View Single Post
Join Date: May 2004
Posts: 26
Reputation: birdman1541 is an unknown quantity at this point 
Solved Threads: 0
birdman1541 birdman1541 is offline Offline
Light Poster

Re: Help me with my HijackThis log

 
0
  #3
May 9th, 2004
Logfile of HijackThis v1.97.7
Scan saved at 12:42:05 PM, on 5/9/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Mujesira Music\My Documents\HijackThis.exe

R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\msconfig.exe /auto
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKLM\..\RunOnce: [_UnwiseDMO] cmd.exe /c del C:\WINDOWS\System32\ATPART~1.DLL
O4 - HKLM\..\RunOnce: [_UnwiseDMO_] cmd.exe /c del C:\WINDOWS\System32\im64.dll
O9 - Extra button: AIM (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{BBD27100-2CF1-4554-B31F-FC598D125320}: NameServer = 205.188.146.146


when i typed javascript:navigator.userAgent in my IE Address bar then hit enter.it gave me this message "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

vx2finder results:
C:\WINDOWS\System32\2adsrch.dll
C:\WINDOWS\System32\2bdsrch.dll
C:\WINDOWS\System32\2cdsrch.dll
C:\WINDOWS\System32\2ddsrch.dll
C:\WINDOWS\System32\2edsrch.dll
C:\WINDOWS\System32\2fdsrch.dll
C:\WINDOWS\System32\2gdsrch.dll
C:\WINDOWS\System32\2hdsrch.dll
C:\WINDOWS\System32\2idsrch.dll
C:\WINDOWS\System32\2jdsrch.dll
C:\WINDOWS\System32\2ldsrch.dll
C:\WINDOWS\System32\2odsrch.dll
C:\WINDOWS\System32\2pdsrch.dll
C:\WINDOWS\System32\2qdsrch.dll
C:\WINDOWS\System32\2rdsrch.dll
C:\WINDOWS\System32\2sdsrch.dll
C:\WINDOWS\System32\2tdsrch.dll
C:\WINDOWS\System32\2udsrch.dll
C:\WINDOWS\System32\2vdsrch.dll
C:\WINDOWS\System32\2wdsrch.dll
C:\WINDOWS\System32\2xdsrch.dll
C:\WINDOWS\System32\2ydsrch.dll
C:\WINDOWS\System32\2zdsrch.dll
C:\WINDOWS\System32\3n1.DLL
C:\WINDOWS\System32\3u1.DLL
C:\WINDOWS\System32\3z1.DLL

Guardian Key--- is called:
User Agent String---
Reply With Quote