Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT-searchingbooth.com


  • This topic is locked This topic is locked
2 replies to this topic

#1 RUSSH

RUSSH

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:06 AM

Posted 19 January 2005 - 12:17 PM

Logfile of HijackThis v1.99.0
Scan saved at 11:12:21 AM, on 1/19/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\WINNT\system32\cba\pds.exe
C:\WINNT\system32\msupd4.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\LDClient\wuser32.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\secure.exe
C:\WINNT\svrrun.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\WINNT\system32\strdit.exe
C:\Program Files\Roxio\GoBack\GBTray.exe
C:\Program Files\candle\art\mgmt\collector\KeeAgent.exe
C:\Program Files\candle\art\Java\kjxJavaW.exe
\bhsv9\emul\bin\TEMgr.exe
\bhsv9\emul\bin\te_vt220.exe
C:\Program Files\AnalogX\CookieWall\cookie.exe
\bhsv9\MBPU-mbpu\bin\winmbww.exe
\bhsv9\MBPU-mbpu\bin\winmbwwi.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\pquser3\My Documents\Stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O2 - BHO: ServerSide - {7FC56022-4EDA-472E-8830-7CA92CCBD025} - C:\Program Files\NetMeeting\SS\ServerSide.dll
O2 - BHO: (no name) - {A9B19337-8C35-4058-BEBC-3872C390F9D5} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E5F64D28-A1B3-0DBD-459D-47142F2BEC9D} - C:\WINNT\oikhsml.dll (file missing)
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKLM\..\Run: [l6HGzmj7y] c:\documents and settings\pquser3\local settings\temp\l6HGzmj7y.exe
O4 - HKLM\..\Run: [version] C:\WINNT\system32\msB.exe
O4 - HKLM\..\Run: [secure] C:\WINNT\system32\secure.exe
O4 - HKLM\..\Run: [svrrun] C:\WINNT\svrrun.exe
O4 - HKLM\..\Run: [SStb.exe] C:\WINNT\SStb.exe
O4 - HKLM\..\Run: [ssqb.exe] C:\WINNT\ssqb.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKCU\..\Run: [hovnRUfsj] strdit.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ADP50103.lnk = bin\TEMgr.exe
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: Inventory Scan.LNK = C:\LDClient\LDISCN32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Start ETEWatch Collector.lnk = C:\Program Files\candle\art\mgmt\collector\KeeAgent.exe
O4 - Global Startup: Start Manager Client.lnk = C:\Program Files\candle\art\Java\kjxJavaW.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O15 - Trusted Zone: http://www.carfaxonline.com
O15 - Trusted Zone: http://www.manheim.com
O15 - Trusted Zone: http://www.mb-advantage.com
O15 - Trusted Zone: http://ieak.netstar.mbusa.com
O15 - Trusted Zone: http://ieaktest.netstar.mbusa.com
O15 - Trusted Zone: http://install.netstar.mbusa.com
O15 - Trusted Zone: http://logon.netstar.mbusa.com
O15 - Trusted Zone: http://logonmm.netstar.mbusa.com
O15 - Trusted Zone: http://mbcares.netstar.mbusa.com
O15 - Trusted Zone: http://newschannel.netstar.mbusa.com
O15 - Trusted Zone: http://releasenotes.netstar.mbusa.com
O15 - Trusted Zone: http://reports.netstar.mbusa.com
O15 - Trusted Zone: http://team.netstar.mbusa.com
O15 - Trusted Zone: http://www.mbusa.com
O15 - Trusted Zone: http://www.rogonline.com
O15 - Trusted Zone: http://www.starmarkonline.com
O15 - Trusted Zone: http://www.carfaxonline.com (HKLM)
O15 - Trusted Zone: http://www.manheim.com (HKLM)
O15 - Trusted Zone: http://www.mb-advantage.com (HKLM)
O15 - Trusted Zone: http://ieak.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://ieaktest.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://install.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://logon.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://logonmm.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://mbcares.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://newschannel.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://releasenotes.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://reports.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://team.netstar.mbusa.com (HKLM)
O15 - Trusted Zone: http://www.mbusa.com (HKLM)
O15 - Trusted Zone: http://www.rogonline.com (HKLM)
O15 - Trusted Zone: http://www.starmarkonline.com (HKLM)
O16 - DPF: {323C9B9A-DB6C-42CE-A706-314535FD8EAF} (FTUploader Control) - http://www.fototime.com/ftweb/activeX/WebUploadControl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50043/QDow_AS2.cab
O16 - DPF: {BAB3E70B-A847-4A88-ACFC-778FCCC00287} (CActSetupObj Object) - http://www.odysseusmarketing.com/actsetup.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://proquest.webex.com/client/v_eureka-...bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AED380A-2625-4175-8A3D-C8B05481ADED}: NameServer = 53.252.51.136,205.190.37.249
O17 - HKLM\System\CS1\Services\Tcpip\..\{4AED380A-2625-4175-8A3D-C8B05481ADED}: NameServer = 53.252.51.136,205.190.37.249
O17 - HKLM\System\CS2\Services\Tcpip\..\{4AED380A-2625-4175-8A3D-C8B05481ADED}: NameServer = 53.252.51.136,205.190.37.249
O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Miscrosoft Updates Service 4 - Unknown - C:\WINNT\system32\msupd4.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Intel Remote Control Service - Intel Corporation - C:\LDClient\wuser32.exe

BC AdBot (Login to Remove)

 


#2 RUSSH

RUSSH
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:06 AM

Posted 19 January 2005 - 03:30 PM

Anyone?

#3 RUSSH

RUSSH
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:06 AM

Posted 19 January 2005 - 06:23 PM

Has anyone had any luck yet?

My computer is really dragging...




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users