home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Hijackthis log

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2112
Discussions: 200,915, Posts: 2,378,974, Members: 246,282
Old November 6th, 2006, 06:54 PM   Digg it!   #1 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
Hijackthis log

hey guys, my comp has been a little laggy so i thought i would run the program and have u guys check out anythin suspicious for me since i have no clue when it comes to that stuff. So heres my log please let me know if there is anythin malicious i should get rid of. thanx

Logfile of HijackThis v1.99.1
Scan saved at 5:54:22 PM, on 06/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\JMRaidTool.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
C:\Program Files\ASUS\ASUS DH Remote\AsDhRemote.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\program files\valve\steam\steam.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Rob\Local Settings\Temp\wzaf7a\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ai Quicker Help] "C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe"
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.0 RC 16\RivaTuner.exe" /S
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edg...ex-2.0.6.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{50275B52-86ED-41B5-8BD1-D5F7C2E73091}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{D75925A4-7CD8-4261-9B01-2BF1500E441B}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{E964512A-6B25-45DC-A124-C2F46A11885E}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
__________________
Core 2 E6600 @ 3.47Ghz
Asus P5W-DH
WD Caviar 250Gb
Maxtor 250Gb
Evga 7600GT KO (590/775)
Ultra 600W Xfinity
BenQ FP202W

Douce33 is offline   Reply With Quote
Old November 6th, 2006, 06:56 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,816
Blog Entries: 15
HijackThis Analyzer & Tutorial
GroundZero3 is online now   Reply With Quote
Old November 6th, 2006, 06:57 PM     #3 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
great, thanx GZ
Douce33 is offline   Reply With Quote
Old November 6th, 2006, 07:06 PM     #4 (permalink)
Ultimate Member
 
mjolnir1134's Avatar
 
Join Date: Jan 2005
Location: The Internet
Posts: 1,998
Try to uninstall the programs causing those bad processes. If the uninstalls were unsuccessful, heres what I do:

Start>Run>type in msconfig>go to "Startup" tab>find nasty process and disable it.>Reboot!

I won't say it can completely delete the folder or program that makes the nasty process, but it can help make it stop running and perhaps make it easier to uninstall.
__________________
Mac Mini—2Ghz—2GB RAM—Snow Leopard
PC—e6420 2.16Ghz—2GB RAM—8800GT—ASUS P5LD2—XP
EEE 1000H—1.6Ghz—1GB RAM—XP
mjolnir1134 is offline   Reply With Quote
Old November 6th, 2006, 07:26 PM     #5 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,271
Wow that very nasty things on those. Best is format and install fresh window xp.

Ok go to run and type msconfig then look at start up tab and read the words.
Here info that say if have virus on msconfig http://www.sysinfo.org/startuplist.php?filter=
__________________
sorry for my bad grammar!
Milwaukee is offline   Reply With Quote
Old November 6th, 2006, 10:05 PM     #6 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,816
Blog Entries: 15
What nasty things are you talking about?
GroundZero3 is online now   Reply With Quote
Old November 6th, 2006, 10:17 PM     #7 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,271
My mistake it have problem with registry files on those. Did you try Crap cleaner?

Did you have Adware se personal and firewall? Is there another problem like pop errors or get bsod? how old those is? Just ask question.
Milwaukee is offline   Reply With Quote
Old November 7th, 2006, 07:24 AM     #8 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
You may have a little infection.

There is some tools that you can use to try to do something with it:

Ad Aware: http://www.download.com/3000-2144-10045910.html

Spybot: http://www.safer-networking.org/en/download/index.html

CW Shredder: http://www.intermute.com/spysubtract..._download.html

Ad Aware tutorial: http://www.bleepingcomputer.com/tuto...utorial48.html

Spybot tutorial: http://www.bleepingcomputer.com/tuto...utorial43.html

BluesMan1 is offline   Reply With Quote
Old November 7th, 2006, 07:28 AM     #9 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
on my comp i currently have ad-aware, spybot, counterspy, avast, and AVG. i had norton but everyone on here told me to get rid of it, but since i did ive been gettin trojans like crazy.
Douce33 is offline   Reply With Quote
Old November 7th, 2006, 07:57 AM     #10 (permalink)
Senior Member
 
Geforce's Avatar
 
Join Date: Dec 2004
Posts: 602
LOL.

Nothing wrong with Norton.. The Home Edition is a bit naff, but it's better than AVG.

McAfee is very good..
__________________
IT Noob
Geforce is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
hijackthis log mateo leet-o Technical Support 1 July 16th, 2005 06:45 PM
hijackthis log mArtOOf Technical Support 5 October 16th, 2004 02:05 PM
Hijackthis Log Help. Please... Gyurza Security and Privacy Issues 2 August 3rd, 2004 07:39 PM
HiJackThis Log willthegrinder General Tech Discussion 4 July 22nd, 2004 05:04 PM
Need Help in HiJackThis Log Army2001 Applications and Operating Systems 0 July 12th, 2004 01:01 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2829)
Why is Khalid Sheikh Mohammed even .. (7)
Is the PSU I received dead? (10)
Install XP pro and a Vista laptop ?.. (8)
HIS HD5770 graphic card question (15)
A good PSU? (10)
Foreign voltage (7)
Print spooler problem (9)
New Computer wont recognize XP disc (7)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Ideal cheap graph card for PC-Gamin.. (15)
EVGA 9800 gtx help with finding a g.. (7)
Modern Warfare 2: Who Bought It? (60)
Mysterious Boot manager (9)
Recent Discussions
Problem with speed step/turbo boost? (0)
SIS 740 and Widescreen (8)
Baffling Problem with my CPU/MoBo's. .. (0)
Display shows 3x5 inch in middle of s.. (0)
Print spooler problem (9)
windows vista security holes (3)
HIS HD5770 graphic card question (15)
Best file format to play on Windows H.. (0)
PSP Go bought in Japan (0)
Foreign voltage (7)
Asus P4G8X Mobo (3)
World's largest Monopoly Game using G.. (329)
EVGA 9800 gtx help with finding a goo.. (7)
Need hard disk drivers (4)
windows 7 internet problem (4)
What OS for a home server? (other tha.. (1)
Boot Problem? (0)
Logitech G9 laser gaming mouse $59.95.. (2)
$5 off any item with the purchase of .. (1)
Ideal cheap graph card for PC-Gaming? (15)
Install XP pro and a Vista laptop ?? (8)
Cloning old drive to new drive (6)
Amptron monitor G17FP-Black (0)
A good PSU? (10)
Is the PSU I received dead? (10)


All times are GMT -4. The time now is 12:24 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28