Jump to content


Photo

Hijackthis log help please - Duplicate Deleted...


  • Please log in to reply
1 reply to this topic

#1 itismejs55

itismejs55

    Member

  • New Member
  • Pip
  • 1 posts

Posted 31 May 2007 - 06:18 PM

Edit: Duplicate Topic deleted... Please stick to 1 Topic per computer...
Sorry. I got got clicky on the post button.

I have run Ad-Aware, AVG and Spy bot, but everything that spybot finds keeps comming back.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 7:18:03 PM, on 5/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\brss01a.exe
G:\WINDOWS\System32\SCardSvr.exe
G:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
G:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Common Files\LightScribe\LSSrvc.exe
V:\Program Files\Streamload\AMD LIVE! Media Vault\MediaMaxXLService.exe
G:\Program Files\McAfee\MPF\MPFSrv.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\WebUpdateSvc.exe
G:\WINDOWS\system32\wentxp.exe
v:\Program Files\RealVNC\VNC4\WinVNC4.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\alg.exe
G:\WINDOWS\system32\HPZipm12.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\WINDOWS\system32\MSTMON_Q.EXE
V:\Program Files\QuickTime\qttask.exe
V:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Google\Google Talk\googletalk.exe
G:\Program Files\AIM95\aim.exe
V:\Program Files\DAEMON Tools\daemon.exe
G:\PROGRA~1\MICROS~2\rapimgr.exe
G:\Program Files\Grisoft\AVG Free\avgcc.exe
G:\WINDOWS\explorer.exe
G:\WINDOWS\system32\rundll32.exe
V:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
G:\WINDOWS\explorer.exe
G:\WINDOWS\system32\rundll32.exe
V:\Program Files\Winamp\winamp.exe
V:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\Explorer.EXE
V:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
G:\WINDOWS\system32\wuauclt.exe
G:\Program Files\Microsoft ActiveSync\wcescomm.exe
G:\hjt\HiJackThis_v2(2).exe
G:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - V:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3366C60C-EFBD-4C8A-BB89-DDC4A6252820} - G:\WINDOWS\system32\pmnnl.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - V:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - G:\WINDOWS\system32\BhoDshop.dll
O2 - BHO: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - (no file)
O2 - BHO: (no name) - {B45B691E-87AB-E65E-DB78-88ADD3B077B7} - G:\WINDOWS\system32\kyl.dll
O2 - BHO: (no name) - {B757D4CB-57B8-452B-BD3B-27D63932D87E} - G:\WINDOWS\system32\pmnnl.dll
O2 - BHO: (no name) - {CA2D181E-8BAE-E66E-DB78-88ADD3B077B7} - G:\WINDOWS\system32\kyl.dll
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - G:\WINDOWS\system32\xfibqhvj.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - g:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "V:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinampAgent] v:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [KONICA MINOLTA PagePro 1350WStatusDisplay] G:\WINDOWS\system32\MSTMON_Q.EXE
O4 - HKLM\..\Run: [QuickTime Task] "V:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "V:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [setup] rundll32.exe "G:\WINDOWS\system32\yxntyqol.dll",realset
O4 - HKCU\..\Run: [googletalk] "G:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [AIM ] G:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [AIM] V:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DAEMON Tools] "v:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [H/PC Connection Agent] "G:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] G:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] G:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1614895754-1060284298-839522115-1010\..\Run: [AIM] V:\Program Files\AIM\aim.exe -cnetwait.odl (User 'Not Justin')
O4 - HKUS\S-1-5-21-1614895754-1060284298-839522115-1010\..\Run: [H/PC Connection Agent] "G:\Program Files\Microsoft ActiveSync\wcescomm.exe" (User 'Not Justin')
O4 - HKUS\S-1-5-21-1614895754-1060284298-839522115-1010\..\Run: [AIM Logger] V:\PROGRA~1\Nalsoft\AIMLOG~1\nalgr.exe /start /minimize (User 'Not Justin')
O4 - HKUS\S-1-5-21-1614895754-1060284298-839522115-1010\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe (User 'Not Justin')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] G:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] G:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = V:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://V:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save to &Xdrive - res://G:\Program Files\Xdrive\Xdrive Desktop\xdrive.exe/std.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - G:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - G:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - G:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - v:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - v:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Secure Online Account Numbers - {F74E75A5-96BF-40ef-A1C8-88EAEBB82AB6} - G:\Program Files\Secure Online Account Numbers\SOAN.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: g:\windows\system32\nwprovau.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comne...login-devel.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,26/mcgdmgr.cab
O20 - Winlogon Notify: browsela - G:\WINDOWS\system32\browsela.dll (file missing)
O20 - Winlogon Notify: iifcaax - iifcaax.dll (file missing)
O20 - Winlogon Notify: pmnnl - G:\WINDOWS\system32\pmnnl.dll
O20 - Winlogon Notify: winmxw32 - winmxw32.dll (file missing)
O21 - SSODL: SysTray.Exiv - {2963ECFC-4E5C-2f3b-B334-D67434FC72E0} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - G:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - G:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Master Browseui - {31EE3286-D785-4E3F-95FC-51D00FDABC01} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - G:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - G:\WINDOWS\System32\brsvc01a.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - G:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - G:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MediaMax XL Service (MediaMaxXLService) - Streamload - V:\Program Files\Streamload\AMD LIVE! Media Vault\MediaMaxXLService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - G:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: MySQL - Unknown owner - G:\Program.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pervasive.SQL Workgroup Engine - Unknown owner - G:\WINDOWS\system32\srvany.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Web Update Service by PowerProgrammer (WebUpdate) - Data Perceptions / PowerProgrammer - G:\WINDOWS\System32\WebUpdateSvc.exe
O23 - Service: WinEncrypt service (wencrservice) - WinEncrypt - G:\WINDOWS\SYSTEM32\wentxp.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - v:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11088 bytes

Edited by itismejs55, 31 May 2007 - 09:12 PM.


#2 SWI Support Robot

SWI Support Robot

    Helper robot

  • SWI Bot
  • PipPipPipPipPip
  • 23,520 posts

Posted 03 June 2007 - 06:30 AM

Welcome to SWI. We apologize for the delay; our helpers have been very busy.
If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

Thank you for your patience.

[this is an automated reply]
This is an automated message. It does not count as help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button