puckett
Topic Starter
Logfile of HijackThis v1.99.1
Scan saved at 3:03:54 PM, on 8/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\hijakthis\HijackThis.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
—-ADS LOG ——
C:\WINDOWS\HKCLFNK.ini : ymmxm (11591 bytes)
C:\WINDOWS\IEPatchUninstall.log : uqlgc (3063 bytes)
C:\WINDOWS\iis6.log : mqwmw (56832 bytes)
C:\WINDOWS\IsUninst.exe : boivc (11591 bytes)
C:\WINDOWS\IsUninst.exe : frorq (0 bytes)
C:\WINDOWS\KB822603.log : mpaae (56832 bytes)
C:\WINDOWS\KB826939.log : qfapw (93184 bytes)
C:\WINDOWS\KB835221.log : annbd (100127 bytes)
C:\WINDOWS\KB835732.log : tglit (93184 bytes)
C:\WINDOWS\KB840374.log : indnv (18944 bytes)
C:\WINDOWS\msgsocm.log : oyvvo (11591 bytes)
C:\WINDOWS\nsreg.dat : zrhgk (56832 bytes)
C:\WINDOWS\n_gevqml.txt : jorpp (100127 bytes)
C:\WINDOWS\n_ixegpo.txt : bpjck (11801 bytes)
C:\WINDOWS\ocgen.log : bssrf (100127 bytes)
C:\WINDOWS\Prairie Wind.bmp : tbrpk (26624 bytes)
C:\WINDOWS\Q329909.log : kmqpi (93184 bytes)
C:\WINDOWS\Q811114.log : nffsni (13581 bytes)
C:\WINDOWS\Q811114.log : sdnbc (10240 bytes)
C:\WINDOWS\QFE.log : naecq (100127 bytes)
C:\WINDOWS\regedit.exe : ggyxpk (11151 bytes)
C:\WINDOWS\Rhododendron.bmp : yhqcju (3567 bytes)
C:\WINDOWS\Santa Fe Stucco.bmp : fkkkj (12143 bytes)
C:\WINDOWS\Santa Fe Stucco.bmp : nfizt (11591 bytes)
C:\WINDOWS\Santa Fe Stucco.bmp : qchvm (30127 bytes)
C:\WINDOWS\setupact.log : gybev (11591 bytes)
C:\WINDOWS\setupact.log : lrpdj (93184 bytes)
C:\WINDOWS\setupapi.log.0.old : lvane (10240 bytes)
C:\WINDOWS\setuplog.txt : ilvbhx (11801 bytes)
C:\WINDOWS\setuplog.txt : yzusp (11591 bytes)
C:\WINDOWS\setuplog.txt : zvdtj (93184 bytes)
C:\WINDOWS\smscfg.ini : wcuzo (100127 bytes)
C:\WINDOWS\UNNeroBurnRights.cfg : jwhud (11591 bytes)
C:\WINDOWS\vb.ini : bxrhf (11591 bytes)
C:\WINDOWS\vb.ini : hhtwg (93184 bytes)
C:\WINDOWS\vbaddin.ini : zltod (30127 bytes)
C:\WINDOWS\wanmpsvc.exe : kfseb (10240 bytes)
C:\WINDOWS\wanmpsvc.exe : uykmz (3063 bytes)
C:\WINDOWS\Windows Update.log : dgdje (18944 bytes)
C:\WINDOWS\winhelp.exe : jasfv (10240 bytes)
C:\WINDOWS\winnt.bmp : ciaxo (100127 bytes)
C:\WINDOWS\winnt256.bmp : eqhnh (93184 bytes)
C:\WINDOWS\wmsetup.log : wagav (100127 bytes)
C:\WINDOWS\wsdu.log : pbqfq (11801 bytes)
C:\WINDOWS\zHotkey.exe : mqjwt (11591 bytes)
C:\WINDOWS\_default.pif : azowv (100127 bytes)
Just concerned about a hidden hijacker…