I ran Hijackthis log on a friends Gateway laptop, Running Vista Home.
I have a friend who amateurly looks at logs like this who was confused by this one so I am hoping some one can help tell me what is going on here
thanks
-Sam Bacon


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:30:24 PM, on 4/3/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

--
End of file - 2199 bytes

Dani AI

Generated

The snippet posted by is too short for a reliable verdict. ’s quick check of what was shown is understandable, but is correct: a partial or truncated HijackThis output can hide startup, browser, and registry entries that are the usual places malware lives. A thorough analysis requires the complete HijackThis logfile plus a little contextual info.

Typical things to watch for in a full HijackThis report:

  • Unknown entries under startup/Run or RunOnce that point to non-system folders (Temp, user profile, or unusual program folders).
  • Browser Helper Objects, toolbars, or BHO entries with random-looking names or DLLs in odd locations.
  • Changes to browser start page/search settings, or unexpected proxy settings.
  • Services or drivers registered from non-standard paths, or duplicate system-process names that don’t live in the System32 folder.
  • Winsock/LSP hooks, HOSTS file modifications, scheduled tasks, and unusual listening network services.
  • Any file paths or filenames that look transient (temp folders) or have lots of numbers/letters rather than human-friendly names.

Practical collection checklist (so the post is usable for analysis):

  1. Run HijackThis elevated and use the program’s "Do a system scan and save a logfile" option; open the saved .txt and copy the entire contents (don’t truncate).
  2. Include OS/version/service pack, visible symptoms (popups, redirects, slow boot), and what security software is installed (names and versions).
  3. If available, add Autoruns and Process Explorer output for startup/process context, and the results of an up-to-date on-demand malware scan (Safe Mode with networking if infection is suspected).

Cautions and final notes: never use HijackThis’s "Fix checked" blindly — remove entries only when their purpose is known or after backup/System Restore. With the complete logfile plus the context above, a confident, accurate analysis is possible.

Recommended Answers

All 3 Replies

Everything's Fine, no unknown processes..

Great, thank you so Much for that help. I will mark the post as solved but can you let me know what I should look for in a Hijack log?

That log is incomplete so it is impossible to say that you are in the clear.
Post up the complete log so we can have another look.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.