my hijack this logfile-plz help

Status
Not open for further replies.

sagar_mutha

Broken In
hello ppl
im running a windows xp sp2 operating system
of late my pc has repeatedly started hanging and it does not shut down as well
i have to switch my pc off directly!
this is my hijack this logfile
plz help!



Logfile of HijackThis v1.98.2
Scan saved at 10:11:06 AM, on 10/15/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\system32\cisvc.exe
G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
G:\Program Files\Norton AntiVirus1\navapsvc.exe
G:\WINDOWS\system32\pctspk.exe
G:\PROGRA~1\QUICKH~1\qhwscsvc.exe
G:\PROGRA~1\QUICKH~1\QHONSVC.EXE
G:\Program Files\Norton AntiVirus1\SAVScan.exe
G:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
G:\Program Files\MSN Messenger\msnmsgr.exe
E:\Program Files\Ares\Ares.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
G:\Program Files\Opera75\opera.exe
G:\Documents and Settings\Sagar\My Documents\utils\hijackthis\HijackThis.exe
G:\Program Files\Symantec\LiveUpdate\AUpdate.exe

O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - G:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - G:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll
O4 - HKCU\..\Run: [Yahoo! Pager] G:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "G:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ares] "E:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - G:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Download with &DAP - G:\PROGRA~1\DAP1\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - G:\PROGRA~1\DAP1\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager... - G:\Program Files\J River\Media Jukebox\DMDownload.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - G:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - G:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: g:\program files\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: g:\program files\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: g:\program files\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: g:\program files\google\google desktop search\googledesktopnetwork1.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA3CD7C7-2646-4778-BDF4-88CAC22D7F15}: NameServer = 61.1.96.65 61.1.128.5
 

ice

In the zone
G:\PROGRA~1\QUICKH~1\qhwscsvc.exe
G:\PROGRA~1\QUICKH~1\QHONSVC.EXE

That i think means ur runnin the QUickheal AV too along with ur Norton.

Id suggest u first try shuttin these files with task manager and then Uninstalling quick heal.

Secondly, im not sure , bout Nav helper, i dont think its spyware, but sounds like a typical spyware program name ,
 

Kl@w-24

Slideshow Bob
Using 2 antivirus softwares together is NOT recommended and can lead to unforeseen difficulties. I'd suggest that u uninstall one of th antivirus programs. Also, did u uncheck th option to display ads while installing Ares ? It cud cause a few problems if u didn't.
 

it_waaznt_me

Coming back to life ..
To proceed with your HijackThis log, Run HijackThis again and put a CheckMark next to these entries and Click on Fix Checked.
Please make sure that all Internet Explorer and Windows Explorer windows are closed.
sagar_mutha said:
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: NavExcel Toolbar - {5AA06644-BC46-4220-A460-47A6EB47C96D} - G:\Program Files\NavExcel Search Toolbar\NavExcelBar.dll

Btw ... Your log looks pretty clean to me ..
 
Status
Not open for further replies.
Top Bottom