another hijackthis log

rykoryko new york
edited March 2004 in Science & Tech
What's happening everyone?

Can someone please review my hijackthis log? I have gone through it a couple of times, but i am not 100% on a couple of entries.

Logfile of HijackThis v1.97.7
Scan saved at 1:02:41 PM, on 3/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\rmctrl.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Creative\VideoBlaster Digital VCR\BT1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\rykouris\Desktop\apps\spyware detection\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newegg.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://us.creative.com/support/downloads/su/ocx/12119/CTSUEng.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37869.0628935185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://us.creative.com/support/downloads/su/ocx/12119/CTPID.cab

Anything look suspicious or evil? :hair:

Anyone know why i have 3 instances of C:\WINDOWS\system32\svchost.exe running in processes? What does this do?

Thanks for the help!

Comments

  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited March 2004
    Nothing looks bad in there, but I would remove some of the Creative items to save resources. Svchost.exe I believe is used to either run certain services or launch a list of services, and having multiple instances is perfectly normal.

    You can safely remove O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
  • rykoryko new york
    edited March 2004
    Gracias,

    Yeah i think i am going to remove all of the stuff at the bottom like the creative, AIM, quicktime, ofoto, etc... crap that is there now.

    Will removing this stuff affect the apps in any way? Will it all come back the next time i run one of these programs?
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited March 2004
    Creative thing (CTPID entry) is to be used for driver tuning with Creative's software.

    rmctrl.exe is part of PowerDVD XP 4.0. It is used with an infrared remote control that comes with that product, if not needed you can remove it.

    See this Link:
    http://www.reger24.de/prozesse/rmctrl.exe.php

    The AIM button, no idea.

    I would leave the googletoolbar3.dll entries (ALL of them) if you have the googletoolbar running, otherwise you can yank them.

    As said, multiple svchost entries are normal, I have 6 of those on my XP Pro boxes normally.

    Looking pretty good unless you have any of the above things not running, in which case there were some registry entries left behind. Also, the latest Google Toolbar is available from a link here:
    http://labs.google.com/ (there are some other nice little things there also).
  • KwitkoKwitko Sheriff of Banning (Retired) By the thing near the stuff Icrontian
    edited March 2004
    ryko wrote:
    Gracias,

    Yeah i think i am going to remove all of the stuff at the bottom like the creative, AIM, quicktime, ofoto, etc... crap that is there now.

    Will removing this stuff affect the apps in any way? Will it all come back the next time i run one of these programs?

    They shouldn't come back, although Quicktime seems to no matter what I do. I would try to manually disable them through their system tray icons first before removing them through HJT. There's a slim chance the programs might reinstall their entries.
  • rykoryko new york
    edited March 2004
    Thanks again guys,

    I think rmctrl.exe is for my creative dvcr remote, so i am going to leave it.........but all the other stuff is going bye-bye.
  • dodododo Landisville, PA
    edited March 2004
    quicktime has its own setting for the tray, look for the options menu.

    ~dodo
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited March 2004
    ryko wrote:
    Thanks again guys,

    I think rmctrl.exe is for my creative dvcr remote, so i am going to leave it.........but all the other stuff is going bye-bye.

    Good idea. Unless you USE AIM. Then leave the AIM stuff also. OR, upgrade the AIM stuff. AIM=AOL Instant Messenger. If not using AIM, junk the entries for it.

    John D.
Sign In or Register to comment.