Forums4Games
 

Go Back   Forums4Games > Welcome to Forums4Games v3.0 > Ozle & Friends

Ozle & Friends A great social experiment gone terribly wrong - Part of Forums4Games
Anything on here look dodgy - Logfile of HijackThis v1.99.1 Scan saved at 21:23:40, on 15/06/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 ...

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 15-06-07, 08:40 PM
Bring on the Trumpets!
Insane
 
Join Date: Oct 2006
Guild: The No Ozles club
Posts: 3,501
Blog Entries: 1
Aeribian IV is on a distinguished road
Points: 15,562, Level: 86 Points: 15,562, Level: 86 Points: 15,562, Level: 86
Activity: 100% Activity: 100% Activity: 100%
Anything on here look dodgy

Logfile of HijackThis v1.99.1
Scan saved at 21:23:40, on 15/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile\Mobile Phone Monitor\epmworker.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\Peter\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - Default URLSearchHook is missing
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DelPnPDirver] C:\Program Files\panasonic\panasonic KX-P7100\DelPnPD.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [My Search Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -2
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'yourreminder.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by133fd.bay133.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Can't see anything that looks like a nasty bit of software to me, a lot of crap yes, but nothing untoward.

Cant help getting other opinions though
__________________

-----------------------
Ozles Place
Reply With Quote
  #2 (permalink)  
Old 15-06-07, 08:47 PM
Bumhug360's Avatar
Busy playing Xbox
 
Join Date: Sep 2006
Posts: 1,745
Blog Entries: 12
My Mood:
Bumhug360 has disabled reputation
Points: 9,825, Level: 68 Points: 9,825, Level: 68 Points: 9,825, Level: 68
Activity: 100% Activity: 100% Activity: 100%
Wii Friend Code: 7952 3131 8962 1278
O10 - Broken Internet access because of LSP provider 'yourreminder.dll' missing



Check your hard disc drive with Spybot S&D from Kolla.de or LSPFix from Cexx.org. This entry should not be fixed! Your best bet to repair it is to try the LSPFix from Cexx.org.

Thats about it (www.hijackthis.de)

Hmm cut and paste didnt work all that great

Last edited by Volcano George; 15-06-07 at 08:47 PM.
Reply With Quote
  #3 (permalink)  
Old 15-06-07, 08:55 PM
Bring on the Trumpets!
Insane
 
Join Date: Oct 2006
Guild: The No Ozles club
Posts: 3,501
Blog Entries: 1
Aeribian IV is on a distinguished road
Points: 15,562, Level: 86 Points: 15,562, Level: 86 Points: 15,562, Level: 86
Activity: 100% Activity: 100% Activity: 100%
Well, the internet isnt actually broken (as im using this machine to post here0

I already got Hijack this, thats where the list came from

Checked with Spybots and virus scan, nothing so far although AVG wasnt updated by the looks of it so trying that now
__________________

-----------------------
Ozles Place
Reply With Quote
  #4 (permalink)  
Old 15-06-07, 08:56 PM
Bumhug360's Avatar
Busy playing Xbox
 
Join Date: Sep 2006
Posts: 1,745
Blog Entries: 12
My Mood:
Bumhug360 has disabled reputation
Points: 9,825, Level: 68 Points: 9,825, Level: 68 Points: 9,825, Level: 68
Activity: 100% Activity: 100% Activity: 100%
Wii Friend Code: 7952 3131 8962 1278
Hijackthis.de can post the logs and tells you whats right and wrong
Reply With Quote
  #5 (permalink)  
Old 15-06-07, 08:58 PM
Bring on the Trumpets!
Insane
 
Join Date: Oct 2006
Guild: The No Ozles club
Posts: 3,501
Blog Entries: 1
Aeribian IV is on a distinguished road
Points: 15,562, Level: 86 Points: 15,562, Level: 86 Points: 15,562, Level: 86
Activity: 100% Activity: 100% Activity: 100%
That is the log from Hijackthis.....
__________________

-----------------------
Ozles Place
Reply With Quote
  #6 (permalink)  
Old 15-06-07, 09:03 PM
Moturdrn's Avatar
Fear the Mantis, Unregistered!
WoW Characters
 
Join Date: Sep 2006
Guild: A^K
Location: West effin' Brom
Posts: 904
My Mood:
Moturdrn has disabled reputation
Points: 5,572, Level: 51 Points: 5,572, Level: 51 Points: 5,572, Level: 51
Activity: 19% Activity: 19% Activity: 19%
Wii Friend Code: 5394 1549 3581 2027
Yup, it is. But you can upload the log (either save the log then upload it to the hijackthis site, or copy and paste it into the text box), and it'll tell you what's potentially malicious etc
__________________

Karak-Hirn

Visko - Maladjusted dark magic junkie of a Sorceress
Tarlna - Fluffy Bride of Khaine... Have a hug! *STAB*

Last edited by Moturdrn; 15-06-07 at 09:03 PM.
Reply With Quote
  #7 (permalink)  
Old 15-06-07, 09:06 PM
Bring on the Trumpets!
Insane
 
Join Date: Oct 2006
Guild: The No Ozles club
Posts: 3,501
Blog Entries: 1
Aeribian IV is on a distinguished road
Points: 15,562, Level: 86 Points: 15,562, Level: 86 Points: 15,562, Level: 86
Activity: 100% Activity: 100% Activity: 100%
Just worked out what you mean!

*edit* and now Motty explained as well, heh
__________________

-----------------------
Ozles Place
Reply With Quote
  #8 (permalink)  
Old 16-06-07, 08:24 PM
Senior Member
 
Join Date: Sep 2006
Posts: 627
Davey is on a distinguished road
Points: 3,451, Level: 38 Points: 3,451, Level: 38 Points: 3,451, Level: 38
Activity: 10% Activity: 10% Activity: 10%
Avast is better than AVG
__________________
hey, guess what, i am playing wow again
Reply With Quote
  #9 (permalink)  
Old 16-06-07, 10:03 PM
Futt's Avatar
Teeny Weeny Member
I'll buy that for a Dollar
 
Join Date: Sep 2006
Posts: 1,031
Futt is on a distinguished road
Points: 4,947, Level: 47 Points: 4,947, Level: 47 Points: 4,947, Level: 47
Activity: 0% Activity: 0% Activity: 0%
Send a message via MSN to Futt Send a message via Skype™ to Futt Wii Friend Code: 8952137552695049
O4 - HKLM\..\RunOnce: [My Search Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -2

MySearch is a piece of crap spyware thingy... This line might just be a leftover from removing it tohugh.
__________________
http://www.futt.org/

Virtue is it's own punishment.
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Tags
    dodgy

    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are Off
    Refbacks are On
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    HWMNBN in dodgy fiat advert Bumhug360 Ozle & Friends 5 22-04-07 09:47 PM


    All times are GMT. The time now is 04:13 AM.


    Powered by vBulletin® Version 3.7.2
    Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
    SEO by vBSEO 3.2.0
    vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
    ©2000 - 2008 Forums4Games
    Dedicated to Laton