Hello d_may =)
Post That log here >> http://www.hijackthis.de/i
and it will automatically analyse it for u,,, Fix the entries which it labels as Nasty :)
To Fix, check the lines in Hijackthis scan and click on Fix Checked !!
HJT Log Tutoriol >> http://aumha.org/a/hjttuto
CAUTION: Before fixing the entries in hijackthis, make sure that they are really Nasty and can be deleted, better u first research for it on Google and then when u will confirm that they shud be deleted, Fix them. And whenever u run Hijackthis, run it from a New folder on ur desktop, so that in case of any problem, u can take advantages of its created backups of fixed items. And in case if u still face problems in dealing with it, just analyse ur log at the above site, and then scroll down where u will see a Save Analyse button, hit it and it will save ur Log Analysation, then copy the link of that page and paste it here, and we will check it for u :)
Main Topics
Browse All Topics





by: d_mayPosted on 2004-12-02 at 08:57:09ID: 12727618
Logfile of HijackThis v1.98.2
xe on.exe es.exe exe t.exe t.exe v.exe CS\acsd.ex e DA.exe s\KodakCCS .exe 2.exe t.exe e Sv.exe n\jusched. exe VDLauncher .exe urround Mixer\CTSysVol.exe VDAudio\CT DVDDet.EXE ER.EXE swctrl.exe ptd40nt.ex e Service\is sch.exe drivers\w3 2x86\3\hpz tsb04.exe h Jukebox\mm_tray.exe s.exe
ternet Explorer\Main,Default_Page _URL = http://www.dell4me.com/myw ay ternet Explorer\Main,Search Bar = http://rd.yahoo.com/custom ize/sbcyds l/defaults /sb/*http: // www.yaho o.com/sear ch/ie.html ternet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/ ternet Explorer\Main,Search Bar = http://rd.yahoo.com/custom ize/sbcyds l/defaults /sb/*http: // www.yaho o.com/sear ch/ie.html ternet Explorer\SearchURL,(Defaul t) = http://rd.yahoo.com/custom ize/sbcyds l/defaults /su/*http: // www.yaho o.com ternet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCt r\System\p anels\blan k.htm ternet Explorer\Main,Local Page = c:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.ht m ndows\Curr entVersion \Internet Settings,ProxyOverride = localhost 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll 002B31F9E5 9} - C:\Program Files\Yahoo!\Common\ycomp5 ,0,8,0.dll B27DDD11DB 2} - C:\Program Files\SpywareGuard\dlprote ct.dll 00874180BB 3} - (no file) 0123456789 0} - C:\WINDOWS\system32\dla\tf swshx.dll 0400523e39 a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll F10577473F 7} - c:\program files\google\googletoolbar 1.dll 09B6AD74AC C} - (no file) 09027A5CD4 F} - c:\program files\google\googletoolbar 1.dll 090271D4F8 8} - C:\Program Files\Yahoo!\Common\ycomp5 ,0,8,0.dll 0400523e39 a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll dll,NvStar tup n\jusched. exe VDLauncher .exe" urround Mixer\CTSysVol.exe VDAudio\CT DVDDet.EXE swctrl.exe " -atboottime ptd40nt.ex e ndexSearch .exe L~1\UPDATE ~1\ISUSPM. exe -startup Service\is sch.exe" -start drivers\w3 2x86\3\hpz tsb04.exe .exe -startgui h Jukebox\mm_tray.exe 1.dll/cmse arch.html 1.dll/cmba cklinks.ht ml 1.dll/cmca che.html izeIEMenu. html olbar.html 1.dll/cmsi milar.html 1.dll/cmtr ans.html 0401C60850 1} - C:\WINDOWS\system32\msjava .dll 0401C60850 1} - C:\WINDOWS\system32\msjava .dll 00103C116D 5} - C:\Program Files\Yahoo!\Common\ylogin .dll 00103C116D 5} - C:\Program Files\Yahoo!\Common\ylogin .dll 0010333D0A D} - C:\Program Files\Yahoo!\Messenger\yhe xbmes.dll 0010333D0A D} - C:\Program Files\Yahoo!\Messenger\yhe xbmes.dll 0400523e39 a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo olbar.html 0400523e39 a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo olbar.html 0B0D0A1DE4 5} - C:\Program Files\AIM\aim.exe 0C0F0318AF E} - C:\WINDOWS\System32\Shdocv w.dll 502d9a03c2 d} - http://wwws.musicmatch.com /mmz/openW ebRadio.ht ml (file missing) A4C89F1AC7 A} - C:\Program Files\IrfanView\Ebay\Ebay. htm ncludes/ps canner/ppc tlcab.CAB 0104BD12D9 4} (PCPitstop Utility) - http://www.pcpitstop.com/p cpitstop/P CPitStop.C AB 0105AA9B6A E} (Symantec AntiVirus scanner) - http://security.symantec.c om/sscv6/S haredConte nt/vc/bin/ AvSniff.ca b 6318989DB1 3} (PPSDKActiveXScanner.MainS creen) - http://www.my-etrust.com/i ncludes/ps canner/axs canner.cab D69DCBA39E F} (DownloadManager Control) - http://download.akamaitool s.com.edge suite.net/ dlmanager/ live/ code/ IE_1070/Do wnloadMana ger.cab CAB1C51A2A B} (HomePrintingCtrl Class) - http://www.ofoto.com/downl oads/hmpr/ HMPR_WIN_I E_1/ axhome pr.cab 305C1750EF 3} (EPUImageControl Class) - http://tools.ebayimg.com/e ps/wl/acti vex/EPUWAL Control_v1 -0-3- 12.ca b 099162EEEC 5} (Symantec RuFSI Utility Class) - http://security.symantec.c om/sscv6/S haredConte nt/common/ bin/ cabsa. cab 8533DE61D0 C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downl oads/BUM/B UM_WIN_IE_ 1/axofupld .cab 0C04F9A3B6 1} (HouseCall Control) - http://a840.g.akamai.net/7 /840/537/2 004061001/ housecall. trendmicro .com/house call/xscan 53.cab F314A91822 8} - http://ak.imgfarm.com/imag es/nocache /myspeedba r/ myinitia lsetup1.0. 0.7.cab 22972D723E A} (AvxScanOnline Control) - http://www.bitdefender.com /scan/Msie /bitdefend er.cab EFB805FC0E 7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ ediags/gs/ install/ gu idedsoluti ons.cab F47A330807 8} (ActiveDataInfo Class) - https://www-secure.symante c.com/tech supp/activ edata/ SymA Data.cab C6C9569B8C 7} (ActiveDataObj Class) - https://www-secure.symante c.com/tech supp/activ edata/ Acti veData.cab 47D1036C65 D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/ hpdj/en/ch eck/qdiagh .cab?325
Scan saved at 10:53:09 AM, on 12/2/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spools
C:\PROGRA~1\COMMON~1\AOL\A
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\CTsvcC
C:\WINDOWS\system32\driver
C:\WINDOWS\System32\nvsvc3
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\ups.ex
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSP
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_05\bi
C:\Program Files\CyberLink\PowerDVD\D
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2\S
C:\Program Files\Creative\SBAudigy2\D
C:\WINDOWS\system32\CTHELP
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tf
C:\Program Files\Scansoft\PaperPort\p
C:\Program Files\Common Files\InstallShield\Update
C:\WINDOWS\system32\spool\
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\MUSICMATCH\Musicmatc
C:\Program Files\RFA\rfagent.exe
C:\WINDOWS\System32\wispti
C:\Documents and Settings\Dale May\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-0
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-0
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bi
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\S
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\D
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\p
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\I
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTA
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatc
O4 - HKCU\..\Run: [RFAgent] C:\Program Files\RFA\rfagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustom
O8 - Extra context menu item: RoboForm &2 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-0
O9 - Extra 'Tools' menuitem: RoboForm &2 - {724d43aa-0d85-11d4-9908-0
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-B
O16 - DPF: ppctlcab - http://www.my-etrust.com/i
O16 - DPF: {0E5F0222-96B9-11D3-8997-0
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
O16 - DPF: {2FC9A21E-2069-4E47-8235-3
O16 - DPF: {3EB4F9EA-51A6-48DA-846A-0
O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1
O16 - DPF: {4C39376E-FA9D-4349-BACC-D
O16 - DPF: {644E432F-49D3-41A1-8DD5-E
O16 - DPF: {6F750200-1362-4815-A476-8
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
O16 - DPF: {E77C0D62-882A-456F-AD8F-7
O16 - DPF: {EB387D2F-E27B-4D36-979E-8