hijack this log
Results 1 to 2 of 2

Thread: hijack this log

  1. #1
    Join Date
    May 2000
    Location
    Lackawaxen,Pa 18435
    Posts
    312

    hijack this log

    Can someone go over this log and see if there is anything bad listed. Thanks


    Logfile of HijackThis v1.98.2
    Scan saved at 11:10:24 PM, on 3/18/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\SYSTEM32\USRmlnkA.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\SYSTEM32\USRshutA.exe
    C:\WINDOWS\SYSTEM32\USRmlnkA.exe
    C:\Program Files\LimeWire\LimeWire 4.2.5\LimeWire.exe
    C:\WINDOWS\system32\CMMON32.EXE
    C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.0\YTPro.exe
    C:\Program Files\Yahoo!\Messenger\YPager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.829\HijackThis.exe
    C:\Program Files\Outlook Express\msimn.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.localnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.localnet.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by LocalNet
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 66.199.231.174 www.google.com
    O1 - Hosts: 66.199.231.174 google.com
    O1 - Hosts: 66.199.231.174 www.google.co.uk
    O1 - Hosts: 66.199.231.174 google.co.uk
    O1 - Hosts: 66.199.231.174 www.google.ca
    O1 - Hosts: 66.199.231.174 google.ca
    O1 - Hosts: 66.199.231.174 www.google.es
    O1 - Hosts: 66.199.231.174 google.es
    O1 - Hosts: 66.199.231.174 www.google.de
    O1 - Hosts: 66.199.231.174 google.de
    O1 - Hosts: 66.199.231.174 www.google.fr
    O1 - Hosts: 66.199.231.174 google.fr
    O1 - Hosts: 66.199.231.174 www.google.com.au
    O1 - Hosts: 66.199.231.174 google.com.au
    O1 - Hosts: 66.199.231.173 www.yahoo.com
    O1 - Hosts: 66.199.231.173 yahoo.com
    O1 - Hosts: 66.199.231.172 www.msn.com
    O1 - Hosts: 66.199.231.172 msn.com
    O1 - Hosts: 66.199.231.172 search.msn.com
    O1 - Hosts: 66.199.231.172 www.go.com
    O1 - Hosts: 66.199.231.172 go.com
    O1 - Hosts: 66.199.231.171 astalavista.com
    O1 - Hosts: 66.199.231.171 www.astalavista.com
    O1 - Hosts: 66.199.231.171 astalavista.box.sk
    O1 - Hosts: 66.199.231.171 cracks.am
    O1 - Hosts: 66.199.231.171 www.cracks.am
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://start.localnet.com/
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102021605109
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://playweb15.pogo.com/game/delux...ploader_v6.cab

  2. #2
    Join Date
    Feb 2004
    Location
    Mandurah, Western Australia
    Posts
    10,157
    Hi. First of all you need to update hijackthis to version 1.99.1. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go here and download the selfextracting zip version. Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete the file manually. Unzip the new version into the hijackthis folder, or in the case of the self-extracting version, it will self install into your Program Files folder.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •