Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log: Please Help Diagnose


  • Please log in to reply
1 reply to this topic

#1 Jenny83

Jenny83

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:00 PM

Posted 15 January 2008 - 12:13 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:02 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 600\bin\ktchnsnk.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\AUTHEN~1\COMMAN~1\avtray.exe
C:\PROGRA~1\AUTHEN~1\COMMAN~1\dvprpt.exe
C:\PROGRA~1\AUTHEN~1\COMMAN~1\untray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Authentium\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Authentium\Command AntiVirus\schscnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\F2000\FServer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.centershift.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centershift.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centershift.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HP OfficeJet Series 600] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 600\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 600\Install"
O4 - HKLM\..\Run: [Smart Start UP] C:\Program Files\NewSoft\Smart Start UP\PnPDetect.exe /Automation
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\AUTHEN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\AUTHEN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\AUTHEN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\AUTHEN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: SpywareGuard.lnk.disabled
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {11004D63-D403-4128-BE38-BA8035F01AE4} (csCAM.csAccountManager) - https://host01slc.centershift.com/store31/x...ountManager.CAB
O16 - DPF: {1178E4A2-86B4-11D5-89FA-00C04F2FABD2} (STANPin.clsPins) - https://www.centershift.com/store31/x/STANPin.CAB
O16 - DPF: {16FAC6F5-C570-4E77-9187-7ED6C9D6451C} (CXPlugin.CXMovein) - https://www.centershift.com/store31/x/csCXPlugIn.CAB
O16 - DPF: {22CF1688-43B2-4BE6-AD4F-0BED3D188416} (BatchPaymentOCX.ctlBPay) - https://www.centershift.com/store31/x/BatchPaymentOCX.CAB
O16 - DPF: {306A3A9D-5711-468C-89E1-08B53607ADEC} (Centershift_ClientManager.CS_CCManager) - https://www.centershift.com/store31/x/Cente...ntManager31.CAB
O16 - DPF: {35A07B73-808D-409F-B12E-8EAE82154C78} (MessagePolling.ctlMsgPolling) - https://www.centershift.com/store31/x/msgPolling.CAB
O16 - DPF: {35D8C241-C955-49C1-8995-7B08DB1D089E} (Lookups.LookupAdmin) - https://www.centershift.com/store31/x/LookupProj.CAB
O16 - DPF: {41A7F6B3-95E6-4E01-B370-DED12CA827B7} (csPrint.Receipt) - https://host01slc.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {4DA69678-F10F-430A-BC87-ED40B89F5875} (hKey.Current_user) - https://www.centershift.com/csweb/components/hkey.CAB
O16 - DPF: {52EEED38-6E2F-4B1D-AE39-99FBB56CF8B1} (CSPayment.clsPayment) - https://host01slc.centershift.com/store31/x/CSPayment.CAB
O16 - DPF: {567ACF49-8D60-4348-B92D-60BF0C2FE5E0} (csDelProcAdmin01_Control.csDelProcAdmin) - https://www.centershift.com/store31/x/csDelProcAdmin01.CAB
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab
O16 - DPF: {6B42B55C-583F-480C-861D-CED3FCAD3512} (csAuctionAdmin.ctlAuctionAdmin) - https://www.centershift.com/store31/x/csAuctionAdmin.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1200413617281
O16 - DPF: {846D1B10-EC6B-4334-9FFA-EABEC4E8F025} (csPopUpCalendar.csCal) - https://www.centershift.com/csweb/components/csCal.CAB
O16 - DPF: {960DDF83-B61A-4707-B8B2-4BA978B8F2BB} - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {9C2FC5A6-1D2B-434D-82D8-38652C74F43A} (CSFSO.FileSystemObject) - https://www.centershift.com/store31/x/CSFSO.CAB
O16 - DPF: {9E84AFC0-6C29-43FE-8AB5-3A9701CBAB01} (Gate31.Controller) - https://host01slc.centershift.com/store31/x/Gate31.CAB
O16 - DPF: {A5F9D5D3-5A9E-40B5-8E5C-9CFAE21AF0DF} (CSInstallPak3.CSInstaller30) - https://www.centershift.com/store31/x/CSinstall30.CAB
O16 - DPF: {A61C74D0-3876-4CBD-9B75-61EC04FE31EE} (Navigator3.CS_Navigator3) - https://www.centershift.com/store31/x/csNavigator3.CAB
O16 - DPF: {A866B6B1-D925-4D7E-BDAD-B03EC0451464} (csYM4.csYield) - https://host01slc.centershift.com/store31/x/csYM4.CAB
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C04E671A-5638-4544-B6B0-8586B10A6E96} (csMoveIn.ctrMoveIn) - https://www.centershift.com/store31/x/csMoveIn.CAB
O16 - DPF: {C0A63B86-4B21-11D3-BD95-D426EF2C7949} (ComponentOne FlexGrid 7.1 (Light)) - http://www.centershift.com/csweb/components/vsflex7L.ocx
O16 - DPF: {C9BADB23-839E-48C7-BA37-4E1433F15E1C} (STANChangeAddress.clsChangeAddress) - https://www.centershift.com/store31/x/STANChangeAddress.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.pogo.com/game/deluxe/zuma/popcaploader_v6.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://demo3.webex.com/client/v_mywebex-t2...bex/ieatgpc.cab
O16 - DPF: {E2DAB340-21E9-4795-8105-394CC6DF75BC} (csStoSA.csStoSAContainer) - https://host01slc.centershift.com/store31/x/csStoSA.CAB
O16 - DPF: {E3C15E7A-56B3-4977-A76E-E9F1B2614FD8} (ArchitectureAdmin.ctlArchitectureAdmin) - https://www.centershift.com/store31/x/ArchitectureAdmin.CAB
O16 - DPF: {EF783396-97FB-400B-A6B0-2AC5A74D65DF} (CentershiftMap.csMap) - https://www.centershift.com/store31/x/csMap30.CAB
O16 - DPF: {F187501F-293B-4E88-93E5-E8A536FAB937} (CSFSO.FileSystemObject) - https://www.centershift.com/csweb/components/CSFSO.CAB
O16 - DPF: {F7A34E78-9C47-4B32-A425-4FF7B0E5F77F} (STANsearchControl.STANuserControl) - https://www.centershift.com/store31/x/csSearch.CAB
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: avinitnt - Authentium, Inc. - C:\Program Files\Authentium\Command AntiVirus\avinitnt.exe
O23 - Service: CA Personal Firewall ASEM - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: schscnt - Authentium, Inc. - C:\Program Files\Authentium\Command AntiVirus\schscnt.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11617 bytes

BC AdBot (Login to Remove)

 


#2 DASOS

DASOS

    Malware hunter


  • Security Colleague
  • 1,662 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greece loutraki 6 km from korinth canal
  • Local time:10:00 PM

Posted 31 January 2008 - 04:22 AM

Hello Jenny83

Welcome to Bleeping Computer!

Sorry about the delay. We're all volunteers here, and it's been very busy. If you still need help, please post a new HijackThis log to make sure nothing has changed.

Before posting the log, please make sure you follow all the steps found in this topic:

Preparation Guide For Use Before Posting A Hijackthis Log <--link

And I'll be happy to take a look at it for you.
=====

I also need to see a different type of log from Hijackthis:
  • Run Hijackthis.
  • Click on "Open the Misc Tools section".
  • Next click on "Open uninstall manager".
  • Press the button 'save list'. It will open a Notepad file.
  • Place the content of that file here in your next reply.
Thanks, for your patience.



Stelios




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users