home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Hijackthis log

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1728
Discussions: 200,510, Posts: 2,374,411, Members: 245,833
Old November 6th, 2006, 06:54 PM   Digg it!   #1 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
Hijackthis log

hey guys, my comp has been a little laggy so i thought i would run the program and have u guys check out anythin suspicious for me since i have no clue when it comes to that stuff. So heres my log please let me know if there is anythin malicious i should get rid of. thanx

Logfile of HijackThis v1.99.1
Scan saved at 5:54:22 PM, on 06/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\JMRaidTool.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
C:\Program Files\ASUS\ASUS DH Remote\AsDhRemote.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\program files\valve\steam\steam.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Rob\Local Settings\Temp\wzaf7a\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ai Quicker Help] "C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe"
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G 1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.0 RC 16\RivaTuner.exe" /S
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edg...ex-2.0.6.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{50275B52-86ED-41B5-8BD1-D5F7C2E73091}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{D75925A4-7CD8-4261-9B01-2BF1500E441B}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\..\{E964512A-6B25-45DC-A124-C2F46A11885E}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS1\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O17 - HKLM\System\CS3\Services\Tcpip\..\{1AD39419-9B39-4758-AA14-21EF8AAB3B85}: NameServer = 85.255.114.37,85.255.112.19
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.37 85.255.112.19
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
__________________
Core 2 E6600 @ 3.47Ghz
Asus P5W-DH
WD Caviar 250Gb
Maxtor 250Gb
Evga 7600GT KO (590/775)
Ultra 600W Xfinity
BenQ FP202W

Douce33 is offline   Reply With Quote
Old November 6th, 2006, 06:56 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,679
Blog Entries: 14
HijackThis Analyzer & Tutorial
GroundZero3 is offline   Reply With Quote
Old November 6th, 2006, 06:57 PM     #3 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
great, thanx GZ
Douce33 is offline   Reply With Quote
Old November 6th, 2006, 07:06 PM     #4 (permalink)
Ultimate Member
 
mjolnir1134's Avatar
 
Join Date: Jan 2005
Location: The Internet
Posts: 1,998
Try to uninstall the programs causing those bad processes. If the uninstalls were unsuccessful, heres what I do:

Start>Run>type in msconfig>go to "Startup" tab>find nasty process and disable it.>Reboot!

I won't say it can completely delete the folder or program that makes the nasty process, but it can help make it stop running and perhaps make it easier to uninstall.
__________________
Mac Mini—2Ghz—2GB RAM—Snow Leopard
PC—e6420 2.16Ghz—2GB RAM—8800GT—ASUS P5LD2—XP
EEE 1000H—1.6Ghz—1GB RAM—XP
mjolnir1134 is offline   Reply With Quote
Old November 6th, 2006, 07:26 PM     #5 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,271
Wow that very nasty things on those. Best is format and install fresh window xp.

Ok go to run and type msconfig then look at start up tab and read the words.
Here info that say if have virus on msconfig http://www.sysinfo.org/startuplist.php?filter=
__________________
sorry for my bad grammar!
Milwaukee is offline   Reply With Quote
Old November 6th, 2006, 10:05 PM     #6 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 26,679
Blog Entries: 14
What nasty things are you talking about?
GroundZero3 is offline   Reply With Quote
Old November 6th, 2006, 10:17 PM     #7 (permalink)
Ultimate Member
 
Milwaukee's Avatar
 
Join Date: Apr 2006
Location: ????????
Posts: 1,271
My mistake it have problem with registry files on those. Did you try Crap cleaner?

Did you have Adware se personal and firewall? Is there another problem like pop errors or get bsod? how old those is? Just ask question.
Milwaukee is offline   Reply With Quote
Old November 7th, 2006, 07:24 AM     #8 (permalink)
Ultimate Member
 
BluesMan1's Avatar
 
Join Date: Jun 2003
Location: Not on this planet..
Posts: 1,102
You may have a little infection.

There is some tools that you can use to try to do something with it:

Ad Aware: http://www.download.com/3000-2144-10045910.html

Spybot: http://www.safer-networking.org/en/download/index.html

CW Shredder: http://www.intermute.com/spysubtract..._download.html

Ad Aware tutorial: http://www.bleepingcomputer.com/tuto...utorial48.html

Spybot tutorial: http://www.bleepingcomputer.com/tuto...utorial43.html

BluesMan1 is offline   Reply With Quote
Old November 7th, 2006, 07:28 AM     #9 (permalink)
Member
 
Join Date: May 2006
Location: Ontario, Canada
Posts: 489
on my comp i currently have ad-aware, spybot, counterspy, avast, and AVG. i had norton but everyone on here told me to get rid of it, but since i did ive been gettin trojans like crazy.
Douce33 is offline   Reply With Quote
Old November 7th, 2006, 07:57 AM     #10 (permalink)
Senior Member
 
Geforce's Avatar
 
Join Date: Dec 2004
Posts: 602
LOL.

Nothing wrong with Norton.. The Home Edition is a bit naff, but it's better than AVG.

McAfee is very good..
__________________
IT Noob
Geforce is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
hijackthis log mateo leet-o Technical Support 1 July 16th, 2005 06:45 PM
hijackthis log mArtOOf Technical Support 5 October 16th, 2004 02:05 PM
Hijackthis Log Help. Please... Gyurza Security and Privacy Issues 2 August 3rd, 2004 07:39 PM
HiJackThis Log willthegrinder General Tech Discussion 4 July 22nd, 2004 05:04 PM
Need Help in HiJackThis Log Army2001 Applications and Operating Systems 0 July 12th, 2004 01:01 AM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1635)
FT HOOD attack: 7 killed 12 injured (67)
Review My Build (6)
HELP!!! What do you think of this s.. (16)
Looking for a graphic card that wil.. (30)
Assosiations (21496)
My 1st pc build (40)
PC Modern Warfare 2: it's much wors.. (12)
Aero in Vista (7)
core i7 extreme 975, nvidia 9400gt (9)
How to Ship a PC (16)
Building my first computer (13)
[F@H SPAM 11/1/09]New month . . . n.. (33)
slaving laptop drive (7)
Recent Discussions
Powe Director v8 (0)
windows 7 retail and rtm (3)
boot from CD-ROM in chipset via P4M80.. (1)
Windows Experience Index is screwed u.. (3)
Review My Build (6)
FAT32 to NTFS file system in Win2kpro (4)
Internet very slow since updating AVG.. (8)
Motherboards and my curse... (25)
HELP!!! What do you think of this sys.. (16)
New Processor, Monitor will not turn .. (2)
2009 Build (4)
My 1st pc build (40)
Freezing During Music/Movies (1)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
Help and Support disappeared from my .. (0)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)
wireless westell versalink model 327w (1)
New build 10 second reboot cycle! Won.. (3)


All times are GMT -4. The time now is 08:16 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28