|
|
#1 (permalink) |
|
Silver Member
![]() Join Date: Nov 2007
Posts: 122
|
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:52:38 PM, on 12/30/2007 Platform: Windows 2003 SP2 (WinNT 5.02.3790) MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830) Boot mode: Normal Running processes: C:\Program Files (x86)\Lavasoft\Ad-Aware 2007\aawservice.exe C:\PROGRA~2\Grisoft\AVG7\avgrssvc.exe C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\sched.exe C:\PROGRA~2\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~2\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~2\Grisoft\AVG7\avgrssvc.exe C:\PROGRA~2\Grisoft\AVG7\avgemc.exe C:\WINDOWS\CDProxyServ.exe C:\WINDOWS\SysWOW64\PnkBstrA.exe C:\Program Files (x86)\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.ex e C:\Program Files (x86)\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files (x86)\CursorXP\CursorXP.exe C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe C:\Program Files (x86)\Analog Devices\SoundMAX\Smax4.exe C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files (x86)\Windows Media Player\wmplayer.exe C:\Program Files (x86)\Grisoft\AVG7\avgwb.dat C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files (x86)\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe C:\PROGRA~2\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispat...=%s&tbid=60001 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/?tbid=60001 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_cu...spx?TbId=60001 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_cu...spx?TbId=60001 R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\ctbr.dll F2 - REG:system.ini: UserInit=userinit O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~2\Crawler\ctbr.dll O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files (x86)\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CursorXP] "C:\Program Files (x86)\CursorXP\CursorXP.exe" -s O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~2\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~2\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~2\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~2\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~2\Crawler\ctbr.dll O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - Unknown owner - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer .exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files (x86)\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~2\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~2\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~2\Grisoft\AVG7\avgrssvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~2\Grisoft\AVG7\avgemc.exe O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe O23 - Service: DirMS_Defragmentation - Unknown owner - C:\Program Files (x86)\MATCO\DirmsService.exe O23 - Service: Event Log (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing) O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files (x86)\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.ex e O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: Net Logon (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc64.exe (file missing) O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Virtual Disk Service (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) -- End of file - 7572 bytes
__________________
Case - Antec 900 Mobo - ASUS nForce 650i SLI Processor - Intel Q6600 quad core Vid Card - eVGA 8600GTS HDD - Western Digital 750GB PSU - Rosewill 900W RAM - GEIL 4GB DDR2 800 |
|
|
|
|
|
#2 (permalink) | |
|
Diamond Member
![]() Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,935
|
EDIT BY CEEWI1:
PLEASE SEE HJT Log Checkup Hello! Since it's just a checkup I didn't expect sth nasty and I haven't found anything nasty. Please run HIjackThis and choose Do a system scan only.
After that just reboot your computer, you can post a fresh HijackThis log although it wouldn't be necesserry I think. Oh yes, I saw you use Spybot and AVG in the same time. Please disable Spybot because two antivirus programs may intefere and slow down your computer a bit. Use Spybot only for scans, not as permanent protection. Cheers! GameMaster
__________________
dznutz: Quote:
Last edited by ceewi1; 12-31-2007 at 01:09 AM. |
|
|
|
|
|
|
#3 (permalink) |
|
Diamond Member
![]() Join Date: Jan 2007
Location: France
Age: 18
Posts: 4,880
|
Actually Spybot isn't an anti-virus.
![]() It's a anti-spyware so you can run both.
__________________
Punk's anti-hackers website Punk's Website making and registering tutorial! Rise And Fall, Rage And Grace The Offspring! Huck it! I just want to be who I want to be
guess that's hard for others to see |
|
|
|
|
|
#4 (permalink) | |
|
Diamond Member
![]() Join Date: Dec 2007
Location: Croatia
Age: 16
Posts: 3,935
|
Well is it good to have both turned on as permanent protection?
I saw ceewi once suggested to turn it off too. I have never seen Spybot in a HijackThis log, really. Ok, anyway. It's same to me hh
__________________
dznutz: Quote:
|
|
|
|
|
|
|
#5 (permalink) |
|
Diamond Member
![]() Join Date: Jan 2007
Location: France
Age: 18
Posts: 4,880
|
hmmm as permanent protection probably not good but as weekly scanners or occasional scanners it's harmless.
__________________
Punk's anti-hackers website Punk's Website making and registering tutorial! Rise And Fall, Rage And Grace The Offspring! Huck it! I just want to be who I want to be
guess that's hard for others to see |
|
|
|
|
|
#6 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,279
|
Please do not do any of the previous HijackThis fixes.
Your logfile indicates that you have the Sony Rootkit infection. You can either Update the XCP software on your computer or Completely uninstall the XCP software and associated content protection files. Your call. Follow the instructions on this page: http://cp.sonybmg.com/xcp/english/updates.html You can leave Spybot running. That aside, your logfile appears to be clean.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#7 (permalink) |
|
Silver Member
![]() Join Date: Nov 2007
Posts: 122
|
I used that uninstaller to uninstall it. Now I have another question... My counter strike: source has just recently started lagging. It was fine for about a month of playing then all of a sudden it has started lagging. I see people running and all of a sudden they'll have taken a few steps and I see them like three steps ahead, I just don't see the movement of how they got there. I'm not sure if the cause of this is something security related or hardware/software malfunction or what. It could also be my router, correct? Anyone know why?
__________________
Case - Antec 900 Mobo - ASUS nForce 650i SLI Processor - Intel Q6600 quad core Vid Card - eVGA 8600GTS HDD - Western Digital 750GB PSU - Rosewill 900W RAM - GEIL 4GB DDR2 800 |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer cant find network unless in safe mode. (hjt log included) | ukulele_ninja | Computer Security | 6 | 12-30-2007 02:42 AM |
| HJT Log for Friends Laptop | HumanMage | Computer Security | 2 | 12-30-2007 01:48 AM |
| HJT log | 34erd | Computer Security | 5 | 08-10-2006 01:04 PM |
| HJT Log what is it? | zeneena | Computer Security | 10 | 12-07-2005 11:11 PM |
| HJT log | 34erd | Computer Security | 1 | 11-29-2005 02:20 PM |