I wanted to see what all the hype is about with Hijack. I have never "HAD" to run it, so I thought I just do it, and see what you guys find :) Enjoy!
Logfile of HijackThis v1.98.0
Scan saved at 1:26:46 AM, on 6/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
G:\WINDOWS\System32\smss.e
xe
G:\WINDOWS\system32\winlog
on.exe
G:\WINDOWS\system32\servic
es.exe
G:\WINDOWS\system32\lsass.
exe
G:\WINDOWS\system32\svchos
t.exe
G:\WINDOWS\System32\svchos
t.exe
G:\WINDOWS\system32\spools
v.exe
G:\WINDOWS\System32\CTsvcC
DA.exe
G:\Program Files\NavNT\defwatch.exe
G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
G:\Program Files\NavNT\rtvscan.exe
G:\Program Files\Navnt\AdvTools\NPROT
ECT.EXE
G:\WINDOWS\System32\nvsvc3
2.exe
G:\WINDOWS\System32\svchos
t.exe
G:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
G:\WINDOWS\System32\MsPMSP
Sv.exe
G:\WINDOWS\Explorer.EXE
D:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCu
eTray.exe
G:\WINDOWS\System32\CTHELP
ER.EXE
G:\PROGRA~1\NavNT\vptray.e
xe
G:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
G:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_S
4I2F1.EXE
G:\Program Files\CyberLink\PowerDVD\P
DVDServ.ex
e
C:\Program Files\ASUS\Probe\AsusProb.
exe
G:\Program Files\Creative\SBAudigy2\S
urround Mixer\CTSysVol.exe
G:\Program Files\Creative\SBAudigy2\D
VDAudio\CT
DVDDet.EXE
G:\Program Files\Creative\Shared Files\CAMTRAY.EXE
G:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
G:\Program Files\MSN Messenger\msnmsgr.exe
G:\Program Files\Creative\MediaSource
\RemoteCon
trol\RcMan
.exe
G:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\SETI@home\SETI@home.
exe
G:\WINDOWS\System32\MsgSys
.EXE
G:\Program Files\Yahoo!\Messenger\ypa
ger.exe
C:\Program Files\AIM\aim.exe
E:\CWShredder.exe
G:\Program Files\Internet Explorer\iexplore.exe
D:\WINZIP\winzip32.exe
G:\Documents and Settings\Jay.PRIMARY\Local
Settings\Temp\HijackThis.e
xe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.comR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6
BB168A7031
0} - G:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=G:\WINDOWS\system
32\userini
t.exe,
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.
205.209 sitefinder.verisign.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - G:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6
BB168A7031
0} - G:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - g:\program files\google\googletoolbar
2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - G:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - g:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [AdobeVersionCue] d:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCu
eTray.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] G:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "G:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [vptray] G:\PROGRA~1\NavNT\vptray.e
xe
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] G:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_S
4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheM
ode
O4 - HKLM\..\Run: [RemoteControl] "G:\Program Files\CyberLink\PowerDVD\P
DVDServ.ex
e"
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.
exe
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\S
urround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] G:\Program Files\Creative\SBAudigy2\D
VDAudio\CT
DVDDet.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [Creative WebCam Tray] G:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "G:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
O4 - HKCU\..\Run: [msnmsgr] "G:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RemoteCenter] G:\Program Files\Creative\MediaSource
\RemoteCon
trol\RcMan
.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [Yahoo! Pager] G:\Program Files\Yahoo!\Messenger\ypa
ger.exe -quiet
O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\SETI@home.
exe -min
O8 - Extra context menu item: &Google Search - res://g:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://g:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://g:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Si&milar Pages - res://g:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://g:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - G:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - G:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - G:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - G:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - G:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'xfire_lsp_7626.dll' missing
O12 - Plugin for .spop: G:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9
952547D571
5} (Creative Software AutoUpdate) -
http://us.creative.com/support/downloads/su/ocx/12119/CTSUEng.cabO16 - DPF: {39B0684F-D7BF-4743-B050-F
DC3F48F7E3
B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cabO16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://akamaidownload.apple.com/530x3824/binaries/iTunesSetup.exeO16 - DPF: {68BCE50A-DC9B-4519-A118-6
FDA19DB450
D} (Info Class) -
http://www.blizzard.com/register/wowbeta/si.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-3
98534BB899
9} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/activedata/SymAData.dllO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/activedata/ActiveData.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-4
6B766368D2
9} (Creative Software AutoUpdate Support Package) -
http://us.creative.com/support/downloads/su/ocx/12119/CTPID.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{3
26E1EF0-5C
8C-40F7-97
B3-16C560F
0FC5B}: Domain = HOME
O17 - HKLM\System\CS1\Services\T
cpip\..\{3
26E1EF0-5C
8C-40F7-97
B3-16C560F
0FC5B}: Domain = HOME