Offistart - Virtual Offices, Office Space, Business Support Services
*Home>>>Service Offices

I ran Hijack this and here is my logfile. Is there a problem?


I KNOW I AM BEING HACKED. I tried everything but I cannot remove them. I used the program HiJackThis and it gave my a logfile but I dont know what files to delete. Here is the logfile and please tell me what I should delete.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:43:02 PM, on 4/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ICROSO~1\userinit....
C:\WINDOWS\?racle\??rss.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\somedumbboy\Desktop\HiJackThis_...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper...
O2 - BHO: (no name) - {46669CE0-0252-05F9-0A10-2E00B9B58D98} - C:\WINDOWS\system32\pzhgtvz.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1...
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSET... /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSET... /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [d051a7ea] rundll32.exe "C:\WINDOWS\system32\ycrmsyox.dll",b
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\system32\ICROSO~1\userinit.e... -vt ndrv
O4 - HKCU\..\Run: [Latsqtc] C:\WINDOWS\?racle\??rss.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

--
End of file - 5098 bytes

I had a program that found ycrmsyox.dll Now everytime I start my computer it says DLL registry error.

1.Start by installing an anti-virus, I don't see any.

2. Remove all sites from your Trusted Zone, a malware has added sites there.

3. Uninstall Limewire. Infected downloads are likely the cause of your problems.

The rest of the clean-up is all yours...A good, automated, do-it-your-self, HijackThis analyzer is available.

"This system has been designed to help you quickly find information about everything contained in your HJT logs. We tap the greatest information databases we've been able to find to help you figure out which items in your log are OK and which ones are bad! Any information we have on the items will be displayed when you run your mouse over that line. Wherever possible you will be linked to a specific thread for help on that item."

Free at:
http://hjt.networktechs.com/

Good luck.

It doesn't look good.

You need to buy a new computer.

well read the list cant find anything about ycrmsyox.dll, and pzhgtvz.dll, i would advise running a full spyware scan with something like adaware se, and a good anti virus like avg

Tags
  Meeting Room   Meeting Space   Conference Room   Offices to Lease   Rent Offices   Business Centers   Service Offices   Branch Offices   Temporary Offices   Shared Offices   Commercial Space   Office Space
Related information
  • It's job was to settle agruments between agencies?

    Are we being quizzed or something? Are do you need help with this question for homework?

    ...
  • This was the first peace time draft.?

    No need for a draft during peace time.

    ...
  • Plz i need to know if this is right or wrong , if wrong what i should do ?

    TRUST ME - ITS A SCAM I know someone has it and been scam All you have to do is put it on spam and ingore it You can't have fbi do it cause its other country

    ...
  • Thepinkpatch.co.uk?

    I know, supposedly give you a free trail period etc. Real crooks and they should be ashamed of themselves. Luckily i did not go further than get your free trial pack, i hate it when people try to d...

  • Clinton Vs Obama?

    Let the record speak for itself--ONLY OBAMA WILL DO. Mama's for Obama!!

    ...
  • Have you made your choice? Clinton or Obama? Would you let me help?

    My choice goes to "None of the Above".

    ...
  • Question about computers..?

    these things can all be deleted as long as you don't use them yourself like limewire and itunes and the other install crap and stuff is just junk you don't really need AIM Aim install...

  • Creditor attorney falsyfying court document?

    Is the document they sent a judgment? Is that what it says? Sometimes creditors will send an unsigned proposed judgment as a way of letting you know they are serious. Check to see if there is a ...

  •  

    Categories--Copyright/IP Policy--Contact Webmaster