Results 1 to 3 of 3

Thread: alcohol120's hijackthis log

  1. #1
    Junior Member
    Join Date
    Oct 2007
    Posts
    5

    Default alcohol120's hijackthis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:48, on 2007-10-14
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS1\System32\smss.exe
    C:\WINDOWS1\system32\winlogon.exe
    C:\WINDOWS1\system32\services.exe
    C:\WINDOWS1\system32\lsass.exe
    C:\WINDOWS1\system32\svchost.exe
    C:\WINDOWS1\System32\svchost.exe
    C:\WINDOWS1\system32\spoolsv.exe
    C:\WINDOWS1\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
    C:\WINDOWS1\Mixer.exe
    C:\WINDOWS1\system32\RUNDLL32.EXE
    C:\WINDOWS1\avp.exe
    C:\WINDOWS1\mgrs.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Fraps\FRAPS.EXE
    C:\WINDOWS1\system32\ctfmon.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS1\system32\nvsvc32.exe
    C:\WINDOWS1\system32\spupdsvc.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
    C:\WINDOWS1\system32\cmd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS1\system32\cmd.exe
    C:\WINDOWS1\system32\cmd.exe
    C:\ComboFix\vfind.cfexe
    C:\WINDOWS1\TEMP\win1D.tmp.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ngohq.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O3 - Toolbar: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS1\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS1\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [avp] C:\WINDOWS1\TEMP\win1D.tmp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [smgr] mgrs.exe
    O4 - HKLM\..\RunServices: [Microsoft] window.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [Fraps] C:\Fraps\FRAPS.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS1\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O21 - SSODL: DrvInfo - {C888CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS1\Media\mmdrv.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS1\Sm9yZGFuIFR1Y2tlcg\command.exe (file missing)
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS1\system32\nvsvc32.exe
    O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

    --
    End of file - 7242 bytes

    please help fast.

  2. #2
    Junior Member
    Join Date
    Oct 2007
    Posts
    5

    Default

    my combofix log..

    ComboFix 07-10-12.4 - me 2007-10-14 16:40:39.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.737 [GMT -4:00]
    Running from: C:\Documents and Settings\me\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\check_LSA7.txt
    C:\d.exe
    C:\Documents and Settings\me\Application Data\addon.dat
    C:\Documents and Settings\me\Application Data\addon.dat
    C:\Documents and Settings\me\Application Data\RACLE~1
    C:\Documents and Settings\me\Application Data\RACLE~1\?racle\
    C:\Documents and Settings\me\Application Data\RACLE~1\regsvr32.exe~
    C:\Documents and Settings\me\Desktop\Find Spyware Remover.lnk
    C:\Documents and Settings\me\Desktop\Free Online Dating.lnk
    C:\Documents and Settings\me\Desktop\Go to Casino.lnk
    C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
    C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
    C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    C:\Program Files\s2f.exe
    C:\Program Files\vsadd-in
    C:\WINDOWS1\avp.exe
    C:\WINDOWS1\b103.exe
    C:\WINDOWS1\b104.exe
    C:\WINDOWS1\b122.exe
    C:\WINDOWS1\b128.exe
    C:\WINDOWS1\b129.exe
    C:\WINDOWS1\Casino.ico
    C:\WINDOWS1\csrss.exe
    C:\WINDOWS1\Free Online Dating.ico
    C:\WINDOWS1\mgrs.exe
    C:\WINDOWS1\retadpu41.exe
    C:\WINDOWS1\sks~1
    C:\WINDOWS1\Spyware Remover.ico
    C:\WINDOWS1\system32\atmtd.dll.tmp
    C:\WINDOWS1\system32\jkkkiji.dll
    C:\WINDOWS1\system32\llnmp.bak2
    C:\WINDOWS1\system32\llnmp.ini
    C:\WINDOWS1\system32\llnmp.ini
    C:\WINDOWS1\system32\pmnll.dll
    C:\WINDOWS1\system32\windows.exe
    C:\WINDOWS1\system32\winemx32.dll
    C:\WINDOWS1\system32\winttr.exe
    C:\WINDOWS1\system32\winttr.exe
    C:\WINDOWS1\updater.exe
    C:\WINDOWS1\updater.exe
    C:\WINDOWS1\wr.txt

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_CMDSERVICE
    -------\LEGACY_NETWORK_MONITOR


    ((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
    .

    2007-10-14 17:38 <DIR> d-------- C:\Documents and Settings\me\Application Data\GetRightToGo
    2007-10-14 16:48 <DIR> d-------- C:\Program Files\Trend Micro
    2007-10-14 16:43 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Spybot - Search & Destroy
    2007-10-14 16:41 35,328 --a------ C:\WINDOWS1\system32\byxutrr.dll
    2007-10-14 16:38 51,200 --a------ C:\WINDOWS1\NirCmd.exe
    2007-10-14 16:32 158,432 --a------ C:\WINDOWS1\system32\53a486f9.sys
    2007-10-14 16:25 158,432 --a------ C:\WINDOWS1\system32\9aad26b4.sys
    2007-10-14 16:22 9,728 --a------ C:\Program Files\hlpsrv.exe
    2007-10-14 16:15 158,432 --a------ C:\WINDOWS1\system32\d3c8e9d0.sys
    2007-10-14 16:07 158,432 --a------ C:\WINDOWS1\system32\bf19c01.sys
    2007-10-14 16:07 103,424 --a------ C:\WINDOWS1\system32\drvmun.dll
    2007-10-14 16:07 35,328 --a------ C:\WINDOWS1\system32\vtuuuvt.dll
    2007-10-14 16:07 34,844 --a------ C:\hpbxpu.exe
    2007-10-14 16:07 15,360 --a------ C:\WINDOWS1\system32\drvmunr.dll
    2007-10-14 16:07 9,216 --a------ C:\Documents and Settings\me\install.exe
    2007-10-14 16:07 48 --a------ C:\Documents and Settings\me\readme.bat
    2007-10-14 15:45 <DIR> d-------- C:\WINDOWS1\system32\config\systemprofile\Application Data\Xfire
    2007-10-14 15:45 <DIR> d-------- C:\WINDOWS1\system32\config\systemprofile\Application Data\Xfire
    2007-10-14 15:40 <DIR> d-------- C:\Documents and Settings\me\Application Data\Xfire
    2007-10-14 15:39 <DIR> d-------- C:\Documents and Settings\me\Application Data\Sony
    2007-10-14 15:39 <DIR> d-------- C:\Documents and Settings\me\Application Data\Publish Providers
    2007-10-14 15:39 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Sony
    2007-10-14 15:36 <DIR> d-------- C:\Documents and Settings\me\Application Data\Ventrilo
    2007-10-14 15:34 <DIR> d-------- C:\Documents and Settings\me\Application Data\acccore
    2007-10-14 15:34 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS1\Documents
    2007-10-14 15:34 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS1\Application Data\TEMP
    2007-10-14 15:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL OCP
    2007-10-14 15:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\AOL
    2007-10-14 15:33 <DIR> d-------- C:\WINDOWS1\system32\config\systemprofile\Application Data\AVG7
    2007-10-14 15:33 <DIR> d-------- C:\WINDOWS1\system32\config\systemprofile\Application Data\AVG7
    2007-10-14 15:23 <DIR> d-------- C:\WINDOWS1\Mozilla
    2007-10-14 15:21 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\Grisoft
    2007-10-14 15:21 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS1\Application Data\AVG7
    2007-10-14 15:13 <DIR> d-------- C:\Documents and Settings
    2007-10-14 15:13 <DIR> d--hs---- C:\Diskeeper
    2007-10-14 04:04 <DIR> d-------- C:\Documents and Settings(2)
    2007-10-14 03:38 <DIR> d-------- C:\Program Files\CursorXP
    2007-10-14 03:19 42,672 --a------ C:\WINDOWS1\system32\wbsys.dll
    2007-10-12 22:28 <DIR> d-------- C:\WINDOWS1\system32\SkillGround
    2007-10-12 22:28 <DIR> d-------- C:\Program Files\SkillGround
    2007-10-11 19:18 <DIR> d--h----- C:\WINDOWS1\msdownld.tmp
    2007-10-11 19:12 <DIR> d-------- C:\Program Files\Stardock
    2007-10-11 19:11 <DIR> d-------- C:\Program Files\RedlightCenter
    2007-10-11 19:11 <DIR> d-------- C:\Program Files\Common Files\PocketSoft
    2007-10-11 18:24 <DIR> d-------- C:\Program Files\Diskeeper Corporation
    2007-10-11 14:33 <DIR> d-------- C:\Program Files\Accessdiver
    2007-10-09 19:32 <DIR> d-------- C:\VAIO
    2007-10-05 15:13 33,280 --a------ C:\WINDOWS1\system32\drivers\AmdLLD.sys
    2007-10-05 14:34 107,888 --a------ C:\WINDOWS1\system32\CmdLineExt.dll
    2007-09-15 15:14 5,824 --a------ C:\WINDOWS1\system32\drivers\ASUSHWIO.SYS
    2007-09-15 15:14 5,810 -ra------ C:\WINDOWS1\system32\drivers\ASACPI.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-14 21:51 --------- d-----w C:\Program Files\Steam
    2007-10-14 19:48 --------- d-----w C:\Program Files\mIRC
    2007-10-14 19:14 --------- d-----w C:\Program Files\Warcraft III
    2007-10-14 19:14 --------- d-----w C:\Program Files\Vg
    2007-10-14 19:14 --------- d-----w C:\Program Files\Common Files\stardock
    2007-10-14 19:13 --------- d-s---w C:\Program Files\Xfire
    2007-10-14 19:13 --------- d-----w C:\Program Files\The Logo Creator v5
    2007-10-11 23:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-10-10 20:57 --------- d-----w C:\Program Files\Tournament.com
    2007-10-10 01:31 --------- d-----w C:\Program Files\Windows Sidebar
    2007-10-06 17:48 --------- d-----w C:\Program Files\ESEA
    2007-09-29 02:30 --------- d-----w C:\Program Files\LimeWire
    2007-09-23 03:07 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2007-09-21 19:00 --------- d-----w C:\Program Files\Norton Security Scan
    2007-09-04 01:29 --------- d-----w C:\Program Files\S2SaTstrat
    2007-08-29 18:22 --------- d-----w C:\Program Files\PCI Audio Applications
    2007-08-29 18:22 --------- d-----w C:\Program Files\C-Media
    2007-08-21 05:05 --------- d-----w C:\Program Files\Mail Bomber
    2007-08-18 20:30 --------- d-----w C:\Program Files\CSStrat
    2007-08-16 16:12 --------- d-----w C:\Program Files\iTunes
    2007-08-16 16:11 --------- d-----w C:\Program Files\Common Files\Apple
    2007-08-16 16:09 --------- d-----w C:\Program Files\QuickTime
    2007-08-16 16:07 --------- d-----w C:\Program Files\Apple Software Update
    2007-07-22 07:09 781,223 ----a-w C:\WINDOWS1\screen saver vgirl 01.scr
    2007-07-22 07:09 1,467,213 ----a-w C:\WINDOWS1\screen saver vgirl 06.scr
    2007-07-22 06:59 356 ----a-w C:\Program Files\INSTALL.LOG
    2006-11-21 16:26 3,484,145 ----a-w C:\Program Files\mani_admin_plugin_mm_i486.so
    2006-11-21 16:25 2,588,672 ----a-w C:\Program Files\mani_admin_plugin_mm.dll
    2006-11-02 12:50 174 --sh--w C:\Program Files\desktop.ini
    2005-08-02 20:46:54 187,904 --sha-r C:\WINDOWS1\Sm9yZGFuIFR1Y2tlcg\asappsrv.dll
    2005-07-29 20:24:26 472 --sha-r C:\WINDOWS1\Sm9yZGFuIFR1Y2tlcg\mA6Vt3IRKIlYsZQ5w0.vbs
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{598F4775-6FB6-477B-9842-E0426824E077}]
    C:\DOCUME~1\me\LOCALS~1\Temp\~DP25.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C888CF11-124F-3562-44AC-E685D962C63C}]
    2006-11-02 05:46 274944 ----s---- C:\WINDOWS1\Media\mmdrv.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS1\system32\NvCpl.dll" [2007-06-29 00:43]
    "nwiz"="nwiz.exe" []
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
    "C-Media Echo Control"="C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe" [2001-12-05 16:47]
    "C-Media Mixer"="Mixer.exe" [2002-01-28 16:16 C:\WINDOWS1\mixer.exe]
    "NvMediaCenter"="C:\WINDOWS1\system32\NvMcTray.dll" [2007-06-29 00:43]
    "amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files\steam\steam.exe" [2007-10-04 19:56]
    "Fraps"="C:\Fraps\FRAPS.EXE" [2006-10-26 05:44]
    "ctfmon.exe"="C:\WINDOWS1\system32\ctfmon.exe" [2006-02-28 08:00]
    "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-02 19:42]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
    "Microsoft"=window.exe

  3. #3
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,962

    Default

    Hello and sorry for the delay.

    Perhaps you missed our stickies, we ask only for a HJT log and the results of an on-line anti virus scan.
    Start with ONLY the Two Logs We Ask For in Our Sticky Topic, NOT CF etc

    Running fixes when the infection has not been analysed, can make things more difficult for our helpers.

    The Waiting Room: Post here if waiting for help longer than four days

    However if members waiting for assistance do not post there, their topic is archived.

    If you need it re-opened, please send me a private message (pm) and provide a link back to your thread.

    Applies only to the original poster, anyone else with similar problems please start your own topic.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •