1
Tech Clinic / HijackThis Logfile (SmartSecurity)
« on: April 06, 2005, 12:25:21 AM »
Sorry, must have not refreshed after doing the config.
StartDreck (build 2.1.7 public stable) - 2005-04-05 @ 22:20:14 (GMT -07:00)
Platform: Windows XP (Win NT 5.1.2600 )
Internet Explorer: 6.0.2600.0000
Logged in as Naythin at MAFIA-CQJWXACFS
»Registry
»Run Keys
»Current User
»Run
*MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
*x3yy=C:\WINDOWS\System32\x3yy\anlogefj.exe
»RunOnce
»Default User
»Run
»RunOnce
»Local Machine
»Run
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
*nwiz=nwiz.exe /install
*D2TradeHack=C:\WINDOWS\System32\D2TradeHack.exe
*ShowNews=C:\Program Files\EstelleReyna\Updater.exe
*ViewMgr=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
*QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
*iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*ViewBarBHO.BHO.1/{A7327C09-B521-4EDB-8509-7D2660C9EC98}
`InprocServer32=C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
»Files
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+408=\SystemRoot\System32\smss.exe
+464=\??\C:\WINDOWS\system32\csrss.exe
+496=\??\C:\WINDOWS\system32\winlogon.exe
+540=C:\WINDOWS\system32\services.exe
+552=C:\WINDOWS\system32\lsass.exe
+712=C:\WINDOWS\system32\svchost.exe
+764=C:\WINDOWS\System32\svchost.exe
+844=C:\WINDOWS\System32\svchost.exe
+872=C:\WINDOWS\System32\svchost.exe
+1052=C:\WINDOWS\system32\spoolsv.exe
+1244=C:\WINDOWS\System32\svchost.exe
+1304=C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
+1584=C:\WINDOWS\system32\D2TradeHack.exe
+1780=C:\WINDOWS\Explorer.EXE
+1940=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
+1956=C:\Program Files\iTunes\iTunesHelper.exe
+1964=C:\WINDOWS\System32\ntddetect.exe
+2012=C:\Program Files\interMute\SpySubtract\SpySub.exe
+228=C:\Program Files\iPod\bin\iPodService.exe
+252=C:\WINDOWS\System32\x3yy\anlogefj.exe
+1864=C:\Program Files\Internet Explorer\IEXPLORE.EXE
+1720=C:\StartDreck\StartDreck.exe
»Application specific
StartDreck (build 2.1.7 public stable) - 2005-04-05 @ 22:20:14 (GMT -07:00)
Platform: Windows XP (Win NT 5.1.2600 )
Internet Explorer: 6.0.2600.0000
Logged in as Naythin at MAFIA-CQJWXACFS
»Registry
»Run Keys
»Current User
»Run
*MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
*x3yy=C:\WINDOWS\System32\x3yy\anlogefj.exe
»RunOnce
»Default User
»Run
»RunOnce
»Local Machine
»Run
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
*nwiz=nwiz.exe /install
*D2TradeHack=C:\WINDOWS\System32\D2TradeHack.exe
*ShowNews=C:\Program Files\EstelleReyna\Updater.exe
*ViewMgr=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
*QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
*iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
*ntddetect=C:\WINDOWS\System32\ntddetect.exe
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*ViewBarBHO.BHO.1/{A7327C09-B521-4EDB-8509-7D2660C9EC98}
`InprocServer32=C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
»Files
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+408=\SystemRoot\System32\smss.exe
+464=\??\C:\WINDOWS\system32\csrss.exe
+496=\??\C:\WINDOWS\system32\winlogon.exe
+540=C:\WINDOWS\system32\services.exe
+552=C:\WINDOWS\system32\lsass.exe
+712=C:\WINDOWS\system32\svchost.exe
+764=C:\WINDOWS\System32\svchost.exe
+844=C:\WINDOWS\System32\svchost.exe
+872=C:\WINDOWS\System32\svchost.exe
+1052=C:\WINDOWS\system32\spoolsv.exe
+1244=C:\WINDOWS\System32\svchost.exe
+1304=C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
+1584=C:\WINDOWS\system32\D2TradeHack.exe
+1780=C:\WINDOWS\Explorer.EXE
+1940=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
+1956=C:\Program Files\iTunes\iTunesHelper.exe
+1964=C:\WINDOWS\System32\ntddetect.exe
+2012=C:\Program Files\interMute\SpySubtract\SpySub.exe
+228=C:\Program Files\iPod\bin\iPodService.exe
+252=C:\WINDOWS\System32\x3yy\anlogefj.exe
+1864=C:\Program Files\Internet Explorer\IEXPLORE.EXE
+1720=C:\StartDreck\StartDreck.exe
»Application specific
\' />"