Sunday, August 2, 2009

IEXPLORE.EXE problem?

Logfile of HijackThis v1.99.1


Scan saved at 12:39:40 AM, on 3/13/2007


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)





Running processes:


C:\windows\System32\smss.exe


C:\windows\system32\csrss.exe


C:\windows\system32\winlogon.exe


C:\windows\system32\services.exe


C:\windows\system32\lsass.exe


C:\windows\system32\svchost.exe


C:\windows\system32\svchost.exe


C:\windows\System32\svchost.exe


C:\windows\system32\svchost.exe


C:\windows\system32\svchost.exe


C:\windows\system32\spoolsv.exe


C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr....


C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc....


C:\WINDOWS\system32\CTSVCCDA.EXE


C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe


C:\windows\system32\nvsvc32.exe


C:\windows\system32\svchost.exe


C:\windows\System32\alg.exe


C:\windows\system32\wscntfy.exe


C:\windows\system32\WgaTray.exe


C:\windows\Explorer.EXE


C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe


C:\windows\system32\ctfmon.exe


C:\Program Files\Google\GoogleToolbarNotifier\1.2.1...


C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE


C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe


C:\DOCUME~1\Jerome\LOCALS~1\Temp\Tempo... Directory 3 for HijackThis.zip\HijackThis.exe





R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =


R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)


O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7...


O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll


O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll


O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll


O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll


O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt....


O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)


O3 - Toolbar: %26amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll


O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe


O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S


O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe


O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1...


O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.ex... -quiet


O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"


O8 - Extra context menu item: %26amp;AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html


O8 - Extra context menu item: %26amp;Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm


O8 - Extra context menu item: E%26amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCE...


O8 - Extra context menu item: Send To %26amp;Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm


O8 - Extra context menu item: Yahoo! %26amp;Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm


O8 - Extra context menu item: Yahoo! %26amp;Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm


O8 - Extra context menu item: Yahoo! %26amp;SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll


O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll


O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INETREPL.DLL


O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INETREPL.DLL


O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INETREPL.DLL


O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\windows\system32\shdocvw.dll


O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm


O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)


O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=3...


O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...


O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll


O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe


O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.ex...


O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.ex...


O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe


O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE


O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe


O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


O23 - Service: NTLOAD - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)


O23 - Service: NTSVCMGR - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)


O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe


O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

IEXPLORE.EXE problem?
Yuck....Well, I think you should download the Spyware Terminator or Ad-aware by Lavasoft - and check your computer for spy- and malwares. Both softwares are free.





And a good antivirus software is available for free, too. I recommend you "Antivir" - free download at http://www.free-av.com -- but, please, DO make regulary upgrades of all these softwares every other day!





Good luck!!!





Greetings from Germany
Reply:Go to this website. http://www.hijackthis.de/ and paste your Hijackthis log file into the space there and Click "Analyze"





It would come p with a full analysis of what you need to look out for and what you can safely remove. You can remove the items that have "X" next to them





Also, I would advise to uninstall yahoo, google and viewpoint toolbars. If you use Firefox (or even IE 7), those browsers have popup blockers and search bars built into them. And the yahoo and google toolbars are sometimes gateways for spyware.








I also saw that you Use AVG. You might want to check a process in your task manager called guard.exe. It is linked to AVG and I've known it to take up and lot of processor capacity from time to time. (It goes hay-wire sometimes)





I hope this helps.


No comments:

Post a Comment