Forum Home
Press F1
 
Thread ID: 108060 2010-03-12 07:05:00 Hijackthis log for Speedy .. Nomad (952) Press F1
Post ID Timestamp Content User
866388 2010-03-12 07:05:00 Speedy, can you please help .

Thanks so much .

Logfile of Trend Micro HijackThis v2 . 0 . 2
Scan saved at 8:02:47 p . m . , on 12/03/2010
Platform: Windows XP SP3 (WinNT 5 . 01 . 2600)
MSIE: Internet Explorer v6 . 00 SP3 (6 . 00 . 2900 . 5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss . exe
C:\WINDOWS\system32\winlogon . exe
C:\WINDOWS\system32\services . exe
C:\WINDOWS\system32\lsass . exe
C:\WINDOWS\system32\Ati2evxx . exe
C:\WINDOWS\system32\svchost . exe
C:\WINDOWS\System32\svchost . exe
C:\Program Files\Ahead\InCD\InCDsrv . exe
C:\WINDOWS\system32\Ati2evxx . exe
C:\WINDOWS\system32\ZoneLabs\vsmon . exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv . exe
C:\Program Files\Alwil Software\Avast4\ashServ . exe
C:\WINDOWS\system32\spoolsv . exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC . exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2 . exe
C:\Program Files\AskBarDis\bar\bin\AskService . exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2 . exe
C:\Program Files\Java\jre6\bin\jqs . exe
C:\Program Files\Google\Update\1 . 2 . 183 . 17\GoogleCrashHandler . exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer . exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv . exe
C:\WINDOWS\System32\svchost . exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService . exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4 . exe
C:\WINDOWS\Explorer . EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv . exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor . exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp . exe
C:\Program Files\Alwil Software\Avast4\ashWebSv . exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp . exe
C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\MOM . exe
C:\Program Files\Adobe\Acrobat 9 . 0\Acrobat\Acrotray . exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer . exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe
C:\WINDOWS\RTHDCPL . EXE
C:\Program Files\ASUS\Six Engine\SixEngine . exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper . exe
C:\Program Files\Logitech\QuickCam\Quickcam . exe
C:\Program Files\Ahead\InCD\InCD . exe
C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\ccc . exe
C:\WINDOWS\System32\svchost . exe
C:\Program Files\Java\jre6\bin\jusched . exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC 2 . EXE
C:\WINDOWS\system32\ctfmon . exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite . exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager . exe
C:\Program Files\DAP\DAP . EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer . exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv . exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv . exe
C:\WINDOWS\system32\wuauclt . exe
C:\Program Files\Mozilla Firefox\firefox . exe
C:\Program Files\MailWasher\MailWasher . exe
C:\Program Files\Windows Media Player\wmplayer . exe
C:\Program Files\Trend Micro\HijackThis\HijackThis . exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www . xnet . co . nz/
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim . dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar . dll
O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3 . dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin . dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5 . 1 . 1309 . 3572\s wg . dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv . dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin . dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1 . DLL
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~1\Toolbar\grabber . dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar . dll
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3 . dll
O4 - HKLM\ . . \Run: [Acronis*True*Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor . exe"
O4 - HKLM\ . . \Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp . exe"
O4 - HKLM\ . . \Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI . ACE\Core-Static\CLIStart . exe" MSRun
O4 - HKLM\ . . \Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager . ex e" -launchedbylogin
O4 - HKLM\ . . \Run: [ avast! ] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp . exe
O4 - HKLM\ . . \Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9 . 0\Acrobat\Acrobat_sl . exe"
O4 - HKLM\ . . \Run: [Acrobat Assistant 8 . 0] "C:\Program Files\Adobe\Acrobat 9 . 0\Acrobat\Acrotray . exe"
O4 - HKLM\ . . \Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient . exe"
O4 - HKLM\ . . \Run: [RTHDCPL] RTHDCPL . EXE
O4 - HKLM\ . . \Run: [Alcmtr] ALCMTR . EXE
O4 - HKLM\ . . \Run: [Six Engine] "C:\Program Files\ASUS\Six Engine\SixEngine . exe" -r
O4 - HKLM\ . . \Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper . exe"
O4 - HKLM\ . . \Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam . exe" /hide
O4 - HKLM\ . . \Run: [InCD] C:\Program Files\Ahead\InCD\InCD . exe
O4 - HKLM\ . . \Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck . exe
O4 - HKLM\ . . \Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask . exe" -atboottime
O4 - HKLM\ . . \Run: [EPSON Stylus Photo 2200 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC 2 . EXE /P32 "EPSON Stylus Photo 2200 (Copy 1)" /O5 "LPT1:" /M "Stylus Photo 2200"
O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched . exe"
O4 - HKLM\ . . \Run: [IMJPMIG8 . 1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG . EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\ . . \Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst . exe /SYNC
O4 - HKLM\ . . \Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP . EXE /SYNC
O4 - HKLM\ . . \Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP . EXE /IMEName
O4 - HKLM\ . . \Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC 2 . EXE /P23 "EPSON Stylus Photo 2200" /O6 "USB001" /M "Stylus Photo 2200"
O4 - HKCU\ . . \Run: [ctfmon . exe] C:\WINDOWS\system32\ctfmon . exe
O4 - HKCU\ . . \Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr . exe" /background
O4 - HKCU\ . . \Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier . exe
O4 - HKCU\ . . \Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite . exe" -onlytray
O4 - HKCU\ . . \Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP . EXE" /STARTUP
O4 - Global Startup: ColorVisionStartup . lnk = C:\Program Files\ColorVision\Utility\ColorVisionStartup . exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2 . lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0 2 . EXE
O4 - Global Startup: Microsoft Office . lnk = C:\Program Files\Microsoft Office\Office10\OSA . EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie . htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie . htm
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll/AcroIEAppendSelLinks . html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll/AcroIEAppend . html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll/AcroIECaptureSelLinks . html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient . dll/AcroIECapture . html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2 . htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL . EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe
O9 - Extra 'Tools' menuitem: @xpsp3res . dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau . dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1 . DLL
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2 . exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService . exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv . exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc . - C:\WINDOWS\system32\Ati2evxx . exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ . exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv . exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv . exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC . exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2 . exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc . - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService . exe
O23 - Service: Google Update Service (gupdate1c9d391b5b58c64) (gupdate1c9d391b5b58c64) - Google Inc . - C:\Program Files\Google\Update\GoogleUpdate . exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService . exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT . exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv . exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc . - C:\Program Files\Java\jre6\bin\jqs . exe
O23 - Service: LVCOMSer - Logitech Inc . - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer . exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc . - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv . exe
O23 - Service: LVSrvLauncher - Logitech Inc . - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch . exe
O23 - Service: ServiceLayer - Nokia . - C:\Program Files\PC Connectivity Solution\ServiceLayer . exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc . - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr . exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon . exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService . exe
Nomad (952)
866389 2010-03-12 07:12:00 You can tick these, then tick fix checked

Close browsers

I would update IE 6 to 7 or 8. Even if you dont use it

Uninstall askbar

R3 - URLSearchHook: (no name) - - (no file)

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Could be zonealarm thats causing it
Speedy Gonzales (78)
866390 2010-03-12 08:02:00 Cheers for that.

I think it is Xnet. I have been using ZA since 1999/2000 and no problems. Other than the conflict with WinXP security but that was fixed with a newer download.

ZA is not the issue. Yes, I have had no problems with Clear Net as an ISP or at university hardwired to their network switch. I left it on 16hrs a day unless when the student network crashed. Xnet wasn't an issue to about a year ago.
Nomad (952)
866391 2010-03-12 08:07:00 Yup I think youre right it is Xnet. Its slow as hell right now. I was going to change to telecom. But since I dont pay for the phone, (the flatmate does),telecom said she'll have to have the net bill put onto her phonebill, before I can change. Or add me to her phonebill, then when the bill comes, we'll have to split it. But, thats not going to happen lol. So, I cant go with telecom Speedy Gonzales (78)
1