PPRuNe Forums - View Single Post - XP keeps trying to dial out
View Single Post
Old 28th January 2005 | 07:39
  #7 (permalink)  
MOR
 
Joined: Feb 2000
Posts: 959
Likes: 0
From: Euroland
Yes, I have AdAware and HijackThis (been down this road a few times before) So I'll update it and post the results.

Haven't tried Bazooka though, I'll download that.

Cheers, helpful dudes!

Right here ya go!

Logfile of HijackThis v1.99.0
Scan saved at 9:44:06 p.m., on 28/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\System32\\Ati2evxx.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\Program Files\\Sophos SWEEP for NT\\SWNETSUP.EXE
C:\\Program Files\\Sophos SWEEP for NT\\SWEEPSRV.SYS
C:\\WINDOWS\\System32\\tlntsvr.exe
C:\\Program Files\\Common Files\\Ulead Systems\\DVD\\ULCDRSvr.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\Ati2evxx.exe
C:\\WINDOWS\\system32\\wscntfy.exe
C:\\WINDOWS\\Explorer.EXE
C:\\WINDOWS\\system32\\RunDll32.exe
C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe
C:\\Program Files\\QuickTime\\qttask.exe
C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe
C:\\WINDOWS\\system32\\CTHELPER.EXE
C:\\WINDOWS\\system32\\wduzwuty.exe
C:\\WINDOWS\\essspk.exe
C:\\WINDOWS\\DvzCommon\\DvzMsgr.exe
C:\\Program Files\\Sophos SWEEP for NT\\ICMON.EXE
C:\\Program Files\\WinZip\\WZQKPICK.EXE
C:\\Program Files\\Palm\\HOTSYNC.EXE
C:\\Program Files\\Paltalk\\pnetaware.exe
C:\\Program Files\\SpywareGuard\\sgmain.exe
C:\\Program Files\\SpywareGuard\\sgbhp.exe
L:\\Hijack This\\HijackThis.exe

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.trademe.co.nz/structure/my_bids_current.asp
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page_bak = http://www.trademe.co.nz/structure/my_bids_current.asp
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = selected by Simon
O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\\WINDOWS\\ZServ.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\\Program Files\\SpywareGuard\\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\\Program Files\\Spybot - Search & Destroy\\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\\program files\\google\\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\\program files\\google\\googletoolbar2.dll
O4 - HKLM\\..\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\\..\\Run: [ATIPTA] C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe
O4 - HKLM\\..\\Run: [QuickTime Task] "C:\\Program Files\\QuickTime\\qttask.exe" -atboottime
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe
O4 - HKLM\\..\\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\\..\\Run: [UpdReg] C:\\WINDOWS\\UpdReg.EXE
O4 - HKLM\\..\\Run: [Jet Detection] "C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe"
O4 - HKLM\\..\\Run: [RealJukeboxSystray] C:\\Program Files\\Real\\RealJukebox\\tsystray.exe
O4 - HKLM\\..\\Run: [NeroFilterCheck] C:\\WINDOWS\\system32\\NeroCheck.exe
O4 - HKLM\\..\\Run: [nwpzccjlvprr] C:\\WINDOWS\\system32\\wduzwuty.exe
O4 - HKLM\\..\\Run: [satmat] C:\\WINDOWS\\satmat.exe
O4 - HKLM\\..\\Run: [farmmext] C:\\WINDOWS\\farmmext.exe
O4 - HKLM\\..\\Run: [EssSpkPhone] essspk.exe
O4 - Startup: HotSync Manager.lnk = C:\\Program Files\\Palm\\HOTSYNC.EXE
O4 - Startup: PalNetaware.lnk = C:\\Program Files\\Paltalk\\pnetaware.exe
O4 - Startup: SpywareGuard.lnk = C:\\Program Files\\SpywareGuard\\sgmain.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\\WINDOWS\\DvzCommon\\DvzMsgr.exe
O4 - Global Startup: Free WebSite Tools.lnk = ?
O4 - Global Startup: InterCheck Monitor.LNK = C:\\Program Files\\Sophos SWEEP for NT\\ICMON.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\\Program Files\\Microsoft Office\\Office10\\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\\Program Files\\WinZip\\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\\program files\\google\\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\\program files\\google\\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\\program files\\google\\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\\PROGRA~1\\MICROS~2\\Office10\\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\\program files\\google\\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\\program files\\google\\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\npjpi142_06.dll
O9 - Extra \'Tools\' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\npjpi142_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O12 - Plugin for .pdf: C:\\Program Files\\Internet Explorer\\PLUGINS\\nppdf32.dll
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
O16 - DPF: {C2F38867-251C-4216-9B1C-BBE89B8700E2} (iVocalize Internet Conference 3 Setup) - http://www.talkingcommunities.com/client3/ivsetup3.cab
O16 - DPF: {CBA13183-40A1-45B9-B3E4-3C35A9F7E749} (DownloadManagerInstall Control) - http://byteswarm.com/agent/1.2.1/DMInstall.cab
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{41C9DCDB-73EF-46B7-B856-EE7F6C6955D7}: NameServer = 203.96.152.4,203.96.152.12
O23 - Service: Ati HotKey Poller - Unknown - C:\\WINDOWS\\System32\\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\\WINDOWS\\system32\\ati2sgag.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\\Program Files\\Common Files\\Macromedia Shared\\Service\\Macromedia Licensing.exe
O23 - Service: Sophos Anti-Virus Network - Sophos Plc - C:\\Program Files\\Sophos SWEEP for NT\\SWNETSUP.EXE
O23 - Service: Sophos Anti-Virus - Sophos Plc - C:\\Program Files\\Sophos SWEEP for NT\\SWEEPSRV.SYS
O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\\Program Files\\Common Files\\Ulead Systems\\DVD\\ULCDRSvr.exe
MOR is offline