Start a Conversation

Unsolved

This post is more than 5 years old

S

127

December 11th, 2005 15:00

HJT FILE

​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 11:31:21 AM, on 12/11/2005 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ​
​C:\WINDOWS\System32\Ati2evxx.exe ​
​C:\Program Files\Alwil Software\Avast4\ashServ.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe ​
​C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\WINDOWS\system32\atiptaxx.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​C:\Program Files\Sony\HotKey Utility\HKserv.exe ​
​C:\WINDOWS\System32\ezSP_Px.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasServ.exe ​
​C:\Program Files\MSN Messenger\msnmsgr.exe ​
​C:\Program Files\Sony\HotKey Utility\HKWnd.exe ​
​C:\Program Files\PowerPanel\Program\PcfMgr.exe ​
​C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\WINDOWS\system32\mssearchnet.exe ​
​C:\WINDOWS\system32\nvctrl.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Documents and Settings\Todd Hall\Desktop\HijackThis.exe ​
​ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.sony.com/vaiopeople​​ ​
​R3 - Default URLSearchHook is missing ​
​O2 - BHO: HomepageBHO - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - C:\WINDOWS\system32\hpFE9E.tmp ​
​O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll ​
​O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing) ​
​O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing) ​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll ​
​O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe ​
​O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe ​
​O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE ​
​O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe ​
​O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe ​
​O4 - HKLM\..\Run: [Windows Registry Scan] regscan32.exe ​
​O4 - HKLM\..\Run: [RefrigeratorMonitor] C:\PROGRA~1\AMN\HLT\AMNREFR.EXE ​
​O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe ​
​O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\BIN\PPCOLink -STATION ​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe ​
​O4 - HKLM\..\Run: [WinampAgent] C:\Documents and Settings\Todd Hall\Desktop\music\Winamp\winampa.exe ​
​O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ​
​O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe ​
​O4 - HKLM\..\Run: [DefencePlus] "C:\Program Files\DefencePlus\DefencePlus.exe" regrun ​
​O4 - HKLM\..\RunServices: [Windows Registry Scan] regscan32.exe ​
​O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl ​
​O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background ​
​O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h ​
​O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares Lite Edition\Ares.exe" -h ​
​O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe ​
​O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe ​
​O4 - Global Startup: PowerPanel.lnk = ? ​
​O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm ​
​O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html ​
​O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html ​
​O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML ​
​O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html ​
​O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OFFICE11\EXCEL.EXE/3000 ​
​O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html ​
​O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll ​
​O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE11\REFIEBAR.DLL ​
​O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - ​​http://by101fd.bay101.hotmail.msn.com/resources/MsnPUpld.cab​​ ​
​O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader.cab​​ ​
​O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe ​
​O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe ​
​O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe ​
​O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe ​
​O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) ​
​O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) ​
​O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe ​
​O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing) ​
​O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe ​
​O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing) ​
​ ​
No Responses!
No Events found!

Top