Hijack log, I should be clean, but let's see...

Reply

Join Date: Aug 2004
Posts: 277
Reputation: DuncanIdaho is an unknown quantity at this point 
Solved Threads: 5
DuncanIdaho DuncanIdaho is offline Offline
Unverified User

Hijack log, I should be clean, but let's see...

 
0
  #1
Aug 31st, 2004
I'm having no problems, all is well, but I have this hijack log, and I figured I might as well let you all have a gander at it.

Logfile of HijackThis v1.98.2
Scan saved at 3:56:42 PM, on 8/31/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Saitek\Software\Profiler.exe
C:\Program Files\Saitek\Software\SaiSmart.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1092191296579
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/tech...ActiveData.cab

You might notice I appear to have a missing copy of MS Messenger, that is completely intentional: I noticed a few years ago that Messenger began opening up everytime I opened Outlook, or hit Hotmail's website. That version had no way to stop that behavior, but the next release had the ability to tell it to Never Run. However, I noticed that, even with it set to Never Run, it STILL opened (then closed immediately, like a sneakly little thief trying hard not to be caught) it everytime I opened Outlook Express, or hit Hotmail's website. Annoyed, I renamed msmsgs.exe, and that stopped it from ever opening. (And cause no problems whatsoever, 2 years or more and Outlook and Hotmail both work just FINE without Messenger mucking about with them).

I guess I just don't trust Microsoft, or anyone for that matter, and it really seems suspicious to me that Messenger should insist on running at ANY time when you specifically set it to NEVER run. Sorry for my little rant, just can't resist the urge to grind my teeth at MS sometimes.

Thanks to any who have a look at my log!
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 1,478
Reputation: mikeandike22 is an unknown quantity at this point 
Solved Threads: 18
mikeandike22's Avatar
mikeandike22 mikeandike22 is offline Offline
Nearly a Posting Virtuoso

Re: Hijack log, I should be clean, but let's see...

 
0
  #2
Aug 31st, 2004
from what i see everything looks fine. Oh and here is a tip you can turn off msn messenger so that it doesnt start up anymore by booting into safe mode(esc+F8 while rebooting) then goto the dir C:/program files/messenger and rename the application msmsg to msmsgoff. If it says that this file is being used by another program then open up the task manager and scroll down to msmsg.exe and end process now you should be able to rename it. I am sorry if i told you some stuff that you already know i didnt look at you techie info or read all of your post.
My Daniweb Blog: This,That, and Everything Else (Blog contest winner)

GetFirefox!
GetOpera!






Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 277
Reputation: DuncanIdaho is an unknown quantity at this point 
Solved Threads: 5
DuncanIdaho DuncanIdaho is offline Offline
Unverified User

Re: Hijack log, I should be clean, but let's see...

 
0
  #3
Aug 31st, 2004
Yup, I renamed it over 2 years ago. Had to rename it again when I installed SP2, as well. Thanks, though, for that bit of advice. Maybe it'll help someone else who is, like me, easily irked by software that doesn't do what you tell it too.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC