HijackThis explained

HijackThis é unha utilidade libre moi útil para eliminar spyware. A ferramenta é diferente da tradicional antispyware scanners, na medida en que fai o usuario en si elixir o que eliminar manualmente. O propio programa non ten ningún virus de datos, senón que permite ó usuario ver as actuais definicións de ordenador e dá-lles a capacidade de eliminar o que queiran. No entanto, borrar entradas que pode daña o ordenador precisa do ordenador. Polo tanto, recoméndase para ser usado cun profesional ou por un profesional.

Para facer a descarga HijackThis, prema Aquí. Se precisa de axuda para analizar o seu rexistro, Sinto-se a liberdade de public-la abaixo con calquera síntoma que pode ter.

Esta entrada foi remitidas na venres, decembro 26th, 2024 at 10:23 pm e está arquivada baixo o How-To Guide. Pode seguir as respostas a esta entrada a través de RSS 2.0 feed. Pode deixar unha resposta, ou trackback do seu propio site.

38 response to "HijackThis explained"

Liveantiviruspccheck.com - Antivirus 2023 ataque Site | virus eliminación Guru dez 28th, 2024 at 4:53

[...] Como resultado dun BHO (Browser helper obxectivos. Estes obxectos poden ser xeralmente eliminar con HijackThis. Prema aquí para aprender Sobre HijackThis. HijackThis Para facer a descarga, prema aquí. Use HijackThis con prudência, unha vez eliminar [.. .]

Websafetyguide. Con - Sistema de Seguridade virus ataque Site | virus eliminación Guru dez 30th, 2024 at 9:23

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Advancedantivirusscan. Con - Inicio de 2009 Antivirus virus | virus eliminación Guru 2. En xaneiro de 2009 ás 4:44

[...] Como resultado dun BHO (Browser helper obxectivos. Estes obxectos poden ser xeralmente eliminar con HijackThis. Prema aquí para aprender Sobre HijackThis. HijackThis Para facer a descarga, prema aquí. Use HijackThis con prudência, unha vez eliminar [.. .]

Virusandspywarescan. Con - Antivirus 2023 virus ataque Site | virus eliminación Guru 3. En xaneiro de 2009 ás 1:09

[...] Como resultado dun BHO (Browser helper obxectivos. Estes obxectos poden ser xeralmente eliminar con HijackThis. Prema aquí para aprender Sobre HijackThis. HijackThis Para facer a descarga, prema aquí. Use HijackThis con prudência, unha vez eliminar [.. .]

Sgviralscan.com - Spyware Guarda 2023 virus | virus eliminación Guru 5. En xaneiro de 2009 ás 5:46

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

PC-seguridade-scanner. Con - Antivirus 2023 virus ataque Site | virus eliminación Guru 5. En xaneiro de 2009 ás 10:19

[...] Como resultado dun BHO (Browser helper obxectivos. Estes obxectos poden ser xeralmente eliminar con HijackThis. Prema aquí para aprender Sobre HijackThis. HijackThis Para facer a descarga, prema aquí. Use HijackThis con prudência, unha vez eliminar [.. .]

Watchnetprotection.com - Sistema de Seguridade virus | virus eliminación Guru 6. En xaneiro de 2009 ás 11:40

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Stabilityinternetscan.com - Sistema de Seguridade virus | virus eliminación Guru 10. En xaneiro de 2009 ás 5:19

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Pro4scan.com / Best4scan.com / Scan6new.com - Internet Antivírus ataque do Site | virus eliminación Guru 10. En xaneiro de 2009 ás 5:42

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Antivirusxppro2009.com virus eliminación | virus eliminación Guru 21. En xaneiro de 2009 ás 1:07

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Internet-antispyware-scan.com ataque do sitio de Antivírus 360 | virus eliminación Guru 21. En xaneiro de 2009 ás 1:24

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Traffchecking.com / aviso / antivirusplus2009.com Antivírus Plus 2023 | virus eliminación Guru 21. En xaneiro de 2009 ás 2:59

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Virtumonde - Vundo Tróia virus eliminación Guía | virus eliminación Guru 22. En xaneiro de 2009 ás 10:58

[...] Explorer versións antigas do programa. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Eliminación Securityonlinescan.com popup | virus eliminación Guru 25. En xaneiro de 2009 ás 4:26

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

Admess.Trojan Zserv.Transponder.Trojan Wstart.TrojanDownloader eliminación Axuda | virus eliminación Guru 25. En xaneiro de 2009 ás 4:31

[...] Pódense xeralmente eliminar con HijackThis. Se quere saber máis sobre o HijackThis, prema aquí. Por favor, use HijackThis com prudência, unha vez eliminar entradas axeitada pode daña-lo teu ordenador, se [...]

GetModule32.exe GetModule34.exe GetModule35.exe virus Arquivo Información | virus eliminación Guru 26. En xaneiro de 2009 ás 1:11

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

afiss i mama 30. de xaneiro de 2009 ás 2:52

Logfile da Trend Micro HijackThis v2.0.2
Scania gardouse en 9:07:57, en 1/29/2009
Plataforma: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Executando procesos:
C: \ Windows \ system32 \ Dwm.exe
C: \ Windows \ system32 \ taskeng.exe
C: \ Windows \ Explorer.EXE
c: \ Program ~ 1 \ mcafee.com \ agent \ mcagent.exe
C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe
C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe
C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe
C: \ Program Files \ HP \ QuickPlay \ QPService.exe
C: \ Program Files \ QuickTime \ QTTask.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ Windows \ ehome \ ehtray.exe
C: \ Users \ Stefan \ AppData \ Local \ Google \ Update \ GoogleUpdate.exe
C: \ Program Files \ Windows Media Player \ wmpnscfg.exe
C: \ Program Files \ Hewlett-Packard \ Digital Imaging \ bin \ hpqtra08.exe
C: \ Windows \ system32 \ wbem \ Unsecapp.exe
C: \ Program Files \ Sony \ Sony Picture Utility \ PMBCore \ SPUVolumeWatcher.exe
C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.EXE
C: \ Program Files \ Hewlett-Packard \ Shared \ HpqToaster.exe
C: \ Program Files \ Hewlett-Packard \ Digital Imaging \ bin \ hpqSTE08.exe
C: \ Windows \ system32 \ taskeng.exe
C: \ Program Files \ STOPzilla! \ STOPzilla.exe
C: \ Program Files \ STOPzilla! \ SZOptions.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = https://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = https://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = https://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = https://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = https://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = https://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch =
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. local
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName =
O1 - hosts::: 1 localhost
O2 - BHO: HP Print Clips - (053F9267-DC04-4294-A72C-58F732D338C0) - C: \ Program Files \ Hewlett-Packard \ smarter Web Printing \ hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link help - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: SITEguard BHO - (1827766B-9F49-4854-8034-F6EE26FCB1EC) - C: \ Program Files \ STOPzilla! \ SZSG.dll
O2 - BHO: SSVHelper class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll
O2 - BHO: scriptproxy - (7DB2D5A0-7241-4E79-B68D-6309F01C5231) - C: \ Program Files \ McAfee \ VirusScan \ scriptsn.dll
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no ficheiro)
O2 - BHO: STOPzilla Browser helper obxecto - (E3215F20-3212-11D6-9F8B-00D0B743919D) - C: \ Program Files \ STOPzilla! \ SZIEBHO.dll
O3 - Toolbar: STOPzilla - (98828DED-A591-462F-83BA-D2F62A68B8B8) - C: \ Program Files \ STOPzilla! \ SZSG.dll
O4 - HKLM \ .. \ run: [hpqSRMon] C: \ Arquivos de programas \ Hewlett-Packard \ Digital Imaging \ bin \ hpqSRMon.exe
O4 - HKLM \ .. \ run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe
O4 - HKLM \ .. \ run: [HP Software Update] C: \ Program Files \ HP \ HP Software Update \ HPWuSchd2.exe
O4 - HKLM \ .. \ run: [mcagent_exe] C: \ Program Files \ McAfee.com \ Axente \ mcagent.exe / runkey
O4 - HKLM \ .. \ run: [HP Health Check Scheduler] c: \ Program Files \ Hewlett-Packard \ HP Health Check \ HPHC_Scheduler.exe
O4 - HKLM \ .. \ run: [hpWirelessAssistant] C: \ Arquivos de programas \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe
O4 - HKLM \ .. \ run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe"
O4 - HKLM \ .. \ run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ RunOnce: [launch]% WINDIR% \ SMINST \ launcher.exe
O4 - HKCU \ .. \ run: [ehTray.exe] C: \ Windows \ ehome \ ehTray.exe
O4 - HKCU \ .. \ run: [Google Update] "C: \ Users \ Stefan \ AppData \ Local \ Google \ Update \ GoogleUpdate.exe" / c
O4 - HKCU \ .. \ run: [AdobeUpdater] C: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe
O4 - HKCU \ .. \ run: [WMPNSCFG] C: \ Arquivos de programas \ Windows Media Player \ WMPNSCFG.exe
O4 - HKCU \ .. \ run: [Antispyware] C: \ Program Files \ Antispyware \ Antispyware.exe-boot
O4 - HKUS \ S-1-5-19 \ .. \ run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'LUGAR SERVICIOS')
O4 - HKUS \ S-1-5-19 \ .. \ run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User 'LUGAR SERVICIOS')
O4 - HKUS \ S-1-5-20 \ .. \ run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User 'Network SERVICIOS')
O4 - Startup: OneNote 2023 screen Clipper e Launcher.lnk = C: \ Arquivos de programas \ Microsoft Office \ Office12 \ ONENOTEM.EXE
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C: \ Program Files \ Sony \ Sony Picture Utility \ PMBCore \ SPUVolumeWatcher.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C: \ Arquivos de programas \ Hewlett-Packard \ Digital Imaging \ bin \ hpqtra08.exe
O8 - Extra context menu item: E & xportar para Microsoft Excel - res: / / C: \ Program ~ 1 \ MICROS ~ 3 \ Office12 \ EXCEL.EXE/3000
O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ ssv.dll
O9 - Extra button: Enviar a OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ Program ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S & final para o OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ Program ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra button: HP Clipbook - (58ECB495-38F0-49cb-A538-10282ABF65E7) - C: \ Program Files \ Hewlett-Packard \ smarter Web Printing \ hpswp_extensions.dll
O9 - Extra button: HP smarter Select - (700259D7-1666-479a-93B1-3250410481E8) - C: \ Program Files \ Hewlett-Packard \ smarter Web Printing \ hpswp_extensions.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ Program ~ 1 \ MICROS ~ 3 \ Office12 \ REFIEBAR.DLL
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O10 - unknown file en Winsock LSP: c: \ Program Files \ Common Files \ is3 \ anti-spyware \ is3lsp.dll
O16 - DPF: (7FC1B346-83E6-4774-8D20-1A6B09B0E737) (Windows Live Photo Upload Control) - https://kiredam2.spaces.live.com/PhotoUpload/VistaMsnPUplden-us.cab
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ Program ~ 1 \ common ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, LP - C: \ Arquivos de programas \ Hewlett-Packard \ HP Quick launch Buttons \ AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe
O23 - Service: Antispyware scanning engine (AntispywareSrv) - unknown owner - C: \ Program Files \ Antispyware \ Antispyware.srv.exe
O23 - Service: Apple Mobile device - Apple Inc - C: \ Program Files \ Common Files \ Apple \ Mobile device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - unknown owner - c: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c: \ Program Files \ Hewlett-Packard \ HP Health Check \ hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Arquivos de programas \ Hewlett-Packard \ Shared \ hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Roxio \ Roxio MyDVD Basic v9 \ InstallShield \ driver \ 1050 \ Intel 32 \ IDriverT.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: LightScribeService Direct Disco Labeling Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C: \ Program ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE
O23 - Service: LiveUpdate notice Service Ex (LiveUpdate notice Ex) - unknown owner - c: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate notice Service - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc - C: \ Program ~ 1 \ McAfee \ MSC \ mcmscsvc.exe
O23 - Service: McAfee Network Axente (McNASvc) - McAfee, Inc - c: \ Program ~ 1 \ common ~ 1 \ McAfee \ MNA \ mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - C: \ Program ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - c: \ Program ~ 1 \ common ~ 1 \ mcafee \ mcproxy \ mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc - C: \ Program ~ 1 \ McAfee \ VIRUSS ~ 1 \ Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - C: \ Program ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
O23 - Service: McAfee Personal devasa Service (MpfService) - McAfee, Inc - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: QuickPlay background Captura Service (QBCS) (QPCapSvc) - unknown owner - C: \ Program Files \ HP \ QuickPlay \ Núcleo \ TV \ QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - unknown owner - C: \ Program Files \ HP \ QuickPlay \ Núcleo \ TV \ QPSched.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Common Files \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe
O23 - Service: stllssvr - Microvision Development, Inc - C: \ Program Files \ Common Files \ SureThing Shared \ stllssvr.exe
O23 - Service: STOPzilla Service (szServer) - iS3, Inc - C: \ Program Files \ Common Files \ iS3 \ Anti-Spyware \ SZServer.exe
O23 - Service: XAudioService - Conexant Systems, Inc - C: \ Windows \ system32 \ drivers \ xaudio.exe

--
Fin do arquivo - 11297 bytes

Cogad.exe (Cogad) Tróia virus Arquivo Información | virus eliminación Guru 3. En febreiro de 2009 en 1:23

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

~ Tmpa.exe (~ Tmpa) Tróia virus Arquivo Información | virus eliminación Guru 4. En febreiro de 2009 en 9:51

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

Burolage.exe (Burolage) Tróia virus Arquivo Información | virus eliminación Guru 4. En febreiro de 2009 en 9:51

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

GetModule36.exe (GetModule36) Tróia virus Arquivo Información | virus eliminación Guru 8. En febreiro de 2009 en 7:12

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

Gand.exe (Ganda) Tróia virus Arquivo Información | virus eliminación Guru 11. En febreiro de 2009 en 11:02

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

Viewtubesoftware.exe (Viewtubesoftware) Tróia virus Arquivo Información | virus eliminación Guru 13. En febreiro de 2009 en 12:54

[...] Prema aquí para aprender Sobre HijackThis. Para facer a descarga HijackThis, prema aquí. [...]

ncyh 25 Feb, 2023, 10:08

Por favor, axuden-me a ler o meu diario. Eu realmente quero solucionar este problema TT

Logfile da Trend Micro HijackThis v2.0.2
Scania gardouse en 6:01:23, en 2/25/2009
Plataforma: Windows XP SP3 (WinNT 5/01/2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Executando procesos:
C: \ Windows \ System32 \ smss.exe
C: \ Windows \ system32 \ winlogon.exe
C: \ Windows \ system32 \ Services.exe
C: \ Windows \ system32 \ lsass.exe
C: \ Windows \ system32 \ svchost.exe
C: \ Windows \ System32 \ svchost.exe
C: \ Windows \ system32 \ svchost.exe
C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe
C: \ Windows \ system32 \ spoolsv.exe
C: \ Windows \ system32 \ userinit.exe
C: \ Program Files \ Common Files \ Apple \ Mobile device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Symantec \ LiveUpdate \ AluSchedulerSvc.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ Windows \ system32 \ nvsvc32.exe
C: \ Windows \ Explorer.EXE
C: \ Program Files \ QvodPlayer \ QvodTerminal.exe
C: \ Windows \ system32 \ svchost.exe
C: \ Windows \ system32 \ SearchIndexer.exe
C: \ Windows \ RTHDCPL.EXE
C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
C: \ Windows \ system32 \ rundll32.exe
C: \ Program Files \ ScanSoft \ PaperPort \ pptd40nt.exe
C: \ Program Files \ Brother \ Brmfcmon \ BrMfcWnd.exe
C: \ Program Files \ Brother \ ControlCenter3 \ brccMCtl.exe
C: \ Program Files \ Common Files \ Symantec Shared \ ccSvcHst.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ Program Files \ Common Files \ Ahead \ lib \ NMBgMonitor.exe
C: \ Windows \ system32 \ ctfmon.exe
C: \ Program Files \ Windows Live \ Messenger \ MsnMsgr.Exe
C: \ Program Files \ Common Files \ Ahead \ lib \ NMIndexStoreSvr.exe
C: \ Program Files \ Veoh Networks \ Veoh \ VeohClient.exe
C: \ Program Files \ Skype \ Phone \ Skype.exe
C: \ Documents and Settings \ Usuario \ Local Settings \ Application Data \ Octoshape \ Octoshape Streaming Services \ OctoshapeClient.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe
C: \ Program Files \ Hamachi \ hamachi.exe
C: \ Windows \ System32 \ svchost.exe
C: \ Program Files \ Skype \ Extensión Manager \ skypePM.exe
C: \ Program Files \ Norton 360 \ ScanStub.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WLLoginProxy.exe
C: \ Arquivos de programas \ Internet Explorer \ IEXPLORE.EXE
C: \ Program ~ 1 \ common ~ 1 \ SYMANT ~ 1 \ CCPD-LC \ symlcsvc.exe
C: \ Program Files \ Common Files \ iS3 \ Anti-Spyware \ SZServer.exe
D: \ Stopzilla \ STOPzilla.exe
D: \ Stopzilla \ SZOptions.exe
C: \ Program Files \ Safari \ Safari.exe
C: \ DOCUME ~ 1 \ user \ LOCALS ~ 1 \ Tempo \ Saf6C1.tmp \ HiJackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = https://www.yahoo.com/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = https://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/ * https://www.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = https://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/ * https://www.yahoo.com/ext / search / search.html
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = https://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/ * https://www.yahoo.com
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = https://www.yahoo.com/
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyServer = 127.0.0.1:8080
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = local; *. local
R3 - URLSearchHook: (no name) - (982CB676-38F0-4D9A-BB72-D9371ABE876E) - (no ficheiro)
O2 - BHO: & Yahoo! Toolbar help - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Program ~ 1 \ Yahoo! \ Companion \ installs \ CPN \ yt.dll
O2 - BHO: Adobe PDF Reader Link help - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: SITEguard BHO - (1827766B-9F49-4854-8034-F6EE26FCB1EC) - D: \ Stopzilla \ SZSG.dll
O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O2 - BHO: NCO 2,0 IE BHO - (602ADB0E-4AFF-4217-8AA1-95DAC4DFA408) - C: \ Program Files \ Common Files \ Symantec Shared \ coShared \ Browser \ 2,6 \ coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - (6D53EC84-6AAE-4787-AEEE-F4628F01010C) - C: \ Program ~ 1 \ Común ~ 1 \ SYMANT ~ 1 \ IDs \ IPSBHO.dll
O2 - BHO: Java (tm) plug-In SSV help - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre6 \ bin \ ssv.dll
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no ficheiro)
O2 - BHO: Windows Live Sign-in help - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: Google Toolbar help - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ Arquivos de programas \ Google \ GoogleToolbar1.dll
O2 - BHO: Windows Live Toolbar help - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ Windows Live Toolbar \ msntb.dll
O2 - BHO: Java (tm) plug-In 2 SSV help - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: STOPzilla Browser helper obxecto - (E3215F20-3212-11D6-9F8B-00D0B743919D) - D: \ Stopzilla \ SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ implantar \ jqs \ IE \ jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ Windows Live Toolbar \ msntb.dll
O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ Arquivos de programas \ Google \ GoogleToolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program ~ 1 \ Yahoo! \ Companion \ installs \ CPN \ yt.dll
O3 - Toolbar: Show Norton Toolbar - (7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA) - C: \ Program Files \ Common Files \ Symantec Shared \ coShared \ Browser \ 2,6 \ CoIEPlg.dll
O3 - Toolbar: STOPzilla - (98828DED-A591-462F-83BA-D2F62A68B8B8) - D: \ Stopzilla \ SZSG.dll
O4 - HKLM \ .. \ run: [IMJPMIG8.1] "C: \ Windows \ IME \ imjp8_1 \ Imjpmig.exe" / Spoil / RemAdvDef / Migration32
O4 - HKLM \ .. \ run: [PHIME2002ASync] C: \ Windows \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / SYNC
O4 - HKLM \ .. \ run: [PHIME2002A] C: \ Windows \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / IMEName
O4 - HKLM \ .. \ run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM \ .. \ run: [Alcmtr] ALCMTR.EXE
O4 - HKLM \ .. \ run: [NvCplDaemon] RUNDLL32.EXE C: \ Windows \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ run: [NeroFilterCheck] C: \ Program Files \ Common Files \ Ahead \ lib \ NeroCheck.exe
O4 - HKLM \ .. \ run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe"
O4 - HKLM \ .. \ run: [NvMediaCenter] RUNDLL32.EXE C: \ Windows \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ run: [Adobe Reader Speed launch] "C: \ Arquivos de programas \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe"
O4 - HKLM \ .. \ run: [SSBkgdUpdate] "C: \ Program Files \ Common Files \ ScanSoft Shared \ SSBkgdUpdate \ SSBkgdupdate.exe"-Embedding-boot
O4 - HKLM \ .. \ run: [PaperPort PTD] C: \ Program Files \ ScanSoft \ PaperPort \ pptd40nt.exe
O4 - HKLM \ .. \ run: [IndexSearch] C: \ Program Files \ ScanSoft \ PaperPort \ IndexSearch.exe
O4 - HKLM \ .. \ run: [BrMfcWnd] C: \ Program Files \ Brother \ Brmfcmon \ BrMfcWnd.exe / AUTORUN
O4 - HKLM \ .. \ run: [SetDefPrt] C: \ Program Files \ Brother \ Brmfl06a \ BrStDvPt.exe
O4 - HKLM \ .. \ run: [ControlCenter3] C: \ Program Files \ Brother \ ControlCenter3 \ brctrcen.exe / autorun
O4 - HKLM \ .. \ run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe"
O4 - HKLM \ .. \ run: [osCheck] "C: \ Program Files \ Norton 360 \ osCheck.exe"
O4 - HKLM \ .. \ run: [AppleSyncNotifier] C: \ Program Files \ Common Files \ Apple \ Mobile device Support \ bin \ AppleSyncNotifier.exe
O4 - HKLM \ .. \ run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKCU \ .. \ run: [BgMonitor_ (79662E04-7C6C-4d9f-84C7-88D8A56B10AA)] "C: \ Program Files \ Common Files \ Ahead \ lib \ NMBgMonitor.exe"
O4 - HKCU \ .. \ run: [ctfmon.exe] C: \ Windows \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ run: [MsnMsgr] "C: \ Program Files \ Windows Live \ Messenger \ MsnMsgr.Exe" / background
O4 - HKCU \ .. \ run: [swg] C: \ Arquivos de programas \ Google \ GoogleToolbarNotifier \ 1.2.1128.5462 \ GoogleToolbarNotifier.exe
O4 - HKCU \ .. \ run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe"
O4 - HKCU \ .. \ run: [Veoh] "C: \ Program Files \ Veoh Networks \ Veoh \ VeohClient.exe" / VeohHide
O4 - HKCU \ .. \ run: [Skype] "C: \ Program Files \ Skype \ Phone \ Skype.exe" / nosplash / minimizar
O4 - HKCU \ .. \ run: [Octoshape Streaming Services] "C: \ Documents and Settings \ Usuario \ Local Settings \ Application Data \ Octoshape \ Octoshape Streaming Services \ OctoshapeClient.exe"-inv: bootrun
O4 - HKCU \ .. \ run: [Steam] "d: \ xogos \ steam \ steam.exe"-silent
O4 - S-1-5-18 Startup: hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe (User 'System')
O4 - S-1-5-18 Startup: IMVU.lnk = C: \ Arquivos de programas \ IMVU \ IMVUClient.exe (User 'System')
O4 -. default Startup: hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe (User 'Default user')
O4 -. default Startup: IMVU.lnk = C: \ Arquivos de programas \ IMVU \ IMVUClient.exe (User 'Default user')
O4 - Startup: hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe
O4 - Startup: IMVU.lnk = C: \ Arquivos de programas \ IMVU \ IMVUClient.exe
O4 - Global Startup: Microsoft Office.lnk = C: \ Arquivos de programas \ Microsoft Office \ Office10 \ Osa.exe
O4 - Global Startup: Windows Search.lnk = C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe
O8 - Extra context menu item: & Windows Live Search - res: / / C: \ Program Files \ Windows Live Toolbar \ msntb.dll / search.htm
O8 - Extra context menu item: engadir a Windows & Live Favorites - https://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E & xportar para Microsoft Excel - res: / / C: \ Program ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000
O8 - Extra context menu item: EII ¢ ¼ Æ ¬ μ ½ Eo »U - C: \ Program Files \ P4P \ cx.htm
O8 - Extra context menu item: E ÓÃËÑ ¹ ¹ o ± i ¨ ³ μÏÂÔØ - C: \ Program Files \ P4P \ dl.htm
O9 - Extra button: Yahoo! Servizos - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O9 - Extra button: run IMVU - (d9288080-1baa-4bc4-9cf8-a92d743db949) - C: \ Documents and Settings \ Usuario \ Menú Inicio \ Programas \ IMVU \ run IMVU.lnk
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ Windows \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @ Xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ Windows \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O10 - unknown file en Winsock LSP: c: \ Windows \ system32 \ nwprovau.dll
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (installation Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper.dll
O16 - DPF: (67A5F8DC-1A4B-4D66-9F24-A704AD929EEE) (System requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient class) - https://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: (CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7) (get_atlcom class) - https://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444553540000) (Shockwave Flash obxecto) - https://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: (F5A7706B-B9C0-4C89-A715-7A0C6B05DD48) (Minesweeper Flags class) - https://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ Program ~ 1 \ common ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
O23 - Service: Apple Mobile device - Apple Inc - C: \ Program Files \ Common Files \ Apple \ Mobile device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Qvod Terminal - Shenzhen QVOD Technology Co.,Ltd - C:\Program Files\QvodPlayer\QvodTerminal.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe


End of file - 14090 bytes

ncyh February 25th, 2024 at 10:09 am

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:01:23 PM, on 2/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QvodPlayer\QvodTerminal.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\user\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Norton 360\ScanStub.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
D:\Stopzilla\STOPzilla.exe
D:\Stopzilla\SZOptions.exe
C:\Program Files\Safari\Safari.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Saf6C1.tmp\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/ *https://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/ *https://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/ *https://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://g.msn.com/0SEENSG/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - D:\Stopzilla\SZSG.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - D:\Stopzilla\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - D:\Stopzilla\SZSG.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKLM\..\Run: [SSBkgdUpdate] “C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [ccApp] “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”
O4 - HKLM\..\Run: [osCheck] “C:\Program Files\Norton 360\osCheck.exe”
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] “C:\Program Files\QuickTime\QTTask.exe” -atboottime
O4 - HKLM\..\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] “C:\Program Files\DNA\btdna.exe”
O4 - HKCU\..\Run: [Veoh] “C:\Program Files\Veoh Networks\Veoh\VeohClient.exe” /VeohHide
O4 - HKCU\..\Run: [Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
O4 - HKCU\..\Run: [Octoshape Streaming Services] “C:\Documents and Settings\user\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe” -inv:bootrun
O4 - HKCU\..\Run: [Steam] “d:\games\steam\steam.exe” -silent
O4 - S-1-5-18 Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘SYSTEM’)
O4 - S-1-5-18 Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe (User ‘SYSTEM’)
O4 - .DEFAULT Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe (User ‘Default user’)
O4 - .DEFAULT Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe (User ‘Default user’)
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: ·¢ËÍͼƬµ½ÊÖ»ú - C:\Program Files\P4P\cx.htm
O8 - Extra context menu item: ʹÓÃËѹ·Ö±Í¨³µÏÂÔØ - C:\Program Files\P4P\dl.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\user\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - https://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - https://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - https://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Qvod Terminal - Shenzhen QVOD Technology Co.,Ltd - C:\Program Files\QvodPlayer\QvodTerminal.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe


End of file - 14090 bytes

Xlswin.exe (Xlswin) Trojan Virus File Information | Virus Removal Guru March 2nd, 2024 at 9:49 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Pp1.exe (Pp1) Worm Virus File Information | Virus Removal Guru March 8th, 2024 at 3:52 am

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Hyetn1i.exe (Hyetn1i) Trojan Virus File Information | Virus Removal Guru March 11th, 2024 at 12:47 am

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

3yseow89.exe (3yseow89) Trojan Virus File Information | Virus Removal Guru March 11th, 2024 at 3:54 am

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Yiar.exe Virus Removal | Virus Removal Guru March 12th, 2024 at 9:00 pm

[...] Manual Removal - Yiar.exe may be removed manually by analyzing your HijackThis log. To download HijackThis, please click HERE. Click Here To Learn About HijackThis. [...]

Updtic.exe (Updtic) Trojan Virus File Information | Virus Removal Guru March 16th, 2024 at 5:55 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Onlinescanservice.com (Onlinescanservice) Virus Attack Site | Virus Removal Guru March 19th, 2024 at 8:52 pm

[...] as a result of a BHO (Browser Helper Object. These objects can generally be remove with HijackThis. Click Here To Learn About HijackThis. To download HijackThis, please click HERE. Please use HijackThis with caution since removing [...]

Winlognn.exe (Winlognn) Trojan Virus File Information | Virus Removal Guru March 23rd, 2024 at 6:14 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

WinIgn.exe (WinIgn) Trojan Virus File Information | Virus Removal Guru March 23rd, 2024 at 6:14 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Nyfa32.exe (Nyfa32) Trojan Virus File Information | Virus Removal Guru March 24th, 2024 at 8:31 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Sys-look-scan.biz (Sys-look-scan) Virus Attack Site | Virus Removal Guru March 30th, 2024 at 6:14 pm

[...] as a result of a BHO (Browser Helper Object. These objects can generally be remove with HijackThis. Click Here To Learn About HijackThis. To download HijackThis, please click HERE. Please use HijackThis with caution since removing [...]

Part.exe (Part) Trojan Virus File Information | Virus Removal Guru April 5th, 2024 at 6:17 pm

[...] Click Here To Learn About HijackThis. To download HijackThis, please click HERE. [...]

Leave a Reply