Monday, May 24, 2010

Hijack this log- whats wrong with my computer?

Logfile of Trend Micro HijackThis v2.0.2


Scan saved at 6:44:30 PM, on 4/25/2008


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Boot mode: Normal





Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\Ati2evxx.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\system32\Ati2evxx.exe


C:\WINDOWS\Explorer.EXE


C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


C:\WINDOWS\eHome\ehRecvr.exe


C:\WINDOWS\eHome\ehSched.exe


C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


C:\WINDOWS\system32\dllhost.exe


C:\WINDOWS\ehome\ehtray.exe


C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


C:\WINDOWS\stsystra.exe


C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe


C:\Program Files\QuickTime\QTTask.exe


C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


C:\Program Files\iTunes\iTunesHelper.exe


C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe


C:\WINDOWS\system32\Rundll32.exe


C:\WINDOWS\eHome\ehmsas.exe


C:\Program Files\Messenger\msmsgs.exe


C:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe


C:\Program Files\iPod\bin\iPodService.exe


C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


C:\Program Files\Trend Micro\HijackThis\HijackThis.exe





R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20ve...


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?...


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?...


R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?...


R1 - HKCU\Software\Microsoft\Windows\CurrentV... Settings,ProxyServer = :0


O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


O2 - BHO: (no name) - {11267AD1-B290-453B-A2D5-06E72F5BAE58} - C:\WINDOWS\system32\awtqrSJb.dll (file missing)


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll


O2 - BHO: (no name) - {BFA7416F-6EBA-43E5-B485-D32C6C78E1DB} - C:\WINDOWS\system32\jkkJbbXo.dll (file missing)


O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll


O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe


O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe


O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE


O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay


O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe


O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe


O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u


O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"


O4 - HKLM\..\Run: [BMfbb4ac12] Rundll32.exe "C:\WINDOWS\system32\weusjuqp.dll",s


O4 - HKCU\..\Run: [Power2GoExpress] NA


O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1...


O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h


O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl


O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = ?


O8 - Extra context menu item: E%26amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCE...


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.D...


O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe


O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O20 - Winlogon Notify: jkkJbbXo - jkkJbbXo.dll (file missing)


O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe


O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS





--


End of file - 7177 bytes


21 hours ago - 3 days left to answer.


Additional Details


21 hours ago





I can open the first page of a webpage but then I can go no further. For example I open yahoo no problem but when I try to click yahoo mail it stops receiving. I did have a virus and I think it changed kernal32 and something else

Hijack this log- whats wrong with my computer?
The members of http://www.whatthetech.com/ can help you with your Hijackthis logs. There is an FAQ on the Hijackthis website pointing to this forum: http://www.spywareinfo.com/~merijn/forum...


No comments:

Post a Comment