download.com/3000-2144-10045910.html

Spybot: http://www.safer-networking.org/en/download/index.html

CW Shredder: http://www.intermute.com/spysubtract..._download.html

Ad Aware tutorial: http://www.bleepingcomputer.com/tuto...utorial48.html

Spybot tutorial: http://www.bleepingcomputer.com/tuto...utorial43.html

BluesMan1 is offline   Reply With Quote
Old November 7th, 2006, 07:28 AM     #9 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
on my comp i currently have ad-aware, spybot, counterspy, avast, and AVG. i had norton but everyone on here told me to get rid of it, but since i did ive been gettin trojans like crazy.
Douce33 is offline   Reply With Quote
Old November 7th, 2006, 07:57 AM     #10 (permalink)
Senior Member
 
Geforce's Avatar
 
Join Date: Dec 2004
Location: Nottingham, UK
Posts: 602
Send a message via MSN to Geforce
LOL.

Nothing wrong with Norton.. The Home Edition is a bit naff, but it's better than AVG.

McAfee is very good..
__________________
IT Noob
Geforce is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
hijackthis log mateo leet-o Technical Support 1 July 16th, 2005 06:45 PM
hijackthis log mArtOOf Technical Support 5 October 16th, 2004 02:05 PM
Hijackthis Log Help. Please... Gyurza Security and Privacy Issues 2 August 3rd, 2004 07:39 PM
HiJackThis Log willthegrinder General Tech Discussion 4 July 22nd, 2004 05:04 PM
Need Help in HiJackThis Log Army2001 Applications and Operating Systems 0 July 12th, 2004 01:01 AM

Most Active Discussions
Is It Just Me? (2996)
Intel Pentium 4 531 (7)
"mastermind" of London at.. (65)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
Replacing integrated video card (5)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
New psu question (1)
Finishing off my first built co.. (4)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 05:40 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28