| | |
Hijack This log, problems?
![]() |
•
•
Join Date: Feb 2004
Posts: 9
Reputation:
Solved Threads: 0
Hi everyone. I made a post a few weeks ago about deleting everything on my hijackthis log (I know... really stupid), but this is the log from what my computer is currently running, if anyone could help me out with what I need/what I have that I don't need, I would really appreciate it.
Logfile of HijackThis v1.97.7
Scan saved at 11:28:17 PM, on 2/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\System\msadc\Help\winreg.exe
C:\PROGRA~1\BROADJ~1\CLIENT~1\CFD.exe
C:\Documents and Settings\Jeff Rautenberg\My Documents\download\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [NAV-AutoUp] SPOOLSRV.EXE
O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Update Agent] winupdate.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{304C4BF2-A542-4371-9FA1-8AC82751B787}: NameServer = 206.141.192.60 206.141.193.55
Thanks everyone,
-Jeff-
Logfile of HijackThis v1.97.7
Scan saved at 11:28:17 PM, on 2/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\System\msadc\Help\winreg.exe
C:\PROGRA~1\BROADJ~1\CLIENT~1\CFD.exe
C:\Documents and Settings\Jeff Rautenberg\My Documents\download\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [NAV-AutoUp] SPOOLSRV.EXE
O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Update Agent] winupdate.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{304C4BF2-A542-4371-9FA1-8AC82751B787}: NameServer = 206.141.192.60 206.141.193.55
Thanks everyone,
-Jeff-
only thing is this ,but if this [206.141.192.60 ]is your IP address then it ok ,if you know its not you IP Address then fix it .
O17 - HKLM\System\CCS\Services\Tcpip\..\{304C4BF2-A542-4371-9FA1-8AC82751B787}: NameServer = 206.141.192.60 206.141.193.55
O17 - HKLM\System\CCS\Services\Tcpip\..\{304C4BF2-A542-4371-9FA1-8AC82751B787}: NameServer = 206.141.192.60 206.141.193.55
Linux boot cd http://www.knopper.net/knoppix/index-en.html
•
•
Join Date: Feb 2004
Posts: 9
Reputation:
Solved Threads: 0
Thanks a lot, how's this look now?
Logfile of HijackThis v1.97.7
Scan saved at 6:40:50 PM, on 2/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\System\msadc\Help\winreg.exe
C:\PROGRA~1\BROADJ~1\CLIENT~1\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\Documents and Settings\Jeff Rautenberg\My Documents\download\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [NAV-AutoUp] SPOOLSRV.EXE
O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Update Agent] winupdate.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
Another question that I had was that I ran an avast virus scan and it found win32:NCaseSpy [trj]. I deleted it and it didn't seem to go away. So I ran the scan again when the computer was booting up and deleted it there. I'm not sure if it is gone or if I have any other viruses. I don't know if you can tell from the hijackthis log, but if you could let me know, I'd appreciate it.
Thanks,
-Jeff-
Logfile of HijackThis v1.97.7
Scan saved at 6:40:50 PM, on 2/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\System\msadc\Help\winreg.exe
C:\PROGRA~1\BROADJ~1\CLIENT~1\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\Documents and Settings\Jeff Rautenberg\My Documents\download\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [NAV-AutoUp] SPOOLSRV.EXE
O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [Windows Update Agent] winupdate.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
Another question that I had was that I ran an avast virus scan and it found win32:NCaseSpy [trj]. I deleted it and it didn't seem to go away. So I ran the scan again when the computer was booting up and deleted it there. I'm not sure if it is gone or if I have any other viruses. I don't know if you can tell from the hijackthis log, but if you could let me know, I'd appreciate it.
Thanks,
-Jeff-
•
•
Join Date: Feb 2004
Posts: 9
Reputation:
Solved Threads: 0
Sorry, but one more thing, I ran ad-aware 6.0 personal and it found 212 items (I not very good w/ computers, so I have no idea what this means.) Are these files that I should delete? I didn't do anything w/ them b/c it seemed like a whole lot of files to delete. Please let me know what I should do w/ them (if anything).
Thanks again!
-Jeff-
Thanks again!
-Jeff-
•
•
•
•
Originally Posted by rauty
Sorry, but one more thing, I ran ad-aware 6.0 personal and it found 212 items (I not very good w/ computers, so I have no idea what this means.) Are these files that I should delete? I didn't do anything w/ them b/c it seemed like a whole lot of files to delete. Please let me know what I should do w/ them (if anything).
Thanks again!
-Jeff-
Linux boot cd http://www.knopper.net/knoppix/index-en.html
actually this file[O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe] could be the results of a virus ,there is an good ,winupdate.exe file but it would be in the c:\windows\system , folder ,do a search for the file and let me know how many you find and where they are located .
Linux boot cd http://www.knopper.net/knoppix/index-en.html
•
•
Join Date: Feb 2004
Posts: 9
Reputation:
Solved Threads: 0
The search turned up winupdate.exe-0f50c4f5.pf in C:\Windows\prefetch, but that's the only file that it found. I obviously don't know much of what I'm talking about, but it does seem like winupdate.exe is causing something b/c I used to have to hit ALT+CTL+DEL and end like 10 tasks or whatever to have my conputer function at a semi-normal speed. Winupdate.exe was one of those.
•
•
Join Date: Feb 2004
Posts: 9
Reputation:
Solved Threads: 0
I did some looking around on the website that you (caperjack) posted on another link. I looked at all of the processes that were running when I pressed ALT+CTL+DEL and it said that svchost.exe, services.exe, lsass.exe, csrss.exe, spoolsv.exe, winlogon.exe, smss.exe, winreg.exe, and explorer.exe were all created from various viruses. That really surprised me b/c my computer seems to be running better than it used to, and if all of those processes were gone, there would be almost nothing left on the menu. Should I do something about these or just leave them there? If anyone knows the answer, please let me know. Thanks a bunch.
-Jeff-
-Jeff-
•
•
•
•
Originally Posted by rauty
I did some looking around on the website that you (caperjack) posted on another link. I looked at all of the processes that were running when I pressed ALT+CTL+DEL and it said that svchost.exe, services.exe, lsass.exe, csrss.exe, spoolsv.exe, winlogon.exe, smss.exe, winreg.exe, and explorer.exe were all created from various viruses. That really surprised me b/c my computer seems to be running better than it used to, and if all of those processes were gone, there would be almost nothing left on the menu. Should I do something about these or just leave them there? If anyone knows the answer, please let me know. Thanks a bunch.
-Jeff-
Linux boot cd http://www.knopper.net/knoppix/index-en.html
![]() |
Similar Threads
- Hijack This Log - Internet Explorer - Problems accessing websites (Viruses, Spyware and other Nasties)
- Hijack This Log - IE problems accessing websites (Viruses, Spyware and other Nasties)
- Hijack This Log, annoying popups (Viruses, Spyware and other Nasties)
- Some log-in problems; HJT log included (Viruses, Spyware and other Nasties)
- Great search homepage (HIjack log inside) (Viruses, Spyware and other Nasties)
- In Desperate Need of Help with hijack this log file; computer full of spyware (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: IE6 has been constantly hijacked by ....
- Next Thread: I've been HiJacked
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus attack audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia education email europe exam exploit facebook fake fancheckvirus gaming gumblar halloween herss.exe hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec trojan unwanted update usa virus viruses vista war warning windows worm yahoo zeroday





