Welcome, Guest

Go Back   TechieHQ - Computer Help Forum · » Operating Systems · System Infection Support
Reload this Page hjt log

hjt log

System Infection Support Support for virus, spy-ware, ad-ware, mal-ware and any other type of system infection.

Reply
 
Thread Tools Display Modes
  #1  
Old Feb 25th, 07, 5:14 PM
Core's Avatar
Core
voyeur
Posts: 1,067
Status: Offline
shield_mod.gifreviewst.png
 
From: San Antonio, TX
Joined: Jun 2003
Rep: Core is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to behold
im_gtalk.gif
hjt log

Broadband connection suffering acute connection problems... common sites timing out etc. Thought I'd run HJT and post the log here in case someone has time to take a look. I don't usually download junk I don't know and trust, but I'm not the sole user of this system...

Logfile of HijackThis v1.99.1
Scan saved at 10:02:50 AM, on 2/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Mary\Finances\System\reminder.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\MSALAK~1\LOCALS~1\Temp\Rar$EX00.859\Hi jackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\OFFICE~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Reminder] E:\Mary\Finances\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\OFFICE~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\OFFICE~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



__________________
Hello, World!
Reply With Quote
Advertisement
  #2  
Old Feb 26th, 07, 12:25 AM
Goober's Avatar
Goober
THQ's Jester
Posts: 2,622
Status: Offline
shield_mod.giftechie.gif
 
From: Colorado
Joined: Jul 2004
Rep: Goober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geekness
im_gtalk.gif
These can be removed:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

These I am questioning:

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE



__________________
You registered for QuakeCon on April 30, 2008, 6:56 pm. You were # 366 to sign up for QuakeCon!
Reply With Quote
  #3  
Old Feb 26th, 07, 2:44 AM
Core's Avatar
Core
voyeur
Posts: 1,067
Status: Offline
shield_mod.gifreviewst.png
 
From: San Antonio, TX
Joined: Jun 2003
Rep: Core is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to beholdCore is a splendid one to behold
im_gtalk.gif
Quote:
Originally Posted by Goober View Post
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
Nice catch. UpdReg is Creative's registration program...knew it was still hanging around. Nwiz turned out to be the direct culprit...it's part of NewDotNet or something of that nature...something I never intentionally installed.

Thanks.



__________________
Hello, World!
Reply With Quote
  #4  
Old Feb 26th, 07, 9:36 AM
Goober's Avatar
Goober
THQ's Jester
Posts: 2,622
Status: Offline
shield_mod.giftechie.gif
 
From: Colorado
Joined: Jul 2004
Rep: Goober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geeknessGoober has much to be proud of his / her geekness
im_gtalk.gif
I would have checked to see what they were but I did not have time to do that when I first looked at your HJT. There is not anything else I notice being wrong with your log, though Crypto and Codex always seem to find something



__________________
You registered for QuakeCon on April 30, 2008, 6:56 pm. You were # 366 to sign up for QuakeCon!
Reply With Quote
  #5  
Old Feb 27th, 07, 7:51 PM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
I didn't see anything else. I did look up the nwiz.exe entry before I seen Core's response and from what I found it was part of NVidia's Nview features.



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
Reply

Tags
hjt, log


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 4:48 PM.