Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished)

 
 
LinkBack Thread Tools Display Modes
Old 11-20-2005, 12:26 PM   #1 (permalink)
Junior Techie
 
Join Date: Jan 2005
Posts: 51
Send a message via AIM to RevCor632
Default My HijackThis log

I got two errors during the scan, but it let me click "OK" and the scan kept going. So anyway, here it is:


Logfile of HijackThis v1.99.1
Scan saved at 0923:09, on 20 Nov 2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Jonathan the Great\Desktop\HijackThis.exe

F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckOD Ls
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [rrwz] C:\PROGRA~1\COMMON~1\rrwz\rrwzm.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
RevCor632 is offline  
Old 11-20-2005, 12:41 PM   #2 (permalink)
Ste
lvl Infinite Psychopath
 
Ste's Avatar
 
Join Date: Aug 2005
Location: Mount Prospect, IL
Posts: 8,567
Send a message via ICQ to Ste Send a message via AIM to Ste Send a message via MSN to Ste
Default

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O4 - HKCU\..\Run: [rrwz] C:\PROGRA~1\COMMON~1\rrwz\rrwzm.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
__________________

Read The Rules!!
Power Supply Guide
Intel Overclocking Thread
AMD Overclocking Thread
Other Important Threads
I'm sorry but I do not accept support requests via IM, email, or personal messages
There will come a day, such a day when all will be told more than they wish to know, what one hears may explain the past, it may explain the future, but it has never made a difference either way and it will change nothing. Some day.... But that is not this day, and I don't know when, I just don't know.
Ste is offline  
Old 11-20-2005, 12:47 PM   #3 (permalink)
Junior Techie
 
Join Date: Jan 2005
Posts: 51
Send a message via AIM to RevCor632
Default

I'm sorry, I'm new at this, the four things you just posted, do I delete them? Or what?
RevCor632 is offline  
Old 11-20-2005, 12:50 PM   #4 (permalink)
Ste
lvl Infinite Psychopath
 
Ste's Avatar
 
Join Date: Aug 2005
Location: Mount Prospect, IL
Posts: 8,567
Send a message via ICQ to Ste Send a message via AIM to Ste Send a message via MSN to Ste
Default

Yes, rescan, select the check boxs next them them then click the button that says, delete/fix I forgot which one it was.
__________________

Read The Rules!!
Power Supply Guide
Intel Overclocking Thread
AMD Overclocking Thread
Other Important Threads
I'm sorry but I do not accept support requests via IM, email, or personal messages
There will come a day, such a day when all will be told more than they wish to know, what one hears may explain the past, it may explain the future, but it has never made a difference either way and it will change nothing. Some day.... But that is not this day, and I don't know when, I just don't know.
Ste is offline  
Old 11-20-2005, 01:00 PM   #5 (permalink)
Junior Techie
 
Join Date: Jan 2005
Posts: 51
Send a message via AIM to RevCor632
Default

Thanks! I deleted them, and I'll post back in a day or two to say if it fixed it.
RevCor632 is offline  
Old 11-20-2005, 01:07 PM   #6 (permalink)
Ste
lvl Infinite Psychopath
 
Ste's Avatar
 
Join Date: Aug 2005
Location: Mount Prospect, IL
Posts: 8,567
Send a message via ICQ to Ste Send a message via AIM to Ste Send a message via MSN to Ste
Default

Well, I suggest a rescan after you delete them.
__________________

Read The Rules!!
Power Supply Guide
Intel Overclocking Thread
AMD Overclocking Thread
Other Important Threads
I'm sorry but I do not accept support requests via IM, email, or personal messages
There will come a day, such a day when all will be told more than they wish to know, what one hears may explain the past, it may explain the future, but it has never made a difference either way and it will change nothing. Some day.... But that is not this day, and I don't know when, I just don't know.
Ste is offline  
Old 11-20-2005, 01:13 PM   #7 (permalink)
Junior Techie
 
Join Date: Jan 2005
Posts: 51
Send a message via AIM to RevCor632
Default

A rescan with HijackThis? I did that, and they were gone.
RevCor632 is offline  
Old 11-20-2005, 01:14 PM   #8 (permalink)
Ste
lvl Infinite Psychopath
 
Ste's Avatar
 
Join Date: Aug 2005
Location: Mount Prospect, IL
Posts: 8,567
Send a message via ICQ to Ste Send a message via AIM to Ste Send a message via MSN to Ste
Default

Ok...
__________________

Read The Rules!!
Power Supply Guide
Intel Overclocking Thread
AMD Overclocking Thread
Other Important Threads
I'm sorry but I do not accept support requests via IM, email, or personal messages
There will come a day, such a day when all will be told more than they wish to know, what one hears may explain the past, it may explain the future, but it has never made a difference either way and it will change nothing. Some day.... But that is not this day, and I don't know when, I just don't know.
Ste is offline  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 03:31 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0