darold Posted September 30, 2009 ID:135555 Share Posted September 30, 2009 Can somebody that knows how to read my HiJackThis Log file please give me a hand reading this. It would be much appreciated. Thanks Sorry I couldnt upload for some reason so I'll paste it hereLogfile of Trend Micro HijackThis v2.0.2Scan saved at 8:17:01 PM, on 9/29/2009Platform: Windows Vista SP2 (WinNT 6.00.1906)MSIE: Internet Explorer v7.00 (7.00.6002.18005)Boot mode: NormalRunning processes:C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeC:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exeC:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Windows\system32\igfxsrvc.exeC:\Windows\System32\rundll32.exeC:\Windows\system32\wbem\unsecapp.exeC:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exeC:\Program Files\Yahoo!\Search Protection\SearchProtection.exeC:\Program Files\Microsoft IntelliType Pro\itype.exeC:\Program Files\Microsoft IntelliPoint\ipoint.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exeC:\Windows\ehome\ehtray.exeC:\Program Files\Creative\MediaSource5\MtdAcqu.exeC:\Windows\ehome\ehmsas.exeC:\Acer\Empowering Technology\eRecovery\ERAGENT.EXEC:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exeC:\Program Files\Internet Explorer\IEUser.exeC:\Windows\system32\SearchFilterHost.exeC:\Windows\System32\osk.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO1 - Hosts: ::1 localhostO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO1 - Hosts: 200.124.131.116 casinocontroller.comO2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dllO2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLLO2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dllO2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dllO3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dllO3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimizedO4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exeO4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exeO4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntryO4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hideO4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resumeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /rO4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXEO4 - HKCU\..\Run: [?????????] ??????????????eO4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe -remO4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKCU\..\Run: [search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exeO4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /sO4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKCU\..\RunOnce: [shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~4.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SU 3.23; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729)" -"http://www.candystand.com/play/ten-pin-bowling"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [] OSK.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [] OSK.exe (User 'Default user')O4 - Startup: FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exeO4 - Global Startup: Empowering Technology Launcher.lnk = ?O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimageO9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dllO9 - Extra button: Platinum Play Online Casino - 0604C341-F858-4CDE-85D5-BC50CFD64DAC - C:\Microgaming\Casino\PlatinumPlay\Casinogame.exe (HKCU)O9 - Extra button: Platinum Play Online Casino - D80BC768-A5CD-403C-8F6C-C16A94A474A3 - C:\Microgaming\Casino\PlatinumPlay\Casinogame.exe (HKCU)O9 - Extra button: Aspinalls Online Poker - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\aspinallsMPP\MPPoker.exe (file missing) (HKCU)O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\D's Nutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\D's Nutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://3dlifeplayer.dl.3dvia.com/player/in...r_installer.exeO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cabO18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dllO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Update Service (gupdate1ca0e2b468aa5af) (gupdate1ca0e2b468aa5af) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exeO23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeO23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeO23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exeO23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exeO23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exeO23 - Service: StumbleUponUpdateService - stumbleupon.com - C:\Program Files\StumbleUpon\StumbleUponUpdateService.exeO23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe--End of file - 13740 bytes Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted October 8, 2009 Root Admin ID:139637 Share Posted October 8, 2009 I'm sorry for the long delay but the site has been swamped with more requests for help than we can handle in a short period of time.If you still need help please let me know, otherwise I'll go ahead and close your post as you've probably moved on by now. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted October 9, 2009 Root Admin ID:140604 Share Posted October 9, 2009 Okay, well since it looks like you have moved on I'll go ahead and close this post now.Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you. Link to post Share on other sites More sharing options...
Recommended Posts