hey guys, could someone please check out my Hijack Thhis log please.
could you tell me if there's anything wrong with this....my comp.
thanks for even reading this,


Logfile of HijackThis v1.97.7
Platform: Windows XP SP1
MSIE: Internet Explorer v6.00 SP1

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Logitech\iTouch\iTouch.exe
E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
E:\PROGRA~1\MOZILLA\FIREFOX.EXE
C:\WINDOWS\System32\wuauclt.exe
E:\Installation files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\program files\adobe acrobat reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {07084BEE-CB52-45C9-5BA5-931B7E910F1E} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [zBrowser Launcher] E:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
O16 - DPF: {A8658086-E6AC-4957-BC8E-8D54A7E8A790} (GDIChk Object) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E4DFABBD-F5F6-11D3-8421-0080C6F79C42} (SpeechControl Class) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -

Dani AI

Generated

Short summary and next steps that expand on the replies below.

is right to get a fresh HijackThis scan from the latest trusted build and save the log in its own folder. is also correct that nothing in the original report jumped out as a clear, active infection, and was correct that orphaned browser helper entries can often be removed by HijackThis — but there are a few important safety steps before doing that.

Practical checklist to follow now (in order):

  1. Get the current HijackThis from a reputable source, run it, and save the new log file. Post that log rather than the old one.
  2. Make a backup first: create a System Restore point and export the registry (or let HijackThis back up changes). Do not fix anything until the backups are made.
  3. Run full scans with an up-to-date antivirus and at least one on-demand antimalware scanner. If the system is slow or symptoms persist, run scanners in Safe Mode.
  4. Check browser LAN/proxy settings in Internet Options and look for unexpected entries. If proxy or homepage settings reappear after removal, treat that as a sign of persistence and escalate scanning.
  5. Use msconfig or Autoruns (Sysinternals) to review startup items and scheduled tasks. If a BHO/toolbar is tied to a legitimate program, reinstall that program instead of deleting the entry.

If you decide to let HijackThis "fix checked" items: only mark entries that are clearly orphaned or confirmed malicious, keep the HijackThis backup, reboot, and re-scan. If entries return or the machine still redirects or shows other symptoms, collect the new HijackThis log and a description of the symptoms and post them — that will narrow down whether this is a simple cleanup or a deeper infection (or even a router/DNS compromise).

Recommended Answers

All 3 Replies

Hi. :) Start off by updating hijackthis to the latest version, which is 1.98.2. Save it in it's own permanent folder just like you have the version you are running now, rescan, and post that log.

on this log theres nothing i can see that is a threat but update your hijcak this and post a new log

You can have HJT fix these:
O2 - BHO: (no name) - {07084BEE-CB52-45C9-5BA5-931B7E910F1E} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)

Are you having a particular problem?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.