


Jun 26 2009, 04:04 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 26-June 09 Member No.: 86,436 Operating System: xp Home |
I'm trying to clean up my girfriend's 18 yr. old son's pc. I keep getting some nasty little buggers showing up when I run Hijack This (lg attached) Any help resolving this would be much appreciated.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:11:13 PM, on 6/26/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: (no name) - {0dff2b8d-38b9-47ea-96de-6243d478d32b} - C:\WINDOWS\system32\jivazona.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [98c15e92] rundll32.exe "C:\WINDOWS\system32\bunuzeka.dll",b O4 - HKLM\..\Run: [CPM9bf26d0e] Rundll32.exe "c:\windows\system32\kuziyado.dll",a O4 - HKLM\..\Run: [lebahohoje] Rundll32.exe "C:\WINDOWS\system32\jitodujo.dll",s O4 - HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe O4 - HKUS\S-1-5-18\..\Run: [Cognac] C:\DOCUME~1\Owner\LOCALS~1\Temp\66.tmp.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Cognac] C:\DOCUME~1\Owner\LOCALS~1\Temp\66.tmp.exe (User 'Default user') O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.amaena.com (HKLM) O15 - Trusted Zone: *.drivecleaner.com (HKLM) O15 - Trusted Zone: *.errorprotector.com (HKLM) O15 - Trusted Zone: *.errorsafe.com (HKLM) O15 - Trusted Zone: *.imageservr.com (HKLM) O15 - Trusted Zone: *.imagesrvr.com (HKLM) O15 - Trusted Zone: *.systemdoctor.com (HKLM) O15 - Trusted Zone: *.winantispyware.com (HKLM) O15 - Trusted Zone: *.winantivirus.com (HKLM) O15 - Trusted Zone: *.winfixer.com (HKLM) O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://192.168.1.2/xplugLite.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: c:\windows\system32\kuziyado.dll,C:\WINDOWS\system32\dufizige.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O20 - Winlogon Notify: awtustSM - awtustSM.dll (file missing) O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll (file missing) O20 - Winlogon Notify: qoMghfEt - qoMghfEt.dll (file missing) O20 - Winlogon Notify: urqpmlj - urqpmlj.dll (file missing) O20 - Winlogon Notify: __c003A344 - C:\WINDOWS\system32\__c003A344.dat O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kuziyado.dll O22 - SharedTaskScheduler: awash - {e3623691-f85d-48d8-8e4d-abe79077f841} - C:\WINDOWS\system32\bcxjqr.dll (file missing) O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kuziyado.dll O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- End of file - 5303 bytes This post has been edited by protoweenie: Jun 26 2009, 04:13 PM |
|
|
|
protoweenie [Resolved] Baseline Jun 26 2009, 04:04 PM
Raktor Hi, welcome to the WTT Forums. My username is Rakt... Jun 26 2009, 04:35 PM
Raktor Hi protoweenie, welcome to the WTT Forums. My user... Jun 27 2009, 08:52 PM
protoweenie Raktor,
Thanks for the reply and the help.
... Jun 28 2009, 08:39 AM
Raktor No problem protoweenie.
A word of warning: Please... Jun 29 2009, 06:49 PM
protoweenie Raktor,
No worries about using my using Combo... Jun 30 2009, 05:17 PM
Raktor We're getting closer.
I have another CFScrip... Jun 30 2009, 07:33 PM
protoweenie Raktor,
Here's the latest.
ComboFix 09-07-... Jul 1 2009, 05:46 PM
Raktor Brilliant job protoweenie.
Just a few more steps... Jul 2 2009, 02:46 AM
protoweenie Hello Raktor,
At the risk of appearing dense, ... Jul 2 2009, 03:31 PM
Raktor Questions are fine.
Submit both of the zip files... Jul 2 2009, 07:08 PM
protoweenie Hello Raktor,
The system is, of course, muc... Jul 3 2009, 06:55 PM
Raktor Final CFScript to remove the final little bits, th... Jul 4 2009, 03:44 AM
protoweenie Raktor,
Final steps completed and issue resol... Jul 4 2009, 07:57 AM
ken545 Since this issue appears to be resolved ... this T... Jul 4 2009, 05:32 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
12 | miller2644 | 156 | Today, 12:05 PM Last post by: Tomk |
|||
![]() |
20 | Wakenaam | 374 | Yesterday, 09:54 AM Last post by: Tomk |
|||
![]() |
16 | mesa215 | 291 | Yesterday, 12:05 AM Last post by: Raktor |
|||
![]() |
23 | cherfxst | 402 | 19th November 2009 - 09:36 PM Last post by: oldman960 |
|||
|
Time is now: 21st November 2009 - 11:48 PM |