Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hjt Log


  • This topic is locked This topic is locked
2 replies to this topic

#1 mrpeerfict

mrpeerfict

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:09 PM

Posted 03 October 2008 - 07:32 AM

My computer has been acting funny, i wanted to know if someone (possibly girlfriend) put spyware/keylogger on my computer, heres my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:08:44 AM, on 10/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:..WINDOWS..System32..smss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..Program Files..Intel..Wireless..Bin..EvtEng.exe
C:..Program Files..Intel..Wireless..Bin..S24EvMon.exe
C:..Program Files..Common Files..Symantec Shared..ccSetMgr.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Common Files..Symantec Shared..ccEvtMgr.exe
C:..Program Files..Common Files..Symantec Shared..ccProxy.exe
C:..Program Files..Common Files..Symantec Shared..SNDSrvc.exe
C:..Program Files..Common Files..Symantec Shared..SPBBC..SPBBCSvc.exe
C:..Program Files..Common Files..Symantec Shared..CCPD-LC..symlcsvc.exe
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..eHome..ehRecvr.exe
C:..WINDOWS..eHome..ehSched.exe
C:..Program Files..Microsoft SQL Server..MSSQL$VAIO_VEDB..Binn..sqlservr.exe
C:..Program Files..Norton Internet Security..Norton AntiVirus..navapsvc.exe
C:..Program Files..Intel..Wireless..Bin..RegSrvc.exe
C:..Program Files..Common Files..Sony Shared..WMPlugIn..SonicStageMonitoring.exe
C:..WINDOWS..system32..svchost.exe
C:..Program Files..Sony..VAIO Event Service..VESMgr.exe
C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VCSW..VCSW.exe
C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VzCdb..VzCdbSvc.exe
C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VzCdb..VzFw.exe
C:..WINDOWS..system32..dllhost.exe
C:..Program Files..Apoint..Apoint.exe
C:..WINDOWS..ehome..ehtray.exe
C:..WINDOWS..system32..hkcmd.exe
C:..WINDOWS..system32..igfxpers.exe
C:..Program Files..Java..jre1.5.0_07..bin..jusched.exe
C:..Program Files..Sony..VAIO Power Management..SPMgr.exe
C:..Program Files..Sony..ISB Utility..ISBMgr.exe
C:..Program Files..Sony..VAIO Update 2..VAIOUpdt.exe
C:..WINDOWS..system32..ICO.EXE
C:..WINDOWS..eHome..ehmsas.exe
C:..Program Files..Napster..napster.exe
C:..Program Files..Sony..Wireless Switch Setting Utility..Switcher.exe
C:..Program Files..DISC..DISCover.exe
C:..Program Files..Sony..VAIO Camera Utility..VCUServe.exe
C:..Program Files..Common Files..Symantec Shared..ccApp.exe
C:..Program Files..Common Files..AOL..1221489808..ee..AOLSoftware.exe
C:..Program Files..Messenger..msmsgs.exe
C:..Program Files..Apoint..Apntex.exe
C:..Program Files..Trend Micro..Tmas..Tmas.exe
C:..Program Files..DISC..DiscStreamHub.exe
C:..Program Files..Common Files..Symantec Shared..Security Console..NSCSRVCE.EXE
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..Java..jre1.5.0_07..bin..jucheck.exe
C:..Program Files..Internet Explorer..iexplore.exe
C:..Program Files..Verizon Wireless..VZAccess Manager..VZAccess Manager.exe
C:..WINDOWS..system32..wbem..wmiapsrv.exe
c:..program files..common files..aol..1221489808..ee..aexplore.exe
C:..Program Files..Internet Explorer..iexplore.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe

R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU..Software..Microsoft..Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:..Program Files..AOL..AOL Toolbar 3.0..aoltb.dll
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:..Program Files..AOL..AOL Search Enhancement..AOLSearch.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:..Program Files..Adobe..Acrobat 7.0..ActiveX..AcroIEHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:..Program Files..AOL..AOL Search Enhancement..AOLSearch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:..Program Files..Java..jre1.5.0_07..bin..ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:..Program Files..AOL..AOL Toolbar 3.0..aoltb.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:..Program Files..Common Files..Symantec Shared..AdBlocking..NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:..Program Files..Norton Internet Security..Norton AntiVirus..NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:..Program Files..Common Files..Symantec Shared..AdBlocking..NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:..Program Files..Norton Internet Security..Norton AntiVirus..NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:..Program Files..AOL..AOL Toolbar 3.0..aoltb.dll
O4 - HKLM......Run: [Apoint] C:..Program Files..Apoint..Apoint.exe
O4 - HKLM......Run: [ehTray] C:..WINDOWS..ehome..ehtray.exe
O4 - HKLM......Run: [igfxtray] C:..WINDOWS..system32..igfxtray.exe
O4 - HKLM......Run: [igfxhkcmd] C:..WINDOWS..system32..hkcmd.exe
O4 - HKLM......Run: [igfxpers] C:..WINDOWS..system32..igfxpers.exe
O4 - HKLM......Run: [VAIO Recovery] C:..WINDOWS..Sonysys..VAIO Recovery..PartSeal.exe
O4 - HKLM......Run: [SunJavaUpdateSched] C:..Program Files..Java..jre1.5.0_07..bin..jusched.exe
O4 - HKLM......Run: [SonyPowerCfg] "C:..Program Files..Sony..VAIO Power Management..SPMgr.exe"
O4 - HKLM......Run: [ISBMgr.exe] C:..Program Files..Sony..ISB Utility..ISBMgr.exe
O4 - HKLM......Run: [VAIO Update 2] "C:..Program Files..Sony..VAIO Update 2..VAIOUpdt.exe" /Stationary
O4 - HKLM......Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM......Run: [NapsterShell] C:..Program Files..Napster..napster.exe /systray
O4 - HKLM......Run: [NvCplDaemon] RUNDLL32.EXE C:..WINDOWS..system32..NvCpl.dll,NvStartup
O4 - HKLM......Run: [Switcher.exe] C:..Program Files..Sony..Wireless Switch Setting Utility..Switcher.exe
O4 - HKLM......Run: [DISCover] C:..Program Files..DISC..DISCover.exe
O4 - HKLM......Run: [VAIOSurvey] c:..program files..sony..vaio survey..surveysa.exe
O4 - HKLM......Run: [VAIOCameraUtility] "C:..Program Files..Sony..VAIO Camera Utility..VCUServe.exe"
O4 - HKLM......Run: [ccApp] "C:..Program Files..Common Files..Symantec Shared..ccApp.exe"
O4 - HKLM......Run: [URLLSTCK.exe] C:..Program Files..Norton Internet Security..UrlLstCk.exe
O4 - HKLM......Run: [HostManager] C:..Program Files..Common Files..AOL..1221489808..ee..AOLSoftware.exe
O4 - HKLM......Run: [PartSeal] C:..WINDOWS..Sonysys..VAIO Recovery..PartSeal.exe
O4 - HKCU......Run: [MSMSGS] "C:..Program Files..Messenger..msmsgs.exe" /background
O4 - Startup: VZAccess Manager.lnk = C:..Program Files..Verizon Wireless..VZAccess Manager..VZAccess Manager.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:..Program Files..Adobe..Acrobat 7.0..Reader..reader_sl.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:..Program Files..Trend Micro..Tmas..Tmas.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:..program files..aol..aol toolbar 3.0..resources..en-US..local..search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:..PROGRA~1..MICROS~4..OFFICE11..EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:..Program Files..AOL..AOL Toolbar 3.0..aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:..PROGRA~1..MICROS~4..OFFICE11..REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http:/.r{}
O17 - HKLM..System..CCS..Services..Tcpip......{D5F8F8D9-66CA-4269-9511 -6409809B0EC5}: NameServer = 66.174.95.44 69.78.96.14
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:..Program Files..Norton Internet Security..ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:..Program Files..Norton Internet Security..comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:..Program Files..Intel..Wireless..Bin..EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:..Program Files..Common Files..InstallShield..Driver..1050..Intel 32..IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:..Program Files..Sony..Image Converter 2..IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:..Program Files..Common Files..Sony Shared..AVLib..MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:..Program Files..Norton Internet Security..Norton AntiVirus..navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..Security Console..NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:..WINDOWS..system32..nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:..Program Files..Common Files..Sony Shared..AVLib..PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:..Program Files..Intel..Wireless..Bin..RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:..Program Files..Intel..Wireless..Bin..S24EvMon.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:..Program Files..Norton Internet Security..Norton AntiVirus..SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..SNDSrvc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:..Program Files..Common Files..Sony Shared..WMPlugIn..SonicStageMonitoring.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..SPBBC..SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:..Program Files..Common Files..Sony Shared..AVLib..SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:..Program Files..Common Files..Sony Shared..AVLib..SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:..Program Files..Common Files..Symantec Shared..CCPD-LC..symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VzCs..VzHardwareResourceManager..VzHardwareResourceMan ager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:..Program Files..Sony..VAIO Event Service..VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:..Program Files..Sony..VAIO Media Integrated Server..VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:..Program Files..Sony..VAIO Media Integrated Server..Platform..SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:..Program Files..Sony..VAIO Media Integrated Server..Platform..UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:..Program Files..Sony..VAIO Media Integrated Server..Platform..VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VCSW..VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VzCdb..VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:..Program Files..Common Files..Sony Shared..VAIO Entertainment Platform..VzCdb..VzFw.exe

--
End of file - 12439 bytes

BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:09 PM

Posted 13 October 2008 - 04:40 PM

:thumbsup: to BleepingComputer.com

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:09 PM

Posted 17 October 2008 - 09:34 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users