|
|
DrJugz
new user
Reg'd: Thu
Posts: 2
Loc: USA
|
|
Please - I really trust that you guys know what I can do to clean my computer up and make it more secure
I'm grateful for all advice.
Thank you
StartupList report, 10/22/2009, 1:12:05 PM StartupList version: 1.52.2 Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE Detected: Windows XP SP3 (WinNT 5.01.2600) Detected: Internet Explorer v8.00 (8.00.6001.18702) * Using default options ==================================================
Running processes:
C:\WINDOWS\System32\smss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\netdde.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\TUProgSt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\VideoLAN\VLC\vlc.exe C:\Program Files\iTunes\iTunes.exe C:\WINDOWS\SYSTEM32\cidaemon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\SYSTEM32\taskmgr.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Documents and Settings\David\My Documents\Downloads\RootkitBuster_2.80.1071\RootkitBuster.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\SNDVOL32.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup: [C:\Documents and Settings\David\Start Menu\Programs\Startup] Trillian.lnk = C:\Program Files\Trillian\trillian.exe
Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup nwiz = nwiz.exe /install SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe" Adobe ARM = "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
--------------------------------------------------
Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Title = UnHackMe Rootkit Check
--------------------------------------------------
Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Messenger (Yahoo!) = "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet Simplify Media = "C:\Program Files\Simplify Media\SimplifyMedia.exe"
--------------------------------------------------
Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents] =
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found* run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run= HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\72NAME~1.SCR drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} WormRadar.com IESiteBlocker.NavFilter - (no file) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9} JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
--------------------------------------------------
Enumerating Task Scheduler jobs:
1-Click Maintenance.job AppleSoftwareUpdate.job GoogleUpdateTaskMachineCore.job GoogleUpdateTaskMachineUA.job User_Feed_Synchronization-{C7C5C855-3E9B-4E4A-992B-2A6317C7FFB6}.job
--------------------------------------------------
Enumerating Download Program Files:
[ScrabbleCubes Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\SCRABB~1.OCX CODEBASE = http://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab
[ZenGems Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\zengems.ocx CODEBASE = http://www.worldwinner.com/games/v54/zengems/zengems.cab
[Office Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\OGACheckControl.DLL CODEBASE = http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
[Microsoft Data Collection Control] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MSDcode.dll CODEBASE = https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
[Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[SkillGam Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\skillgam.ocx CODEBASE = http://www.worldwinner.com/games/v47/skillgam/skillgam.cab
[FunGamesLoader Object] InProcServer32 = C:\WINDOWS\Downloaded Program Files\FunGamesLoader.dll CODEBASE = http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
[TPIR Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\tpir.ocx CODEBASE = http://www.worldwinner.com/games/v50/tpir/tpir.cab
[Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Adobe\Director\swdir.dll CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[Symantec AntiVirus scanner] InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll CODEBASE = http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
[Brickout Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\brickout.ocx CODEBASE = http://www.worldwinner.com/games/v48/brickout/brickout.cab
[Pool Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\pool.ocx CODEBASE = http://www.worldwinner.com/games/v50/pool/pool.cab
[Jigsaw Genius Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\jigsaw.ocx CODEBASE = http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab
[SolitaireRush Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\SOLITA~1.OCX CODEBASE = http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
[WWHearts Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\wwhearts.ocx CODEBASE = http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
[BJA Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\bja.ocx CODEBASE = http://www.worldwinner.com/games/v63/bjattack/bja.cab
[MUCatalogWebControl Class] InProcServer32 = C:\WINDOWS\system32\MicrosoftUpdateCatalogWebControl.dll CODEBASE = http://catalog.update.microsoft.com/v7/s...b?1209288830937
[Bejeweled Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\BEJEWE~1.OCX CODEBASE = http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
[SpiderSolitaire Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\SPIDER~1.OCX CODEBASE = http://www.worldwinner.com/games/v56/spidersolitaire/spidersolitaire.cab
[Blockwerx Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\BLOCKW~1.OCX CODEBASE = http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab
[WUWebControl Class] InProcServer32 = C:\WINDOWS\system32\wuweb.dll CODEBASE = http://www.update.microsoft.com/windowsu...b?1205032081547
[Symantec RuFSI Utility Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll CODEBASE = http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
[FreeCell Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\freecell.ocx CODEBASE = http://www.worldwinner.com/games/v41/freecell/freecell.cab
[MUWebControl Class] InProcServer32 = C:\WINDOWS\system32\muweb.dll CODEBASE = http://www.update.microsoft.com/microsof...b?1205109141234
[OnlineScanner Control] InProcServer32 = C:\PROGRA~1\ESET\ESETON~1\ONLINE~1.OCX CODEBASE = http://download.eset.com/special/eos-beta/OnlineScanner.cab
[Wwlaunch Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab
[WordMojo Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\wordmojo.ocx CODEBASE = http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab
[Cubis Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\cubis.ocx CODEBASE = http://www.worldwinner.com/games/v57/cubis/cubis.cab
[Sol Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\sol.ocx CODEBASE = http://www.worldwinner.com/games/v46/sol/sol.cab
[WoF Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\wof.ocx CODEBASE = http://www.worldwinner.com/games/v57/wof/wof.cab
[WwLuxor Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\luxor.ocx CODEBASE = http://www.worldwinner.com/games/v49/luxor/luxor.cab
[SwapIt Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\swapit.ocx CODEBASE = http://www.worldwinner.com/games/v67/swapit/swapit.cab
[Hangman Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\hangman.ocx CODEBASE = http://www.worldwinner.com/games/v41/hangman/hangman.cab
[Tilecity Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\tilecity.ocx CODEBASE = http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
[Royal Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\royal.ocx CODEBASE = http://www.worldwinner.com/games/v45/royal/royal.cab
[DinerDash Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\DINERD~1.OCX CODEBASE = http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
[Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc4.cab
[Paint Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\paint.ocx CODEBASE = http://www.worldwinner.com/games/v43/paint/paint.cab
[FamilyFeud Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\FAMILY~1.OCX CODEBASE = http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
[Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
[FlashXControl Object] InProcServer32 = C:\WINDOWS\system32\FlashAX\FlashAX.ocx CODEBASE = https://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
[GolfSol Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\golfsol.ocx CODEBASE = http://www.worldwinner.com/games/v44/golfsol/golfsol.cab
[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}] CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
[WWSpades Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\wwspades.ocx CODEBASE = http://www.worldwinner.com/games/v53/wwspades/wwspades.cab
[Flash Casino Helper Control] InProcServer32 = C:\WINDOWS\system32\FlashAX2\iefax.dll CODEBASE = https://plugins.valueactive.eu/flashax/iefax.cab
[PCPitstop Exam] InProcServer32 = C:\WINDOWS\Downloaded Program Files\pcpitstop2.dll CODEBASE = http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll NameSpace #5: C:\WINDOWS\system32\wshbth.dll
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll UPnPMonitor: C:\WINDOWS\system32\upnpui.dll
-------------------------------------------------- End of report, 14,579 bytes Report generated in 0.172 seconds
Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
|
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 31982
Loc: belfast
|
|
Welcome to the Webuser forum. 
Please go to the top of HIJACK THIS LOGS forum, read the post at the top from THE FAT CONTROLLER which explains how to post a HIJACK THIS LOG, Not a startup list, and post the log back in this thread.
-------------------- IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.
When the only tool you own is a hammer, every problem begins to look like a nail.
|
DrJugz
new user
Reg'd: Thu
Posts: 2
Loc: USA
|
|
I apologize for seemingly dropping a chromosome somewhere shortly after registering and posting that mistake.
Please forgive me. Here is the log. 
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:23:50 PM, on 10/22/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\netdde.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Simplify Media\SimplifyMedia.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Trillian\trillian.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\VideoLAN\VLC\vlc.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\SYSTEM32\cidaemon.exe C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\PROGRAM FILES\GOOGLE\CHROME\APPLICATION\CHROME.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O1 - Hosts: 200.124.131.116 casinocontroller.com O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe" O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Microgaming\Poker\pokertimeMPP\MPPoker.exe (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra button: Grand Mondial Casino - 014FA561-CE56-4EFA-A297-A40307E303B0 - C:\Microgaming\Casino\GrandMondial\Casinogame.exe (HKCU) O9 - Extra button: Blackjack Ballroom Casino - 4E90F4D8-39D4-4333-8405-FA886C6BE559 - C:\Microgaming\Casino\BJBallroom\Casinogame.exe (HKCU) O9 - Extra button: Sun Vegas - EDDC56AE-3B81-473B-B0E8-6F933C1F41A4 - C:\Microgaming\Casino\SunVegas\Casinogame.exe (HKCU) O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\David\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU) O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\David\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU) O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v47/scrabblecubes/scrabblecubes.cab O16 - DPF: {038E2507-7A48-41E2-94AD-7F23D199AF4E} (ZenGems Control) - http://www.worldwinner.com/games/v54/zengems/zengems.cab O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - http://www.worldwinner.com/games/v47/skillgam/skillgam.cab O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.com/games/v48/brickout/brickout.cab O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v50/pool/pool.cab O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/s...b?1209288830937 O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} (SpiderSolitaire Control) - http://www.worldwinner.com/games/v56/spidersolitaire/spidersolitaire.cab O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsu...b?1205032081547 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v41/freecell/freecell.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1205109141234 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v46/sol/sol.cab O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v67/swapit/swapit.cab O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v41/hangman/hangman.cab O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - http://www.worldwinner.com/games/v44/golfsol/golfsol.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v53/wwspades/wwspades.cab O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
-- End of file - 14030 bytes
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 31982
Loc: belfast
|
|
the first thing we need to sort out is your security. you have no anti virus or firewall running.
Go HERE and get a FREE anti virus and firewall. run a full scan with the anti virus then post a fresh HJT log.
-------------------- IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.
When the only tool you own is a hammer, every problem begins to look like a nail.
|
|
|