bubbasider Posted May 27, 2005 Share Posted May 27, 2005 Logfile of HijackThis v1.99.1 Scan saved at 5:06:10 PM, on 5/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss[Caution: ExecutableFile] C:\WINDOWS\System32\winlogon[Caution: ExecutableFile] C:\WINDOWS\system32\services[Caution: ExecutableFile] C:\WINDOWS\system32\lsass[Caution: ExecutableFile] C:\WINDOWS\system32\svchost[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\system32\spoolsv[Caution: ExecutableFile] C:\WINDOWS\Explorer[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\ACS\AOLAcsd[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon[Caution: ExecutableFile] c:\Program Files\Common Files\Symantec Shared\ccSetMgr[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\wanmpsvc[Caution: ExecutableFile] c:\Program Files\Common Files\Symantec Shared\ccEvtMgr[Caution: ExecutableFile] C:\Program Files\Java\j2re1.4.2_03\bin\jusched[Caution: ExecutableFile] C:\windows\system\hpsysdrv[Caution: ExecutableFile] C:\WINDOWS\System32\hkcmd[Caution: ExecutableFile] C:\Program Files\Common Files\Symantec Shared\ccApp[Caution: ExecutableFile] C:\WINDOWS\LTMSG[Caution: ExecutableFile] C:\WINDOWS\system32\ps2[Caution: ExecutableFile] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04[Caution: ExecutableFile] C:\WINDOWS\System32\hphmon03[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\ACS\AOLDial[Caution: ExecutableFile] C:\WINDOWS\Nmkluxh[Caution: ExecutableFile] C:\WINDOWS\system32\avifile7[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler[Caution: ExecutableFile] C:\WINDOWS\ALCXMNTR[Caution: ExecutableFile] C:\WINDOWS\system32\MUSICMATCH32[Caution: ExecutableFile] C:\WINDOWS\system32\ccfgnt05[Caution: ExecutableFile] C:\Program Files\Blubster\Blubster[Caution: ExecutableFile] C:\Program Files\Spyware Doctor\swdoctor[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\110208~1\EE\AOLHOS~1[Caution: ExecutableFile] C:\Program Files\interMute\SpamSubtract\SpamSub[Caution: ExecutableFile] C:\WINDOWS\system32\LVComS[Caution: ExecutableFile] C:\WINDOWS\system32\wscntfy[Caution: ExecutableFile] C:\WINDOWS\System32\HPHipm09[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\110208~1\EE\AOLServiceHost[Caution: ExecutableFile] C:\WINDOWS\system32\wuauclt[Caution: ExecutableFile] c:\Program Files\Norton AntiVirus\navapsvc[Caution: ExecutableFile] C:\Program Files\Windows Media Player\wmplayer[Caution: ExecutableFile] C:\Program Files\America Online 9.0c\waol[Caution: ExecutableFile] C:\Program Files\America Online 9.0c\shellmon[Caution: ExecutableFile] C:\Documents and Settings\Owner\Desktop\bubba's stuff\HijackThis[Caution: ExecutableFile] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customi ... .yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm R3 - Default URLSearchHook is missing O2 - BHO: MyQuickSearch Search Assistant BHO - {04011C11-2F3B-44ed-977C-270CA669C6B2} - C:\Program Files\MyQuickSearch\SrchAstt\1.bin\MQSSRCAS.DLL (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing) O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched[Caution: ExecutableFile] O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv[Caution: ExecutableFile] O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd[Caution: ExecutableFile] O4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray[Caution: ExecutableFile]" /r O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD[Caution: ExecutableFile] O4 - HKLM\..\Run: [VTTimer] VTTimer[Caution: ExecutableFile] O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp[Caution: ExecutableFile]" O4 - HKLM\..\Run: [LTMSG] LTMSG[Caution: ExecutableFile] 7 O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2[Caution: ExecutableFile] O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04[Caution: ExecutableFile] O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03[Caution: ExecutableFile] O4 - HKLM\..\Run: [bbqiipi] C:\WINDOWS\System32\bretiuxh[Caution: ExecutableFile] O4 - HKLM\..\Run: [ozir] C:\WINDOWS\ozir[Caution: ExecutableFile] O4 - HKLM\..\Run: [wlqr] C:\WINDOWS\wlqr[Caution: ExecutableFile] O4 - HKLM\..\Run: [wjkd] C:\WINDOWS\wjkd[Caution: ExecutableFile] O4 - HKLM\..\Run: [gxkn] C:\WINDOWS\gxkn[Caution: ExecutableFile] O4 - HKLM\..\Run: [odohofwh] C:\WINDOWS\odohofwh[Caution: ExecutableFile] O4 - HKLM\..\Run: [abqxsbup] C:\WINDOWS\abqxsbup[Caution: ExecutableFile] O4 - HKLM\..\Run: [gpyb] C:\WINDOWS\gpyb[Caution: ExecutableFile] O4 - HKLM\..\Run: [bmvul] C:\WINDOWS\bmvul[Caution: ExecutableFile] O4 - HKLM\..\Run: [hcv] C:\WINDOWS\hcv[Caution: ExecutableFile] O4 - HKLM\..\Run: [crcjwf] C:\WINDOWS\crcjwf[Caution: ExecutableFile] O4 - HKLM\..\Run: [ozqf] C:\WINDOWS\ozqf[Caution: ExecutableFile] O4 - HKLM\..\Run: [ajin] C:\WINDOWS\ajin[Caution: ExecutableFile] O4 - HKLM\..\Run: [bij] C:\WINDOWS\bij[Caution: ExecutableFile] O4 - HKLM\..\Run: [ab2f6] C:\WINDOWS\gntfngu[Caution: ExecutableFile] O4 - HKLM\..\Run: [X91lncD] C:\documents and settings\dawn\local settings\temp\X91lncD[Caution: ExecutableFile] O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial[Caution: ExecutableFile] O4 - HKLM\..\Run: [srnm] C:\WINDOWS\Nmkluxh[Caution: ExecutableFile] O4 - HKLM\..\Run: [Jawa322] C:\WINDOWS\jawa32[Caution: ExecutableFile] O4 - HKLM\..\Run: [xbeo] C:\WINDOWS\oqrt[Caution: ExecutableFile] O4 - HKLM\..\Run: [YS2Ck] C:\documents and settings\owner\local settings\temp\YS2Ck[Caution: ExecutableFile] O4 - HKLM\..\Run: [575711536d96] C:\WINDOWS\system32\avifile7[Caution: ExecutableFile] O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102085546\EE\AOLHostManager[Caution: ExecutableFile] O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler[Caution: ExecutableFile]" O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL[Caution: ExecutableFile]" -Run O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR[Caution: ExecutableFile] O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart[Caution: ExecutableFile] O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray[Caution: ExecutableFile] O4 - HKLM\..\Run: [Musicmatch Jukebox Player] MUSICMATCH32[Caution: ExecutableFile] O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost[Caution: ExecutableFile] O4 - HKLM\..\Run: [a0f8f94ecfbb] C:\WINDOWS\system32\ccfgnt05[Caution: ExecutableFile] O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [blubster] C:\Program Files\Blubster\Blubster[Caution: ExecutableFile] SILENT O4 - HKLM\..\Run: [v3tg3nR] ipvta[Caution: ExecutableFile] O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS[Caution: ExecutableFile]" /background O4 - HKCU\..\Run: [Jawa322] C:\WINDOWS\jawa32[Caution: ExecutableFile] O4 - HKCU\..\Run: [spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor[Caution: ExecutableFile]" /Q O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL[Caution: ExecutableFile]" -b O4 - HKCU\..\Run: [e02mRhd2U] inkfaxui[Caution: ExecutableFile] O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480[Caution: ExecutableFile] O4 - HKCU\..\RunOnce: [Musicmatch Jukebox Player] MUSICMATCH32[Caution: ExecutableFile] O4 - Startup: PowerReg Scheduler[Caution: ExecutableFile] O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub[Caution: ExecutableFile] O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576[Caution: ExecutableFile] O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08[Caution: ExecutableFile] O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf[Caution: ExecutableFile] O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL[Caution: ExecutableFile]/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: ExecutableFile] O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: ExecutableFile] O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409 O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wo ... rdmojo.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ ... brkpie.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promot ... WebAAS.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZI ... b34246.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolweb01.pogo.com/game/deluxe/in ... der_v6.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://moviefone.kontiki.com/securedeli ... in/kdx.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{240DEFAB-6439-462A-AEAE-04186A914523}: NameServer = 205.188.146.145 O17 - HKLM\System\CS1\Services\Tcpip\..\{240DEFAB-6439-462A-AEAE-04186A914523}: NameServer = 205.188.146.145 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd[Caution: ExecutableFile] O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon[Caution: ExecutableFile] O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv[Caution: ExecutableFile] O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr[Caution: ExecutableFile] O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc[Caution: ExecutableFile] O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr[Caution: ExecutableFile] O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc[Caution: ExecutableFile] O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09[Caution: ExecutableFile] O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan[Caution: ExecutableFile] O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc[Caution: ExecutableFile] peez and ty, o and w/e crap you find, i dont know about cus 6 people use this pc :lol: and my b-day wa sin jan. its now may. and im so glad my dad "got me my own pc,like he promised" :lol: :lol: :lol: :roll: :roll: :evil: :( w/e thx guys :twisted: 8) bubba 8) :twisted: I Frug I (35) Always looking for friends. Link to comment Share on other sites More sharing options...
Hulk12 Posted May 28, 2005 Share Posted May 28, 2005 I can tell from just looking at it that it has some serious nasty things. Scan with your anti-virus program and your spyware programs to see if you can clean that thing up. Then re-post the log. Also have you noticed any un-wanted tool-bars in IE? Link to comment Share on other sites More sharing options...
bubbasider Posted May 30, 2005 Author Share Posted May 30, 2005 ya.........i dont want to know what my dad looks at..... :lol: ...... :roll: .......but i use aol....not I.E. ima run my anti stuff ( i dont have antivirus,other programs ) but im gonna scan then repost....it is 8:49 now for me east...ill report back in some I Frug I (35) Always looking for friends. Link to comment Share on other sites More sharing options...
devilheart14 Posted May 30, 2005 Share Posted May 30, 2005 ( i dont have antivirus,other programs ) ..... :shock: ........ ok go get Ad-Aware, spybot and firefox(better then other browsers(up to u but)) then scan with them all and repost Aussie Aussie Aussie, :D Link to comment Share on other sites More sharing options...
Mr_Alfabet Posted June 1, 2005 Share Posted June 1, 2005 damn lol... this is some serious [cabbage].... :P try lookin at ur installed programs in the config screen, then remove all progs u dont need, or dont use anymore Link to comment Share on other sites More sharing options...
devilheart14 Posted June 1, 2005 Share Posted June 1, 2005 been a while....... throw up a cleaned log and we will have a look Aussie Aussie Aussie, :D Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now