Christian Darrall
Active Member
errm people i really do think i have a problem (spyware)
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Q2hyaXN0aWFuIERhcnJhbGw\command.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\BearShare\BearShare.exe
C:\WINNT\wupdmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\osaupd.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Windows Media Player\mplayer2.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\explorer.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\Icp3p2BxK0.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
c:\Program Files\paytime.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\0mcamcap.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\TheMatrixHasYou.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\uninstDsk.exe
C:\Documents and Settings\Christian Darrall\Local Settings\Temp\wz1214\HijackThis.exe
C:\WINNT\uninstDsk.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.5.5.2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINNT\system32\winbrume.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINNT\system32\azesearch4.ocx
O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINNT\system32\iasada.dll
O3 - Toolbar: Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINNT\system32\azesearch4.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [rock] rock.exe
O4 - HKLM\..\Run: [intell321.exe] C:\WINNT\system32\intell321.exe
O4 - HKLM\..\Run: [c3252441.exe] C:\WINNT\system32\c3252441.exe
O4 - HKLM\..\Run: [46bd1e6e.exe] C:\WINNT\system32\46bd1e6e.exe
O4 - HKLM\..\Run: [ntdll.dll] c:\Program Files\paytime.exe
O4 - HKLM\..\Run: [d321301b.exe] C:\WINNT\system32\d321301b.exe
O4 - HKLM\..\Run: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKLM\..\RunServices: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [c3252441.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\c3252441.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [46bd1e6e.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\46bd1e6e.exe
O4 - HKCU\..\Run: [d321301b.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\d321301b.exe
O4 - HKCU\..\Run: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: wupdmgr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/en-us/wlscbase7617.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1146996718421
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F41F3E82-322D-49E3-9D9E-49438A9656CC}: NameServer = 62.31.112.39,62.31.144.39
O20 - Winlogon Notify: prwsks - C:\WINNT\
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\system32\dcom_16.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\Q2hyaXN0aWFuIERhcnJhbGw\command.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
ermm do i have to say any more
and this was suppost to be a computer for homework, coursework and safe internet exploring, hah i dont think so some how.
plz can you send a fix to a private message, use as much detail as pos plz, only cuz ill be away in spain and a close mate will fix it for me.
and if he talks on threads I WANNA KNOW bibi
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Q2hyaXN0aWFuIERhcnJhbGw\command.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\BearShare\BearShare.exe
C:\WINNT\wupdmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\osaupd.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Windows Media Player\mplayer2.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\explorer.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\Icp3p2BxK0.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
c:\Program Files\paytime.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\0mcamcap.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\system32\TheMatrixHasYou.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\WINNT\uninstDsk.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\WINNT\uninstDsk.exe
C:\Documents and Settings\Christian Darrall\Local Settings\Temp\wz1214\HijackThis.exe
C:\WINNT\uninstDsk.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.5.5.2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINNT\system32\winbrume.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINNT\system32\azesearch4.ocx
O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINNT\system32\iasada.dll
O3 - Toolbar: Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINNT\system32\azesearch4.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [rock] rock.exe
O4 - HKLM\..\Run: [intell321.exe] C:\WINNT\system32\intell321.exe
O4 - HKLM\..\Run: [c3252441.exe] C:\WINNT\system32\c3252441.exe
O4 - HKLM\..\Run: [46bd1e6e.exe] C:\WINNT\system32\46bd1e6e.exe
O4 - HKLM\..\Run: [ntdll.dll] c:\Program Files\paytime.exe
O4 - HKLM\..\Run: [d321301b.exe] C:\WINNT\system32\d321301b.exe
O4 - HKLM\..\Run: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKLM\..\RunServices: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [c3252441.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\c3252441.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [46bd1e6e.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\46bd1e6e.exe
O4 - HKCU\..\Run: [d321301b.exe] C:\Documents and Settings\Christian Darrall\Local Settings\Application Data\d321301b.exe
O4 - HKCU\..\Run: [0mcamcap] C:\WINNT\system32\0mcamcap.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: wupdmgr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/en-us/wlscbase7617.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1146996718421
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F41F3E82-322D-49E3-9D9E-49438A9656CC}: NameServer = 62.31.112.39,62.31.144.39
O20 - Winlogon Notify: prwsks - C:\WINNT\
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\system32\dcom_16.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\Q2hyaXN0aWFuIERhcnJhbGw\command.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
ermm do i have to say any more
and this was suppost to be a computer for homework, coursework and safe internet exploring, hah i dont think so some how.
plz can you send a fix to a private message, use as much detail as pos plz, only cuz ill be away in spain and a close mate will fix it for me.
and if he talks on threads I WANNA KNOW bibi
Last edited: