General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

Someone please have a look at the results of my virus scan?!

Thread Tools
 
Search this Thread
 
Old 05-05-2005, 05:14 PM
  #1  
XRT_si
PassionFord Post Whore!!
Thread Starter
iTrader: (2)
 
XRT_si's Avatar
 
Join Date: Mar 2005
Location: London
Posts: 6,861
Received 54 Likes on 51 Posts
Default Someone please have a look at the results of my virus scan?!

Logfile of HijackThis v1.99.1
Scan saved at 17:26:06, on 05/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Tbridge\Flatbed.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PopupKillerTracksEraser\PopupKillerTray.exe
C:\Documents and Settings\Chris & Jen\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk/broadband
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-space.com/
O2 - BHO: (no name) - {00110011-4B0B-44D5-9718-90C88817369B} - C:\WINDOWS\NavExt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~2.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: PopupKillerIEDLL.CPopupKillerIEDLL - {A09790E7-DD00-4A83-B632-5B563423CFBB} - C:\Program Files\PopupKillerTracksEraser\PopupKillerIEDLL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [mfcpqhdanbw] C:\WINDOWS\System32\wamspy.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Detector.lnk = ?
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/broadband
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\dbobrrqv.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66ACDCF9-64A9-4DC3-9606-F06D5A9846B6}: NameServer = 80.225.248.178 80.225.248.186
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe




Bit confuzzled?!! Cheers anyone!
Old 05-05-2005, 05:21 PM
  #2  
Ginge !
just finding my feet
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,052
Received 2 Likes on 2 Posts
Default

no but im sure someone here can help
Old 05-05-2005, 05:23 PM
  #3  
craig todd
Advanced PassionFord User
 
craig todd's Avatar
 
Join Date: Feb 2005
Location: middlesbrough
Posts: 2,008
Likes: 0
Received 0 Likes on 0 Posts
Default

wipe the comp and start again
Old 05-05-2005, 05:29 PM
  #4  
Ginge !
just finding my feet
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,052
Received 2 Likes on 2 Posts
Default

why do people sugest that

surely likes like ford saying buy a rebuild the engine when ya say theres oil leaking from the sump gasket
Old 05-05-2005, 05:36 PM
  #5  
CarlRsT
I've found that life I needed.. It's HERE!!
 
CarlRsT's Avatar
 
Join Date: Sep 2003
Location: Blackpool
Posts: 1,286
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by b19bal
why do people sugest that

surely likes like ford saying buy a rebuild the engine when ya say theres oil leaking from the sump gasket
it normally means u gotta
Old 05-05-2005, 05:36 PM
  #6  
L33 BYT
PassionFord Post Whore!!

 
L33 BYT's Avatar
 
Join Date: Jul 2003
Location: SUFFOLK
Posts: 7,482
Likes: 0
Received 0 Likes on 0 Posts
Default

wipe the comp and start again


Mate download a program called Lavasoft Adware - This will get rid of some of the spy ware that your PC is running. Such as;
C:\Program Files\Web_Rebates\WebRebates1.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search-space.com/
Should also remove Registry keys like the above.

Then do a google search for Free AVG antivirus. Download. Install and this should clear any Adware and Virus.
Old 05-05-2005, 05:42 PM
  #7  
RSeb
I've found that life I needed.. It's HERE!!
 
RSeb's Avatar
 
Join Date: Apr 2004
Location: Hampshire
Posts: 1,130
Likes: 0
Received 0 Likes on 0 Posts
Default

ive looked at it and it means fook all to me!! now what?
Old 05-05-2005, 05:43 PM
  #8  
Ginge !
just finding my feet
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,052
Received 2 Likes on 2 Posts
Default

Originally Posted by RSeb
ive looked at it and it means fook all to me!! now what?
Old 05-05-2005, 06:17 PM
  #9  
Fast Guy
Advanced PassionFord User
 
Fast Guy's Avatar
 
Join Date: Sep 2003
Location: N Yorks
Posts: 1,529
Received 9 Likes on 6 Posts
Default

You really want to post your hijack this log on a specialist forum as it needs someone who knows what they're doing to recommend your next move

Have a look on here

http://www.pcadvisor.co.uk/

There's a couple of people on there who can look at it, or if you use their search facility you should be able to find where they recommed you stick it

PS that isn't actually a vrius scan as it isn't anti virus software, more spyware
Old 05-05-2005, 06:24 PM
  #10  
EscortWRC
PassionFord Post Troll
 
EscortWRC's Avatar
 
Join Date: Jun 2003
Posts: 2,985
Likes: 0
Received 0 Likes on 0 Posts
Default

You have all sorts of issues on there

Get Ad Aware and also Spybot Search & Destroy

get the latest updates and then run them both
Old 05-05-2005, 06:26 PM
  #11  
Ginge !
just finding my feet
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,052
Received 2 Likes on 2 Posts
Default

basicly no more child porn !!!!!!!
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
DixieTheKid
Ford Sierra/Sapphire/RS500 Cosworth
11
06-06-2020 11:20 AM
nicodinho
Ford Non RS / XR / ST parts for sale.
6
07-10-2015 12:56 PM
Shaunc
Escort Range
4
23-09-2015 06:00 AM



Quick Reply: Someone please have a look at the results of my virus scan?!



All times are GMT. The time now is 11:36 AM.