Jump to content


hijack this and backups


  • You cannot reply to this topic
16 replies to this topic

#1 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 03:39 PM

I'm almost ashamed to admit it but I have never done a back up. Since joining this forum I've seen how you advise people in terms they understand! Can you tell me simply how to do one and what to use.
Also I have AVG, Microsoft Antispy, CCleaner and cws shredder. Can I put Spyware blaster with these or would you recommend anything else instead? Do I download Hijack this only if things go wrong, or download it now and save it for trouble?
Hazelnut :huh:
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#2 OFFLINE   Tarun

    Lunarian

  • Banned
  • PipPipPipPipPip
  • 3,071 posts

Posted 07 June 2005 - 04:09 PM

hazelnut, on Jun 7 2005, 11:39 AM, said:

I'm almost ashamed to admit it but I have never done a back up. Since joining this forum I've seen how you advise people in terms they understand! Can you tell me simply how to do one and what to use.
Also I have AVG, Microsoft Antispy, CCleaner and cws shredder. Can I put Spyware blaster with these or would you recommend anything else instead? Do I download Hijack this only if things go wrong, or download it now and save it for trouble?
Hazelnut  :huh:

<{POST_SNAPBACK}>

It would depend on the type of backup you're talking about.

#3 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 04:12 PM

Tarun, on Jun 7 2005, 04:09 PM, said:

It would depend on the type of backup you're talking about.

<{POST_SNAPBACK}>

Just a backup of files in case something went wrong, my progs, addresses etc.
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#4 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 04:18 PM

Quote

I'm almost ashamed to admit it but I have never done a back up. Since joining this forum I've seen how you advise people in terms they understand! Can you tell me simply how to do one and what to use.
depending on what you want to backup... most importantly is of coz your important documents... you can just copy them into a different drive if you have one... just in case C:\ break down... or burn them into a CD/DVD Rom or any optical drive... you may even want to consider zipping it to reduce the size of the file(s)...
registry key backup can be done using CCleaner itself before cleaning up your registry keys ("issue" tab)... just make sure you keep the backup in a safe place...
* must sure that under Option -> Advanced, the "Show prompt to backup registry issues" checkbox is CHECKED!
there are other programs that also allow you to backup your registry hive... such as ERUNT http://www.snapfiles...ad/dlerunt.html...

Quote

Also I have AVG, Microsoft Antispy, CCleaner and cws shredder. Can I put Spyware blaster with these or would you recommend anything else instead?
YES! spyware blaster should be included... you may also want to try using firefox instead of internet explorer... how about trying adaware too...

Quote

Do I download Hijack this only if things go wrong, or download it now and save it for trouble?
not necessary to use it only if you have problem... just run it and paste the log file in this forum... tarun will help you to browse through... :D
--==aGumon==--

#5 OFFLINE   Tarun

    Lunarian

  • Banned
  • PipPipPipPipPip
  • 3,071 posts

Posted 07 June 2005 - 04:34 PM

hazelnut, on Jun 7 2005, 12:12 PM, said:

Just a backup of files in case something went wrong, my progs, addresses etc.

<{POST_SNAPBACK}>

For this, you could simply burn a cd. Also, if you have another hard drive or partition you could also move the files there.

I do backups myself on occasion. I'll back up my Documents folder and a few others of importance.

agumon is right on many things. ;)

For what you really should have on your computer, visit here.

#6 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 04:41 PM

Quote

agumon is right on many things. wink.gif
got praised by tarun... hehe :D
--==aGumon==--

#7 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 04:59 PM

agumon, on Jun 7 2005, 04:41 PM, said:

got praised by tarun... hehe :D

<{POST_SNAPBACK}>

Just downloaded spyware blaster from your site Tarun. It says windows can't open this but to search online for a program to open it. Is this alright?
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#8 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 05:05 PM

Quote

Just downloaded spyware blaster from your site Tarun. It says windows can't open this but to search online for a program to open it. Is this alright?
you should be able to install it... just like any other program installer... make sure that the file extension is *.exe
--==aGumon==--

#9 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 05:13 PM

agumon, on Jun 7 2005, 05:05 PM, said:

you should be able to install it... just like any other program installer... make sure that the file extension is *.exe

<{POST_SNAPBACK}>

Its on my desktop says spywareblaster setup 34.4 when I click it nothing happens but what I said before. Have I done something wrong?
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#10 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 05:15 PM

try downloading here: http://www.majorgeeks.com/downloadget.php?...37615f4682b4cef
clean your internet cache first...
--==aGumon==--

#11 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 05:31 PM

agumon, on Jun 7 2005, 05:15 PM, said:

try downloading here: http://www.majorgeeks.com/downloadget.php?...37615f4682b4cef
clean your internet cache first...

<{POST_SNAPBACK}>

Thanks for the quick replies, Have (for me a major first) downloaded hijack and done a log. No idea at all what it means, the only thing I could make out was that Staples is my home page!! No, it's Google . Will do spyblaster next.
Logfile of HijackThis v1.99.1
Scan saved at 18:20:45, on 07/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSI\BToes Bluetooth Software\BTTray.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Bernard\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.staples.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.staples.co.uk/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1099047545781
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#12 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 05:36 PM

Quote

Thanks for the quick replies, Have (for me a major first) downloaded hijack and done a log. No idea at all what it means, the only thing I could make out was that Staples is my home page!! No, it's Google
you can post a new thread and paste your hijack-this log there...

Quote

Will do spyblaster next.
nothing much to do with spyware blaster actually... just check on "Enable all Protection" on the first menu... that is all... and remember to check for updates every one to two week... (the auto update feature is not free)
--==aGumon==--

#13 OFFLINE   agumon

    Digimon

  • Members
  • PipPipPipPip
  • 1,199 posts
  • Gender:Male
  • Location:Digital World

Posted 07 June 2005 - 05:39 PM

didnt saw your hijack-this log file earlier...

Edited by agumon, 07 June 2005 - 05:43 PM.

--==aGumon==--

#14 OFFLINE   Tarun

    Lunarian

  • Banned
  • PipPipPipPipPip
  • 3,071 posts

Posted 07 June 2005 - 06:38 PM

Generated by Tarun's HijackThis Converter.

Changed registry value. Safe to remove:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

Created registry value. Safe to remove:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.staples.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

Enumeration of suspicious auto-loading registry entries. Safe to remove:
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?

Extra IE context menu items. Safe to remove:
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm

Extra "Tools" menu items and buttons. Safe to remove:
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

Changing of IERESET.INF. Safe to remove:
O14 - IERESET.INF: START_PAGE_URL=http://www.staples.co.uk/

#15 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 07 June 2005 - 07:20 PM

Tarun, on Jun 7 2005, 06:38 PM, said:

Generated by Tarun's HijackThis Converter.

Changed registry value.  Safe to remove:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

Created registry value.  Safe to remove:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.staples.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

Enumeration of suspicious auto-loading registry entries.  Safe to remove:
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?

Extra IE context menu items.  Safe to remove:
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie_ctx.htm

Extra "Tools" menu items and buttons.  Safe to remove:
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

Changing of IERESET.INF.  Safe to remove:
O14 - IERESET.INF: START_PAGE_URL=http://www.staples.co.uk/

<{POST_SNAPBACK}>


Can't believe all the help you people give out,
Did the changes apart from Google as it is my home page. When I clicked fix checked it did I think but also said I had to tell the maker (I've forgotten his name) and say that- error hash sign 52(bad file name or number in sub getlong path(? exe)- had occured. Will every thing be alright ? I'll try and do another hi-jack thing

of HijackThis v1.99.1
Scan saved at 20:10:07, on 07/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSI\BToes Bluetooth Software\BTTray.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Bernard\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1099047545781
O17 - HKLM\System\CCS\Services\Tcpip\..\{38E1DD90-1702-4DB2-B399-194079CBB33D}: NameServer = 80.225.248.50 80.225.248.58
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\MSI\BToes Bluetooth Software\bin\btwdins.exe
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: X10 Device Network Service (x10nets

sorry to be so a bother! Hazelnut
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs

#16 OFFLINE   Tarun

    Lunarian

  • Banned
  • PipPipPipPipPip
  • 3,071 posts

Posted 07 June 2005 - 08:59 PM

Simply redo the same ones. :)

#17 OFFLINE   hazelnut

    try to stay calm

  • Moderators
  • 9,833 posts
  • Gender:Female
  • Location:Huddersfield uk

Posted 08 June 2005 - 01:18 PM

Tarun, on Jun 7 2005, 08:59 PM, said:

Simply redo the same ones.  :)

<{POST_SNAPBACK}>


Everything seems fine now, thanks for everything, hope to talk to you all again sometime.
P.S. Learnt an awful lot! :rolleyes:

Hazelnut
CCLEANER, RECUVA, DEFRAGGLER AND SPECCY DOCUMENTATION CAN BE FOUND HERE

http://www.piriform.com/docs