Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT Log - andresmtz


  • Please log in to reply
4 replies to this topic

#1 Lemming

Lemming

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:09:17 AM

Posted 26 April 2005 - 09:32 PM

My log looks clean I believe.

Logfile of HijackThis v1.99.1
Scan saved at 9:30:09 PM, on 4/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Andres Mtz\Desktop\Anti SpyAd Ware\ADSSpy.exe
C:\Program Files\Opera 8 Beta\Opera.exe
C:\Documents and Settings\Andres Mtz\Desktop\Anti SpyAd Ware\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {37A53174-024B-42D0-8B7C-E42122FDC7DB} (MGameRunDll3 Class) - http://wizweb.nefficient.co.kr/wizweb/wizg...g/mgrunmng3.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {7417F730-7BAB-409E-8BB7-6936D361B869} (MLauncher Class) - http://download.mgame.com/download/cab/MLauncher.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

___________

Panda Free Online Scan:


Incident Status Location

Spyware:Spyware/CommonName No disinfected Windows Registry
Adware:Adware/NavHelper No disinfected C:\Program Files\Ares
Adware:Adware/ILookup No disinfected Windows Registry
Virus:Application/Eblaster No disinfected Windows Registry
Virus:Trj/Downloader.CGD No disinfected C:\Documents and Settings\Andres Mtz\Desktop\Shortcuts\bubbletrouble.exe
Virus:Bck/Assasin.R No disinfected C:\Documents and Settings\Andres Mtz\My Documents\Setups\windowmode.zip[windowmode.exe]
Deleted both bubbletrouble.exe and windowmode.zip

But how about the Windows Registry's?
Posted Image

Freeware: Ad-Aware, Spybot S&D, Avast Antivirus, Kerio Firewall, Cleanup, SpywareBlaster, SpywareGuard

Jesus is the Answer for the World today!
Prayer Changes!

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,717 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:08:17 AM

Posted 27 April 2005 - 12:06 AM

THey are not affecting you but you can delete them from the registry manually if you want

#3 Lemming

Lemming
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:09:17 AM

Posted 27 April 2005 - 03:01 PM

Thanks for the reply.

How do I find them on the registry?

What are they called?
Posted Image

Freeware: Ad-Aware, Spybot S&D, Avast Antivirus, Kerio Firewall, Cleanup, SpywareBlaster, SpywareGuard

Jesus is the Answer for the World today!
Prayer Changes!

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,717 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:08:17 AM

Posted 27 April 2005 - 06:05 PM

I do not know off the top of my head. If they are not giving you more info from the program reporting the errors, you may want to google it.

#5 Lemming

Lemming
  • Topic Starter

  • Members
  • 58 posts
  • OFFLINE
  •  
  • Local time:09:17 AM

Posted 28 April 2005 - 06:53 AM

Thanks once again.

:thumbsup:
Posted Image

Freeware: Ad-Aware, Spybot S&D, Avast Antivirus, Kerio Firewall, Cleanup, SpywareBlaster, SpywareGuard

Jesus is the Answer for the World today!
Prayer Changes!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users