Please kindly check my HJT log.

Discussion in 'adware, spyware & hijack cleaning' started by HiSpeed, Jan 8, 2004.

Thread Status:
Not open for further replies.
  1. HiSpeed

    HiSpeed Guest

    Hi, everyone at WildersSecurity.

    I am a new member. If possible, please kindly have a look at my log to see if it is clean. Thankyou in advance.

    Logfile of HijackThis v1.97.7
    Scan saved at 01:12:26, on 01/08/04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    I:\WINDOWS\SYSTEM\KERNEL32.DLL
    I:\WINDOWS\SYSTEM\MSGSRV32.EXE
    I:\WINDOWS\SYSTEM\MPREXE.EXE
    I:\WINDOWS\SYSTEM\mmtask.tsk
    I:\NAVY SEALS\AVG ANTI-VIRUS\AVGSERV9.EXE
    I:\NAVY SEALS\SYGATE PERSONAL FIREWALL PRO\SMC.EXE
    I:\NAVY SEALS\AVAST 4\ASHSERV.EXE
    I:\WINDOWS\EXPLORER.EXE
    I:\WINDOWS\TASKMON.EXE
    I:\WINDOWS\SYSTEM\SYSTRAY.EXE
    I:\NAVY SEALS\STEPUP MENU\TRAYICON.EXE
    I:\NAVY SEALS\AVG ANTI-VIRUS\AVGCC32.EXE
    I:\WINDOWS\SYSTEM\RPCSS.EXE
    I:\WINDOWS\SYSTEM\WMIEXE.EXE
    I:\NAVY SEALS\AVAST 4\ASHMAISV.EXE
    I:\WINDOWS\SYSTEM\SPOOL32.EXE
    I:\NAVY SEALS\MS OFFICE 97\OFFICE\MSOFFICE.EXE
    I:\NAVY SEALS\MS OFFICE 97\OFFICE\OSA.EXE
    I:\NAVY SEALS\SPYWAREGUARD\SGMAIN.EXE
    I:\NAVY SEALS\WALLMASTER PRO\WALLMAST.EXE
    I:\NAVY SEALS\SPYWAREGUARD\SGBHP.EXE
    I:\WINDOWS\SYSTEM\INTERNAT.EXE
    I:\WINDOWS\SYSTEM\DDHELP.EXE
    I:\NAVY SEALS\TAUSCAN\TAUMON.EXE
    I:\WINDOWS\NETDDE.EXE
    I:\NAVY SEALS\MPOWER\MPOWER.EXE
    I:\NAVY SEALS\SONIQUE\SONIQUE.EXE
    I:\NAVY SEALS\MOZILLA FIREBIRD\MOZILLAFIREBIRD.EXE
    C:\UTILITIES\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hispeed.rogers.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Electronics Engineering
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cache:8080
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://windows.microsoft.com/isapi/redir.dll?prd=windowsupdate&clcid=&pver=&ar=WindowsUpdate
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - I:\NAVY SEALS\SPYWAREGUARD\DLPROTECT.DLL
    O2 - BHO: (no name) - {41353F8B-78CE-48A5-BE44-153ED293D192} - I:\NAVYSEAL\POPUPPOP\POPLIB.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\NAVYSEAL\SPYBOTS&\SDHELPER.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\NAVY SEALS\ACROBAT READER\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - I:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] I:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] I:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [StepUp Taskbar Icon Handler] "I:\Navy Seals\StepUp Menu\TrayIcon.exe" /S
    O4 - HKLM\..\Run: [AVG_CC] i:\NAVYSEAL\AVGANTI-\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [Tau Monitor] I:\NAVY SEALS\TAUSCAN\TAUMON.EXE
    O4 - HKLM\..\Run: [SmcService] I:\NAVYSEAL\SYGATEPE\SMC.EXE -startgui
    O4 - HKLM\..\Run: [ScriptSentry] I:\NAVY SEALS\SCRIPT SENTRY\SCRIPTSENTRY.exe /check
    O4 - HKLM\..\Run: [ashMaiSv] I:\NAVYSEAL\AVAST4\ashmaisv.exe
    O4 - HKLM\..\Run: [EPSON Stylus C44 Series] I:\WINDOWS\SYSTEM\E_S09IC1.EXE /P23 "EPSON Stylus C44 Series" /O5 "LPT1:" /M "Stylus C44"
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [Avgserv9.exe] i:\NAVYSEAL\AVGANTI-\Avgserv9.exe
    O4 - HKLM\..\RunServices: [SmcService] I:\NAVY SEALS\SYGATE PERSONAL FIREWALL PRO\SMC.EXE
    O4 - HKLM\..\RunServices: [avast!] I:\Navy Seals\avast 4\ashServ.exe
    O4 - HKCU\..\Run: [FUIClearHis] I:\NAVY SEALS\FRESHUI\FRESHUI.EXE 0 1 2 3 4 6 7 8 9 10 11 12 13 14 15 16 17
    O4 - HKLM\..\RunOnce: [MRUBlaster] I:\NAVY SEALS\MRU-BLASTER\indexcleaner.exe -CC
    O4 - Startup: Microsoft Office Shortcut Bar.lnk = I:\Navy Seals\MS Office 97\Office\MSOFFICE.EXE
    O4 - Startup: Office Startup.lnk = I:\Navy Seals\MS Office 97\Office\OSA.EXE
    O4 - Startup: SpywareGuard.lnk = I:\Navy Seals\SpywareGuard\sgmain.exe
    O4 - Startup: WallMaster Pro.lnk = I:\Navy Seals\WallMaster Pro\wallmast.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: PopupPopper Control Panel (HKLM)
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O12 - Plugin for .spop: I:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37982.0460763889
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

    Best regards,

    HiSpeedV.
     
  2. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Hi HiSpeed,

    Welcome aboard :)

    That log looks very clean to me, it should be with a well protected system like that ;)

    Please confirm that you have put the following restrictions / controlled options yourself as an administrator :

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Are you having any issues?

    Thanks!

    Cheers,
     
  3. HiSpeed

    HiSpeed Guest

    Hi, Unzy.

    Thankyou for taking the time to look over my log. I put those restrictions there to prevent my friends from messing up my windows settings.

    Best regards,

    HiSpeedV.
     
  4. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Hi again,

    A smart decision indeed :)

    looks like you got things under control and that you know what you are doing

    Take care


    Cheers,
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.