| Result |
Good-Bad |
Search |
Hijack This Log File Entry |
| | |
| Bad | 1 - 11 | SS(8,138) - GS Comments_(0)
| R0 - HKCU\Software\Microsoft\InternetExplorer\Toolbar,LinksFolderName = |
| Bad | 0 - 13 | SS(19,355) - GS Comments_(0)
| R0 - HKCU\Software\Microsoft\InternetExplorer\Main,Local Page = |
| Bad | 0 - 3 | SS(19,355) - GS Comments_(0)
| R0 - HKLM\Software\Microsoft\InternetExplorer\Main,Local Page = |
| Unknown | 0 - 0 | SS(62) - GS Comments_(0)
| O23 - Service: MBAMService - MalwarebytesCorporation - C:\Program Files\Malwarebytes'Anti-Malware\mbamservice.exe |
| Unknown | 0 - 0 | SS(59) - GS Comments_(0)
| O23 - Service: Remote Packet Capture Protocol v.0(experimental) (rpcapd) - CACE Technologies, Inc.- C:\Program Files\WinPcap\rpcapd.exe |
| Unknown | 0 - 0 | SS(9) - GS Comments_(0)
| C:\Program Files\ASUS\Six Engine\SixEngine.exe |
| Unknown | 0 - 0 | SS(74) - GS Comments_(0)
| C:\Program Files\Malwarebytes'Anti-Malware\mbamgui.exe |
| Unknown | 0 - 0 | SS(75) - GS Comments_(0)
| O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware]"C:\Program Files\Malwarebytes'Anti-Malware\mbamgui.exe" /starttray |
| Unknown | 0 - 0 | SS(139) - GS Comments_(0)
| C:\Program Files\Comodo\COMODO InternetSecurity\cmdagent.exe |
| Unknown | 0 - 0 | SS(0) - GS Comments_(0)
| C:\Program Files\Comodo\COMODO InternetSecurity\cfp.exe |
| Unknown | 0 - 0 | SS(0) - GS Comments_(0)
| O4 - HKLM\..\Run: [COMODO Internet Security]"C:\Program Files\Comodo\COMODO InternetSecurity\cfp.exe" -h |
| Unknown | 0 - 0 | SS(160) - GS Comments_(0)
| O23 - Service: wampapache - Apache SoftwareFoundation -c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe |
| Unknown | 0 - 0 | SS(12) - GS Comments_(0)
| O23 - Service: Cobian Backup 9 service(CobianBackupAmanita) - Luis Cobian - C:\ProgramFiles\Cobian Backup 9\cbService.exe |
| Unknown | 0 - 0 | SS(9) - GS Comments_(0)
| O4 - HKLM\..\Run: [Six Engine] "C:\ProgramFiles\ASUS\Six Engine\SixEngine.exe" -r |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| C:\Program Files\Texter\texter.exe |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| O4 - Startup: Texter.lnk = C:\ProgramFiles\Texter\texter.exe |
| Unknown | 0 - 0 | SS(10) - GS Comments_(0)
| O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}-http://download.eset.com/special/eos/OnlineScanner.cab |
| Unknown | 0 - 0 | SS(139) - GS Comments_(0)
| O23 - Service: COMODO Internet Security HelperService (cmdAgent) - COMODO - C:\ProgramFiles\COMODO\COMODO Internet Security\cmdagent.exe |
| Unknown | 0 - 0 | SS(113) - GS Comments_(0)
| C:\WINDOWS\system32\NMSAccessU.exe |
| Unknown | 0 - 0 | SS(113) - GS Comments_(0)
| O23 - Service: NMSAccessU - Unknown owner -C:\WINDOWS\system32\NMSAccessU.exe |
| Unknown | 0 - 0 | SS(217) - GS Comments_(0)
| O23 - Service: wampmysqld - Unknown owner -c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe |
| Unknown | 0 - 0 | SS(12) - GS Comments_(0)
| C:\Program Files\Cobian Backup 9\cbService.exe |
| Unknown | 0 - 0 | SS(7) - GS Comments_(0)
| O23 - Service: Acronis Nonstop Backup service(afcdpsrv) - Acronis - C:\Program Files\CommonFiles\Acronis\CDP\afcdpsrv.exe |
| Unknown | 0 - 0 | SS(207) - GS Comments_(0)
| O8 - Extra context menu item: Add to &Evernote -res://C:\ProgramFiles\Evernote\Evernote3.5\enbar.dll/2000 |
| Unknown | 0 - 0 | SS(63) - GS Comments_(0)
| O9 - Extra button: Add to Evernote -{E0B8C461-F8FB-49b4-8373-FE32E92528A6} -C:\Program Files\Evernote\Evernote3.5\enbar.dll |
| Unknown | 0 - 0 | SS(63) - GS Comments_(0)
| O9 - Extra 'Tools' menuitem: Add to Evernote -{E0B8C461-F8FB-49b4-8373-FE32E92528A6} -C:\Program Files\Evernote\Evernote3.5\enbar.dll |
| Unknown | 0 - 0 | SS(87) - GS Comments_(0)
| C:\Program Files\Evernote\Evernote3.5\Evernote.exe |
| Unknown | 0 - 0 | SS(620) - GS Comments_(0)
| O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\ProgramFiles\Common Files\Java\Java Update\jusched.exe" |
| Unknown | 0 - 0 | SS(620) - GS Comments_(0)
| C:\Program Files\Common Files\Java\JavaUpdate\jusched.exe |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| C:\Program Files\Wonderful\wonderfl.exe |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| O4 - Startup: The Wonderful Icon.lnk = C:\ProgramFiles\Wonderful\wonderfl.exe |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| C:\Program Files\Telbo.com\Telbo\Telbo.exe |
| Unknown | 0 - 0 | SS(289) - GS Comments_(0)
| C:\Documents and Settings\nero\ApplicationData\Dropbox\bin\Dropbox.exe |
| Unknown | 0 - 0 | SS(2) - GS Comments_(0)
| C:\Documents and Settings\nero\StartMenu\Programs\Startup\hideDesktop.exe |
| Unknown | 0 - 0 | SS(24) - GS Comments_(0)
| C:\Documents and Settings\nero\StartMenu\Programs\Startup\TrueCrypt.exe |
| Unknown | 0 - 0 | SS(16) - GS Comments_(0)
| D:\Nero\Portable Apps\foobar2000\foobar2000.exe |
| Unknown | 0 - 0 | SS(14) - GS Comments_(0)
| C:\Documents and Settings\nero\ApplicationData\Mozilla\Firefox\Profiles\i4px9v7i.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe |
| Unknown | 0 - 0 | SS(8,622) - GS Comments_(0)
| O1 - Hosts: 195.110.124.133 lsd.eu |
| Unknown | 0 - 0 | SS(8,622) - GS Comments_(0)
| O1 - Hosts: 195.110.124.188 www.auxout.eu |
| Unknown | 0 - 0 | SS(8,622) - GS Comments_(0)
| O1 - Hosts: 195.110.124.188 www.auxout.com |
| Unknown | 0 - 0 | SS(8,622) - GS Comments_(0)
| O1 - Hosts: 195.110.124.188 auxout.eu |
| Unknown | 0 - 0 | SS(8,622) - GS Comments_(0)
| O1 - Hosts: 195.110.124.188 auxout.com |
| Unknown | 0 - 0 | SS(8) - GS Comments_(0)
| O2 - BHO: LastPass Browser Helper Object -{95D9ECF5-2A4D-4550-BE49-70D42F71296E} -C:\Documents and Settings\nero\ApplicationData\LastPass\LPBar.dll |
| Unknown | 0 - 0 | SS(279) - GS Comments_(0)
| O4 - HKCU\..\Run: [Telbo] "C:\ProgramFiles\Telbo.com\Telbo\Telbo.exe" -nosplash-minimized |
| Unknown | 0 - 0 | SS(302) - GS Comments_(0)
| O4 - HKCU\..\Run: [Evernote] "C:\ProgramFiles\Evernote\Evernote3.5\evernote.exe"/minimized |
| Unknown | 0 - 0 | SS(289) - GS Comments_(0)
| O4 - Startup: Dropbox.lnk = C:\Documents andSettings\nero\ApplicationData\Dropbox\bin\Dropbox.exe |
| Unknown | 0 - 0 | SS(12,193) - GS Comments_(0)
| O4 - Startup: hideDesktop.exe |
| Unknown | 0 - 0 | SS(12) - GS Comments_(0)
| O4 - Startup: Shortcut to AtomicAlarmClock.lnk =C:\Program Files\Atomic AlarmClock\AtomicAlarmClock.exe |
| Unknown | 0 - 0 | SS(436) - GS Comments_(0)
| O4 - Startup: Shortcut to Skype.lnk = C:\ProgramFiles\Skype\Phone\Skype.exe |
| Unknown | 0 - 0 | SS(30) - GS Comments_(0)
| O4 - Startup: Shortcut to trillian.lnk =C:\Program Files\Trillian\trillian.exe |
| Unknown | 0 - 0 | SS(12,215) - GS Comments_(0)
| O4 - Startup: TrueCrypt.exe |
| Unknown | 0 - 0 | SS(9,249) - GS Comments_(0)
| O8 - Extra context menu item: LastPass -file://C:\Documents and Settings\nero\ApplicationData\LastPass\context.html?cmd=lastpass |
| Unknown | 0 - 0 | SS(9,235) - GS Comments_(0)
| O8 - Extra context menu item: LastPass Fill Forms- file://C:\Documents andSettings\nero\ApplicationData\LastPass\context.html?cmd=fillforms |
| Unknown | 0 - 0 | SS(7,779) - GS Comments_(0)
| O17 -HKLM\System\CCS\Services\Tcpip\..\{5C8C836B-6FD3-4A83-A887-88AEA1ABBBE3}: NameServer =156.154.70.1,4.2.2.5 |
| Unknown | 0 - 0 | SS(7,766) - GS Comments_(0)
| O17 -HKLM\System\CCS\Services\Tcpip\..\{6009A838-7D94-4D00-87CA-E431613E6EB1}: NameServer =8.8.8.8,8.8.4.4 |
| Unknown | 0 - 0 | SS(7,778) - GS Comments_(0)
| O17 -HKLM\System\CCS\Services\Tcpip\..\{65E849BB-B899-4BA5-AA8B-3946184CC3FE}: NameServer =8.8.8.8,8.8.4.4 |
| Unknown | 0 - 0 | SS(7,774) - GS Comments_(0)
| O17 -HKLM\System\CCS\Services\Tcpip\..\{A48C6DDE-FC90-4EFD-8A07-1119455F7D35}: NameServer =156.154.70.22,156.154.71.22 |
| Unknown | 0 - 0 | SS(110) - GS Comments_(0)
| O20 - AppInit_DLLs: prio.dll C:\WINDOWS\system32\guard32.dll |
| Unknown | 0 - 0 | SS(14) - GS Comments_(0)
| O23 - Service: Subversion SVN (svnserver) -http://subversion.tigris.org/ - c:\ProgramFiles\Subversion\bin\svnserve.exe |
| Unknown | 0 - 0 | SS(39) - GS Comments_(0)
| O23 - Service: TeamViewer 5 (TeamViewer5) -TeamViewer GmbH - C:\Documents andSettings\nero\temp\TeamViewer\Version5\TeamViewer_Service.exe |
| Good | 1 - 0 | SS(74) - GS Comments_(0)
| O23 - Service: FLEXnet Licensing Service - AcressoSoftware Inc. - C:\Program Files\CommonFiles\Macrovision Shared\FLEXnetPublisher\FNPLicensingService.exe |
| Good | 1 - 0 | SS(200) - GS Comments_(0)
| C:\Program Files\Avira\AntiVir Desktop\avguard.exe |
| Good | 1 - 0 | SS(226) - GS Comments_(0)
| C:\Program Files\Avira\AntiVir Desktop\sched.exe |
| Good | 1 - 0 | SS(200) - GS Comments_(0)
| C:\Program Files\Avira\AntiVir Desktop\avgnt.exe |
| Good | 1 - 0 | SS(200) - GS Comments_(0)
| O4 - HKLM\..\Run: [avgnt] "C:\ProgramFiles\Avira\AntiVir Desktop\avgnt.exe" /min |
| Good | 1 - 0 | SS(226) - GS Comments_(0)
| O23 - Service: Avira AntiVir Scheduler(AntiVirSchedulerService) - Avira GmbH -C:\Program Files\Avira\AntiVir Desktop\sched.exe |
| Good | 1 - 0 | SS(200) - GS Comments_(0)
| O23 - Service: Avira AntiVir Guard(AntiVirService) - Avira GmbH - C:\ProgramFiles\Avira\AntiVir Desktop\avguard.exe |
| Good | 1 - 0 | SS(15) - GS Comments_(0)
| O2 - BHO: PDF-XChange Viewer IE-Plugin -{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} -C:\Program Files\Tracker Software\PDFViewer\PDFXCviewIEPlugin.dll |
| Good | 1 - 0 | SS(4,507) - GS Comments_(0)
| O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}(WUWebControl Class) -http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242606617328 |
| Good | 1 - 0 | SS(4,386) - GS Comments_(0)
| O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}(MUWebControl Class) -http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245944111429 |
| | | |