Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Dec 27 2007, 05:09 PM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 25 Joined: 24-June 06 Member No.: 57,428 Operating System: Windows XP |
Computer seems slow and also when doing virus scan from alwil is saying directx 9 is corrupted. Any help or info would be greatly appreciated. Thanks
Logfile of HijackThis v1.99.1 Scan saved at 5:07:29 PM, on 12/27/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\BCMSMMSG.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} (Lexmark eDiagnostics Class) - https://ediagnostics.lexmark.com/serval.cab O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe ComboFix 07-12-21.4 - Aarons 2007-12-27 16:47:42.1 - NTFSx86 Running from: C:\Documents and Settings\Aarons\Local Settings\Temporary Internet Files\Content.IE5\KS4W4A31\ComboFix[1].exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Aarons\Application Data\MCROSO~1 C:\Documents and Settings\Aarons\Application Data\tmp106.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp109.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp1B.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp1D.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp1E.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp20.tmp.exe C:\Documents and Settings\Aarons\Application Data\tmp6.tmp.exe C:\Program Files\Common Files\misc001 C:\Program Files\Common Files\simtest C:\Program Files\dns C:\Program Files\dns\affid.dat C:\Program Files\dns\cwebpage.dll C:\Program Files\dns\uid.dat C:\Program Files\dns\urls.dat C:\Program Files\dns\version.txt C:\Program Files\dns\x.bmp C:\Program Files\outlook C:\Program Files\windows C:\Program Files\ystem~1 C:\WINDOWS\asks~1 C:\WINDOWS\gebbyx.dll C:\WINDOWS\opommm.dll C:\WINDOWS\system32\_000005_.tmp.dll C:\WINDOWS\system32\_000006_.tmp.dll C:\WINDOWS\system32\_000022_.tmp.dll C:\WINDOWS\system32\bszip.dll C:\WINDOWS\system32\cmd.com C:\WINDOWS\system32\drivers\fad.sys C:\WINDOWS\system32\kr_done1 C:\WINDOWS\system32\netstat.com C:\WINDOWS\system32\NTSVC.ocx C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\regedit.com C:\WINDOWS\system32\taskkill.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\tmp4.tmp.dll C:\WINDOWS\system32\tracert.com C:\WINDOWS\system32\UpMedia C:\WINDOWS\wr.txt . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) 5:02 PM 12/27/2007 . -------\LEGACY_FAD -------\LEGACY_FOPN -------\LEGACY_IPRIP -------\LEGACY_SE500MDMD -------\Iprip -------\nm ((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 ))))))))))))))))))))))))))))))) . 2007-12-27 16:28 . 2007-12-27 16:28 <DIR> d-------- C:\Program Files\BillP Studios 2007-12-27 16:28 . 2007-12-27 16:28 <DIR> d-------- C:\Documents and Settings\Aarons\Application Data\WinPatrol 2007-12-22 19:22 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl 2007-12-22 19:11 . 2007-12-22 19:11 <DIR> d-------- C:\Documents and Settings\Aarons\LimeWire Store Purchased 2007-12-22 19:11 . 2007-12-22 19:11 <DIR> d-------- C:\Documents and Settings\Aarons\LimeWire Shared 2007-12-22 19:11 . 2007-12-23 20:44 <DIR> d-------- C:\Documents and Settings\Aarons\LimeWire Saved 2007-12-21 18:11 . 2004-01-13 17:16 286,720 --a------ C:\WINDOWS\SYSTEM32\LXBMPMNT.DLL 2007-12-21 17:58 . 2007-12-21 17:58 <DIR> d-------- C:\Lxk4200 2007-11-27 21:59 . 2007-11-27 22:14 <DIR> d-------- C:\WINDOWS\SxsCaPendDel . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-23 01:22 --------- d-----w C:\Program Files\Java 2007-12-23 01:10 --------- d-----w C:\Program Files\LimeWire 2007-12-10 22:56 --------- d-----w C:\Documents and Settings\Aarons\Application Data\AdobeUM 2007-12-09 02:59 --------- d-----w C:\Program Files\Common Files\Adobe 2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-11-28 04:14 --------- d-----w C:\Program Files\Trial123PDFConvert 2007-11-28 04:00 --------- d-----w C:\Program Files\RealArcade 2007-11-28 04:00 --------- d-----w C:\Program Files\Coupons 2007-11-28 03:57 --------- d-----w C:\Program Files\Corel 2007-11-28 03:56 --------- d-----w C:\Documents and Settings\Aarons\Application Data\Corel 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-10 05:30 --------- d-----w C:\Program Files\iTunes 2007-11-10 05:30 --------- d-----w C:\Program Files\iPod 2007-11-10 05:25 --------- d-----w C:\Program Files\QuickTime 2007-07-07 21:40 722,176 ----a-w C:\Documents and Settings\TEMP.COMPUTER1\gotomypc_428.exe 2007-05-12 22:17 722,176 ----a-w C:\Documents and Settings\Aarons\gotomypc_428.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [] "McRegWiz"="c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe" [] "MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-07 00:19] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 00:07] "BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36] "WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 10:06] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "iqzz"="C:\PROGRA~1\COMMON~1\iqzz\iqzzm.exe" [] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Del29796"="" [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoRecentDocsMenu"= 1 (0x1) C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "mcupdmgr.exe"=3 (0x3) . Contents of the 'Scheduled Tasks' folder "2007-12-22 00:40:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-27 16:58:44 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-27 17:01:14 - machine was rebooted . 2007-12-21 09:02:30 --- E O F --- |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
27 | sooty4 | 290 | Today, 02:51 PM Last post by: little eagle |
|||
![]() |
0 | singseeker | 13 | Today, 12:14 PM Last post by: singseeker |
|||
![]() |
12 | J1nX | 98 | Today, 10:12 AM Last post by: LDTate |
|||
![]() |
4 | chi86 | 45 | Yesterday, 01:00 PM Last post by: Tomk |
|||
|
Time is now: 1st December 2008 - 07:23 PM |