Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Jul 24 2008, 09:30 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 1 Joined: 24-July 08 Member No.: 80,480 Operating System: windows xp |
I CAN KILL THE PROCESS USING TASK MANAGER BUT IT RELOADS HERE IS THE HIJACKTHIS LOG Logfile of HijackThis v1.99.1 Scan saved at 6:13:38 PM, on 7/24/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Running processes: E:\WINNT\System32\smss.exe E:\WINNT\system32\winlogon.exe E:\WINNT\system32\services.exe E:\WINNT\system32\lsass.exe E:\WINNT\system32\Ati2evxx.exe E:\WINNT\system32\svchost.exe E:\WINNT\System32\svchost.exe E:\WINNT\system32\spoolsv.exe E:\WINNT\system32\HDDSvc.exe E:\Program Files\CA\eTrust Antivirus\InoRpc.exe E:\Program Files\CA\eTrust Antivirus\InoRT.exe E:\Program Files\CA\eTrust Antivirus\InoTask.exe E:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe E:\WINNT\System32\svchost.exe E:\WINNT\system32\Ati2evxx.exe E:\WINNT\Explorer.EXE E:\PROGRA~1\CA\ETRUST~1\realmon.exe G:\Advanced WindowsCare V2\MemCleaner.exe E:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\WINNT\system32\ctfmon.exe E:\WINNT\system32\taskmgr.exe g:\Hijackthis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Adobe\ActiveX\AcroIEHelper.dll (file missing) O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - E:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [Realtime Monitor] E:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [SmartRAM] G:\Advanced WindowsCare V2\MemCleaner.exe /m O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] E:\WINNT\system32\ctfmon.exe O4 - HKCU\..\Run: [Acrobat Assistant 7.0] G:\Adobe\Distillr\Acrotray.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - E:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mrrcomputers.local O17 - HKLM\Software\..\Telephony: DomainName = mrrcomputers.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mrrcomputers.local O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: WgaLogon - E:\WINNT\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINNT\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - E:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - Unknown owner - E:\WINNT\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - E:\WINNT\system32\ati2sgag.exe O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - E:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - E:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - E:\WINNT\system32\HDDSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - E:\Program Files\CA\eTrust Antivirus\InoTask.exe O23 - Service: Event Log Watch (LogWatch) - Computer Associates - E:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe SUGGESTIONS? MEIR R. |
|
|
|
Aug 1 2008, 02:40 PM
Post
#2
|
|
![]() Forum God Group: Root Admin Posts: 43,067 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
![]() Sorry about the delay in responding If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment. |
|
|
|
Aug 6 2008, 06:40 PM
Post
#3
|
|
![]() Forum God Group: Root Admin Posts: 43,067 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
13 | brunette9910 | 93 | Yesterday, 11:06 PM Last post by: Tomk |
|||
![]() |
20 | lucella31 | 223 | Yesterday, 08:48 PM Last post by: ktreffin |
|||
![]() |
40 | RussF92767 | 277 | Yesterday, 08:20 PM Last post by: LDTate |
|||
![]() |
22 | rhalexda | 172 | Yesterday, 07:34 PM Last post by: LDTate |
|||
![]() |
40 | Keej3 | 424 | Yesterday, 06:53 PM Last post by: mschroe919 |
|||
|
Time is now: 7th October 2008 - 05:58 AM |