Tuesday, August 17, 2010

Can Anyone help me analyze my Hijack This Log?

Logfile of HijackThis v1.99.1


Scan saved at 12:46:30 AM, on 5/14/2007


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)





Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\Explorer.EXE


C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe


C:\WINDOWS\MMKeybd.exe


C:\Program Files\Common Files\Symantec Shared\ccApp.exe


C:\WINDOWS\AGRSMMSG.exe


C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe


C:\Program Files\iTunes\iTunesHelper.exe


C:\WINDOWS\system32\ctfmon.exe


C:\Program Files\Microsoft ActiveSync\Wcescomm.exe


C:\PROGRA~1\MICROS~3\rapimgr.exe


C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe


C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe


C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe


C:\Program Files\Netropa\OSD.exe


C:\WINDOWS\Nhksrv.exe


C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSv...


C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe


C:\WINDOWS\System32\dllhost.exe


C:\Program Files\Common Files\LightScribe\LSSrvc.exe


C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe


C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe


C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT...


C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe


C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1...


C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe


C:\Program Files\iPod\bin\iPodService.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\Program Files\Messenger\msmsgs.exe


C:\Documents and Settings\Terry Spycher\Desktop\HijackThis.exe





R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


O1 - Hosts: 205.238.40.52 www.winmx.com err.winmx.com


O1 - Hosts: 205.238.40.1 cache0.winmx.com test3201.winmx.com test3205.winmx.com


O1 - Hosts: 205.238.40.2 cache1.winmx.com test3202.winmx.com test3206.winmx.com


O1 - Hosts: 82.43.224.20 cache2.winmx.com test3203.winmx.com test3207.winmx.com


O1 - Hosts: 82.204.21.111 cache3.winmx.com test3204.winmx.com test3208.winmx.com


O1 - Hosts: 205.238.40.1 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com


O1 - Hosts: 205.238.40.1 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com


O1 - Hosts: 205.238.40.1 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com


O1 - Hosts: 82.43.224.20 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com


O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com


O1 - Hosts: 82.204.21.111 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com


O1 - Hosts: 82.204.21.111 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com


O1 - Hosts: 205.238.40.1 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com


O1 - Hosts: 205.238.40.1 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com


O1 - Hosts: 205.238.40.1 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com


O1 - Hosts: 205.238.40.2 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com


O1 - Hosts: 82.43.224.20 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com


O1 - Hosts: 82.43.224.20 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com


O1 - Hosts: 82.204.21.111 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com


O1 - Hosts: 82.204.21.111 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com


O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll


O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll


O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll


O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll


O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp


O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer


O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe


O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe


O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"


O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe


O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1


O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"


O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe


O8 - Extra context menu item: E%26amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCE...


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll


O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll


O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.D...


O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)


O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=6...


O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=3...


O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp...


O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...


O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - http://housecall65.trendmicro.com/housec...


O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/F...


O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp...


O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll


O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll


O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll


O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe


O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSv...


O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe


O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe


O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe


O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe


O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.E...


O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe


O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe


O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe


O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.E...


O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe


O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\S...


O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe


O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\N...


O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Can Anyone help me analyze my Hijack This Log?
You certainly have a bunch of things running. The first 7 entries are necessary. The PowerDVD entry is unnecessary but harmless.





C:\WINDOWS\MMKeybd.exe - not sure, maybe a keyboard driver?





C:\Program Files\Common Files\Symantec Shared\ccApp.exe - Part of Norton Anti-Virus





C:\WINDOWS\AGRSMMSG.exe - This is part of the Softmodem Assistant. It is non-essential, but probably should not be terminated unless it is causing problems.





C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe - part of Adobe Acrobat, but not necessary.





C:\Program Files\iTunes\iTunesHelper.exe - This was installed with Quicktime, it is not particularly necessary.





C:\WINDOWS\system32\ctfmon.exe - part of Microsoft Office. It activates the Alternative User Input Text Input Processor (TIP) and the Microsoft Office XP Language Bar. It probably should not be terminated unless it is causing trouble.





C:\Program Files\Microsoft ActiveSync\Wcescomm.exe - Windows synchonization manager for Windows CE handhelds. Do not terminate this advice while connected to the handheld.





C:\PROGRA~1\MICROS~3\rapimgr.exe - Another part of ActiveSync for synchronizing with mobile devices.





I don't know why you have 3 copies Yahoo! Widget Engine or exactly what it is. I believe it is a toolbar, but I'm not sure.





OSD.EXE has something to do with the display. It is not a critical component.





Nhksrv.exe is related to owning a Dell PC. It is used to disable hotkeys while the screen saver is active. It is non-essential.





All the Symantec and Norton stuff are okay, but you may wish to do what others suggested and get a less greedy utilities suite. New versions of NAV and NSW keep getting larger and larger and having more and more processes.





The dllhost.exe file is necessary.





LSSrvc.exe is for Nero LightScribe. It is not system critical, but you may lose the label writing capability.





iPodService.exe is a part of ITunes. It is not system critical, but ITunes might not work properly.





Msmsgs.exe is the main part of MSN Messenger. It is not system critical. This loads a tray bar as well.











The multiple svchost.exe files are fishy. That is a necessary system file, but it can be used in conjuction with malware, so if the reason it is running cannot be found, it could be fishy:





http://www.liutilities.com/products/wint...





The R0 entries are fine.





All the O1 entries (hosts entries) are fine. That just means that PiePatch is installed to make WinMX work.





The 2 O9's with missing files should be fixed.





I may update this later....analyzing this is a lot of work.
Reply:Your BHOs are fine. The toolbars are not malicious. On the O4 entries, the QuickTime Task isn't necessary and can be safely deleted. QuickTime will put it back if it wants it. On unfamilar files, you can put their names in a search engine and most of them will return hits. Report Abuse

Reply:Some things are better managed elsewhere. One thing to do is review your system services. Here is a tweak guide for those: http://www.blackviper.com/WinX...


This can be used to reduce vulnerabilities and memory usage by disabling what you don't use. Report Abuse

Reply:http://hjt.networktechs.com/ This provides three links to helping you determin whats what.





http://www.prevx.com/hijackthis.asp


Paste your log here. It will tell you whats what automaticly. (it does not get everything though.. Most of the commen things.





http://exelib.com/hijack


Here is another one that will auto analize what you have runnning.





http://www.bleepingcomputer.com/tutorial...


A great tool for hijack this, It tells you how to use hijack this, and what the BHO, R1, R2 R3 and such stands for
Reply:-Please mentioned what is exactly your problem so we can help you.


-I suggest to you that to uninstall ( Symantec SystemWorks ) or any Symantec Norton Antivirus from your computer, and go with ( AVG Anti-Virus Free Edition 7.5.467 ) it is much better than Norton.
Reply:You have 26 BAD entries that need removing!!! And a bunch of other Fuzzy Algorithmchecks....


Copy/Paste your logfile in the box and click analyze.


So, here's the site you go to (bookmark this for future use like I did!) To find out what's bad and good in the hijackthis logfile...


http://www.hijackthis.de/
Reply:In addition to the forum just mentioned, you can also try here:





http://forums.spywareinfo.com/





and post your HiJackThis log. You will get an extremely rapid, very precise answer as to whether or not you still have any infections and, if so, exactly what to do.





After everything is all cleaned up I recommend installing SpyBot (it's free; just make sure to keep it updated):


http://www.safer-networking.org/





and SpywareTerminator (also free):


http://www.spywareterminator.com/





Good luck!
Reply:Wow, your computer must be hella slow. You have so much updating software and on top of it all Symantec is all over the place. You probably take forever opening a program or doing anything. Anything in system32 is neccessary. Try to go to


Start%26gt;Run%26gt;Msconfig (type that and hit ok)


Than go to the startup tab and uncheck everything that is not in system32. Or just everything. Click ok and save changes and restart. See how much faster your computer is now...


to unchange just do the same thing but check stuff you want to run.
Reply:let the experts take a look at whats happening on your computer.Visit the HijackThis Logs and Analysis forum.


http://www.bleepingcomputer.com/forums/i...


No comments:

Post a Comment