Author Topic: hijack this notepad results  (Read 1166 times)

Offline flipper1

  • Newbie
  • *
  • Posts: 10
  • Karma: +0/-0
    • View Profile
hijack this notepad results
« on: January 16, 2006, 04:16:32 PM »
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Aladdin Systems\iClean\iClean.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\fswsclds.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\shelly\My Documents\Unzipped\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {76EAE03C-F2B1-4397-97E8-390920B7C2DC} - (no file)
O2 - BHO: (no name) - {8A8F5616-35CF-4C44-9DC0-652E548C3C4b} - C:\WINDOWS\system32\otyyltns.dll
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\system32\setdrv32.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iClean] "C:\Program Files\Aladdin Systems\iClean\iClean.exe" /I
O4 - HKLM\..\RunServices: [Microsoft Windows System] gkukxpvp.exe
O4 - Startup: LimeWire On Startup.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O16 - DPF: Ali Baba Slots TM by pogo -
O16 - DPF: Armored Attack by pogo -
O16 - DPF: Big Shot Roulette TM by pogo -
O16 - DPF: Blackjack by pogo -
O16 - DPF: Buckaroo Blackjack TM by pogo -
O16 - DPF: Checkers by pogo -
O16 - DPF: Command and Conquer Comanche by pogo -
O16 - DPF: Dominoes by pogo -
O16 - DPF: EZ Win Bingo by pogo -
O16 - DPF: Greenback Bayou by pogo -
O16 - DPF: Hearts by pogo -
O16 - DPF: High Stakes Poker by pogo -
O16 - DPF: High Stakes Pool by pogo -
O16 - DPF: Its Outta Here 2 by pogo -
O16 - DPF: Jigsaw Detective by pogo -
O16 - DPF: Jokers Wild Poker by pogo -
O16 - DPF: Jungle Gin by pogo -
O16 - DPF: Keno by pogo -
O16 - DPF: Lottso by pogo -
O16 - DPF: Mah Jong Garden by pogo -
O16 - DPF: Multiline Slots by pogo -
O16 - DPF: NASCAR Web Racing by pogo -
O16 - DPF: Pai Gow by pogo -
O16 - DPF: Payday FreeCell by pogo -
O16 - DPF: Pebble Beach 3 Hole Challenge by pogo -
O16 - DPF: Pebble Beach Golf by pogo -
O16 - DPF: Perfect Pair Solitaire by pogo -
O16 - DPF: Perfect Passer by pogo -
O16 - DPF: Phlinx by pogo -
O16 - DPF: Pinochle by pogo -
O16 - DPF: Pirate's Gold by pogo -
O16 - DPF: Pop Fu by pogo -
O16 - DPF: Poppit TM by pogo -
O16 - DPF: Quick Shot by pogo -
O16 - DPF: Ricochet by pogo -
O16 - DPF: SciFi Slots by pogo -
O16 - DPF: Showbiz Slots 2 by pogo -
O16 - DPF: Spades by pogo -
O16 - DPF: Spider Solitaire by pogo -
O16 - DPF: Squelchies by pogo -
O16 - DPF: Sweet Tooth TM by pogo -
O16 - DPF: Tank Hunter by pogo -
O16 - DPF: Texas Hold'em Poker by pogo -
O16 - DPF: The Sims Pinball by pogo -
O16 - DPF: Top Down Baseball Challenge by pogo -
O16 - DPF: Tri-Peaks by pogo -
O16 - DPF: Tumble Bees by pogo -
O16 - DPF: Turbo 21 TM by pogo -
O16 - DPF: Vert Skater by pogo -
O16 - DPF: Video Poker by pogo -
O16 - DPF: Word Whomp by pogo -
O16 - DPF: Word Whomp Whackdown by pogo -
O16 - DPF: WordJong by pogo -
O16 - DPF: World Class Solitaire by pogo -
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} -
O16 - DPF: {012F24D4-35B0-11D0-BF2D-0000E8D0D156} -
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} -
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} -
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} -
O16 - DPF: {AB9820A0-02A9-11D5-A72F-004F4E002BD6} -
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O16 - DPF: {E12F0983-F19C-4A7C-A7A7-CD8F15EAEB21} -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{28D59922-6E28-42FA-B1D6-99AFA4FDCE3D}: NameServer = 198.164.4.62 198.164.30.62
O20 - Winlogon Notify: setdrv32 - C:\WINDOWS\SYSTEM32\setdrv32.dll
O21 - SSODL: IEFilter - {EDD2B86A-3686-4CD1-8A7E-70F3A7CDE287} - C:\WINDOWS\system32\IEFilter.dll
O23 - Service: AVG6 Service (AvgServ) - GRISOFT© SOFTWARE s.r.o - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\fswsclds.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
hijack this notepad results
« Reply #1 on: January 16, 2006, 04:22:35 PM »
CLOSED, please stick to your other post, don't start a new one
Additionally, I asked you to include your WHOLE log
You keep cutting off the top part
Here's the link to your other thread
http://www.thetechguide.com/forum/index.php?showtopic=25661

NOTE: I will keep locking or deleting any new threads you start if related to this same computer and same problems
« Last Edit: January 16, 2006, 04:22:57 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here