| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 102789 | 2009-09-01 10:11:00 | Hijackthis log file | Nomad (952) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 806096 | 2009-09-01 10:11:00 | Can someone pls have a look a this, for someone's PC, done ccleaner, malwarebytes, trojan remover, gonna remove avg LATER and put in avast . Cheers Logfile of Trend Micro HijackThis v2 . 0 . 2 Scan saved at 8:31:53 p . m . , on 1/09/2009 Platform: Windows XP SP3 (WinNT 5 . 01 . 2600) MSIE: Internet Explorer v8 . 00 (8 . 00 . 6001 . 18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss . exe C:\WINDOWS\system32\winlogon . exe C:\WINDOWS\system32\services . exe C:\WINDOWS\system32\lsass . exe C:\WINDOWS\system32\svchost . exe C:\WINDOWS\System32\svchost . exe C:\WINDOWS\system32\spoolsv . exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService . exe C:\PROGRA~1\AVG\AVG8\avgwdsvc . exe C:\WINDOWS\Explorer . EXE C:\Program Files\Bonjour\mDNSResponder . exe C:\WINDOWS\system32\HPConfig . exe C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr . exe C:\Program Files\Java\jre6\bin\jqs . exe C:\WINDOWS\System32\MsPMSPSv . exe C:\PROGRA~1\AVG\AVG8\avgrsx . exe C:\PROGRA~1\AVG\AVG8\avgnsx . exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx . exe C:\Program Files\HPQ\One-Touch\OneTouch . EXE C:\Program Files\Synaptics\SynTP\SynTPLpr . exe C:\Program Files\Synaptics\SynTP\SynTPEnh . exe C:\WINDOWS\System32\hphmon05 . exe C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc . exe C:\WINDOWS\system32\carpserv . exe C:\Program Files\Hewlett-Packard\Toolbox2 . 0\Apache Tomcat 4 . 0\webapps\Toolbox\StatusClient\StatusClient . exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2 . exe C:\PROGRA~1\AVG\AVG8\avgtray . exe C:\Program Files\Hewlett-Packard\Toolbox2 . 0\Javasoft\JRE\1 . 3 . 1\bin\javaw . ex e C:\Program Files\iTunes\iTunesHelper . exe C:\Program Files\Java\jre6\bin\jusched . exe C:\Program Files\Messenger\msmsgs . exe C:\WINDOWS\system32\ctfmon . exe C:\Program Files\iPod\bin\iPodService . exe C:\Program Files\Internet Explorer\IEXPLORE . EXE C:\Program Files\Internet Explorer\IEXPLORE . EXE C:\Program Files\Yahoo!\Companion\Installs\cpn\ytbb . exe C:\Program Files\Trend Micro\HijackThis\HijackThis . exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = . ask . com/web?o=13110&l=dis" target="_blank">www . ask . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = . microsoft . com/fwlink/?LinkId=54896" target="_blank">go . microsoft . com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = . microsoft . com/fwlink/?LinkId=69157" target="_blank">go . microsoft . com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer . exe //ICWLaunch R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = * . local R3 - URLSearchHook: Yahoo!Xtra Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt . dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt . dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5 . 0\Reader\ActiveX\AcroIEHelper . ocx O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar . dll O2 - BHO: WormRadar . com IESiteBlocker . NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie . dll O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3 . 0 . 1203 . 0\msneshellx . dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv . dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin . dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstan ce . dll O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3 . 0 . 1203 . 0\msneshellx . dll O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar . dll O3 - Toolbar: Yahoo!Xtra Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt . dll O4 - HKLM\ . . \Run: [ATIModeChange] Ati2mdxx . exe O4 - HKLM\ . . \Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx . exe O4 - HKLM\ . . \Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks . exe /s O4 - HKLM\ . . \Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch . EXE O4 - HKLM\ . . \Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset . exe O4 - HKLM\ . . \Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr . exe O4 - HKLM\ . . \Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh . exe O4 - HKLM\ . . \Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05 . exe O4 - HKLM\ . . \Run: [HPHmon05] C:\WINDOWS\System32\hphmon05 . exe O4 - HKLM\ . . \Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil . exe" O4 - HKLM\ . . \Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc . exe" O4 - HKLM\ . . \Run: [CARPService] carpserv . exe O4 - HKLM\ . . \Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2 . 0\Apache Tomcat 4 . 0\webapps\Toolbox\StatusClient\StatusClient . exe /auto O4 - HKLM\ . . \Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2 . 0\hpbpsttp . exe O4 - HKLM\ . . \Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig . exe -c Direct -p DOT4_001 -pn "hp LaserJet 1010 Series Driver" -n 0 -l 1033 -sl 120000 O4 - HKLM\ . . \Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2 . exe O4 - HKLM\ . . \Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray . exe O4 - HKLM\ . . \Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask . exe" -atboottime O4 - HKLM\ . . \Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper . exe" O4 - HKLM\ . . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched . exe" O4 - HKCU\ . . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs . exe" /background O4 - HKCU\ . . \Run: [ctfmon . exe] C:\WINDOWS\system32\ctfmon . exe O4 - HKUS\S-1-5-18\ . . \Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify . exe (User 'SYSTEM') O4 - HKUS\ . DEFAULT\ . . \Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify . exe (User 'Default user') O4 - Global Startup: Microsoft Office . lnk = C:\Program Files\Microsoft Office\Office10\OSA . EXE O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR . DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe O9 - Extra 'Tools' menuitem: @xpsp3res . dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag . exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe O14 - IERESET . INF: START_PAGE_URL=http://qau8l . hpwis . com O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - . facebook . com/controls/2008 . 10 . 10_v5 . 5 . 8/FacebookPhotoUploader5 . cab" target="_blank">upload . facebook . com O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - . scan . onecare . live . com/resource/download/scanner/wlscbase1140 . cab" target="_blank">cdn . scan . onecare . live . com O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - . macromedia . com/get/shockwave/cabs/flash/swflash . cab" target="_blank">fpdownload2 . macromedia . com O17 - HKLM\System\CCS\Services\Tcpip\ . . \{6F81AFB1-E63E-47FE-887B-95CCE30E11FE}: NameServer = 203 . 96 . 152 . 4,203 . 96 . 152 . 12 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp . dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx . dll O23 - Service: Apple Mobile Device - Apple Inc . - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService . exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s . r . o . - C:\PROGRA~1\AVG\AVG8\avgwdsvc . exe O23 - Service: Bonjour Service - Apple Inc . - C:\Program Files\Bonjour\mDNSResponder . exe O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig . exe O23 - Service: HPWirelessMgr - Hewlett-Packard Co . - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr . exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT . exe O23 - Service: iPod Service - Apple Inc . - C:\Program Files\iPod\bin\iPodService . exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc . - C:\Program Files\Java\jre6\bin\jqs . exe O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr . exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12 . exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv . exe -- End of file - 9364 bytes |
Nomad (952) | ||
| 806097 | 2009-09-01 10:21:00 | You can tick these then tick fix checked Close browsers Uninstall askbar O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background I would uninstall Symantec as well O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE |
Speedy Gonzales (78) | ||
| 806098 | 2009-09-01 10:36:00 | Thanks, how do I know they have Symantec? Also if I tick that box it won't rid MSN Messenger right? | Nomad (952) | ||
| 806099 | 2009-09-01 10:39:00 | You can leave msn's entry there, if you want. It wont remove it, it'll just stop it from loading on startup O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user') It looks like a program was uninstalled, but these 2 entries are still running on startup Try the nortons removal tool.. There maybe remnants of the program on the hdd |
Speedy Gonzales (78) | ||
| 806100 | 2009-09-01 10:46:00 | I've found Autorun (technet.microsoft.com) to be an effective tool for start up programs. The amount of mislead people that use msconfig.. cricky! Sorry to 'Hi-jack' this thread, but thought it would be a good chance to recommend a handy tool. |
Chris09 (15218) | ||
| 806101 | 2009-09-01 10:47:00 | Thanks Speedy, so it is pretty clean ... Prob he only has 256MB reduced to 192MB with the onboard graphics in his laptop. It was sold with XP, maybe that is why it is slow... Hopefully ridding AVG will help. |
Nomad (952) | ||
| 1 | |||||