Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

 Need help on hijackthis log

views
     
TSyamato
post Aug 19 2011, 02:56 AM, updated 15y ago

stop calling me yameteh =.=|||
*****
Senior Member
760 posts

Joined: Aug 2006
From: coming back through stratosphere


can any1 who are experience on hijackthis have a look on my system log.

CODE
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:47:39 AM, on 19/08/11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\DOCUME~1\zyon\LOCALS~1\Temp\RarSFX0\ppsap.exe
C:\PROGRA~1\Microsoft ActiveSync\rapimgr.exe
C:\Program Files\Codebox\BitMeter\BitMeter2.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Temp Download\HousecallLauncher.exe
C:\DOCUME~1\zyon\LOCALS~1\Temp\7zS1AB.tmp\setup.exe
D:\Temp Download\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://malaysia.search.yahoo.com/search?fr=mcafee&p=%s
O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.27 gwgt1.joymax.com
O1 - Hosts: 121.128.133.28 gwgt1.joymax.com
O2 - BHO: ThunderAtOnce Class - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - S-1-5-18 Startup: Bitmeter2.lnk = C:\Program Files\Codebox\BitMeter\BitMeter2.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Bitmeter2.lnk = C:\Program Files\Codebox\BitMeter\BitMeter2.exe (User 'Default user')
O4 - Startup: Bitmeter2.lnk = C:\Program Files\Codebox\BitMeter\BitMeter2.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{CC1F44B9-6D20-4B05-AD3C-2BBCAF88AA0E}: NameServer = 8.8.8.8,8.8.4.4
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0136791244555907) (0136791244555907mcinstcleanup) - Unknown owner - C:\DOCUME~1\zyon\LOCALS~1\Temp\0136791244555907mcinst.exe (file missing)
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MS OsWork(MS NetWork Services) (MS OsWork) - Unknown owner - C:\WINDOWS\system32\msot32.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8414 bytes


much appreciated.

Regards,

yamato
chrisling
post Aug 19 2011, 02:46 PM

Helper Trainee+
******
Senior Member
1,684 posts

Joined: Nov 2006
From: KL


O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.27 gwgt1.joymax.com
O1 - Hosts: 121.128.133.28 gwgt1.joymax.com

You did modify the host file yourself? Or by your administrator? If not please remove it. What issue you have with your system now? And you're still using SP2, any reason not to upgrade to SP3?

Thanks.
qhalidx
post Aug 19 2011, 02:53 PM

Getting Started
**
Junior Member
148 posts

Joined: Sep 2005


saw most of your service are abit dodgy..like the installer in the temp file, MSOT and your gamemon.des.exe

and the most dodgy is..
C:\DOCUME~1\zyon\LOCALS~1\Temp\7zS1AB.tmp\setup.exe <-prolly a virus.
TSyamato
post Aug 20 2011, 08:29 AM

stop calling me yameteh =.=|||
*****
Senior Member
760 posts

Joined: Aug 2006
From: coming back through stratosphere


QUOTE(chrisling @ Aug 19 2011, 02:46 PM)
O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.27 gwgt1.joymax.com
O1 - Hosts: 121.128.133.28 gwgt1.joymax.com

You did modify the host file yourself? Or by your administrator? If not please remove it. What issue you have with your system now? And you're still using SP2, any reason not to upgrade to SP3?

Thanks.
*
yea i did added those host by myself to connect to a game server.

my problem is that my pc runs ridiculously slow, i checked the mem & cpu usage are normal but i the system & internet connection is very very sluggish & retard.
H4XF4XTOR
post Aug 21 2011, 04:37 PM

【ツ】PANDAMON 【ツ】
*******
Senior Member
3,081 posts

Joined: May 2011
From: ▁ ▂ ▃ ▄ ▅ ▆ █ 100 %



upload or copy paste your log in here

HijackThis.de Security
TSyamato
post Aug 21 2011, 04:49 PM

stop calling me yameteh =.=|||
*****
Senior Member
760 posts

Joined: Aug 2006
From: coming back through stratosphere


QUOTE(H4XF4XTOR @ Aug 21 2011, 04:37 PM)
upload or copy paste your log in here

HijackThis.de Security
*
thanks,

the link does help alot wink.gif
H4XF4XTOR
post Aug 21 2011, 04:58 PM

【ツ】PANDAMON 【ツ】
*******
Senior Member
3,081 posts

Joined: May 2011
From: ▁ ▂ ▃ ▄ ▅ ▆ █ 100 %



QUOTE(yamato @ Aug 21 2011, 04:49 PM)
thanks,

the link does help alot wink.gif
*
no problem at all...glad to help biggrin.gif
wcypierre
post Aug 21 2011, 10:22 PM

Newbie Programmer
Group Icon
Elite
4,619 posts

Joined: Jul 2011
QUOTE(H4XF4XTOR @ Aug 21 2011, 04:37 PM)
upload or copy paste your log in here

HijackThis.de Security
*
These log scanners are not quite accurate actually(got quite a lot of false positives). Requesting help from a trained HJT staff would be much better as they are better in it thumbup.gif

No offense though notworthy.gif
H4XF4XTOR
post Aug 21 2011, 10:46 PM

【ツ】PANDAMON 【ツ】
*******
Senior Member
3,081 posts

Joined: May 2011
From: ▁ ▂ ▃ ▄ ▅ ▆ █ 100 %



QUOTE(wcypierre @ Aug 21 2011, 10:22 PM)
These log scanners are not quite accurate actually(got quite a lot of false positives). Requesting help from a trained HJT staff would be much better as they are better in it  thumbup.gif

No offense though  notworthy.gif
*
none taken..just helping out though.. couldnt agree more with your statement biggrin.gif
wcypierre
post Aug 21 2011, 11:14 PM

Newbie Programmer
Group Icon
Elite
4,619 posts

Joined: Jul 2011
I just don't want that later the TS is misleaded by other users and cause their computers to break and it also makes the hjt staff's job harder. doh.gif
H4XF4XTOR
post Aug 22 2011, 10:26 AM

【ツ】PANDAMON 【ツ】
*******
Senior Member
3,081 posts

Joined: May 2011
From: ▁ ▂ ▃ ▄ ▅ ▆ █ 100 %



no,just giving TS some basic info about what is the log looks like
chrisling
post Aug 22 2011, 11:14 AM

Helper Trainee+
******
Senior Member
1,684 posts

Joined: Nov 2006
From: KL


QUOTE(chrisling @ Aug 19 2011, 02:46 PM)
O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.27 gwgt1.joymax.com
O1 - Hosts: 121.128.133.28 gwgt1.joymax.com

You did modify the host file yourself? Or by your administrator? If not please remove it. What issue you have with your system now? And you're still using SP2, any reason not to upgrade to SP3?

Thanks.
*
I'm still waiting the answer before I proceed to offer my help here...
TSyamato
post Aug 22 2011, 11:51 AM

stop calling me yameteh =.=|||
*****
Senior Member
760 posts

Joined: Aug 2006
From: coming back through stratosphere


yup sp2. ungenuine OS so couldnt upgrade to sp3.

hope i dont get flame for the ungenuine copy as this thread is discussing about hijack log and not sp.
H4XF4XTOR
post Aug 23 2011, 01:39 PM

【ツ】PANDAMON 【ツ】
*******
Senior Member
3,081 posts

Joined: May 2011
From: ▁ ▂ ▃ ▄ ▅ ▆ █ 100 %



QUOTE(yamato @ Aug 22 2011, 11:51 AM)
yup sp2. ungenuine OS so couldnt upgrade to sp3.

hope i dont get flame for the ungenuine copy as this thread is discussing about hijack log and not sp.
*
no,i believe you can....

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0185sec    0.62    5 queries    GZIP Disabled
Time is now: 21st December 2025 - 07:39 PM