Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 07-22-2004, 02:13 PM   #1
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Browser Hijacked ?

Im deleting these files all the time with ad aware and HijackThis .. but they still contnue to show up... the thing is it always change my starting site to another....

pls help me out guys if you have any ideas...
Lacki_K is offline   Reply With Quote
Old 07-22-2004, 02:30 PM   #2
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,565
Send a message via AIM to Panama Red
Read the following thread, download and run Hijack This! and post your HT log back here with an explanation consitent with the other thread guidelines.

http://forum.pcmech.com/showthread.php?t=103171
Panama Red is offline   Reply With Quote
Old 07-22-2004, 02:44 PM   #3
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Logfile of HijackThis v1.97.7
Scan saved at 21:41:06, on 2004-07-22
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\Program\USB Storage RW\shwicon.exe
C:\HP\KBD\KBD.EXE
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\Program\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\Program\Delade filer\Logitech\QCDriver3\LVCOMS.EXE
C:\Program\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\rundll32.exe
C:\Program\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\services.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\dllcache\win32\csrss.exe
C:\Program\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program\Messenger\msmsgs.exe
C:\Documents and Settings\Ägaren\Mina dokument\Mina Program\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\GAREN~1\LOKALA~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {89425322-EE5B-4E19-B021-23D5EFE7C7A7} - C:\WINDOWS\System32\opkmbb.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program\google\googletoolbar_en_2.0.111-big.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar_en_2.0.111-big.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WCOLOREAL] C:\Program\Coloreal\coloreal.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMS] C:\Program\Delade filer\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Google Search - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmtrans.html
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.burj-al-arab.com/flashcab/ipix/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...126.5078587963
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
Lacki_K is offline   Reply With Quote
Old 07-22-2004, 02:48 PM   #4
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Is this enough?

ok the reason i run hijack this is because i thought it would fix my problem but after i pressed the "fix checked" it didnt do anything

my problem is that it changes my starting site all the time... i have tried ad aware also.. but they still continue to show up after i delete them...

i dont know what to do

i was away for 3 weeks and my dad ****ed my pc up
Lacki_K is offline   Reply With Quote
Old 07-22-2004, 03:01 PM   #5
Member (4 bit)
 
Join Date: Jul 2004
Posts: 11
DO you use Mozilla Firefox. What is your home web page on your browser. Explorer is really bad, has a bunch of holes in it that Firefox doesnt really have.
Heyjude04 is offline   Reply With Quote
Old 07-22-2004, 03:21 PM   #6
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Hi Lacki_K

please download http://tools.zerosrealm.com/pv.zip

Extract it, run runme.bat choose option1 a bunch of stuff will appear in the notepad. Post everything here.

Lobos
Lobos is offline   Reply With Quote
Old 07-22-2004, 03:37 PM   #7
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Here is option 1 .. Explorers Dll's
Hope it helps....

@Heyjude04 ... I use the login site for my broadband connection
im not sure what this mozilla firefox is, but i dont think i use anything named like that...





Module information for 'Explorer.EXE'
MODULE BASE SIZE PATH
Explorer.EXE 1000000 1015808 C:\WINDOWS\Explorer.EXE 6.00.2800.1106 (xpsp1.020828-1920) Utforskaren
ntdll.dll 77f50000 692224 C:\WINDOWS\System32\ntdll.dll 5.1.2600.1217 (xpsp2.030429-2131) DLL-fil för NT Layer
kernel32.dll 77e60000 958464 C:\WINDOWS\system32\kernel32.dll 5.1.2600.1106 (xpsp1.020828-1920) Klient-DLL för Windows NT BASE API
msvcrt.dll 77c00000 339968 C:\WINDOWS\system32\msvcrt.dll 7.0.2600.1106 (xpsp1.020828-1920) Windows NT CRT DLL
ADVAPI32.dll 77dc0000 643072 C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.1106 (xpsp1.020828-1920) Advanced Windows 32 Base API
RPCRT4.dll 78000000 552960 C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.1361 (xpsp2.040109-1800) Remote Procedure Call Runtime
GDI32.dll 7e190000 266240 C:\WINDOWS\system32\GDI32.dll 5.1.2600.1346 (xpsp2.040109-1800) GDI Client DLL
USER32.dll 77d30000 573440 C:\WINDOWS\system32\USER32.dll 5.1.2600.1255 (xpsp2.030804-1745) Klient-DLL-fil för Windows XP
SHLWAPI.dll 772c0000 413696 C:\WINDOWS\system32\SHLWAPI.dll 6.00.2800.1514 (xpsp2.040109-1800) Shell Light-weight Utility Library
SHELL32.dll 773c0000 8372224 C:\WINDOWS\system32\SHELL32.dll 6.00.2800.1556 (xpsp2_gdr.040517-1325) DLL-fil för Windows-gränssnittet
ole32.dll 7ccc0000 1196032 C:\WINDOWS\system32\ole32.dll 5.1.2600.1362 (xpsp2.040109-1800) Microsoft OLE för Windows
OLEAUT32.dll 77110000 569344 C:\WINDOWS\system32\OLEAUT32.dll 3.50.5016.0 Microsoft OLE 3.50 for Windows NT(TM) and Windows 95(TM) Operating Systems
BROWSEUI.dll 71500000 1036288 C:\WINDOWS\System32\BROWSEUI.dll 6.00.2800.1400 Bibliotek för gränssnittsläsare
SHDOCVW.dll 71700000 1347584 C:\WINDOWS\System32\SHDOCVW.dll 6.00.2800.1400 Shell Doc Object och Control Library
UxTheme.dll 5b270000 212992 C:\WINDOWS\System32\UxTheme.dll 6.00.2800.1106 (xpsp1.020828-1920) Bibliotek för Microsoft UxTheme
LPK.DLL 62f00000 32768 C:\WINDOWS\System32\LPK.DLL 5.1.2600.0 (xpclient.010817-1148) Language Pack
USP10.dll 72f70000 368640 C:\WINDOWS\System32\USP10.dll 1.0409.2600.1106 (xpsp1.020828-1920) Uniscribe Unicode script processor
comctl32.dll 71950000 933888 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1515_x-ww_7bb98b8a\comctl32.dll 6.0 (xpsp2.040410-0905) User Experience Controls Library
comctl32.dll 77330000 569344 C:\WINDOWS\system32\comctl32.dll 5.82 (xpsp1.020828-1920) Common Controls Library
appHelp.dll 75f20000 122880 C:\WINDOWS\system32\appHelp.dll 5.1.2600.1106 (xpsp1.020828-1920) Application Compatibility Client Library
CLBCATQ.DLL 7a170000 528384 C:\WINDOWS\System32\CLBCATQ.DLL 2001.12.4414.53
COMRes.dll 77040000 819200 C:\WINDOWS\System32\COMRes.dll 2001.12.4414.42
VERSION.dll 77bf0000 28672 C:\WINDOWS\system32\VERSION.dll 5.1.2600.0 (xpclient.010817-1148) Version Checking and File Installation Libraries
cscui.dll 76600000 323584 C:\WINDOWS\System32\cscui.dll 5.1.2600.1106 (xpsp1.020828-1920) Client Side Caching UI
CSCDLL.dll 765e0000 110592 C:\WINDOWS\System32\CSCDLL.dll 5.1.2600.0 (xpclient.010817-1148) Agent för frånkopplat nätverk
themeui.dll 5bb30000 462848 C:\WINDOWS\System32\themeui.dll 6.00.2800.1106 (xpsp1.020828-1920) Programmeringsgränssnitt (API) för Windows-teman
Secur32.dll 76f80000 65536 C:\WINDOWS\System32\Secur32.dll 5.1.2600.1106 (xpsp1.020828-1920) Security Support Provider Interface
MSIMG32.dll 76360000 20480 C:\WINDOWS\System32\MSIMG32.dll 5.1.2600.1106 (xpsp1.020828-1920) GDIEXT Client DLL
USERENV.dll 75a50000 675840 C:\WINDOWS\system32\USERENV.dll 5.1.2600.1106 (xpsp1.020828-1920) Userenv
msutb.dll 60130000 196608 C:\WINDOWS\System32\msutb.dll 5.1.2600.1106 (xpsp1.020828-1920) Server-DLL-fil för MSUTB
MSCTF.dll 746f0000 278528 C:\WINDOWS\System32\MSCTF.dll 5.1.2600.1106 (xpsp1.020828-1920) DLL-fil för MSCTF-servern
netapi32.dll 71c10000 319488 C:\WINDOWS\System32\netapi32.dll 5.1.2600.1562 (xpsp2_gdr.040517-1325) Net Win32 API DLL
MLANG.dll 74740000 585728 C:\WINDOWS\System32\MLANG.dll 6.00.2600.0000 (xpclient.010817-1148) Multi Language Support DLL
urlmon.dll 1a400000 499712 C:\WINDOWS\system32\urlmon.dll 6.00.2800.1400 OLE32-tillägg för Win32
ntshrui.dll 76980000 147456 C:\WINDOWS\System32\ntshrui.dll 5.1.2600.1106 (xpsp1.020828-1920) Shell-tillägg för delning
ATL.DLL 76b10000 86016 C:\WINDOWS\System32\ATL.DLL 3.00.9435 ATL Module for Windows NT (Unicode)
msi.dll 1100000 2101248 C:\WINDOWS\System32\msi.dll 2.0.2600.1106 Windows Installer
LINKINFO.dll 76970000 28672 C:\WINDOWS\System32\LINKINFO.dll 5.1.2600.0 (xpclient.010817-1148) Windows Volume Tracking
hkmodule.dll 10000000 28672 C:\HP\KBD\hkmodule.dll
WININET.dll 63000000 614400 C:\WINDOWS\system32\WININET.dll 6.00.2800.1405 Internet-tillbehör för Win32
CRYPT32.dll 762a0000 561152 C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.1123 (xpsp2.020921-0842) 32-bitars kryptografi-API
MSASN1.dll 76280000 65536 C:\WINDOWS\system32\MSASN1.dll 5.1.2600.1362 (xpsp2.040109-1800) ASN.1 Runtime APIs
DSOUND.dll 51080000 368640 C:\WINDOWS\System32\DSOUND.dll 5.3.0000000.900 built by: DIRECTX DirectSound
WINMM.dll 76b30000 184320 C:\WINDOWS\System32\WINMM.dll 5.1.2600.1106 (xpsp1.020828-1920) MCI API DLL
wdmaud.drv 72cf0000 36864 C:\WINDOWS\System32\wdmaud.drv 5.1.2600.0 (XPClient.010817-1148) WDM Audio driver mapper
msacm32.drv 72ce0000 32768 C:\WINDOWS\System32\msacm32.drv 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper
MSACM32.dll 77bd0000 81920 C:\WINDOWS\System32\MSACM32.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft ACM-ljudfilter
midimap.dll 77bc0000 28672 C:\WINDOWS\System32\midimap.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft MIDI Mapper
KsUser.dll 5ef80000 16384 C:\WINDOWS\System32\KsUser.dll 5.3.0000000.900 built by: DIRECTX User CSA Library
nView.dll 2470000 815104 C:\WINDOWS\System32\nView.dll 6.14.01.4201 NVIDIA nView Desktop and Window Manager 42.01
PSAPI.DLL 76be0000 45056 C:\WINDOWS\System32\PSAPI.DLL 5.1.2600.1106 (xpsp1.020828-1920) Process Status Helper
POWRPROF.dll 74aa0000 28672 C:\WINDOWS\System32\POWRPROF.dll 6.00.2600.0000 (xpclient.010817-1148) Power Profile Helper DLL
OLEPRO32.DLL 5f2f0000 106496 C:\WINDOWS\System32\OLEPRO32.DLL 5.0.5014 Microsoft (R) OLE Property Support DLL
DDRAW.dll 51000000 315392 C:\WINDOWS\System32\DDRAW.dll 5.3.0000000.900 built by: DIRECTX Microsoft DirectDraw
DCIMAN32.dll 73b90000 24576 C:\WINDOWS\System32\DCIMAN32.dll 5.1.2600.0 (xpclient.010817-1148) DCI Manager
NVWRSSV.DLL fa0000 155648 C:\WINDOWS\System32\NVWRSSV.DLL 6.14.01.4201 NVIDIA nView Desktop and Window Manager
WINSTA.dll 76340000 61440 C:\WINDOWS\System32\WINSTA.dll 5.1.2600.1106 (xpsp1.020828-1920) Winstation Library
webcheck.dll 74b00000 270336 C:\WINDOWS\System32\webcheck.dll 6.00.2800.1106 (xpsp1.020828-1920) Webbplatsövervakare
stobject.dll 74ad0000 131072 C:\WINDOWS\System32\stobject.dll 5.1.2600.1106 (xpsp1.020828-1920) Systray shell-tjänstobjekt
BatMeter.dll 74ac0000 36864 C:\WINDOWS\System32\BatMeter.dll 6.00.2600.0000 (xpclient.010817-1148) Battery Meter Helper DLL
SETUPAPI.dll 76660000 954368 C:\WINDOWS\System32\SETUPAPI.dll 5.1.2600.1106 (xpsp1.020828-1920) API för installationsprogrammet för Windows
WTSAPI32.dll 76f40000 32768 C:\WINDOWS\System32\WTSAPI32.dll 5.1.2600.1106 (xpsp1.020828-1920) Windows Terminal Server SDK APIs
NETSHELL.dll 75cd0000 1646592 C:\WINDOWS\system32\NETSHELL.dll 5.1.2600.1106 (xpsp1.020828-1920) Användargränssnitt för nätverksanslutning
credui.dll 76bf0000 184320 C:\WINDOWS\system32\credui.dll 5.1.2600.1106 (xpsp1.020828-1920) Användargränssnitt för referenshanteraren
WS2_32.dll 71aa0000 86016 C:\WINDOWS\system32\WS2_32.dll 5.1.2600.0 (xpclient.010817-1148) Windows Socket 2.0 32-Bit DLL
WS2HELP.dll 71a90000 32768 C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.0 (xpclient.010817-1148) Windows Socket 2.0 Helper for Windows NT
iphlpapi.dll 76d50000 94208 C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.2 (xpsp1.020828-1920) API för IP Helper
printui.dll 74b50000 536576 C:\WINDOWS\System32\printui.dll 5.1.2600.1106 (xpsp1.020828-1920) Print UI DLL
WINSPOOL.DRV 72fd0000 143360 C:\WINDOWS\System32\WINSPOOL.DRV 5.1.2600.1106 (xpsp1.020828-1920) Drivrutin för Windows-bufferthanterare
ACTIVEDS.dll 76e30000 192512 C:\WINDOWS\System32\ACTIVEDS.dll 5.1.2600.0 (xpclient.010817-1148) DLL-fil för Active Directory Router Layer
adsldpc.dll 76e00000 151552 C:\WINDOWS\System32\adsldpc.dll 5.1.2600.1106 (xpsp1.020828-1920) ADs LDAP-provider C DLL
WLDAP32.dll 76f50000 184320 C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.1106 (xpsp1.020828-1920) Win32 LDAP API DLL
CFGMGR32.dll 74ab0000 28672 C:\WINDOWS\System32\CFGMGR32.dll 5.1.2600.0 (xpclient.010817-1148) Configuration Manager Forwarder DLL
MPR.dll 71b10000 69632 C:\WINDOWS\system32\MPR.dll 5.1.2600.0 (xpclient.010817-1148) DLL-fil för router med flera providers
fxsst.dll 69370000 573440 C:\WINDOWS\System32\fxsst.dll 5.2.1776.1023 Faxtjänsten
FXSAPI.dll 69590000 458752 C:\WINDOWS\System32\FXSAPI.dll 5.2.1776.1023 Microsoft Fax API Support DLL
NTMARTA.DLL 76cd0000 126976 C:\WINDOWS\System32\NTMARTA.DLL 5.1.2600.1106 (xpsp1.020828-1920) Windows NT MARTA-provider
SAMLIB.dll 71be0000 69632 C:\WINDOWS\System32\SAMLIB.dll 5.1.2600.1106 (xpsp1.020828-1920) SAM Library DLL
drprov.dll 75f40000 24576 C:\WINDOWS\System32\drprov.dll 5.1.2600.0 (xpclient.010817-1148) Microsoft Terminal Server Network Provider
ntlanman.dll 71c00000 53248 C:\WINDOWS\System32\ntlanman.dll 5.1.2600.1106 (xpsp1.020828-1920) Microsoft® Lan Manager
NETUI0.dll 71cc0000 90112 C:\WINDOWS\System32\NETUI0.dll 5.1.2600.0 (xpclient.010817-1148) NT LM UI Common Code - GUI Classes
NETUI1.dll 71c80000 245760 C:\WINDOWS\System32\NETUI1.dll 5.1.2600.0 (xpclient.010817-1148) NT LM UI Common Code - Networking classes
NETRAP.dll 71c70000 24576 C:\WINDOWS\System32\NETRAP.dll 5.1.2600.0 (xpclient.010817-1148) Net Remote Admin Protocol DLL
davclnt.dll 75f50000 36864 C:\WINDOWS\System32\davclnt.dll 5.1.2600.0 (xpclient.010817-1148) DLL-fil för Webb-DAV-klient
igfxpph.dll 9d0000 225280 C:\WINDOWS\System32\igfxpph.dll 3,0,0,1918 igfxpph Module
hccutils.DLL a40000 118784 C:\WINDOWS\System32\hccutils.DLL 3,0,0,1918 hccutils Module
igfxres.dll de0000 159744 C:\WINDOWS\System32\igfxres.dll 3,0,0,1918 xxxxres Module
igfxsrvc.dll 2860000 327680 C:\WINDOWS\System32\igfxsrvc.dll 3,0,0,1918 igfxsrvc Module
browselc.dll 72420000 73728 C:\WINDOWS\System32\browselc.dll 6.00.2800.1106 (xpsp1.020828-1920) Bibliotek för gränssnittsläsare
SXS.DLL 75e70000 688128 C:\WINDOWS\System32\SXS.DLL 5.1.2600.1515 (xpsp2.040410-0905) Fusion 2.5
comdlg32.dll 76390000 282624 C:\WINDOWS\system32\comdlg32.dll 6.00.2800.1106 (xpsp1.020828-1920) DLL-fil med vanliga dialogrutor
scrauth.dll 3770000 122880 C:\Program\Delade filer\Symantec Shared\Script Blocking\scrauth.dll 1, 1, 1, 131 ScriptBlocking Authenticator
ScrBlock.dll 37a0000 131072 C:\Program\Delade filer\Symantec Shared\Script Blocking\ScrBlock.dll 1, 1, 1, 131 ScriptBlocking
wintrust.dll 76c20000 176128 C:\WINDOWS\System32\wintrust.dll 5.131.2600.0 (xpclient.010817-1148) API för autentisering av Microsoft Trust
IMAGEHLP.dll 76c80000 139264 C:\WINDOWS\system32\IMAGEHLP.dll 5.1.2600.1106 (xpsp1.020828-1920) Windows NT Image Helper
rsaenh.dll ffd0000 143360 C:\WINDOWS\System32\rsaenh.dll 5.1.2600.1029 (xpsp1.020426-1800) Microsoft Base Cryptographic Provider
jscript.dll 6b700000 589824 c:\windows\system32\jscript.dll 5.6.0.8513 Microsoft (r) JScript
DUSER.dll 6c730000 278528 C:\WINDOWS\System32\DUSER.dll 5.1.2600.1106 (xpsp1.020828-1920) Windows DirectUser Engine
MSGINA.dll 75950000 991232 C:\WINDOWS\System32\MSGINA.dll 5.1.2600.1343 (xpsp2.040109-1800) Inloggnings-GINA för Windows NT
ODBC32.dll 3ef0000 204800 C:\WINDOWS\System32\ODBC32.dll 3.520.9042.0 Microsoft Data Access - ODBC Driver Manager
odbcint.dll 1f850000 94208 C:\WINDOWS\System32\odbcint.dll 3.520.7713.0 Microsoft Data Access - ODBC-resurser
mscoree.dll 79170000 155648 C:\WINDOWS\System32\mscoree.dll 1.1.4322.573 Microsoft .NET Runtime Execution Engine
Shfusion.dll 796e0000 253952 C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Shfusion.dll 1.1.4322.573 Microsoft COM Runtime Fusion Assembly Viewer
MSVCR71.dll 7c340000 352256 C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll 7.10.3052.4 Microsoft® C Runtime Library
shdoclc.dll 76150000 565248 C:\WINDOWS\System32\shdoclc.dll 6.00.2600.0000 (xpclient.010817-1148) Shell Doc Object och Control Library
MFC42.DLL 73da0000 991232 C:\WINDOWS\System32\MFC42.DLL 6.00.8665.0 MFCDLL Shared Library - Retail Version
MFC42LOC.DLL 61ec0000 53248 C:\WINDOWS\System32\MFC42LOC.DLL 6.00.8665.0 MFC Språkspecifika resurser
AlbumUI.dll 3b60000 348160 C:\Program\Logitech\ImageStudio\AlbumUI.dll 7.3.0.1113 QuickCam Gallery Activity
QCUI.dll 3bd0000 393216 C:\Program\Logitech\ImageStudio\QCUI.dll 7.3.0.1113 QuickCam User Interface Library
AVIFIL32.dll 73b20000 86016 C:\WINDOWS\System32\AVIFIL32.dll 5.1.2600.1106 (xpsp1.020828-1920) Filstödsbibliotek för Microsoft AVI
MSVFW32.dll 73ba0000 131072 C:\WINDOWS\System32\MSVFW32.dll 5.1.2600.1106 (xpsp1.020828-1920) Microsoft Video för Windows-DLL
LTWVC12n.dll 3c30000 876544 C:\Program\Logitech\ImageStudio\LTWVC12n.dll 12.1.0.011 LEADTOOLS(r) DLL for Win32
LTFIL12n.DLL 1ffc0000 147456 C:\Program\Logitech\ImageStudio\LTFIL12n.DLL 12.1.0.011 LEADTOOLS(r) DLL for Win32
LTKRN12n.dll 1fff0000 430080 C:\Program\Logitech\ImageStudio\LTKRN12n.dll 12.1.0.011 LEADTOOLS(r) DLL for Win32
LQCUI.dll 3d20000 36864 C:\Program\Logitech\ImageStudio\LQCUI.dll 7.3.0.1113 QuickCam User Interface Language
LAlbumUI.dll 3d50000 196608 C:\Program\Logitech\ImageStudio\LAlbumUI.dll 7.3.0.1113 QuickCam Gallery Language
LTDIS12N.DLL 1ff70000 303104 C:\WINDOWS\System32\LTDIS12N.DLL 12.1.0.011 LEADTOOLS(r) DLL for Win32
LTIMG12N.DLL 3d90000 180224 C:\WINDOWS\System32\LTIMG12N.DLL 12.1.0.011 LEADTOOLS(r) DLL for Win32
LTEFX12N.DLL 1fc40000 245760 C:\WINDOWS\System32\LTEFX12N.DLL 12.1.0.011 LEADTOOLS(r) DLL for Win32
WMVCore.DLL 8530000 2084864 C:\WINDOWS\System32\WMVCore.DLL 9.00.00.2980 built by: lab03_dev(bld4act) Windows Media Playback/Authoring DLL
WMASF.DLL 7260000 233472 C:\WINDOWS\System32\WMASF.DLL 9.00.00.2980 built by: lab03_dev(bld4act) Windows Media ASF DLL
msdmo.dll 26e0000 28672 C:\WINDOWS\System32\msdmo.dll
dxmasf.dll 6c4d0000 512000 C:\WINDOWS\System32\dxmasf.dll 6.4.09.1125 Källfilter för Windows Media
DRMClien.DLL 91a0000 315392 C:\WINDOWS\System32\DRMClien.DLL 9.00.00.2980 DRM Client DLL
actxprxy.dll 71d30000 110592 C:\WINDOWS\System32\actxprxy.dll 6.00.2600.0000 (XPClient.010817-1148) ActiveX Interface Marshaling Library
pclepim1.dll 2640000 61440 C:\WINDOWS\System32\pclepim1.dll 2.00 PCLEPIM1 32-bit AVI Codec
l3codeca.acm 6880000 565248 C:\WINDOWS\System32\l3codeca.acm 1, 9, 0, 0305 MPEG Layer-3 Audio Codec for MSACM
WZSHLSTB.DLL 16200000 24576 C:\PROGRAM\WINZIP\WZSHLSTB.DLL 4.1 (32-bit) WinZip Shell Extension DLL
rarext.dll 2590000 176128 C:\Program\WinRAR\rarext.dll
NavShExt.dll 25d0000 98304 C:\Program\Norton SystemWorks\Norton Antivirus\NavShExt.dll 10.00.13 Norton AntiVirusNAVShellExt Module
MSVCP70.dll 7c080000 487424 C:\WINDOWS\System32\MSVCP70.dll 7.00.9466.0 Microsoft® C++ Runtime Library
MSVCR70.dll 7c000000 344064 C:\WINDOWS\System32\MSVCR70.dll 7.00.9466.0 Microsoft® C Runtime Library
NDRVEX.DLL 26f0000 73728 C:\Program\Norton SystemWorks\Norton Utilities\NDRVEX.DLL 17.0.0.82 Norton Shared Component
mscms.dll 73b00000 77824 C:\WINDOWS\System32\mscms.dll 5.1.2600.1106 (xpsp1.020828-1920) Microsoft Color Matching System DLL
shmedia.dll 5cfd0000 139264 C:\WINDOWS\System32\shmedia.dll 6.00.2800.1125 (xpsp2.020921-0842) Shell-tillägg för extrahering av mediefilsegenskaper
mydocs.dll 72400000 102400 C:\WINDOWS\System32\mydocs.dll 6.00.2600.0000 (xpclient.010817-1148) Gränssnitt för Mina dokument
RASAPI32.DLL 76ed0000 225280 C:\WINDOWS\System32\RASAPI32.DLL 5.1.2600.1106 (xpsp1.020828-1920) Programmeringsgränssnitt för Fjärråtkomst
rasman.dll 76e80000 69632 C:\WINDOWS\System32\rasman.dll 5.1.2600.1106 (xpsp1.020828-1920) Remote Access Connection Manager
TAPI32.dll 76ea0000 176128 C:\WINDOWS\System32\TAPI32.dll 5.1.2600.1106 (xpsp1.020828-1920) Klient-DLL för Microsoft® Windows(TM)-telefoni-API
rtutils.dll 76e70000 53248 C:\WINDOWS\System32\rtutils.dll 5.1.2600.0 (xpclient.010817-1148) Routing Utilities
sensapi.dll 722a0000 20480 C:\WINDOWS\System32\sensapi.dll 5.1.2600.1106 (xpsp1.020828-1920) SENS Connectivity API DLL
AcroIEHelper.ocx ec0000 32768 C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx 1, 0, 0, 1 AcroIEHelper Module
opkmbb.dll 25c0000 45056 C:\WINDOWS\System32\opkmbb.dll
wiashext.dll 5a9f0000 577536 C:\WINDOWS\System32\wiashext.dll 5.1.2600.0 (XPClient.010817-1148) Shell-mappen UI för Imaging-enheter
gdiplus.dll 78190000 1708032 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\gdiplus.dll 5.1.3101.0 (xpsp1.020828-1920) Microsoft GDI+
sti.dll 73b70000 73728 C:\WINDOWS\System32\sti.dll 5.1.2600.1106 (xpsp1.020828-1920) Klient-DLL-fil för stillbildsenheter
Cuteshell.dll 30a0000 176128 C:\Program\GlobalSCAPE\CuteFTP\Cuteshell.dll 50, 6, 3, 2 CuteFTP Shell Integration Module
asfsipc.dll 70f90000 28672 C:\WINDOWS\System32\asfsipc.dll 1.1.00.3917 ASFSipc Object
MSISIP.DLL 60b10000 53248 C:\WINDOWS\System32\MSISIP.DLL 2.0.2600.0 MSI Signature SIP Provider
wshext.dll 74e70000 65536 C:\WINDOWS\System32\wshext.dll 5.6.0.6626 Microsoft (r) Shell Extension for Windows Script Host
wshSV.DLL 591d0000 53248 C:\WINDOWS\System32\wshSV.DLL 5.6.0.6626 Microsoft (r) Windows Script Host, internationella resurser
ScrTrust.dll 32b0000 65536 C:\Program\Delade filer\Symantec Shared\Script Blocking\ScrTrust.dll 1, 1, 1, 131 ScriptBlocking Trust Verifier
MCPS.DLL 365a0000 86016 c:\Program\MICROS~4\Office10\MCPS.DLL 10.0.2625 Media Catalog Proxy/Stub
MSVCP60.DLL 76060000 397312 C:\WINDOWS\System32\MSVCP60.DLL 6.00.8972.0 Microsoft (R) C++ Runtime Library
Lacki_K is offline   Reply With Quote
Old 07-22-2004, 03:43 PM   #8
Professional gadfly
 
doctorgonzo's Avatar
 
Join Date: Jan 2002
Location: Minneapolis, MN
Posts: 6,364
Send a message via MSN to doctorgonzo
Quote:
Originally Posted by Lacki_K
im not sure what this mozilla firefox is, but i dont think i use anything named like that...
Mozilla Firefox is a browser like IE. Unlike IE, it is much more secure when it comes to being hijacked, insofar as it never happens. IE "helpfully" downloads things like toolbars and ActiveX controls without telling you, which is how your PC gets screwed up. This does not happen with Mozilla.
doctorgonzo is offline   Reply With Quote
Old 07-22-2004, 03:47 PM   #9
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
i will try Mozilla and use it if its user firnedly... but id really like to fix IE also.,..
Lacki_K is offline   Reply With Quote
Old 07-22-2004, 03:55 PM   #10
Member (4 bit)
 
Join Date: Jul 2004
Posts: 11
You can't really fix IE, unless microsoft gives an update. Stop going to porn sites that might help. Get firefox use ad-aware. If they keep coming back then its something else. FIrefox is basically the same thing as IE, but the cool thing is if you hit ctrl+t and new browser opens up in the same window... i love it.
Heyjude04 is offline   Reply With Quote
Old 07-22-2004, 05:03 PM   #11
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Download these three programs

TheKillbox from here:http://tools.zerosrealm.com/killbox.zip Unzip the files to a folder,

Click here to down load CWShredder by Merijn Bellekom, the creator of Hijack This


Download sphjfix from here: http://www.rokop-security.de/main/do...p=getit&lid=59


------------------------------------------------------
then double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:

(full path of file from above next to the

C:\WINDOWS\System32\opkmbb.dll

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The filenameand path should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

--------------------------------------------------

Run CWShredder

Run it, press 'Fix', and allow it to fix all it finds.
And remember to click "Fix" (Not "Scan only")

-------------------------------------------------------
run Sphjfix

your computer will be restarted and it will finish the process


come back and post a fresh hijack this log


Lobos
Lobos is offline   Reply With Quote
Old 07-22-2004, 05:31 PM   #12
Shiro Usagi
Premium Member
 
Cricket's Avatar
 
Join Date: Sep 1999
Location: Kaneohe, Hawaii
Posts: 34,002
Hey Lobos, what's that pv.zip you had Lacki_K run on his/her computer? And what about Killbox and sphjfix?

How's things going on the web security front? I'm guessing you've been real busy.

Cricket
Cricket is offline   Reply With Quote
Old 07-22-2004, 08:48 PM   #13
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
They are tools for dealing with certain strains of cws some of the tools have multiple uses

Lobos
Lobos is offline   Reply With Quote
Old 07-23-2004, 12:12 AM   #14
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
heyjude - we appreciate your opinion and many of us do share it, but this is not a thread for suggesting an alternative browser - this is a thread for fixing specific issues.

Lacki - vulgar language is not permitted on these forums, censored or not. Thank you.
glc is online now   Reply With Quote
Old 07-23-2004, 08:14 AM   #15
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Lobos thank you so much for this info ...

Here is the latest log..





Logfile of HijackThis v1.97.7
Scan saved at 15:10:35, on 2004-07-23
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\Program\USB Storage RW\shwicon.exe
C:\HP\KBD\KBD.EXE
C:\Program\VERITAS Software\Update Manager\sgtray.exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\Program\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\Program\Delade filer\Logitech\QCDriver3\LVCOMS.EXE
C:\Program\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\rundll32.exe
C:\Program\Messenger\msmsgs.exe
C:\Program\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\Program\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\services.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\dllcache\win32\csrss.exe
C:\Program\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Documents and Settings\Ägaren\Mina dokument\Mina Program\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login1.comhem.se/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program\google\googletoolbar_en_2.0.111-big.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar_en_2.0.111-big.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [WCOLOREAL] C:\Program\Coloreal\coloreal.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMS] C:\Program\Delade filer\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Google Search - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program\google\GoogleToolbar_en_2.0.111-big.dll/cmtrans.html
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...126.5078587963
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
Lacki_K is offline   Reply With Quote
Old 07-23-2004, 08:40 AM   #16
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
Lacki, you need to download the new version of HJT - yours is not current.
glc is online now   Reply With Quote
Old 07-23-2004, 09:59 AM   #17
Member (5 bit)
 
Join Date: Apr 2004
Posts: 29
Which one is HJT... glc ?

And by the way... my problem was fixed after this
Lacki_K is offline   Reply With Quote
Old 07-23-2004, 02:58 PM   #18
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Click here to download Hijack This. Save it to the folder you have the other one in this is v1.98.0

keep a look out for v1.98.1 pretty soon

Lobos
Lobos is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 12:57 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2