Results 1 to 5 of 5

Thread: hijack this

  1. #1
    Member
    Join Date
    Jan 2006
    Location
    Christchurch
    Posts
    180

    Default hijack this

    is there any thing i need to watch out for and how do i tell

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\BitLord\BitLord.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Windows\explorer.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis 1.99.1\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spikedhumor.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O17 - HKLM\System\CCS\Services\Tcpip\..\{96997BBF-3EE1-4915-9334-4692CF803F10}: NameServer = 203.96.152.4,203.96.152.12
    O17 - HKLM\System\CS1\Services\Tcpip\..\{96997BBF-3EE1-4915-9334-4692CF803F10}: NameServer = 203.96.152.4,203.96.152.12
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
    Windows 7 64 bit Ultimate
    AMD Phenom 2 X6 1055T @4GHZ
    2x 2GB G.Skill Ripjaw DDR3-1600
    ASUS M4A89GTD SATA 3 USB 3
    ATI ASUS Radion HD 5870 @ 900 1300
    G Skill Falcon 2 SSD 64GB
    2X ViewSonic 22"
    Saitek Eclipse 2
    Logitech MX Revolution.

  2. #2
    Junior Member
    Join Date
    Aug 2006
    Posts
    10

    Talking Re: hijack this


    From what I when i do a search is its a spyware removel tool
    http://search.msn.com/results.aspx?q...99.1&FORM=MSNH

    Of Course that might just be its front. It could in fact be just a reverse tool and actualy be spyware.

    If you think its spyware and it really starts lagging your PC down run a Anti-virus scan..... wait your running vista. I dont think there is any Anti-virus software for vista. The problem with beta. If you experince problems just go back to XP otherwise it doesnt really look like its anything to worry about.

    Cheers.
    Hassan

  3. #3
    Member
    Join Date
    Dec 2004
    Location
    NZ
    Posts
    44,851

    Default Re: hijack this

    Post your log here

    http://www.hijackthis.de/en#anl

    Anything saying unknown or nasty, do a search in google or yahoo.

    To see what it belongs to.

  4. #4
    Member
    Join Date
    Jan 2006
    Location
    Christchurch
    Posts
    180

    Default Re: hijack this

    thanks alot speedy you helped me out yesterday too you the man
    Windows 7 64 bit Ultimate
    AMD Phenom 2 X6 1055T @4GHZ
    2x 2GB G.Skill Ripjaw DDR3-1600
    ASUS M4A89GTD SATA 3 USB 3
    ATI ASUS Radion HD 5870 @ 900 1300
    G Skill Falcon 2 SSD 64GB
    2X ViewSonic 22"
    Saitek Eclipse 2
    Logitech MX Revolution.

  5. #5
    Junior Member
    Join Date
    Aug 2006
    Posts
    10

    Red face Re: hijack this

    LOL im such a noob I though you though It was a Virus lol

Similar Threads

  1. hijack this
    By password in forum PressF1
    Replies: 3
    Last Post: 08-04-2008, 05:03 PM
  2. Hijack this.
    By password in forum PressF1
    Replies: 2
    Last Post: 24-03-2008, 02:38 PM
  3. Hijack log
    By kjaada in forum PressF1
    Replies: 2
    Last Post: 31-08-2007, 10:56 AM
  4. Hijack.
    By Cicero in forum PressF1
    Replies: 39
    Last Post: 12-03-2007, 10:30 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •