the last couple of days my computer ran into a couple of viruses and trojans. especially scvhost exe. Here's my hjt log. hopefully someone can back up me clean my computer. Thanks in advanceLogfile of turn Micro HijackThis v2.0.0 (BETA)Scan saved at 11:48:44 PM on 26/08/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\SYSTEM32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\spoolsv exeC:\WINDOWS\Explorer exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp exeC:\WINDOWS\system32\CTsvcCDA exeC:\WINDOWS\runservice exeC:\WINDOWS\System32\nvsvc32 exeC:\WINDOWS\System32\svchost exeC:\Program Files\Pure Networks\Network Magic\nmsrvc exeC:\schedule Files\Java\jre1.6.0_02\bin\jusched exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp exeC:\Program Files\iTunes\iTunesHelper exeC:\schedule Files\Pure Networks\communicate Magic\nmapp exeC:\PROGRA~1\MSNMES~1\msnmsgr exeC:\WINDOWS\system32\ctfmon exeC:\Documents and Settings\Famille\Desktop\PAULINE\Meteomedia\Weathe rEye exeC:\WINDOWS\System32\svchost exeC:\schedule Files\iPod\bin\iPodService exeC:\schedule Files\Common Files\Real\modify_OB\realsched exeC:\Program Files\Internet Explorer\IEXPLORE. EXEC:\Program Files\MSN Messenger\usnsvc exeC:\Download\Programs\HiJackThis_v2 exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,go away Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = F2 - REG:system ini: Shell=Explorer exe scvhost exeF3 - REG:win ini: run=C:\WINDOWS\scvhost exeO2 - BHO: Adobe PDF Reader cerebrate Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper dllO2 - BHO: SSVHelper categorise - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO2 - BHO: (no label) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient dllO4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\schedule Files\Java\jre1.6.0_02\bin\jusched exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32. EXE C:\WINDOWS\system32\NvCpl dll,NvStartupO4 - HKLM\..\Run: [TkBellExe] "C:\schedule Files\Common Files\Real\Update_OB\realsched exe" -osbootO4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper exe"O4 - HKLM\..\Run: [nmapp] "C:\schedule Files\Pure Networks\Network Magic\nmapp exe" -autorun -nosplashO4 - HKLM\..\Run: [Windows modify] C:\WINDOWS\scvhost exeO4 - HKLM\..\Run: [msconfig] C:\WINDOWS\scvhost exeO4 - HKLM\..\Run: [icq lite] C:\WINDOWS\scvhost exeO4 - HKLM\..\Run: [Update Checker] C:\WINDOWS\scvhost exeO4 - HKLM\..\Run: [AntiVir] C:\WINDOWS\scvhost exeO4 - HKLM\..\Run: [] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [Windows Update] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [msconfig] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [icq lite] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [modify Checker] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [AntiVir] C:\WINDOWS\scvhost exeO4 - HKLM\..\RunServices: [] C:\WINDOWS\scvhost exeO4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr exe" /backgroundO4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus exe" /WinStartO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [MétéoIMédia] C:\Documents and Settings\Famille\Desktop\PAULINE\Meteomedia\Weathe rEye exeO4 - HKUS\S-1-5-19\..\Run: [CTFMON. EXE] C:\WINDOWS\System32\CTFMON. EXE (User 'LOCAL function')O4 - HKUS\S-1-5-20\..\Run: [CTFMON. EXE] C:\WINDOWS\System32\CTFMON. EXE (User 'communicate function')O4 - HKUS\S-1-5-21-343818398-1960408961-725345543-500\..\Run: [CTFMON. EXE] C:\WINDOWS\System32\CTFMON. EXE (User 'Administrator')O4 - HKUS\S-1-5-18\..\Run: [CTFMON. EXE] C:\WINDOWS\System32\CTFMON. EXE (User 'SYSTEM')O4 - HKUS\. DEFAULT\..\Run: [CTFMON. EXE] C:\WINDOWS\System32\CTFMON. EXE (User 'fail user')O4 - Startup: Adobe Gamma lnk = C:\schedule Files\Common Files\Adobe\Calibration\Adobe Gamma Loader exeO4 - Global Startup: Adobe Acrobat Speed Launcher lnk = ?O8 - Extra context menu item: alter link aim to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient dll/AcroIECapture htmlO8 - Extra.
Forex Groups - Tips on Trading
Related article:
http://www.cybertechhelp.com/forums/showthread.php?t=163537
comments | Add comment | Report as Spam
|