Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Nov 21 2008, 10:39 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 21-November 08 Member No.: 259,321 |
Some help please...
I believe I have MALWARE... my PC is slow and seems to be endlessly communicating with another PC. Zone Alarm firewall shows constant download and upload activities. HEEELLP! PBG4 Recall my HIJACKTHIS LOG Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:45:02 AM, on 11/19/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\RAMpage\RAMpage.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\System32\ezSP_Px.exe D:\Drive D Program Files\BUFFALO\ABRECEIVER\ABReceiver.exe C:\WINDOWS\System32\ctfmon.exe D:\Drive D Program Files\BUFFALO\cm3_tray.exe D:\Drive D Program Files\BUFFALO\bwsvc\bwsvc.exe C:\WINDOWS\system32\gearsec.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\MsPMSPSv.exe D:\Drive D Program Files\Firefox\firefox.exe C:\Program Files\Outlook Express\msimn.exe C:\WINDOWS\system32\NOTEPAD.EXE D:\Drive D Program Files\HijackThis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Drive D Program Files\Adobe reader 6\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [RAMpage] "C:\Program Files\RAMpage\RAMpage.exe" M=28 T=4 P="C:\Program Files\RAMpage\RAMpageConfig.exe" O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [MediaFace Integration] D:\Drive D Program Files\Fellowes\MediaFACE 4.0\SetHook.exe O4 - HKLM\..\Run: [ABRECEIVER] "D:\Drive D Program Files\BUFFALO\ABRECEIVER\ABReceiver.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: ClientManager2.lnk = D:\Drive D Program Files\BUFFALO\Client Manager2\ClientMgr2.exe O4 - Global Startup: ClientManager3.lnk = D:\Drive D Program Files\BUFFALO\cm3_tray.exe O4 - Global Startup: Microsoft Office.lnk = E:\Drive E Program Files\Office\OSA9.EXE O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O23 - Service: Bwsvc - BUFFALO INC. - D:\Drive D Program Files\BUFFALO\bwsvc\bwsvc.exe O23 - Service: GearSecurity - GEAR Software - C:\WINDOWS\system32\gearsec.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 3441 bytes |
|
|
|
PBG4 RECALL I believe I have MALWARE.. Nov 21 2008, 10:39 PM
Animal I have moved your Topic that includes a HijackThis... Nov 21 2008, 10:51 PM![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2009 - 01:05 AM |