Sitcoms Online - Main Page / Message Boards - Main Page / News Blog / Photo Galleries / DVD Reviews / Buy TV Shows on DVD and Blu-ray

View Today's Active Threads (No Chit Chat/Chit Chat Only) / View New Posts (No Chit Chat/Chit Chat Only) / Mark All Boards Read / Chit Chat Board

Chit Chat - Main Board / Games / Movies / Music / Sports / Video Games / Chit Chat - Classic / View Latest Threads in All Chit Chat Boards


Sitcoms Online Message Boards - Forums  

Go Back   Sitcoms Online Message Boards - Forums > Chit Chat > Chit Chat - Classic
Register Community View Today's Active Threads (No CC/CC Only) Search Photo Galleries Calendar FAQ

Notices

SitcomsOnline.com News Blog Headlines Facebook X/Twitter Bluesky Threads Instagram YouTube RSS

SitcomsOnline Digest: Paramount and Warner Merger on Hold; Paramount+ Cancels Crutch
Hulu's Desperate Housewives Wisteria Lane Block Party; Whitmer Thomas HBO Comedy Special
Fox's Stewie Announces Voice Cast; Clash of the Thundermans Premiere Date and Details, with Ariel Winter Joining the Cast
Nirvanna the Band the Show on Hulu & Hulu on Disney+; Netflix's Untold Returns August 25
First Look at Netflix's A Different World; Great American Family's 6th Annual Christmas Slate Begins in October with Laura Vandervoort Movie
Stuart Fails to Save the Universe Official Podcast; All-Star Cast for Elizabeth Banks Apple TV Comedy
Sitcom Stars on Talk Shows; This Week in Sitcoms (Week of July 20, 2026)


New on DVD and Blu-ray

Abbott Elementary - The Complete Fourth Season (DVD) The Office - The Complete Series - Superfan Extended Episodes (Blu-ray) The Bill Dana Show - The Complete Series (DVD) I Love Lucy - The Complete Series - 75th Anniversary Edition (Blu-ray) Perfect Strangers - The Complete Series (Blu-ray)

01/20/26 - The Woody Woodpecker and Friends Golden Age Collection (Blu-ray)
01/27/26 - The New Fred and Barney Show - The Complete Series (Blu-ray)
02/11/26 - Tom and Jerry - The Complete CinemaScope Collection (Blu-ray)
03/24/26 - Looney Tunes Collector's Vault - Volume 2 (Blu-ray)
04/11/26 - Abbott Elementary - The Complete Fourth Season (DVD)
04/21/26 - Famous Studios Champion Collection (Blu-ray) (DVD)
05/19/26 - I Love Lucy - The Complete Series - 75th Anniversary Edition (DVD)
05/19/26 - Looney Tunes Cartoons - The Complete Series (Blu-ray) (DVD)
06/16/26 - Difficult People - The Complete Series (Blu-ray)
06/30/26 - Dastardly and Muttley in Their Flying Machines - The Complete Series (Blu-ray)
07/14/26 - The Office - The Complete Series - Superfan Extended Episodes (Blu-ray)
07/28/26 - The Bill Dana Show - The Complete Series (DVD)
07/28/26 - I Love Lucy - The Complete Series - 75th Anniversary Edition (Blu-ray)
08/25/26 - Perfect Strangers - The Complete Series (Blu-ray)
09/22/26 - Bridget Loves Bernie - The Complete Series (Blu-ray)

More Recent and Upcoming TV DVD and Blu-ray Releases / TV Shows on DVD, Blu-ray and Prime Video / DVD Reviews Archive


Search Sitcoms Online:



Donate

Please make a donation if you can help with Sitcoms Online's web hosting costs. Thanks for your support!

We receive a small commission on all DVDs, Blu-rays, CDs, Books, and any other items ordered through our Amazon.com links as an associate. Thanks for using our links for your online shopping!

Reply
 
Thread Tools Search this Thread
Old 12-12-2005, 11:07 PM   #1
MsOrange
Bringin' Sexy Back
Forum Veteran
 
Join Date: Dec 27, 2004
Posts: 6,133
Default HiJack This

My computer has been acting really really sluggish lately... i've updated everything, ran a scan in safe mode, etc.. but it's still acting funny. I might just be being paranoid, but I was hoping someone with a little more experience dealing with these logs could help me out... thanks

Logfile of HijackThis v1.99.1
Scan saved at 10:05:20 PM, on 12/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\macromed\flash\GetFlash.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\Office10\POWERPNT.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinAce\WinAce.exe
C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\~AceTemp\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://prod.campuscruiser.com/PageSe...welcome&cp=168
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Profiles\default\gbbt0o5p.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\jkklk.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDT/ie/bridge-c18.cab
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://www.imgag.com/cp/install/AxCtp.cab
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.co...x/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll (file missing)
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
MsOrange is offline   Reply With Quote
Old 12-12-2005, 11:58 PM   #2
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,211
Default

looks like you've got the Vundo trojan and VX2.Look2Me malware in there, and there are probably things that you can remove to speed things up a bit

anyways stuff you need to look at:

Running processes:
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (check here for info to disable this)
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe (java update scheduler - you should be able to disable this)
C:\HP\KBD\KBD.EXE (this is a keyboard driver for the extra buttons on your keyboard - you may be able to do without it)
C:\Program Files\QuickTime\qttask.exe (quicktime component - you should be able to disable this)
C:\WINDOWS\system32\ctfmon.exe (this is installed with MS Office and can be removed if you dont use the speech functions)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (this can be disabled)

(you can probably reset all of these custom search page settings, but it wont speed up your computer any)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://prod.campuscruiser.com/PageSe...welcome&cp=168
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Profiles\default\gbbt0o5p.slt\prefs.js)

O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\jkklk.dll (file missing) (Vundo Trojan - removal tool & info
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (you can probably remove this toolbar - do a search for removal instructions)
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe (this is ANOTHER keyboard driver - you may be able to disable one of these)
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (this is an update manager/installer for MACROVISION copyright protection software - i would try to remove this)

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 (can be removed if you dont use this feature)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll (this is part of the VX2.Look2Me trojan - easiest removal is to update CoolWebShredder and run it twice in SAFEMODE, also AdAware has a removal tool you can download on their site)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (you can safely remove these)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (you can safely remove these)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (you can safely remove these)
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab (you can safely remove these)
O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll (file missing) (the Trojan MAY be gone, but still has some components still on your system, I would use the removal tool then search for this file and then remove these entries in HijackThis
robyrob is offline   Reply With Quote
Old 12-13-2005, 12:37 AM   #3
MsOrange
Bringin' Sexy Back
Forum Veteran
 
Join Date: Dec 27, 2004
Posts: 6,133
Default

you rock Roby
MsOrange is offline   Reply With Quote
Old 12-13-2005, 01:03 AM   #4
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,211
Default

thanks, just trying to help
robyrob is offline   Reply With Quote
Old 12-13-2005, 06:12 PM   #5
musicradio77
Disney Expert
Forum Veteran
 
musicradio77's Avatar
 
Join Date: Jul 14, 2003
Location: Brooklyn, NY USA
Posts: 6,475
Send a message via MSN to musicradio77 Send a message via Yahoo to musicradio77
Default

No thanks for the HijackThis. AVG Free Version is better than HijackThis.
__________________
Musicradio77 Productions
musicradio77 is offline   Reply With Quote
Old 12-13-2005, 08:30 PM   #6
theshark8777
Hats for Bats
Forum Veteran
 
theshark8777's Avatar
 
Join Date: Jan 23, 2001
Location: northeast Ohio.
Posts: 5,315
Default

Quote:
Originally Posted by musicradio77
No thanks for the HijackThis. AVG Free Version is better than HijackThis.
Aren't they two different programs that do two different things?
__________________
Who ate all the pecan Sandies??
theshark8777 is offline   Reply With Quote
Old 12-13-2005, 09:05 PM   #7
Penny Lane
Butter Pie
Forum Icon
 
Penny Lane's Avatar
 
Join Date: Jul 03, 2001
Location: Beneath the blue suburban skies
Posts: 51,300
Default

Quote:
Originally Posted by musicradio77
No thanks for the HijackThis. AVG Free Version is better than HijackThis.

Yes, I agree AVG is great! I have had no problems(knock on wood) since I downloaded it.
__________________
Vulgarity is no substitute for wit- Lady Violet Crawley
Penny Lane is offline   Reply With Quote
Old 12-13-2005, 11:26 PM   #8
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,211
Default

Quote:
Originally Posted by musicradio77
No thanks for the HijackThis. AVG Free Version is better than HijackThis.
i'm sorry, but you are comparing apples to Studebakers man.
robyrob is offline   Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:59 AM.


Although the administrators and moderators of the Sitcoms Online Message Boards will attempt to keep all objectionable messages off this forum, it is impossible for us to review all messages. All messages express the views of the author, and neither the owners of the Sitcoms Online Message Boards, nor vBulletin Solutions Inc. (developers of vBulletin) will be held responsible for the content of any message. The owners of the Sitcoms Online Message Boards reserve the right to remove, edit, move or close any thread for any reason.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.