GunZ Factor Forums

Go Back   GunZ Factor Forums > GunZFactor Forums > Technical Support

Become a Gold or Silver Member

Reply
 
Thread Tools
Old 11-24-2007, 06:47 PM   #1 (permalink)
Gunzfactorian Hero
 
Purr's Avatar
 

Join Date: Aug 2006
Posts: 3,551
Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.

Default hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:45:22 PM, on 24/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
C:\Users\Purr\Desktop\HiJackThis.exe

O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Media Center] RunDLL32.exe C:\Windows\ehome\ehuihlp.dll,BootMediaCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nm...MStarter25.cab
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - file:///F:/win/setup/iaieplay.dll
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/game...lugin11USA.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/s...wserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6...ws-i586-jc.cab
O16 - DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} (IAMCE Class) - file:///F:/win/setup/iamce.dll
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdf8305.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/game...lugin10USA.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3676 bytes
Purr is offline   Reply With Quote
Old 11-24-2007, 07:09 PM   #2 (permalink)
Nys
Moderator
 
Nys's Avatar
 

Join Date: Mar 2006
Location: Miami, Florida
Posts: 3,979
Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.
Send a message via AIM to Nys Send a message via MSN to Nys
Default Re: hijack this log

Before we begin anything, I would like you to download some sort of antivirus for your computer. Without one, anything I may ask you to do will ultimatly be useless.

One that I like to use a lot is AVG Antivirus. Download and install that, then post a new HJT log.
__________________
Yes, I'm a wow nerd ... ^^;
Nys is offline   Reply With Quote
Old 11-24-2007, 07:11 PM   #3 (permalink)
Gunzfactorian
 
Witch's Avatar
 

Join Date: Nov 2007
Location: 유럽
Posts: 161
Witch is a glorious beacon of light.Witch is a glorious beacon of light.Witch is a glorious beacon of light.

Send a message via MSN to Witch
Default Re: hijack this log

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Unnecessary (deactivated) entry that can be fixed. This entry was classified from our visitors as good. (Safe)

(unknown)
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nm...MStarter25.cab

Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! ( ? )

(unknown)
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - file:///F:/win/setup/iaieplay.dll

Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! ( ? )

(unknown)
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/game...lugin11USA.cab

Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! ( ? )

(unknown)
O16 - DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} (IAMCE Class) - file:///F:/win/setup/iamce.dll

Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! ( ? )

(unknown)
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdf8305.cab

Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! ( ? )

About the rest, safe / very safe.
__________________
Witch ~ 魔女 ~ 마녀

아이디: Antiquity ( Dead ... )

Playing rarely on alt...



^ Click, thank you. <3

Last edited by Witch; 11-24-2007 at 07:16 PM.
Witch is offline   Reply With Quote
Old 11-24-2007, 07:11 PM   #4 (permalink)
Gunzfactorian Hero
 
Purr's Avatar
 

Join Date: Aug 2006
Posts: 3,551
Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.

Default Re: hijack this log

run a scan with avg or just install?
Purr is offline   Reply With Quote
Old 11-24-2007, 07:19 PM   #5 (permalink)
Gunzfactorian Postcount God
 
AcceI's Avatar
 

Join Date: Dec 2006
Location: Calgary, AB
Posts: 10,471
AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.AcceI has a reputation beyond repute.
Default Re: hijack this log

Quote:
Originally Posted by Nys View Post
Before we begin anything, I would like you to download some sort of antivirus for your computer. Without one, anything I may ask you to do will ultimatly be useless.

One that I like to use a lot is AVG Antivirus. Download and install that, then post a new HJT log.
i dislike avg antivirus T.T
AcceI is offline   Reply With Quote
Old 11-24-2007, 07:39 PM   #6 (permalink)
Gunzfactorian Hero
 
Purr's Avatar
 

Join Date: Aug 2006
Posts: 3,551
Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.Purr has a reputation beyond repute.

Default Re: hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:45:22 PM, on 24/11/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
C:\Users\Purr\Desktop\HiJackThis.exe

O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Media Center] RunDLL32.exe C:\Windows\ehome\ehuihlp.dll,BootMediaCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter25 Class) - http://download.netmarble.com/web/nm...MStarter25.cab
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - file:///F:/win/setup/iaieplay.dll
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/game...lugin11USA.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - DivX Video Player - DivX Codec - DivX Converter - DivX Web Player - Download DivX for Windows
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6...ws-i586-jc.cab
O16 - DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} (IAMCE Class) - file:///F:/win/setup/iamce.dll
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdf8305.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/game...lugin10USA.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3676 bytes

o man to slow
Purr is offline   Reply With Quote
Old 11-24-2007, 07:51 PM   #7 (permalink)
Gunzfactorian Guardian
 
goodboy5's Avatar
 

Join Date: Jun 2007
Location: Perth, Australia
Posts: 1,605
goodboy5 has much to be proud of.goodboy5 has much to be proud of.goodboy5 has much to be proud of.goodboy5 has much to be proud of.goodboy5 has much to be proud of.goodboy5 has much to be proud of.

Send a message via AIM to goodboy5 Send a message via MSN to goodboy5 Send a message via Yahoo to goodboy5
Default Re: hijack this log

Try windows live onecare.
__________________
(Ijji: thekiller254)
Level: 51
Clan: Im long gone.
goodboy5 is offline   Reply With Quote
Old 11-24-2007, 08:34 PM   #8 (permalink)
Nys
Moderator
 
Nys's Avatar
 

Join Date: Mar 2006
Location: Miami, Florida
Posts: 3,979
Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.Nys has much to be proud of.
Send a message via AIM to Nys Send a message via MSN to Nys
Default Re: hijack this log

Quote:
Originally Posted by Purr View Post
run a scan with avg or just install?
Both ...
__________________
Yes, I'm a wow nerd ... ^^;
Nys is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT -5. The time now is 09:04 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34