IPB

Welcome Guest ( Log In | Register )

2 Pages V   1 2 >  
Closed TopicStart new topic
> Hjt Log
therock247uk
post Nov 20 2006, 09:04 PM
Post #1


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




Logfile of HijackThis v1.99.1
Scan saved at 09:03:30 tongue.gifM, on 20/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Gaim\gaim.exe
C:\Program Files\KeyNote\keynote.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\PC\Desktop\installers\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: dlexpertclick Class - {A6927151-F5B4-11D4-AE7A-00D00925CF52} - C:\PROGRA~1\DLExpert\dll\iehelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by DLExpert (Faster) - C:\Program Files\DLExpert\get.htm
O8 - Extra context menu item: Download &All by DLExpert (Faster) - C:\Program Files\DLExpert\getall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1124997701498
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{197ADB47-F488-41FD-8AF8-1B63BBF28C1D}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{197ADB47-F488-41FD-8AF8-1B63BBF28C1D}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{197ADB47-F488-41FD-8AF8-1B63BBF28C1D}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache 2.0\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
Go to the top of the page
 
+Quote Post
andydf
post Nov 20 2006, 09:06 PM
Post #2


Newbie Member
Group Icon

Group: Visiting Staff
Posts: 7
Joined: 19-December 05
Member No.: 234



Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
    C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    C:\WINDOWS\system32\vmnat.exe
    C:\WINDOWS\system32\vmnetdhcp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\mIRC\mirc.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Gaim\gaim.exe
    C:\Program Files\KeyNote\keynote.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\PC\Desktop\installers\HijackThis.exe



  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

tongue.gif
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:07 PM
Post #3


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




PC no longer boot can you tell me why?! mad.gif laugh.gif blink.gif
Go to the top of the page
 
+Quote Post
andydf
post Nov 20 2006, 09:11 PM
Post #4


Newbie Member
Group Icon

Group: Visiting Staff
Posts: 7
Joined: 19-December 05
Member No.: 234



Nope, not a clue huh.gif

There's a great program called WinantivirusPro you could try or......

You should trace a user called Rambro, i'm sure he'll help you tongue.gif
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:17 PM
Post #5


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




/me cant even boot to try WinantivirusPro

HELP ME!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

ph34r.gif laugh.gif
Go to the top of the page
 
+Quote Post
andydf
post Nov 20 2006, 09:28 PM
Post #6


Newbie Member
Group Icon

Group: Visiting Staff
Posts: 7
Joined: 19-December 05
Member No.: 234



Ok get hold of the biggest hammer you can find.

Then hit the bloody thing as hard as you can several times. Reboot and see what happens ph34r.gif

If it still don't start bin it tongue.gif
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:31 PM
Post #7


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




Ok I hit a thing called the mobo with the hammer now it wont even turn on!!! mad.gif

HELP ME!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!???!?!!?

sad.gif
Go to the top of the page
 
+Quote Post
andydf
post Nov 20 2006, 09:41 PM
Post #8


Newbie Member
Group Icon

Group: Visiting Staff
Posts: 7
Joined: 19-December 05
Member No.: 234



I cannot help you any further, you have totally FUBARed your PC

I cannot be held responsible if you don't follow advise,.

I didn't tell you to hit the mobo just a few taps on the side was all that was needed.

Phone Emachines and buy a new one or try our new phone support

IPB Image

Dial 999
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:43 PM
Post #9


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




laugh.gif
Go to the top of the page
 
+Quote Post
sari
post Nov 20 2006, 09:47 PM
Post #10


Domestic Goddess/Anti spam admin
Group Icon

Group: Administrator
Posts: 178
Joined: 17-August 04
Member No.: 2



I'm new here, but I think you can download a new motherboard from www.motherboardsrus.com - download and install that, then pour Pepsi on it and see if it works.
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:48 PM
Post #11


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




Ok did that then I smelled something burning then something blew up is that how its supposed to work? huh.gif
Go to the top of the page
 
+Quote Post
sari
post Nov 20 2006, 09:50 PM
Post #12


Domestic Goddess/Anti spam admin
Group Icon

Group: Administrator
Posts: 178
Joined: 17-August 04
Member No.: 2



That was just all the crud burning out of your PC - your data can get backed up in there and make things slower.
Go to the top of the page
 
+Quote Post
therock247uk
post Nov 20 2006, 09:52 PM
Post #13


Owner/Site Administrator
Group Icon

Group: Administrator
Posts: 3,093
Joined: 17-August 04
From: Newark, Nottingham, UK
Member No.: 1




But I poured pepsi on my hard drive to will it still work? sad.gif

/me don't want all his nice pictures destoyed. sad.gif sad.gif sad.gif
Go to the top of the page
 
+Quote Post
sari
post Nov 20 2006, 09:54 PM
Post #14


Domestic Goddess/Anti spam admin
Group Icon

Group: Administrator
Posts: 178
Joined: 17-August 04
Member No.: 2



Pepsi will only destroy porn files. If you don't have any port, you data should be ok.
Go to the top of the page
 
+Quote Post
andydf
post Nov 20 2006, 09:54 PM
Post #15


Newbie Member
Group Icon

Group: Visiting Staff
Posts: 7
Joined: 19-December 05
Member No.: 234



don't worry about your pics, porn and pepsi go well together
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:



 



Add to Google Subscribe in Bloglines Lo-Fi Version Time is now: 20th November 2008 - 12:22 PM