Computing.Net > Forums > Security and Virus > Help with Hijackthis log

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Help with Hijackthis log

Reply to Message Icon

Name: Snatch
Date: April 10, 2006 at 03:57:20 Pacific
OS: Windows XP Pro
CPU/Ram: Athlon XP 1700/1GB
Product: Gigabyte
Comment:

Hi, when using Spy Sweeper I keep getting the winlogonhook and Zlob coming up in the scan, I select delete but every other scan is coming up with the exact same thing. Also I'm getting PurityScan and Security 2k Hijacker, everytime I scan and delete these they seem to come back at another scan time. I also had a warning come up on a popup window telling me this ....Attention! Your system is under control of remote computer with IP address 227.4.167.118. The remote computer has access to the following folders on your PC:
- \WINDOWS\System32
- \Program Files\Internet Explorer
- \My Documents
- Drive C:\ files
Click here to download official anti-spyware software

Your private info is collected by W32.Sinnaka.A@mm

Your Country: AU, Australia

They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)

Operation System: OS Windows

Risk status for futher investigation: VERY HIGH RISK

Time of investigation: Sun Apr 9 5:52:00 PDT 2006



Malware Wipe
• Over 40,000 threats in the database
• Exclusive algorythm of cleaning
• IE Safe Mode - simply cleans your browser!
• Manual / automatic update system
• Autostart items / IE Objects / Running Processes manager
• Dialer blocker, Popup blocker

• Visit Website • Free Download Pest Trap
• Daily updated threat databases
• Intelligent threat scanner
• Application advanced firewall
• IE security improvements
• Advanced system securty features
• Multiple scan options (fast / normal / deep)

• Visit Website • Free Download


I'm not real sure what is going on but am pretty sure something isn't right. Thanks to anyone who can help in regards to this. :)



Sponsored Link
Ads by Google

Response Number 1
Name: bofra
Date: April 11, 2006 at 11:09:34 Pacific
Reply:

try turning of system restore,
restart in safe mode,
scan for spyware and viruses again,

info:http://www.symantec.com/avcenter/venc/data/trojan.zlob.html

may need to edit registry with regedit,


0

Response Number 2
Name: jabuck
Date: April 11, 2006 at 14:59:15 Pacific
Reply:

Please run this free online scan from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html
Click Accept
When the updates are finished downloading, click Next, Scan Settings
Under Scan using the following antivirus database:, select extended
Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK
Click My Computer and wait for the scan to finish
Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.

Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


0

Response Number 3
Name: Snatch
Date: April 12, 2006 at 07:18:18 Pacific
Reply:

Ok, I have just done the online scan and hijackthis and here are ther results ... Thanks for your help.

Kaspersky Scan.

---------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, April 12, 2006 9:58:39 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 12/04/2006
Kaspersky Anti-Virus database records: 187762
---------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 69622
Number of viruses found: 7
Number of infected objects: 36
Number of suspicious objects: 0
Duration of the scan process: 01:14:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\shelley\Local Settings\Temp\A~NSISu_.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\Documents and Settings\shelley\Local Settings\Temp\A~NSISu_.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0033623.exe Infected: Trojan-Downloader.Win32.PurityScan.bt skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0036950.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0036950.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0037033.exe Infected: not-a-virus:AdWare.Win32.MediaTickets.u skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0048292.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0048292.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{03D1D36E-BB71-4814-90F1-B5136BF5DF50}\RP145\A0050826.exe Infected: not-a-virus:AdWare.Win32.MediaTickets.u skipped
C:\WINDOWS\mtuninst.exe Infected: not-a-virus:AdWare.Win32.MediaTickets.u skipped
C:\WINDOWS\system32\ѕecurity\wυauclt.exe Infected: not-a-virus:AdWare.Win32.PurityScan.eg skipped
F:\Appz\Chat Watch 4.3.2.zip/Chat Watch 4.3.2/cw_setup.exe/data0017 Infected: not-a-virus:Monitor.Win32.ChatWatch.422 skipped
F:\Appz\Chat Watch 4.3.2.zip/Chat Watch 4.3.2/cw_setup.exe Infected: not-a-virus:Monitor.Win32.ChatWatch.422 skipped
F:\Appz\Chat Watch 4.3.2.zip ZIP: infected - 2 skipped
F:\Appz\FLASHGET_1.5.zip/FLASHGET_1.5/FGF150.EXE/WISE0018.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
F:\Appz\FLASHGET_1.5.zip/FLASHGET_1.5/FGF150.EXE/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
F:\Appz\FLASHGET_1.5.zip/FLASHGET_1.5/FGF150.EXE Infected: not-a-virus:AdWare.Win32.Cydoor skipped
F:\Appz\FLASHGET_1.5.zip ZIP: infected - 3 skipped
F:\Appz\Sysapp\freekgbkeylogger-193.exe/ci-temp0.cab/winlogon.dll Infected: not-a-virus:Monitor.Win32.KGBSpy.34 skipped
F:\Appz\Sysapp\freekgbkeylogger-193.exe/ci-temp0.cab Infected: not-a-virus:Monitor.Win32.KGBSpy.34 skipped
F:\Appz\Sysapp\freekgbkeylogger-193.exe CreateInstall: infected - 2 skipped
F:\Appz\Sysapp\kgbkeylogger-293.exe/ci-temp0.cab/winlogon.dll Infected: not-a-virus:Monitor.Win32.KGBSpy.34 skipped
F:\Appz\Sysapp\kgbkeylogger-293.exe/ci-temp0.cab Infected: not-a-virus:Monitor.Win32.KGBSpy.34 skipped
F:\Appz\Sysapp\kgbkeylogger-293.exe CreateInstall: infected - 2 skipped
F:\Appz\Xoftspy\XoftSpy421_139\XoftSpy421_139.exe/data0013 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
F:\Appz\Xoftspy\XoftSpy421_139\XoftSpy421_139.exe NSIS: infected - 1 skipped
F:\Appz\XoftSpy421_139.zip/XoftSpy421_139/XoftSpy421_139.exe/data0013 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
F:\Appz\XoftSpy421_139.zip/XoftSpy421_139/XoftSpy421_139.exe Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
F:\Appz\XoftSpy421_139.zip ZIP: infected - 2 skipped
F:\Appz\XoftSpy421_167.exe/data0013 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
F:\Appz\XoftSpy421_167.exe NSIS: infected - 1 skipped
F:\Appz\XoftspySetup_lb.exe/data0058 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
F:\Appz\XoftspySetup_lb.exe NSIS: infected - 1 skipped
F:\Uzipped-APPZ\FLASHGET_1.5\FGF150.EXE/WISE0018.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
F:\Uzipped-APPZ\FLASHGET_1.5\FGF150.EXE/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
F:\Uzipped-APPZ\FLASHGET_1.5\FGF150.exe WiseSFX: infected - 2 skipped

Scan process completed.

Hijackthis Log.

Logfile of HijackThis v1.99.1
Scan saved at 10:04:38 PM, on 4/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Wireless Device\Wireless Keyboard\osd.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\NOTEPAD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.exe

O2 - BHO: Nothing - {7a932ed2-1737-4ab8-b84d-c71779958551} - C:\WINDOWS\system32\hp4743.tmp
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bigpond.com/
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139311882204
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wa.bigpond.net.au
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


0

Response Number 4
Name: jabuck
Date: April 13, 2006 at 15:34:32 Pacific
Reply:

You have an older version of a spyware named SmitRem, alias SpyStrike or Spyware Quake.

Go to the following link Spyware Quake Removal go through the removal instructions.

Post a new HT log.


0

Response Number 5
Name: Snatch
Date: April 20, 2006 at 01:40:34 Pacific
Reply:


Logfile of HijackThis v1.99.1
Scan saved at 4:38:17 PM, on 4/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
C:\Program Files\Wireless Device\Wireless Keyboard\osd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.exe

O2 - BHO: Nothing - {7a932ed2-1737-4ab8-b84d-c71779958551} - C:\WINDOWS\system32\hpC865.tmp (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = C:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bigpond.com/
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139311882204
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = wa.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wa.bigpond.net.au
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



0

Related Posts

See More



Response Number 6
Name: jabuck
Date: April 21, 2006 at 18:54:33 Pacific
Reply:

Run Ht again, close all windows and browsers except HT, place a check to the left of the following item and press "fix checked":

O2 - BHO: Nothing - {7a932ed2-1737-4ab8-b84d-c71779958551} - C:\WINDOWS\system32\hpC865.tmp (file missing)

Your log will be clean after removing that entry. Are you running better?


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Help with Hijackthis log

Help with Hijackthis log www.computing.net/answers/security/help-with-hijackthis-log/18159.html

help with hijackthis log www.computing.net/answers/security/help-with-hijackthis-log/8588.html

Help with HijackThis log www.computing.net/answers/security/help-with-hijackthis-log/7984.html