This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] is there anything i should be worried about?

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here is my hijackthis log, and i was just wanting someone to analyze it and let me know if theres anything on there that needs to be fixed or what not…..thanks






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:49 AM, on 4/29/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" -startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe

–
End of file - 5622 bytes
Hi,

Sorry about the delay in replying, we have been very busy lately.

I can't see anything worrying, is there any reason you have to be suspicious?

If you want me to have a deeper look of your system, please do the following.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Right-click dds.scr and select Run As Administrator… to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 23:51:42.77 on Fri 05/08/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3062.1823 [GMT -7:00] AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aolsoftware.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\e-dawg\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Page = uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8 uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8 uWindow Title = Windows Internet Explorer provided by Yahoo! uSearch Bar = mDefault_Page_URL = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local mSearchAssistant = uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\ievkbd.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File uRun: [Aim6] uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe" mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe" mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe" dRun: [iLike] c:\program files\ilike\1.2.14\ilikesidebar.exe /checkforupdate mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Notify: igfxcui - igfxdev.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: VESWinlogon - VESWinlogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\e-dawg\appdata\roaming\mozilla\firefox\profiles\0wxondol.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?fr=fp-yie8 FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2008-3-26 20496] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032] R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2009-3-19 17408] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-4-15 3668480] R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2008-2-16 73472] R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2008-2-16 43904] R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2008-2-16 9344] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2008-2-16 818688] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2008-2-16 28464] S4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-4-8 464264] S4 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-4-8 234888] S4 uCamMonitor;CamMonitor;c:\program files\arcsoft\magic-i visual effects\uCamMonitor.exe [2009-4-5 104960] S4 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\sony\vaio media integrated server\UCLS.exe [2009-3-19 745472] S4 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\sony\vaio media integrated server\platform\SV_Httpd.exe [2009-3-19 397312] S4 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\sony\vaio media integrated server\platform\UPnPFramework.exe [2009-3-19 1089536] S4 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2008-2-16 292128] S4 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2008-2-16 79136] S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-21 24652] S4 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] =============== Created Last 30 ================ 2009-05-01 08:28 –d—– c:\program files\Orban 2009-04-30 18:51 –d—– c:\program files\AVSMedia 2009-04-30 15:58 –d—– c:\users\e-dawg\appdata\roaming\AVS4YOU 2009-04-30 15:58 –d—– c:\programdata\AVS4YOU 2009-04-30 15:58 –d—– c:\progra~2\AVS4YOU 2009-04-30 15:58 –d—– c:\program files\AVS4YOU 2009-04-30 15:57 –d—– c:\program files\common files\AVSMedia 2009-04-30 15:57 974,848 a——- c:\windows\system32\mfc70.dll 2009-04-30 15:57 487,424 a——- c:\windows\system32\msvcp70.dll 2009-04-30 15:57 1,700,352 a——- c:\windows\system32\GdiPlus.dll 2009-04-30 15:57 344,064 a——- c:\windows\system32\msvcr70.dll 2009-04-30 15:57 24,576 a——- c:\windows\system32\msxml3a.dll 2009-04-30 14:54 –d—– c:\users\e-dawg\.SunDownloadManager 2009-04-30 14:07 –d—– c:\users\e-dawg\appdata\roaming\iLike 2009-04-30 06:27 –d—– c:\program files\iLike 2009-04-28 03:26 –d—– c:\program files\common files\Corel 2009-04-27 22:52 –d—– c:\temp\Sony Corporation 2009-04-27 22:52 –d—– C:\Temp 2009-04-27 22:10 –d—– c:\program files\SystemRequirementsLab 2009-04-27 21:40 –d—– c:\users\e-dawg\appdata\roaming\Blitware 2009-04-21 18:26 –d—– c:\program files\iPod 2009-04-21 18:26 –d—– c:\program files\iTunes 2009-04-17 23:14 –d—– c:\program files\common files\i4j_jres 2009-04-17 18:14 –d—– c:\programdata\Ulead Systems 2009-04-17 17:44 –d—– c:\program files\Trend Micro 2009-04-15 12:14 3,668,480 a——- c:\windows\system32\drivers\NETw5v32.sys 2009-04-15 12:14 2,756,608 a——- c:\windows\system32\NETw5r32.dll 2009-04-15 12:14 663,552 a——- c:\windows\system32\NETw5c32.dll 2009-04-15 07:20 –d—– C:\VAIO Entertainment 2009-04-09 15:08 –d—– c:\windows\hsperfdata_e-dawg 2009-04-09 15:07 –d—– c:\users\e-dawg\appdata\roaming\updatetool 2009-04-09 15:06 –d—– C:\glassfishv3-prelude 2009-04-09 09:18 –d—– c:\program files\Sun ==================== Find3M ==================== 2009-05-07 19:05 794,656 a–sh— c:\windows\system32\drivers\fidbox2.dat 2009-05-06 21:30 3,796 a–sh— c:\windows\system32\drivers\fidbox2.idx 2009-05-04 13:49 4,515,872 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-05-03 16:42 36,360 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-04-28 06:17 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-04-28 01:35 143,360 a——- c:\windows\inf\infstrng.dat 2009-04-28 01:35 51,200 a——- c:\windows\inf\infpub.dat 2009-04-28 01:35 86,016 a——- c:\windows\inf\infstor.dat 2009-04-24 12:57 410,984 a——- c:\windows\system32\deploytk.dll 2009-03-30 23:24 2,560 a——- c:\windows\_MSRSTRT.EXE 2009-03-20 23:01 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2009-03-20 20:27 33,808 a——- c:\windows\system32\drivers\klbg.sys 2009-03-20 20:27 101,287 a——- c:\windows\system32\drivers\klin.dat 2009-03-20 20:27 89,601 a——- c:\windows\system32\drivers\klick.dat 2009-03-19 16:32 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-03-19 15:33 665,600 a——- c:\windows\inf\drvindex.dat 2009-03-19 03:40 0 a—h— c:\windows\system32\drivers\Sony_VGN-CR410E.mrk 2009-03-16 20:38 40,960 a——- c:\windows\apppatch\apihex86.dll 2009-03-16 20:38 13,824 a——- c:\windows\system32\apilogen.dll 2009-03-16 20:38 24,064 a——- c:\windows\system32\amxread.dll 2009-03-08 04:34 914,944 a——- c:\windows\system32\wininet.dll 2009-03-08 04:34 43,008 a——- c:\windows\system32\licmgr10.dll 2009-03-08 04:33 18,944 a——- c:\windows\system32\corpol.dll 2009-03-08 04:33 109,056 a——- c:\windows\system32\iesysprep.dll 2009-03-08 04:33 109,568 a——- c:\windows\system32\PDMSetup.exe 2009-03-08 04:33 132,608 a——- c:\windows\system32\ieUnatt.exe 2009-03-08 04:33 107,520 a——- c:\windows\system32\RegisterIEPKEYs.exe 2009-03-08 04:33 107,008 a——- c:\windows\system32\SetIEInstalledDate.exe 2009-03-08 04:33 103,936 a——- c:\windows\system32\SetDepNx.exe 2009-03-08 04:33 420,352 a——- c:\windows\system32\vbscript.dll 2009-03-08 04:32 72,704 a——- c:\windows\system32\admparse.dll 2009-03-08 04:32 71,680 a——- c:\windows\system32\iesetup.dll 2009-03-08 04:32 66,560 a——- c:\windows\system32\wextract.exe 2009-03-08 04:32 169,472 a——- c:\windows\system32\iexpress.exe 2009-03-08 04:31 34,816 a——- c:\windows\system32\imgutil.dll 2009-03-08 04:31 48,128 a——- c:\windows\system32\mshtmler.dll 2009-03-08 04:31 45,568 a——- c:\windows\system32\mshta.exe 2009-03-08 04:22 156,160 a——- c:\windows\system32\msls31.dll 2009-03-05 23:59 1,900,544 a——- c:\windows\system32\usbaaplrc.dll 2009-03-02 21:46 3,599,328 a——- c:\windows\system32\ntkrnlpa.exe 2009-03-02 21:46 3,547,632 a——- c:\windows\system32\ntoskrnl.exe 2009-03-02 21:39 183,296 a——- c:\windows\system32\sdohlp.dll 2009-03-02 21:39 551,424 a——- c:\windows\system32\rpcss.dll 2009-03-02 21:39 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll 2009-03-02 21:37 98,304 a——- c:\windows\system32\iasrecst.dll 2009-03-02 21:37 54,784 a——- c:\windows\system32\iasads.dll 2009-03-02 21:37 44,032 a——- c:\windows\system32\iasdatastore.dll 2009-03-02 20:04 666,624 a——- c:\windows\system32\printfilterpipelinesvc.exe 2009-03-02 19:38 17,408 a——- c:\windows\system32\iashost.exe 2009-02-13 01:49 72,704 a——- c:\windows\system32\secur32.dll 2009-02-13 01:49 1,255,936 a——- c:\windows\system32\lsasrv.dll 2009-02-08 20:10 2,033,152 a——- c:\windows\system32\win32k.sys 2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 23:52:49.43 ===============

Attachments:

Nothing malicious showing there. Are you having any problems?

If you want another opinion, give the following scan a go:

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Malwarebytes' Anti-Malware 1.36 Database version: 2106 Windows 6.0.6001 Service Pack 1 5/10/2009 5:23:17 PM mbam-log-2009-05-10 (17-23-08).txt Scan type: Quick Scan Objects scanned: 75901 Time elapsed: 4 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\urlsearchhook.toolbarurlsearchhook.1 (Trojan.BHO) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ****note that this is the origional log file with the trojans being detected….i of corse followed your directions and i clicked on "remove selected", and as i am writing this, the program is preforming a full system scan….the one i did to start with was just a quick scan….as soon as its done i will post those results as well….thanks….oh and by the way, why didn't my anti-virus program find those trojans? i have Kaspersky and it has been a phenomenal program thus far….its always been very quick at detecting everything…is that a relatively new or unheard of trojan?
by the way, thank you for recommending that program, Malwarebytes'…..i just purchased the full version because i was so happy with the performance. thanks :thumbup:
here is my Malwarebytes' full system scan log…… Malwarebytes' Anti-Malware 1.36 Database version: 2106 Windows 6.0.6001 Service Pack 1 5/10/2009 7:31:45 PM mbam-log-2009-05-10 (19-31-45).txt Scan type: Full Scan (C:\|) Objects scanned: 226979 Time elapsed: 2 hour(s), 3 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

by the way, why didn't my anti-virus program find those trojans? i have Kaspersky and it has been a phenomenal program thus far…

Well, due to the sheer number of different Malware programs and components out there, it is very unlikely that any one program would be able to get all of it. It there was a program that got everything, I am sure everyone would be using it :)

How are things running?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI