Jump to content

Someone Examine this HJT log?


Da Pirates

Recommended Posts

Logfile of Trend Micro HijackThis v2.0.2

 

Scan saved at 10:22:18 PM, on 9/27/2008

 

Platform: Windows Vista (WinNT 6.00.1904)

 

MSIE: Internet Explorer v7.00 (7.00.6000.16546)

 

Boot mode: Normal

 

 

 

Running processes:

 

C:\Windows\system32\Dwm[Caution: Executable File]

 

C:\Windows\Explorer[Caution: Executable File]

 

C:\Windows\system32\taskeng[Caution: Executable File]

 

C:\Program Files\Windows Defender\MSASCui[Caution: Executable File]

 

C:\Program Files\Synaptics\SynTP\SynTPEnh[Caution: Executable File]

 

C:\Program Files\Hp\QuickPlay\QPService[Caution: Executable File]

 

C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL[Caution: Executable File]

 

C:\Windows\System32\rundll32[Caution: Executable File]

 

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain[Caution: Executable File]

 

C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg[Caution: Executable File]

 

C:\Program Files\Java\jre1.6.0\bin\jusched[Caution: Executable File]

 

C:\Program Files\Common Files\AOL\1193092694\ee\aolsoftware[Caution: Executable File]

 

C:\Program Files\Lexmark 2500 Series\lxddmon[Caution: Executable File]

 

C:\Program Files\Lexmark 2500 Series\lxddamon[Caution: Executable File]

 

C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc[Caution: Executable File]

 

C:\Program Files\Microsoft Office\Office12\GrooveMonitor[Caution: Executable File]

 

C:\Program Files\Alwil Software\Avast4\ashDisp[Caution: Executable File]

 

C:\Program Files\iTunes\iTunesHelper[Caution: Executable File]

 

C:\Program Files\Hp\HP Software Update\hpwuSchd2[Caution: Executable File]

 

C:\Program Files\Windows Sidebar\sidebar[Caution: Executable File]

 

C:\Windows\ehome\ehtray[Caution: Executable File]

 

C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare[Caution: Executable File]

 

C:\Program Files\Microsoft Office\Office12\ONENOTEM[Caution: Executable File]

 

C:\Program Files\AOL 9.0\waol[Caution: Executable File]

 

C:\Windows\ehome\ehmsas[Caution: Executable File]

 

C:\Program Files\Hewlett-Packard\Shared\HpqToaster[Caution: Executable File]

 

C:\Program Files\Mozilla Firefox\firefox[Caution: Executable File]

 

C:\Program Files\AOL 9.0\shellmon[Caution: Executable File]

 

C:\Program Files\PeerGuardian2\pg2[Caution: Executable File]

 

C:\Program Files\Trend Micro\HijackThis\HijackThis[Caution: Executable File]

 

 

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptop

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptop

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

 

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

 

O1 - Hosts: ::1 localhost

 

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

 

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL

 

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

 

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

 

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

 

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui[Caution: Executable File] -hide

 

O4 - HKLM\..\Run: [NvSvc] RUNDLL32[Caution: Executable File] C:\Windows\system32\nvsvc.dll,nvsvcStart

 

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32[Caution: Executable File] C:\Windows\system32\NvCpl.dll,NvStartup

 

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32[Caution: Executable File] C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

 

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh[Caution: Executable File]

 

O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService[Caution: Executable File]"

 

O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl[Caution: Executable File] /Start

 

O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler[Caution: Executable File]

 

O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain[Caution: Executable File]

 

O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg[Caution: Executable File]

 

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched[Caution: Executable File]"

 

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1193092694\ee\AOLSoftware[Caution: Executable File]

 

O4 - HKLM\..\Run: [lxddmon[Caution: Executable File]] "C:\Program Files\Lexmark 2500 Series\lxddmon[Caution: Executable File]"

 

O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon[Caution: Executable File]"

 

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032[Caution: Executable File]" /s

 

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc[Caution: Executable File]" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

 

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor[Caution: Executable File]"

 

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl[Caution: Executable File]"

 

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp[Caution: Executable File]

 

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask[Caution: Executable File]" -atboottime

 

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier[Caution: Executable File]

 

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper[Caution: Executable File]"

 

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2[Caution: Executable File]

 

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher[Caution: Executable File]

 

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar[Caution: Executable File] /autoRun

 

O4 - HKCU\..\Run: [ehTray[Caution: Executable File]] C:\Windows\ehome\ehTray[Caution: Executable File]

 

O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL[Caution: Executable File]" -b

 

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /detectMem (User 'LOCAL SERVICE')

 

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32[Caution: Executable File] oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

 

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /detectMem (User 'NETWORK SERVICE')

 

O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM[Caution: Executable File]

 

O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare[Caution: Executable File]

 

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL[Caution: Executable File]/3000

 

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

 

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

 

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

 

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

 

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

 

O13 - Gopher Prefix:

 

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL

 

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

 

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd[Caution: Executable File]

 

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService[Caution: Executable File]

 

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv[Caution: Executable File]

 

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc[Caution: Executable File]

 

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ[Caution: Executable File]

 

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv[Caution: Executable File]

 

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv[Caution: Executable File]

 

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder[Caution: Executable File]

 

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb[Caution: Executable File]

 

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService[Caution: Executable File]

 

O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service[Caution: Executable File]

 

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex[Caution: Executable File]

 

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT[Caution: Executable File]

 

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService[Caution: Executable File]

 

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc[Caution: Executable File]

 

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1[Caution: Executable File]

 

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst[Caution: Executable File] (file missing)

 

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc[Caution: Executable File]

 

O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv[Caution: Executable File]

 

O23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms[Caution: Executable File]

 

O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore[Caution: Executable File]

 

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9[Caution: Executable File]

 

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr[Caution: Executable File]

 

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio[Caution: Executable File]

 

 

 

--

 

End of file - 10354 bytes

 

 

 

 

 

 

 

 

 

NOTE: I have to share this computer with my mom -.- that's why that AOL (Etc) crap is on there.

BR BR BR? HUEHUEHEUEHUE

Link to comment
Share on other sites

Mlbfan13, your log looks fine to me... Unless AOL messed with your TCP/IP stack... And if that's the case, you're going to have a hell of a time fixing it. :|

 

 

 

BTW, what browser are you currently running? :-s

 

 

 

~D. V. Devnull

tifuserbar-dsavi_x4.jpg and normally with a cool mind.

(Warning: This user can be VERY confusing to some people... And talks in 3rd person for the timebeing due to how insane they are... Sometimes even to themself.)

Link to comment
Share on other sites

Mlbfan13, your log looks fine to me... Unless AOL messed with your TCP/IP stack... And if that's the case, you're going to have a hell of a time fixing it. :|

 

 

 

BTW, what browser are you currently running? :-s

 

 

 

~D. V. Devnull

 

I think Firefox as i see Firefox in there.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.