1
   

highjackthis/HJT report

 
 
littlek
 
Reply Mon 18 Sep, 2006 06:09 pm
Help! Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 7:55:37 AM, on 2/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\DOCUME~1\KRISTI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis_199.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,050 • Replies: 18
No top replies

 
littlek
 
  1  
Reply Mon 18 Sep, 2006 06:29 pm
I'll add that starting last night, my time/date reset to february. And I get an error message on start up warning of...... (looking through the list)..... a program that doesn't seem to be on the list - a *login*.com sort of title.

AND, my HJT is from february 2005. When I clicked on Timber's help thread and the highjackthis button, it started my own and I can't figure out where to safely download a newer version.
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 06:31 pm
Help with what? That logfile shows nothing malicious or even suspect. There's some Startup clutter, but even there, noticeable system performance impact should be little or nothing.
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 06:32 pm
So what is my problem?
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 06:33 pm
<now there's a loaded question!>
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 06:35 pm
Whatever your problem might be, that log doesn't offer any clues to potential problems - what problems are you having?
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 06:38 pm
Besides the norton ghost issues (validation and problems after reinstall which you addressed in a different thread) and the cursor being in all the wrong places (like next to the smilies to the left when I click near them), now my date and time have been reset and I get an error message when I log on saying that some *login*.com doesn't yet have a valid security certificate and do I want to continue.
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 06:39 pm
Oops, by the way, thanks for the quick response. Can you tell me what website I can go to to download hjt's current version? For some reason I am paranoid about picking a hjt executable file without knowing whih are legit. Seems like a good way to give my computer a virus.
0 Replies
 
gustavratzenhofer
 
  1  
Reply Mon 18 Sep, 2006 06:41 pm
I knew timber would be quick to respond to this type of query. He's almost as fast as H20 Man responding to a water softener question, but not quite.
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 07:00 pm
And I have to use the slider on the right side of the screen to scroll up and down about 70% of the time as arrow-up/down and page up/down don't usually work.
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 07:13 pm
You're right to be concerned about making sure you only download legitimate files. Your version of HJT appears to be the current one, though ... so I'm not sure why you'd wanna download another.
Anyhow - here's a link right to the author's website - http://www.merijn.org/files/hijackthis.zip

Could you be a little more specific about the security certificate message you get - like mebbe post the exact message?

What have your date & time been reset to, and what were you doing around the time thsat happened?
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 07:15 pm
They were set to february 1 2005 last night (and 12 hours difference). I was on a2k, reading and maybe at other websites, but I can't really remember.
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 07:17 pm
About the hjt program, I thought it was old.... thaks for the info.
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 07:19 pm
Just a guess, but might be related to your fussing around with Ghost - is that anything like the default time/date setting that was originally there when you first fired up that machine?
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 07:23 pm
oooooohhhhh.... yes, that would have been close to (or maybe exactly) the date my b-in-law started setting up this computer.

Now to figure out the rest of it.
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 08:01 pm
Well then - I'd say either now we have a useful clue, or there's been an amazing coincidence Laughing
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 08:03 pm
Heehee.... I thought the time thing started last night, but maybe that was something else.

I ran a pcpitstop scan and everything there looked more or less ok. I Ran a defrag on their suggestion and it just finished. Perhaps it's time (well, not tonight) to go through your tutorial step by step to clean up my system.....
0 Replies
 
timberlandko
 
  1  
Reply Mon 18 Sep, 2006 08:15 pm
I dunno as there's anything to "clean up" - your HJT log shows nothing indicating anything of concern. I'm gonna guess if anything, you've got some screwed up files in Windows itself. If you have an actual install disk for your version and servicepack of windows, you might wanna try the System File Check utility. With no other apps running, particularly any real-time monitoring/protecting apps, such as antivirus or antispyware, go to Start>Run, type (without the quotes) "sfc /scannnow" (note the space between "sfc and "/scannow", and note also the forward slash (/) and the 2 "n"s in "/scannow"), click "OK". A progress box should appear. During the process, you most likely will be asked to insert your WinXP installation disk, so have one handy (a vendor's "Restore" disk won't work without some fiddling, but alternately, any WinXP install disk - provided it is the same version - Home or Pro ... gotta be the same as what you have; Pro won't work on a Home version and vice-versa - and Service Pack as your installed Windows ... in your case SP2 ... will - and actually, all that's needed is the I386 file from the install disk, which can be copied from any WinXP install disk of the proper version and incorporating the appropriate Service Pack, even a "Restore" disk, placed in a folder on your machine, and targeted manually when you are prompted for your install disk). When the process has completed, reboot and see if your problems remain. One important note: after doing this, you'll hafta reinstall all Windows updates and patches released subsequent to the publication of Service Pack 2; they'll be gone.
0 Replies
 
littlek
 
  1  
Reply Mon 18 Sep, 2006 09:14 pm
OK, I'll try to do that tomorrow. This week looks busy and I'm behind on homework. Aaaaannnnd, as embarassing as this is to admit, that date wasn't when my computer was bought/configured. I got this computer in feb/march 2006, not 2005. I guess it's a sign to drop it for tonight and go to bed..... Thanks Timber.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » highjackthis/HJT report
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.06 seconds on 04/23/2024 at 04:48:34