BAZ PREBBLE's hijackthis log

  1. #1
    DJDK is offline Senior Member

    BAZ PREBBLE's hijackthis log

    Logfile of HijackThis v1.99.1
    Scan saved at 15:22:01, on 29/03/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
    D:\WINDOWS\system32\cisvc.exe
    D:\WINDOWS\system32\CTsvcCDA.EXE
    D:\WINDOWS\System32\snmp.exe
    D:\WINDOWS\System32\svchost.exe
    D:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
    D:\WINDOWS\System32\MsPMSPSv.exe
    D:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
    D:\Program Files\McAfee\McAfee Firewall\CPD.EXE
    D:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
    D:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
    D:\WINDOWS\Explorer.EXE
    D:\WINDOWS\system32\ntvdm.exe
    D:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
    D:\Program Files\McAfee\McAfee Firewall\CPD.EXE
    D:\Program Files\Creative\ShareDLL\CtNotify.exe
    D:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
    D:\Program Files\Creative\SBLive\RemoteCenter\Rc\RcMan.EXE
    D:\Program Files\Kodak\Picture Easy Software\Program\PezDownload.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Creative\ShareDLL\MediaDet.exe
    D:\OPLIMIT\ocrawr32.exe
    D:\Program Files\Creative\SBLive\RemoteCenter\Rc\EAX.exe
    D:\Program Files\Creative\SBLive\RemoteCenter\Rc\VRC.exe
    D:\Program Files\Creative\SBLive\RemoteCenter\Center\RCenter. exe
    D:\Program Files\Creative\SBLive\RemoteCenter\Rc\OSDMenu.EXE
    D:\WINDOWS\system32\wuauclt.exe
    D:\PROGRA~1\SPYWAR~1\swdoctor.exe
    D:\Program Files\Messenger\msmsgs.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Documents and Settings\BARRY\My Documents\INTER DOWN LOADS\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\about.htm
    F3 - REG:win.ini: load=d:\oplimit\ocraware.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {06A7C56B-52DB-644A-6811-764E042306FD} - D:\DOCUME~1\JAZ\APPLIC~1\32SOFT~1\blehace.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: ToolHelper - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - blank (file missing)
    O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - D:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
    O4 - HKLM\..\Run: [VirusScanMSC] "D:\Program Files\McAfee\McAfee VirusScan\VsStat.exe" /EMBEDDING
    O4 - HKLM\..\Run: [MCUpdateExe] D:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
    O4 - HKLM\..\Run: [Disc Detector] D:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "D:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [BoneDrive16Bird] D:\Documents and Settings\All Users\Application Data\Sixthheartbonedrive\Infobird.exe
    O4 - HKLM\..\RunOnce: [SpybotSnD] "D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKCU\..\Run: [RemoteCenter] D:\Program Files\Creative\SBLive\RemoteCenter\Rc\RcMan.EXE
    O4 - Global Startup: Kodak Picture Easy 3.1 Batch Transfer.lnk = D:\Program Files\Kodak\Picture Easy Software\Program\PezDownload.exe
    O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Intellisync Lite for NEC 616.lnk = ?
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .mpeg: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O12 - Plugin for .pdf: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O15 - Trusted Zone: http://www.ntlworld.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...4/mcinsctl.cab
    O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
    O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/sh...,2/mcmysec.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{610EC8D5-49B9-4637-A75F-72250E5545EB}: NameServer = 212.74.114.129 212.74.114.193
    O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - D:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: McAfee Firewall - Unknown owner - D:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
    O23 - Service: McShield - Unknown owner - D:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe


  2. #2
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\about.htm
    O2 - BHO: (no name) - {06A7C56B-52DB-644A-6811-764E042306FD} - D:\DOCUME~1\JAZ\APPLIC~1\32SOFT~1\blehace.exe
    O2 - BHO: ToolHelper - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - blank (file missing)
    O4 - HKLM\..\Run: [BoneDrive16Bird] D:\Documents and Settings\All Users\Application Data\Sixthheartbonedrive\Infobird.exe

    Click Fix Checked

    Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

    Delete the following files and folders:
    D:\DOCUME~1\JAZ\APPLIC~1\32SOFT~1
    D:\Documents and Settings\All Users\Application Data\Sixthheartbonedrive

    Reboot and post a fresh log

+ Reply to Thread