PDA

View Full Version : highjackthis


mdlsFREAK
04-28-2005, 10:26 PM
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\conor watson\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1079917728718

jenkins
04-28-2005, 10:31 PM
Thank you for posting your HijackThis log. What do you want?

odoe
04-28-2005, 10:54 PM
If you could clarify your problem so I know if I should leave your thread here or launch you over to GS.

mdlsFREAK
04-28-2005, 10:54 PM
any suspicious tasks?

edit- my bad for not being more specific

odoe
04-28-2005, 11:02 PM
That's cool.
It doesn't look like it. I don't know what this line is
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

But everything else looks ok. You have a creative card right? Are you experiencing symptoms that would make you think something is fishy?

mdlsFREAK
04-28-2005, 11:28 PM
internet crashes every 20 minutes

jenkins
04-29-2005, 12:04 AM
I'm not sure what that BHO is. You could try killing it, and see what happens. If your machine catches on fire, I didn't do it. (Hijack has a backup feature.)

Also, try running LSP fix and see if anything fishy shows up their. For more info on Network stuff, try posting in that forum.

mdlsFREAK
04-29-2005, 12:49 AM
ahahhhhh! so thats where those pop ups were comin from! ...BHO is broser host somthing the info of it said it gives limmitless access to you system to highjackers ...one of the examples was pop ups..haha fixed that problem ..i hope

That_Sound_Guy
04-29-2005, 01:19 AM
ahahhhhh! so thats where those pop ups were comin from! ...BHO is broser host somthing the info of it said it gives limmitless access to you system to highjackers ...one of the examples was pop ups..haha fixed that problem ..i hope

Browser Helper Object, and yes some of them can be very bad and hard as hell to kill.

DustMite
04-29-2005, 01:46 AM
Do you know there is an online analyzer for hijackthis? You copy your log file and paste it into the white box on the web page and click the button that says analyze. It will then open a new page with the results. It's easier than posting and waiting for a response. It's actually pretty helpful and is easier than trying to explain what everything is.

Link to page: http://hijackthis.de/index.php?langselect=english

Try it.. you might like it. :D

...just my $0.02... :cool:

Phoenix86
04-29-2005, 11:00 AM
Here's another analyzer.

http://hjt.iamnotageek.com

Check for suspicious services, HJT should start analyzing those as well... Also visit the spyware sticky here. Good luck.

http://www.mentallyretired.com/h3/index.cfm/u_45754 (http://www.mentallyretired.com/h3/index.cfm?a=doMyStats&u_id=45754)

mdlsFREAK
04-29-2005, 06:42 PM
awesome thanx

mdlsFREAK
04-29-2005, 06:48 PM
hmmm..these bho's are a bit hard to dispose of ..any tips?

Phoenix86
04-29-2005, 06:53 PM
Safe-mode, safe-mode, safe-mode.

Run HJT, Ad-aware and MS Antispy (full scans, not the intelligent ones). Remove all baddies. Run again until no baddies show. Reboot. Rinse and repeate until nothing shows up on the first scan of the reboot for all three. This process has removed almost every spyware I have encountered.

Scans in safe mode are slow. Good luck.

http://www.mentallyretired.com/h3/index.cfm/u_45754 (http://www.mentallyretired.com/h3/index.cfm?a=doMyStats&u_id=45754)

mdlsFREAK
04-29-2005, 07:23 PM
no water needed! :D

Phoenix86
05-02-2005, 10:01 AM
Get it removed?

http://www.mentallyretired.com/h3/index.cfm/u_45754 (http://www.mentallyretired.com/h3/index.cfm?a=doMyStats&u_id=45754)

mdlsFREAK
05-03-2005, 06:53 PM
yup...and i just got bitdefender 8 so i shouldnt be seeing any problems....lets hope

serbiaNem
05-03-2005, 10:08 PM
My solution to spyware/adware is to not get it in the first place. Research the software you are installing to make sure it is clean. Do not download any suspicious active-x controls and use firefox if you can. Also make sure to update your computer and run a firewall. I ran spybot snd, adaware, ms antispyware and they all come up clean. Having an antivirus is also a good idea.