Question:
Safe hijackthis logfile?
anonymous
2008-08-29 03:41:36 UTC
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:41:51 AM, on 8/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ProxyFirewall] C:\Program Files\ProxyFirewall\ProxyFirewall.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1217118467399
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {8E82893F-7ED1-4811-A247-580DCC0E2629} (SFLauncherTDE Class) - http://sf.gg.in.th/activex/StarterSFTDE.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog
Three answers:
josh
2008-08-29 04:07:05 UTC
...What?
Masked Musketeer
2008-08-29 11:22:04 UTC
I'd help you, but I have no idea how to read HJK logfiles.



Sign up for a forum username at :

http://www.bleepingcomputer.com/



They can help you with Hijackthis logs.
Extreme Gamer
2008-08-29 12:34:25 UTC
your hijack this log contains a threat



O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll



remove it and use these free programs(it seems that you are using avg 8,ad-aware and spybot and hey are all bad except spybot so keep spybot and use these completely free programs



uninstall any security program you are using and install these free programs



1-Anti-virus



a-avira personal classic edition(free)(detection rate 99.6%)



http://www.download.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?tag=lst-3&cdlPid=10831109



2-Anti-spyware



a-super antispyware free(one of the most recommended antispywares)



http://www.download.com/SUPERAntiSpyware-Free-Edition/3000-8022_4-10523889.html



b- a-squared free(will get rid of all kinds of spyware,backdoors.trojans,keyloggers and etc)



http://www.download.com/A-squared-Free/3000-2239_4-10262215.html?tag=lst-1&cdlPid=10832180





3-firewall



a-comodo firewall pro(free)(the only free firewall to pass matousec leaktest with an excellent score 95% (after installing it go to firewall tab then stealth port wizard and set it to block all incoming conections)



note:this won't affect any p2p propgrams(limewire,bitcomet and etc)



http://www.download.com/Comodo-Firewall-Pro/3000-10435_4-10460704.html?tag=lst-1&cdlPid=10849947





4-browser



a-firefox 3.0(safest browser,fastest browser and most enjoyable browser)



http://www.download.com/mozilla-firefox/?tag=lst-3&cdlPid=10854845



5-browser add-ons(firefox)



a-mcafee site advisor(warns you of bad sites)



http://www.download.com/McAfee-SiteAdvisor-for-Firefox/3000-11745_4-10493671.html?tag=lst-1&cdlPid=10663377



b-Adblock Plus(blocks ads )



https://addons.mozilla.org/en-US/firefox/addon/1865







6-pc utilties



a-ccleaner:(cleans temporary internet files,history cookies , fixes the registry and etc)



http://www.download.com/CCleaner/3000-2144_4-10315544.html?tag=lst-1&cdlPid=10837066



b-revouninstaller: (uninstall the programs and removes the traces left in registry )(completely remove sticky programs like norton because it scans the registry for traces left in the registry after uninstalling the programs



http://www.download.com/Revo-Uninstaller/3000-2096_4-10687648.html?tag=mncol&cdlPid=10854684



c- advanced windowcare personal(free)( scan for spyware,protect you from spyware,optimize your pc,repair the registry and many more)



http://www.download.com/Advanced-WindowsCare-Personal/3000-2086_4-10407614.html?part=dl-AdvancedW&subj=uo&tag=button



i helped you but next time don't post a hijackthis log on yahoo answers because few people can help you here post the hijackthis log next time on a forum or you can e-mail me on cc_ccc97@yahoo.com(not the original e-mail because it may be spammed but i can hep you through it.)


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...