Jump to content

[hijackthis] my log file anything wrong with it


Recommended Posts

I just downloaded this someone check it out and tell me if theres anything wrong:

Logfile of HijackThis v1.99.1

Scan saved at 12:27:32 AM, on 1/23/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2

(6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil

Software\Avast4\ashServ.exe

C:\Program Files\F-Secure Internet

Security\fswsclds.exe

C:\Program Files\Common Files\Microsoft

Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\System32\tcpsvcs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.ex

e

C:\Program Files\Zone

Labs\ZoneAlarm\zlclient.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Common

Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe

C:\Program Files\Gaim\gaim.exe

C:\Program Files\NetZero\exec.exe

C:\Program Files\NetZero\exec.exe

C:\Program Files\NetZero\qsacc\x1exec.exe

C:\WINDOWS\system32\DllHost.exe

C:\Documents and

Settings\holenone\Desktop\Unused Desktop

Shortcuts\NoAds\NoAds.exe

C:\Documents and Settings\holenone\My

Documents\Downloads\runescape.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\holenone\My

Documents\Aaron's Schoolwork\Aaron's

Folder\Virus

Downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://www.dellnet.com/

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://my.netzero.net/s/search?r=minisearch

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://my.netzero.net/s/search?r=minisearch

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.msnbc.com/

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://my.netzero.net/s/search?r=minisearch

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://my.netzero.net/s/search?r=minisearch

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://my.netzero.net/s/search?r=minisearch

R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.msnbc.com/

R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,SearchAssistant =

http://my.netzero.net/s/search?r=minisearch

R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet

Explorer\SearchURL,(Default) =

http://my.netzero.net/s/search?r=minisearch

R1 - HKLM\Software\Microsoft\Internet

Explorer\SearchURL,(Default) =

http://my.netzero.net/s/search?r=minisearch

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Local Page =

R1 -

HKCU\Software\Microsoft\Windows\CurrentVe

rsion\Internet Settings,ProxyServer =

http=127.0.0.1:7900

R1 -

HKCU\Software\Microsoft\Windows\CurrentVe

rsion\Internet Settings,ProxyOverride =

*.www.runescape.com;64.136.29.30;64.136.21.30;6

4.136.29.34;searchap.untd.com;127.0.0.1;localhost

;*microsoft.com;*windowsupdate.com;*wustat.win

dows.com;*.pogo.com;*.worldwinner.com;*test-spe

ed.com;liveupdate.symantecliveupdate.com;*syma

ntec.com;*.nai.com;*.networkassociates.com;*phot

osite.com;*.dir.untd.com;www.runescape.com;<local

>

R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: URLSearchHook Class -

{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8

} - C:\Program Files\NZSearch\SearchEnh1.dll

F2 - REG:system.ini:

UserInit=c:\windows\system32\userinit.exe

N3 - Netscape 7:

user_pref("browser.startup.homepage",

"www.google.com"); (C:\Documents and

Settings\holenone\Application

Data\Mozilla\Profiles\default\f8oy6al4.slt\pre

fs.js)

N3 - Netscape 7:

user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetsc

ape%5CNetscape%5Csearchplugins%5CSBWeb_

01.src"); (C:\Documents and

Settings\holenone\Application

Data\Mozilla\Profiles\default\f8oy6al4.slt\pre

fs.js)

O2 - BHO: Popup-Blocker Class -

{52706EF7-D7A2-49AD-A615-E903858CF284}

- C:\Program Files\NetZero\qsacc\X1IEBHO.dll

O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-206D7942484F}

- C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

- C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: (no name) -

{77AC92B0-1130-7E9D-0643-0C9B392FDEF0}

- (no file)

O2 - BHO: (no name) -

{8ACA3AE9-EB62-8DC3-5901-F88408A827AC}

- (no file)

O2 - BHO: (no name) -

{B02FD047-52CE-636F-A2AB-428FE89044F5}

- (no file)

O3 - Toolbar: ZeroBar -

{F0F8ECBE-D460-4B34-B007-56A92E8F84A7}

- C:\Program Files\NetZero\Toolbar.dll

O4 - HKLM\..\Run: [NvCplDaemon]

RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Zone Labs Client] C:\Program

Files\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Common

Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [DellSupport] "C:\Program

Files\Dell Support\DSAgnt.exe" /startup

O4 - HKCU\..\Run: [spc_w] "C:\Program

Files\NZSearch\nzspc.exe" -w

O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\RunOnce: [untd_recovery]

"C:\Program Files\NetZero\qsacc\x1exec.exe"

O4 - Global Startup: Digital Line Detect.lnk = ?

O8 - Extra context menu item: Display All

Images with Full Quality - res://C:\Program

Files\NetZero\qsacc\appres.dll/228

O8 - Extra context menu item: Display Image

with Full Quality - res://C:\Program

Files\NetZero\qsacc\appres.dll/227

O8 - Extra context menu item: E&xport to

Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXC

EL.EXE/3000

O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Research -

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBA

R.DLL

O9 - Extra button: AIM -

{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

C:\Program Files\AIM\aim.exe

O9 - Extra button: (no name) -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

(no file)

O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe

O16 - DPF:

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

(MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v

6/V5Controls/en/x86/client/muweb_site.cab?11

34797152250

O16 - DPF:

{6E5A37BF-FD42-463A-877C-4EB7002E68AE}

(Housecall ActiveX 6.5) -

http://us-housecall.trendmicro-europe.com/hous

ecall/applet/html/native/x86/win32/activex/hc

Impl.cab

O16 - DPF:

{77E32299-629F-43C6-AB77-6A1E6D7663F6}

(Groove Control) -

http://www.nick.com/common/groove/gx/Groove

AX27.cab

O17 -

HKLM\System\CCS\Services\Tcpip\..\{109F542

1-3CA8-4647-8F0B-FEA7907BFF8F}:

NameServer = 64.136.28.120 64.136.20.120

O17 -

HKLM\System\CS1\Services\Tcpip\..\{109F542

1-3CA8-4647-8F0B-FEA7907BFF8F}:

NameServer = 64.136.28.120 64.136.20.120

O18 - Protocol: msnim -

{828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file

missing)

O20 - AppInit_DLLs: scorillont.dll

MsgPlusLoader.dll

O20 - Winlogon Notify: ntvdscm - ntvdscm.dll

(file missing)

O23 - Service: avast! iAVS4 Control Service

(aswUpdSv) - Unknown owner - C:\Program

Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner

- C:\Program Files\Alwil

Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown

owner - C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe" /service (file

missing)

O23 - Service: avast! Web Scanner - Unknown

owner - C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe" /service (file

missing)

O23 - Service: F-Secure Windows Security

Center Legacy Detection Service (Fswsclds) -

F-Secure Corporation - C:\Program

Files\F-Secure Internet Security\fswsclds.exe

O23 - Service: InstallDriver Table Manager

(IDriverT) - Macrovision Corporation -

C:\Program Files\Common

Files\InstallShield\Driver\11\Intel

32\IDriverT.exe

O23 - Service: iPodService - Apple Computer,

Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Intel® NMS (NMSSvc) - Intel

Corporation -

C:\WINDOWS\System32\NMSSvc.exe

O23 - Service: NVIDIA Display Driver Service

(NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: TrueVector Internet Monitor

(vsmon) - Zone Labs, LLC -

C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.ex

e

Link to comment
Share on other sites


  • 4 weeks later...

Well, you sure got a lot of help it seems. Type the names of the processes you think are bad into Google and it will give you info in the first search result if it is bad.

I'm worried about the following:

Alwil

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\System32\MsPMSPSv.exe

NetZero is garbage. That's your ISP. Sorry to hear that, they have given you a lot of garbage to store on your HD.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...