please can some1 have a look at my log. any advice greatly app . i am a newbie too all this and didnt figure out firewalls before i started messin on the web. thanx in advance i think wat u guys do is great "and for free????" ta pugz
Logfile of HijackThis v1.97.7
Scan saved at 19:03:12, on 11/05/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
C:\WINDOWS\System32\DRIVER
S\CDANTSRV
.EXE
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\ZONELA
BS\vsmon.e
xe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\Real
Play.exe
C:\WINDOWS\System32\rundll
32.exe
C:\PROGRA~1\ZONELA~1\ZONEA
L~1\zlclie
nt.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
C:\WINDOWS\System32\rundll
32.exe
C:\WINDOWS\System32\extrac
m32.exe
C:\Program Files\Free Downloads Accelerator\fdaagent.exe
C:\WINDOWS\System32\rundll
32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\InterVideo\WinDVD4PR
\WinSchedu
ler.exe
C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
C:\Program Files\ACER\ACER Internet Keyboard\MMKbd.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpohmr08.exe
C:\WINDOWS\System32\msiexe
c.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpoevm08.exe
C:\PROGRA~1\INCRED~1\bin\I
MAPP.EXE
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\INTERNET\icc\i
cc2000.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\IncrediMail\bin\IncM
ail.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
C:\DOCUME~1\wendy\LOCALS~1
\Temp\Incr
ediMail\hi
jackthis.E
XE
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\WINDOWS\System32
/left.html
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://searchbar.findthewebsiteyouneed.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://searchbar.findthewebsiteyouneed.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.acer.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://search.yahoo.com/search?p=%sR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,SearchAssist
ant = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
32\Userini
t.exe
O2 - BHO: (no name) - {00000000-0000-0000-0000-0
0000000024
0} - C:\Program Files\ClearSearch\IE_ClrSc
h.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {087173EF-9829-4F49-8340-A
524177D3F6
0} - C:\WINDOWS\System32\inetp6
0.dll
O2 - BHO: (no name) - {0DDBB570-0396-44C9-986A-8
F6F61A51C2
F} - C:\WINDOWS\System32\msiefr
40.dll
O2 - BHO: (no name) - {2D7CB618-CC1C-4126-A7E3-F
5B12D3BCF7
1} - c:\windows\ngpw34.dll
O2 - BHO: (no name) - {98DE779A-2364-4293-AB71-2
B97C61C464
0} - C:\PROGRA~1\FREEDO~1\fdahl
p99.dll
O2 - BHO: (no name) - {DE614603-6320-4046-A7A7-6
A69CEC26F1
4} - C:\WINDOWS\mslagent\4b_1,0
,0,9_mslag
ent.dll (file missing)
O2 - BHO: (no name) - {E9147A0A-A866-4214-B47C-D
A821891240
F} - c:\windows\ngsw31.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4
A4827C2E4C
8} - C:\WINDOWS\nem214.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\system32\msdxm.
ocx
O3 - Toolbar: (no name) - {5F1ABCDB-A875-46c1-8345-B
72A4567E48
6} - (no file)
O3 - Toolbar: FDA Bar - {9595C62C-76C6-49A6-9BDA-3
253DD7A34F
F} - C:\Program Files\Free Downloads Accelerator\fdabar99.dll
O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5
297EF71F44
4} - C:\WINDOWS\System32\stlbdi
st.DLL
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Rundll32_8] rundll32.exe C:\WINDOWS\System32\inetp6
0.dll,DllR
unServer
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEA
L~1\zlclie
nt.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
O4 - HKLM\..\Run: [Rundll32_7] rundll32.exe C:\WINDOWS\System32\msiefr
40.dll,Dll
RunServer
O4 - HKLM\..\Run: [WebScan] C:\Program Files\Acceleration Software\Anti-Virus\defsca
ngui.exe -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [CFDStart] C:\WINDOWS\WinMuschi.exe -m
O4 - HKCU\..\Run: [Internet Washer Pro] C:\Program Files\Internet Washer Pro\iw.exe min
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypa
ger.exe -quiet
O4 - HKCU\..\Run: [Eastenders Screenmate] C:\Program Files\Eastenders Screenmates\SM.exe
O4 - HKCU\..\Run: [extracm32.exe] C:\WINDOWS\System32\extrac
m32.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\I
ncMail.exe
/c
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGCOMLIB_1035.dll,InstantA
ccess
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [dlmMgr] "C:\Program Files\Common Files\Adobe\ESD\AdobeDownl
oadManager
.exe"
O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVD4PR
\WinSchedu
ler.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
O4 - Global Startup: Internet Keyboard.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\r
esources\W
ebMenuImg.
htm
O8 - Extra context menu item: &RSDN Search - res://c:\windows\toolbar_n
ieuw14.dll
/GoRSDN.dl
l.htm
O8 - Extra context menu item: Download with Free Downloads Accelerator - C:\Program Files\Free Downloads Accelerator\fdaie.htm
O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://www.acer.comO16 - DPF: Yahoo! Bingo -
http://download.games.yahoo.com/games/clients/y/xt0_x.cabO16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: Yahoo! Dots -
http://download.games.yahoo.com/games/clients/y/dtt1_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cabO16 - DPF: Yahoo! Tic-Tac-Toe -
http://download.games.yahoo.com/games/clients/y/ft3_x.cabO16 - DPF: {00B71CFB-6864-4346-A978-C
0A14556272
C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab27571.cabO16 - DPF: {0733B8F9-8B52-4693-A9FA-8
29E12D27F7
8} (preload control) -
http://www.thepaymentcentre.com/build/preload2.cabO16 - DPF: {093F9CF8-0DE1-491C-95D5-5
EC257BD4CA
3} -
http://akamai.downloadv3.com/binaries/IA/dtc32_EN_XP.cabO16 - DPF: {13197ACE-6851-45C3-A7FF-C
281324D548
9} -
http://www.2nd-thought.com/files/install013.exeO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {1E89F686-B78D-4C85-9EFC-3
474516E3FE
2} -
http://www.gogig.com/go/111058.exeO16 - DPF: {1EB17D1C-141D-4D9D-91CB-2
4D99215851
D} -
http://akamai.downloadv3.com/binaries/IA/netia32_EN_XP.cabO16 - DPF: {2119776A-F1AD-4FCD-9548-F
1E1C615350
C} -
http://www.stop-sign.com/pub/download/scandl_cnry.cabO16 - DPF: {2C38A62E-D257-40E8-8BB7-5
624E38FEB0
A} -
http://www.germie.com/mandi/2731.exeO16 - DPF: {421A63BA-4632-43E0-A942-3
B4AB645BE5
1} -
http://i.rn11.com/iwasher/pptproactauthmirror/internetwasherpro.cabO16 - DPF: {6A060448-60F9-11D5-A6CD-0
002B31F745
5} (ExentInf Class) -
http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocxO16 - DPF: {88C51E90-8E9C-4C96-8A45-5
74D88B63FA
F} (Matrix Class) -
http://acceso.masminutos.com/laaplicacion.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4
DFAD1796A8
D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab27571.cabO16 - DPF: {A02780C3-7F77-4E28-855B-2
8890F3CF37
A} -
http://akamai.downloadv3.com/binaries/DialHTML/EGCOMLIB_1035_pack_XP.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-5
85D6E6453F
D} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {CC110316-5BE7-4AAA-AEDD-1
A5B147BE34
C} (MyWebOperator Class) -
http://198.143.27.5/Loader.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {DB893839-10F0-4AF9-92FA-B
23528F530A
F} -
http://deposito.hostance.net/dialer/1014754.exeO16 - DPF: {E44151C8-0C6C-4A7D-B677-4
FCC9552E95
7} -
http://www.bcnx.com/suninfoconnect-lo.cabO16 - DPF: {E8EDB60C-951E-4130-93DC-F
AF1AD25F8E
7} -
http://xbs.climaxbucks.com/mt/dialers/fc/UniDist.CABO16 - DPF: {E9041F85-3C18-4A7E-A29D-E
24F84B79BF
1} -
http://216.133.83.162/downloads/UGO20.exeO16 - DPF: {F00F4763-7355-4725-82F7-0
DA94A256D4
6} (IMDownloader Class) -
http://www2.incredimail.com/contents/setup/downloader/imloader.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
87CAF3EE8C
6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F
385591623A
F} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab27571.cabO16 - DPF: {FFFF0003-0001-101A-A3C9-0
8002B2F49F
B} -
http://64.237.46.147/uk/smsfort.exeO17 - HKLM\System\CCS\Services\T
cpip\..\{5
EA818C2-A8
2D-48A0-AA
95-3CA5319
30026}: NameServer = 212.74.114.193 212.74.112.66
sorry forgot to add tiscali is my isp zone alarm,avg,nvidea graphics,win xp and a hewlett packard printer. sorry if this is too late