Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Help with HJT Log File  (Read 5131 times)

0 Members and 1 Guest are viewing this topic.

NNEagle

    Topic Starter


    Beginner

    Thanked: 1
    Help with HJT Log File
    « on: November 14, 2007, 09:30:23 AM »
    Request help from this log file. This computer is a Company one. We are required to update and keep it running. No admin rights and that is not a bother.

    About ten days ago, I noticed the Symantec Client Security file showing emtpy. Immediately downloaded AVG and  Skybot.

    Since of late, the computer tends to hang on each and everything request. Just wondering if there is something wrong and if you could help me out.

    Thanks for your time
    Pentium 4(R) CPU 2.80GHZ
    2.97 GHZ, 248 MB of Ram
    Windows XP SP2
    Eagle

    NNEagle

      Topic Starter


      Beginner

      Thanked: 1
      Re: Help with HJT Log File
      « Reply #1 on: November 14, 2007, 09:35:48 AM »
      OOps   sorry for this. How do I post the HJT file please?
      Eagle

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Help with HJT Log File
      « Reply #2 on: November 14, 2007, 10:09:44 AM »
      Download HijackThis  to your desktop.
      Double-click on the file you just downloaded.
      Click on the "Install" button to install.
      It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
      Please do not change the default install location.
      Upon install, HijackThis should open for you.

      Next click on the "Do a system scan and save a log file" button.
      HijackThis will scan and then a log will open in notepad.
      In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
      Please save the log as a text (.txt) file.
      In your post, add the log as an Attachment.

      * Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
      ** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

      You may need a few different posts to get the whole log in




      NNEagle

        Topic Starter


        Beginner

        Thanked: 1
        Re: Help with HJT Log File
        « Reply #3 on: November 14, 2007, 10:53:54 AM »
        I am not able to post any replies in here. I keep getting a message about an error that has occured.
        The HJT file has been saved as a Text Document(*.txt) but when I try to send the attachment. I get an error message all over again saying that this fomat is not supported etc etc. Any ideas

        Hope this reply goes through
        Eagle

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Help with HJT Log File
        « Reply #4 on: November 14, 2007, 11:17:53 AM »
        That should work, if needed copy and paste the log in the reply.

        You may need more than one post to fit it all in.

        Just be sure it begins with "Logfile of HijackThis"

        And ends with "End of logfile"

        I will attach a guide for attachments I wrote.

        [getting disk space - attachment deleted by admin]

        NNEagle

          Topic Starter


          Beginner

          Thanked: 1
          Re: Help with HJT Log File
          « Reply #5 on: November 14, 2007, 11:30:30 AM »
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 8:25:42 PM, on 11/14/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\netdde.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\Symantec\pcAnywhere\awhost32.exe
          C:\Program Files\Symantec AntiVirus\DefWatch.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\inetsrv\inetinfo.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\System32\snmp.exe
          C:\Program Files\Symantec AntiVirus\Rtvscan.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\PROGRA~1\SYMANT~1\VPTray.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Picasa2\PicasaMediaDetector.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
          C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
          C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
          C:\WINDOWS\explorer.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal/offshore
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal/offshore
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
          O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [TweakRAM] G:\Computer\TweakRAM61\TweakRAM\TweakRAM.exe
          O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] J:\Computer\RegistryBooster 2\RegistryBooster.exe /S
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
          O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C
          Eagle

          NNEagle

            Topic Starter


            Beginner

            Thanked: 1
            Re: Help with HJT Log File
            « Reply #6 on: November 14, 2007, 11:31:32 AM »
            571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O14 - IERESET.INF: START_PAGE_URL=http://portal/offshore
            O15 - Trusted Zone: *.ensco.ws
            O15 - Trusted Zone: *.enscous.com
            O15 - Trusted Zone: *.ensco.ws (HKLM)
            O15 - Trusted Zone: *.enscous.com (HKLM)
            O16 - DPF: Yahoo! Chat -
            O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
            O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.20/WinSSWebAgent.CAB
            O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
            O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.runaware.com/dolphin/wficat.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144333461035
            O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
            O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
            O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
            O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ensco.ws
            O17 - HKLM\Software\..\Telephony: DomainName = ensco.ws
            O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ensco.ws
            O20 - Winlogon Notify: Reliability - C:\WINDOWS\
            O21 - SSODL: adsnv - {8F61586C-5D1B-4c76-BB3A-3B88F96A18B0} - C:\WINDOWS\system32\adsnv.dll (file missing)
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
            O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
            O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
            O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
            O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

            --
            End of file - 10789 bytes
            Eagle

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Help with HJT Log File
            « Reply #7 on: November 14, 2007, 12:00:22 PM »
            First, you are running two antivirus. This is unnecessary. It causes system conflicts and slowdowns. This could be the source of the system hanging. Antivirus running together tend to "argue" with one another. Pick one and uninstall the other. If you are paying for Symantec and happy with it then I would uninstall the AVG.

            =====

            Is ensco your ISP?

            =====

            Check your Trusted Zones and possibly reset them.

               1. Do not open Internet Explorer. Make sure all browser Windows and other applications (including email) are closed.
               2. Right-click the Internet Explorer icon on the desktop.
               3. Choose 'Properties'.
               4. Click the 'Security' tab.
               5. Click the 'Trusted Sites' icon to highlight
               6. Click the 'Sites' button to review the list of sites included.
               7. If you see an unwanted site on the list, click once on the site link displayed to highlight it, then click the 'Remove' button.
               8. When finished viewing or modifying the Trusted Sites list, click OK and then click Apply (if any changes were made).
               9. Click OK to exit the Properties menu.

            =====

            Open HijackThis (HJT) and select "Do a system scan only"
            Place a check mark next to these entries.
            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C
            O14 - IERESET.INF: START_PAGE_URL=http://portal/offshore <---Unless this is your ISP and you need it.
            O21 - SSODL: adsnv - {8F61586C-5D1B-4c76-BB3A-3B88F96A18B0} - C:\WINDOWS\system32\adsnv.dll (file missing)


            Close all windows except for HijackThis (HJT) and select "Fix checked"

            =====

            I did not see any malware in the log, if things are not right after performing these steps we can do some more thorough scans.

            After completing these steps, please submit a new HijackThis log.

            NNEagle

              Topic Starter


              Beginner

              Thanked: 1
              Re: Help with HJT Log File
              « Reply #8 on: November 14, 2007, 12:49:28 PM »
              Ensco is my ISP.

              At the Security tab of Internet Explorer.I just got displays related to the Administrators, Radio Room (me) and System. Could not go further from there even though I clicked on Radio Room and System.

              Here is my new HJT after doing what you asked me to do

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 10:33:39 PM, on 11/14/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Windows Defender\MsMpEng.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\netdde.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Symantec\pcAnywhere\awhost32.exe
              C:\Program Files\Symantec AntiVirus\DefWatch.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\inetsrv\inetinfo.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\System32\snmp.exe
              C:\Program Files\Symantec AntiVirus\Rtvscan.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
              C:\PROGRA~1\SYMANT~1\VPTray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\Picasa2\PicasaMediaDetector.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal/offshore
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal/offshore
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
              O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
              O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
              O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
              O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
              O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              Eagle

              NNEagle

                Topic Starter


                Beginner

                Thanked: 1
                Re: Help with HJT Log File
                « Reply #9 on: November 14, 2007, 12:51:02 PM »
                O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [TweakRAM] G:\Computer\TweakRAM61\TweakRAM\TweakRAM.exe
                O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] J:\Computer\RegistryBooster 2\RegistryBooster.exe /S
                O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O14 - IERESET.INF: START_PAGE_URL=http://portal/offshore
                O15 - Trusted Zone: *.ensco.ws
                O15 - Trusted Zone: *.enscous.com
                O15 - Trusted Zone: *.ensco.ws (HKLM)
                O15 - Trusted Zone: *.enscous.com (HKLM)
                O16 - DPF: Yahoo! Chat -
                O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
                O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.20/WinSSWebAgent.CAB
                O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
                O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.runaware.com/dolphin/wficat.cab
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144333461035
                O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
                O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
                O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ensco.ws
                O17 - HKLM\Software\..\Telephony: DomainName = ensco.ws
                O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ensco.ws
                O20 - Winlogon Notify: Reliability - C:\WINDOWS\
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

                --
                End of file - 9475 bytes
                Eagle

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Help with HJT Log File
                « Reply #10 on: November 14, 2007, 01:25:36 PM »
                The log isn't showing any malware, do you need your ISP in the trusted zones? We can fix this with HijackThis but only if you do not need them there.

                =====

                Lets run a more in depth scan to be sure

                First some house cleaning to speed up the scan.

                Please download ATF Cleaner by Atribune. ATF Cleaner.exe This program does not require an installation. The executable actually runs the program.

                NOTE: ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
                * Double-click ATF-Cleaner.exe to run the program.
                * Under Main choose: Select All
                * Click the Empty Selected button.

                If you use Firefox browser
                * Click Firefox at the top and choose: Select All
                * Click the Empty Selected button.
                NOTE: If you would like to keep your saved passwords, please click No at the prompt.

                If you use Opera browser
                * Click Opera at the top and choose: Select All
                * Click the Empty Selected button.
                NOTE: If you would like to keep your saved passwords, please click No at the prompt.

                Click Exit on the Main ATF Cleaner menu to close the program.

                =====

                Use the  ESET Nod32 Online Scanner

                Click YES, I accept the Terms of Use. Then Start.

                The scan report is saved by default in C:\Program Files\EsetOnlineScanner\log.txt

                Add the EsetOnlineScanner\log.txt in your post.

                This scan will take a while so no need to sit and wait on it.

                NNEagle

                  Topic Starter


                  Beginner

                  Thanked: 1
                  Re: Help with HJT Log File
                  « Reply #11 on: November 14, 2007, 04:11:11 PM »
                   I am not sure about wanting my ISP in the trusted zones. That was put in there by the Administrator.

                  This is the log from the EsetOnlineScanner.

                  # version=4
                  # OnlineScanner.ocx=1.0.0.56
                  # OnlineScannerDLLA.dll=1, 0, 0, 51
                  # OnlineScannerDLLW.dll=1, 0, 0, 51
                  # OnlineScannerUninstaller.exe=1, 0, 0, 49
                  # vers_standard_module=2658 (20071114)
                  # vers_arch_module=1.059 (20071108)
                  # vers_adv_heur_module=1.066 (20070917)
                  # EOSSerial=b17ce3ca79b19948bff4f4af358f6350
                  # end=finished
                  # remove_checked=true
                  # unwanted_checked=true
                  # utc_time=2007-11-14 10:39:37
                  # local_time=2007-11-15 01:39:37 (+0300, Arab Standard Time)
                  # country="United States"
                  # osver=5.1.2600 NT Service Pack 2
                  # scanned=306546
                  # found=0
                  # scan_time=3876
                  Eagle

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Help with HJT Log File
                  « Reply #12 on: November 14, 2007, 04:18:49 PM »
                  I don't want to do anything set up by the Admin that may have negative results.

                  The log is clean so looks like you are in the clear as of now.

                  To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? It mentions many free programs so it is worth a look.

                  If you have any more problems just post here or make a new post and we will have a look.

                  Safe surfing....

                  NNEagle

                    Topic Starter


                    Beginner

                    Thanked: 1
                    Re: Help with HJT Log File
                    « Reply #13 on: November 14, 2007, 04:27:25 PM »
                    Thank you very much for all the help and time take to get this old junk bag to work top form once again.

                    Will always remain grateful to you and the team at Computer Hope. This is not the first time that I was helped. And it was always a successful ending.

                    Thank you once again
                    Eagle