Home » Spyware Protection » Hijacked Browser Analysis » 

Logfile of HijackThis v1.99.1 - jbmac

You may need to review these entries:

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B69B827A-C669-49D6-AC9A-E27ACCA5852F} - C: \ WINDOWS \ System32 \ bfh.dll (file missing)
O4 - HKLM \ .. \ Run: [websx] C: \ Program Files \ websx \ int307770.exe -auto
O4 - HKLM \ .. \ Run: [seaWDurlIE] C: \ WINDOWS \ System32 \ seaWDurlIE.exe
O4 - HKCU \ .. \ Run: [Spyware Begone] c: \ freescan \ freescan.exe -FastScan
O8 - Extra context menu item: Easy-WebPrint Print - res: / / C: \ Program Files \ Canon \ Easy-WebPrint \ Resource.dll / RC_Print.html


Scan saved at 6:55:19 AM, on 05 / 24 / 2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ WINDOWS \ Explorer.EXE
C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgamsvr.exe
C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgupsvc.exe
C: \ Program Files \ Ahead \ InCD \ InCDsrv.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ VS7Debug \ mdm.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb09.exe
C: \ Program Files \ Ahead \ InCD \ InCD.exe
C: \ Program Files \ HP \ hpcoretech \ hpcmpmgr.exe
C: \ Program Files \ Hewlett-Packard \ HP Software Update \ HPWuSchd.exe
C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgcc.exe
C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgemc.exe
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ WINDOWS \ System32 \ ctfmon.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ Works Shared \ wkcalrem.exe
C: \ Program Files \ Microsoft AntiSpyware \ gcasDtServ.exe
C: \ Program Files \ Microsoft AntiSpyware \ gcasServ.exe
C: \ Documents and Settings \ Brian.BRIAN-0IVECAGH5 \ My Documents \ HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C: \ Program Files \ Adobe \ Acrobat 6.0 \ Reader \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C: \ PROGRA~1 \ SPYBOT~1 \ SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c: \ program files \ google \ googletoolbar1.dll
O2 - BHO: (no name) - {B69B827A-C669-49D6-AC9A-E27ACCA5852F} - C: \ WINDOWS \ System32 \ bfh.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C: \ Program Files \ Canon \ Easy-WebPrint \ Toolband.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \ WINDOWS \ System32 \ msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \ program files \ google \ googletoolbar1.dll
O4 - HKLM \ .. \ Run: [WorksFUD] C: \ Program Files \ Microsoft Works \ wkfud.exe
O4 - HKLM \ .. \ Run: [Microsoft Works Portfolio] C: \ Program Files \ Microsoft Works \ WksSb.exe / AllUsers
O4 - HKLM \ .. \ Run: [Microsoft Works Update Detection] C: \ Program Files \ Microsoft Works \ WkDetect.exe
O4 - HKLM \ .. \ Run: [HPDJ Taskbar Utility] C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb09.exe
O4 - HKLM \ .. \ Run: [websx] C: \ Program Files \ websx \ int307770.exe -auto
O4 - HKLM \ .. \ Run: [NeroCheck] C: \ WINDOWS \ System32 \ \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [InCD] C: \ Program Files \ Ahead \ InCD \ InCD.exe
O4 - HKLM \ .. \ Run: [HP Component Manager] "C: \ Program Files \ HP \ hpcoretech \ hpcmpmgr.exe"
O4 - HKLM \ .. \ Run: [HP Software Update] "C: \ Program Files \ Hewlett-Packard \ HP Software Update \ HPWuSchd.exe"
O4 - HKLM \ .. \ Run: [AVG7_CC] C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgcc.exe / STARTUP
O4 - HKLM \ .. \ Run: [AVG7_EMC] C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgemc.exe
O4 - HKLM \ .. \ Run: [seaWDurlIE] C: \ WINDOWS \ System32 \ seaWDurlIE.exe
O4 - HKLM \ .. \ Run: [gcasServ] "C: \ Program Files \ Microsoft AntiSpyware \ gcasServ.exe"
O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Program Files \ Messenger \ msmsgs.exe" / background
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ System32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [Spyware Begone] c: \ freescan \ freescan.exe -FastScan
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmsearch.html
O8 - Extra context menu item: &Translate English Word - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmwordtrans.html
O8 - Extra context menu item: Backward Links - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res: / / C: \ PROGRA~1 \ MICROS~2 \ Office10 \ EXCEL.EXE / 3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res: / / C: \ Program Files \ Canon \ Easy-WebPrint \ Resource.dll / RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res: / / C: \ Program Files \ Canon \ Easy-WebPrint \ Resource.dll / RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res: / / C: \ Program Files \ Canon \ Easy-WebPrint \ Resource.dll / RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res: / / C: \ Program Files \ Canon \ Easy-WebPrint \ Resource.dll / RC_Print.html
O8 - Extra context menu item: Similar Pages - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll / cmtrans.html
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - website: dl.filekicker.com / send / file / 128985-NZIL / PhPSetup.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - website: v5.windowsupdate.microsoft.com / v5consumer / V5Controls / en / x86 / client / wuweb_site.cab?1101071562873
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - website: a840.g.akamai.net / 7 / 840 / 537 / 2004061001 / housecall.trendmicro.com / housecall / xscan53.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - website: ipgweb.cce.hp.com / rdqna / downloads / msxml4.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C: \ PROGRA~1 \ Grisoft \ AVGFRE~1 \ avgupsvc.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C: \ Program Files \ Ahead \ InCD \ InCDsrv.exe


Mail this pageMail this page