| Result |
Good-Bad |
Search |
Hijack This Log File Entry |
| | |
| Bad | 0 - 13 | SS(19,354) - GS Comments_(0)
| R0 - HKCU\Software\Microsoft\InternetExplorer\Main,Local Page = |
| Unknown | 0 - 0 | SS(3,264) - GS Comments_(0)
| C:\Program Files\Google\Update\GoogleUpdate.exe |
| Unknown | 0 - 0 | SS(0) - GS Comments_(0)
| F:\Program Files\Java\jre6\bin\jqs.exe |
| Unknown | 0 - 0 | SS(0) - GS Comments_(0)
| O23 - Service: Java Quick Starter(JavaQuickStarterService) - Sun Microsystems, Inc.- F:\Program Files\Java\jre6\bin\jqs.exe |
| Unknown | 0 - 0 | SS(620) - GS Comments_(0)
| F:\Program Files\Java\jre6\bin\jusched.exe |
| Unknown | 0 - 0 | SS(620) - GS Comments_(0)
| O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\ProgramFiles\Java\jre6\bin\jusched.exe" |
| Unknown | 0 - 0 | SS(150) - GS Comments_(0)
| O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\ProgramFiles\Zone Labs\ZoneAlarm\zlclient.exe" |
| Unknown | 0 - 0 | SS(11) - GS Comments_(0)
| C:\WINDOWS\system32\JMRaidTool.exe |
| Unknown | 0 - 0 | SS(92) - GS Comments_(0)
| F:\ProgramFiles\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe |
| Unknown | 0 - 0 | SS(87) - GS Comments_(0)
| F:\ProgramFiles\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe |
| Unknown | 0 - 0 | SS(33) - GS Comments_(0)
| F:\Program Files\Logitech\QuickCam\Quickcam.exe |
| Unknown | 0 - 0 | SS(12,194) - GS Comments_(0)
| O4 - HKLM\..\Run: [BCWipeTM Startup] "f:\ProgramFiles\Jetico\BCWipe\BCWipeTM.exe" startup |
| Unknown | 0 - 0 | SS(92) - GS Comments_(0)
| O4 - HKLM\..\Run: [TrueImageMonitor.exe]F:\ProgramFiles\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe |
| Unknown | 0 - 0 | SS(87) - GS Comments_(0)
| O4 - HKLM\..\Run: [AcronisTimounterMonitor]F:\ProgramFiles\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe |
| Unknown | 0 - 0 | SS(340) - GS Comments_(0)
| O4 - HKLM\..\Run: [LogitechQuickCamRibbon]"F:\Program Files\Logitech\QuickCam\Quickcam.exe"/hide |
| Unknown | 0 - 0 | SS(44) - GS Comments_(0)
| O4 - HKCU\..\Run: [AlcoholAutomount] "f:\ProgramFiles\Alcohol Soft\Alcohol 120\axcmd.exe"/automount |
| Unknown | 0 - 0 | SS(7,523) - GS Comments_(0)
| O4 -HKUS\S-1-5-21-1606980848-1767777339-839522115-1008\..\Run: [ctfmon.exe]C:\WINDOWS\system32\ctfmon.exe (User 'Doggie') |
| Unknown | 0 - 0 | SS(7,522) - GS Comments_(0)
| O4 -HKUS\S-1-5-21-1606980848-1767777339-839522115-1024\..\Run: [ctfmon.exe]C:\WINDOWS\system32\ctfmon.exe (User 'Gerard') |
| Unknown | 0 - 0 | SS(7,602) - GS Comments_(0)
| O4 - S-1-5-21-1606980848-1767777339-839522115-1024Startup: Launch Microsoft Office Outlook.lnk =F:\Program Files\MicrosoftOffice\OFFICE11\OUTLOOK.EXE (User 'Gerard') |
| Unknown | 0 - 0 | SS(7,602) - GS Comments_(0)
| O4 - S-1-5-21-1606980848-1767777339-839522115-1024User Startup: Launch Microsoft Office Outlook.lnk= F:\Program Files\MicrosoftOffice\OFFICE11\OUTLOOK.EXE (User 'Gerard') |
| Unknown | 0 - 0 | SS(12,522) - GS Comments_(0)
| O4 - Global Startup: ZapSqm.cmd |
| Unknown | 0 - 0 | SS(23) - GS Comments_(0)
| O16 - DPF: {BE153019-DCDB-479E-827B-C2AAB8CDCA64}(OSDetect Control) -https://images.synovate.com/americas/5j6400/osdetect.ocx |
| Unknown | 0 - 0 | SS(3,264) - GS Comments_(0)
| O23 - Service: Google Update Service(gupdate1c9878fb37ee722) (gupdate1c9878fb37ee722)- Google Inc. - C:\ProgramFiles\Google\Update\GoogleUpdate.exe |
| Good | 2 - 0 | SS(69) - GS Comments_(0)
| C:\Program Files\CommonFiles\Acronis\Schedule2\schedul2.exe |
| Good | 2 - 0 | SS(50) - GS Comments_(0)
| C:\Program Files\CommonFiles\Acronis\Schedule2\schedhlp.exe |
| Good | 1 - 0 | SS(50) - GS Comments_(0)
| O4 - HKLM\..\Run: [Acronis Scheduler2 Service]"C:\Program Files\CommonFiles\Acronis\Schedule2\schedhlp.exe" |
| Good | 1 - 0 | SS(15) - GS Comments_(1)
| O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}(Crucial cpcScan) -http://www.crucial.com/controls/cpcScanner.cab |
| Good | 1 - 0 | SS(150) - GS Comments_(0)
| F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe |
| Good | 2 - 0 | SS(14) - GS Comments_(1)
| O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE |
| Good | 1 - 0 | SS(41,238) - GS Comments_(0)
| O15 - Trusted Zone:http://download.windowsupdate.com |
| Good | 1 - 0 | SS(34) - GS Comments_(0)
| C:\WINDOWS\System32\dllhost.exe |
| Good | 1 - 0 | SS(487) - GS Comments_(0)
| F:\Program Files\Mozilla Firefox\firefox.exe |
| Good | 2 - 0 | SS(40) - GS Comments_(3)
| C:\WINDOWS\RTHDCPL.EXE |
| Good | 2 - 0 | SS(40) - GS Comments_(0)
| O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE |
| Good | 1 - 0 | SS(255) - GS Comments_(0)
| O4 - Global Startup: Adobe Reader Speed Launch.lnk= F:\Program Files\Adobe\Acrobat7.0\Reader\reader_sl.exe |
| Good | 1 - 0 | SS(208) - GS Comments_(0)
| O2 - BHO: (no name) -{53707962-6F74-2D53-2644-206D7942484F} -F:\PROGRA~1\SPYBOT~1\SDHelper.dll |
| Good | 2 - 0 | SS(45,449) - GS Comments_(0)
| R1 - HKLM\Software\Microsoft\InternetExplorer\Main,Default_Search_URL =http://go.microsoft.com/fwlink/?LinkId=54896 |
| Good | 2 - 0 | SS(47,950) - GS Comments_(0)
| R1 - HKLM\Software\Microsoft\InternetExplorer\Main,Search Page =http://go.microsoft.com/fwlink/?LinkId=54896 |
| Good | 1 - 0 | SS(47) - GS Comments_(0)
| C:\Program Files\Intel\Intel Matrix StorageManager\iaantmon.exe |
| Good | 1 - 0 | SS(43) - GS Comments_(0)
| C:\Program Files\Intel\Intel Matrix StorageManager\iaanotif.exe |
| Good | 1 - 0 | SS(43) - GS Comments_(0)
| O4 - HKLM\..\Run: [IAAnotif] C:\ProgramFiles\Intel\Intel Matrix StorageManager\iaanotif.exe |
| Good | 1 - 0 | SS(47) - GS Comments_(0)
| O23 - Service: Intel(R) Matrix Storage EventMonitor (IAANTMon) - Intel Corporation -C:\Program Files\Intel\Intel Matrix StorageManager\iaantmon.exe |
| Good | 1 - 0 | SS(47,950) - GS Comments_(0)
| R1 - HKCU\Software\Microsoft\InternetExplorer\Main,Search Page =http://go.microsoft.com/fwlink/?LinkId=54896 |
| Good | 1 - 0 | SS(206) - GS Comments_(0)
| O2 - BHO: Windows Live Sign-in Helper -{9030D464-4C02-4ABF-8ECC-5164760863C6} -C:\Program Files\Common Files\MicrosoftShared\Windows Live\WindowsLiveLogin.dll |
| Good | 2 - 0 | SS(46,776) - GS Comments_(0)
| R0 - HKLM\Software\Microsoft\InternetExplorer\Main,Start Page =http://go.microsoft.com/fwlink/?LinkId=69157 |
| Good | 2 - 0 | SS(45,450) - GS Comments_(0)
| R1 - HKLM\Software\Microsoft\InternetExplorer\Main,Default_Page_URL =http://go.microsoft.com/fwlink/?LinkId=69157 |
| Good | 1 - 0 | SS(48) - GS Comments_(0)
| C:\WINDOWS\System32\vssvc.exe |
| Good | 1 - 0 | SS(74) - GS Comments_(0)
| O23 - Service: FLEXnet Licensing Service -Macrovision Europe Ltd. - C:\Program Files\CommonFiles\Macrovision Shared\FLEXnetPublisher\FNPLicensingService.exe |
| Good | 1 - 0 | SS(11) - GS Comments_(0)
| O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE |
| Good | 1 - 0 | SS(70) - GS Comments_(0)
| c:\program files\commonfiles\logishrd\lvmvfm\LVPrcSrv.exe |
| Good | 1 - 0 | SS(37) - GS Comments_(0)
| C:\Program Files\CommonFiles\LogiShrd\LComMgr\Communications_Helper.exe |
| Good | 1 - 0 | SS(17) - GS Comments_(0)
| C:\Program Files\CommonFiles\Logishrd\LQCVFX\COCIManager.exe |
| Good | 1 - 0 | SS(37) - GS Comments_(0)
| O4 - HKLM\..\Run: [LogitechCommunicationsManager]"C:\Program Files\CommonFiles\LogiShrd\LComMgr\Communications_Helper.exe" |
| Good | 1 - 0 | SS(34,847) - GS Comments_(0)
| R1 -HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local |
| Good | 1 - 0 | SS(70) - GS Comments_(0)
| O23 - Service: Process Monitor (LVPrcSrv) -Logitech Inc. - c:\program files\commonfiles\logishrd\lvmvfm\LVPrcSrv.exe |
| Good | 1 - 0 | SS(243) - GS Comments_(0)
| O4 - HKLM\..\Run: [JMB36X Configure]C:\WINDOWS\system32\JMRaidTool.exe boot |
| Good | 1 - 0 | SS(896) - GS Comments_(0)
| O4 - HKCU\..\Run: [MsnMsgr] "C:\ProgramFiles\Windows Live\Messenger\MsnMsgr.Exe"/background |
| Good | 1 - 0 | SS(11) - GS Comments_(0)
| C:\WINDOWS\SkyTel.EXE |
| Good | 3 - 0 | SS(106) - GS Comments_(0)
| O9 - Extra button: (no name) -{e2e2dd38-d088-4134-82b7-f2ba38496583} -C:\windows\Network Diagnostic\xpnetdiag.exe |
| Good | 3 - 0 | SS(106) - GS Comments_(0)
| O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001- {e2e2dd38-d088-4134-82b7-f2ba38496583} -C:\windows\Network Diagnostic\xpnetdiag.exe |
| Good | 1 - 0 | SS(275) - GS Comments_(0)
| C:\Program Files\WindowsLive\Messenger\MsnMsgr.Exe |
| Good | 1 - 0 | SS(237) - GS Comments_(0)
| O4 - HKLM\..\Run: [CanonMyPrinter] C:\ProgramFiles\Canon\MyPrinter\BJMyPrt.exe /logon |
| Good | 1 - 0 | SS(333) - GS Comments_(0)
| O2 - BHO: Adobe PDF Reader Link Helper -{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -F:\Program Files\Adobe\Acrobat7.0\ActiveX\AcroIEHelper.dll |
| Good | 1 - 0 | SS(24) - GS Comments_(0)
| C:\Program Files\CommonFiles\LogiShrd\LVCOMSER\LVComSer.exe |
| Good | 1 - 0 | SS(24) - GS Comments_(0)
| O23 - Service: LVCOMSer - Logitech Inc. -C:\Program Files\CommonFiles\LogiShrd\LVCOMSER\LVComSer.exe |
| Good | 1 - 0 | SS(58) - GS Comments_(0)
| O23 - Service: TrueVector Internet Monitor (vsmon)- Check Point Software Technologies LTD -C:\Windows\System32\ZoneLabs\vsmon.exe |
| Good | 1 - 0 | SS(116) - GS Comments_(0)
| F:\Program Files\DiskeeperCorporation\Diskeeper\DkService.exe |
| Good | 1 - 0 | SS(116) - GS Comments_(0)
| O23 - Service: Diskeeper - Diskeeper Corporation -F:\Program Files\DiskeeperCorporation\Diskeeper\DkService.exe |
| Good | 1 - 0 | SS(822) - GS Comments_(0)
| O8 - Extra context menu item: E&xport to MicrosoftExcel -res://F:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 |
| Good | 1 - 0 | SS(436) - GS Comments_(0)
| O9 - Extra button: Research -{92780B25-18CC-41C8-B9BE-3C9C571A8263} -F:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL |
| Good | 1 - 0 | SS(13) - GS Comments_(0)
| O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5}(Keynote Connector Launcher 2) -http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab |
| Good | 1 - 0 | SS(229) - GS Comments_(0)
| O4 - HKLM\..\Run: [CanonSolutionMenu] C:\ProgramFiles\Canon\SolutionMenu\CNSLMAIN.exe /logon |
| Good | 1 - 0 | SS(78) - GS Comments_(0)
| F:\Program Files\Alcohol Soft\Alcohol120\StarWind\StarWindServiceAE.exe |
| Good | 1 - 0 | SS(78) - GS Comments_(0)
| O23 - Service: StarWind AE Service(StarWindServiceAE) - Rocket Division Software -F:\Program Files\Alcohol Soft\Alcohol120\StarWind\StarWindServiceAE.exe |
| Good | 1 - 0 | SS(147) - GS Comments_(0)
| F:\Program Files\AlwilSoftware\Avast4\aswUpdSv.exe |
| Good | 1 - 0 | SS(146) - GS Comments_(0)
| F:\Program Files\Alwil Software\Avast4\ashServ.exe |
| Good | 1 - 0 | SS(150) - GS Comments_(0)
| F:\Program Files\AlwilSoftware\Avast4\ashMaiSv.exe |
| Good | 1 - 0 | SS(141) - GS Comments_(0)
| F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe |
| Good | 1 - 0 | SS(141) - GS Comments_(0)
| O4 - HKLM\..\Run: [avast!]F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe |
| Good | 1 - 0 | SS(147) - GS Comments_(0)
| O23 - Service: avast! iAVS4 Control Service(aswUpdSv) - ALWIL Software - F:\ProgramFiles\Alwil Software\Avast4\aswUpdSv.exe |
| Good | 1 - 0 | SS(146) - GS Comments_(0)
| O23 - Service: avast! Antivirus - ALWIL Software -F:\Program Files\Alwil Software\Avast4\ashServ.exe |
| Good | 1 - 0 | SS(150) - GS Comments_(0)
| O23 - Service: avast! Mail Scanner - ALWILSoftware - F:\Program Files\AlwilSoftware\Avast4\ashMaiSv.exe |
| Good | 1 - 0 | SS(6,171) - GS Comments_(0)
| F:\Program Files\TrendMicro\HijackThis\HijackThis.exe |
| Good | 1 - 0 | SS(322) - GS Comments_(0)
| O2 - BHO: Java(tm) Plug-In SSV Helper -{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -F:\Program Files\Java\jre6\bin\ssv.dll |
| Good | 1 - 0 | SS(121) - GS Comments_(0)
| O2 - BHO: Java(tm) Plug-In 2 SSV Helper -{DBC80044-A445-435b-BC74-9C25C1C588A9} -F:\Program Files\Java\jre6\bin\jp2ssv.dll |
| Good | 1 - 0 | SS(109) - GS Comments_(0)
| O2 - BHO: JQSIEStartDetectorImpl -{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -F:\ProgramFiles\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll |
| Good | 1 - 0 | SS(176) - GS Comments_(0)
| O2 - BHO: Adobe PDF Conversion Toolbar Helper -{AE7CD045-E861-484f-8273-0445EE161910} - (no file) |
| Good | 1 - 0 | SS(170) - GS Comments_(0)
| O3 - Toolbar: Adobe PDF -{47833539-D0C5-4125-9FA8-0819E2EAAC93} - (no file) |
| Good | 1 - 0 | SS(4,386) - GS Comments_(0)
| O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}(MUWebControl Class) -http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186163365750 |
| | | |