This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

vishakhasakhi's HJT log file

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Without know what process is taking up system resources, it's hard to know exactly what the problem is. One last item to try. Please register (it's free, don't worry) with PCPitStop and run the full tests here. When the tests are complete, a results page will pop up. Click "Share these results with TechExpress" on the left-hand side. Then copy the URL provided and post it here for me.
And, here's new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 8:45:14 AM, on 8/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\ISafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft

Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\CAVRID.exe
C:\Program Files\Nokia\Nokia PC Suite

6\LaunchApplication.exe
C:\Program Files\Common

Files\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Plaxo\2.1.0.80\InstallStub.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Microsoft Internet Explorer

provided by Comcast
R1 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
F2 - REG:system.ini:

UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EVoIpSessionCookie Class -

{424B6AD1-785D-43e7-9C9B-AB96E77477D0} - C:\Program

Files\attcv\Programs\EVoIPAxCtrls.dll
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN

Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust

EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust

EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program

Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

-onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common

Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCPitstop Optimize Registration

Reminder] C:\Program

Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate]

C:\WINDOWS\Plaxo\2.1.0.80\InstallStub.exe -a
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program

Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: SpySubtract.lnk = C:\Program

Files\InterMute\SpySubtract\SpySub.exe
O9 - Extra button: Create Mobile Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program

Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program

Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program

Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: ComcastHSI -

{669B269B-0D4E-41FB-A3D8-FD67CA94F646} -

http://www.comcast.net/ (file missing)
O9 - Extra button: Support -

{8828075D-D097-4055-AA02-2DBFA9D85E8A} -

http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help -

{97809617-3937-4F84-B335-9BB05EF1A8D4} -

http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM -

{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program

Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger -

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no

file) (HKCU)
O12 - Plugin for .mov: C:\Program Files\Internet

Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}

(StagingUI Object) -

http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.

cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}

(PCPitstop Utility) -

http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623}

(AlternaTIFF ActiveX) -

http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {10E0E75E-6701-4134-9D95-C0942ED1F1C8}

(Snapfish Outlook Import ActiveX Control) -

http://www.snapfish.com/SnapfishOutlookImport.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX

ActiveX Control) -

http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814}

(MeadCo ScriptX Advanced) -

https://www.taylorbeanonline.com/scriptx/smsx.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8}

(ZoneBuddy Class) -

http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06}

(NeoterisSetup Control) -

https://secure.limefinancial.net/dana-cached/setup/Neote

risSetup.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}

(ZonePAChat Object) -

http://zone.msn.com/binframework/v10/ZPAChat.cab32846.ca

b
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

(MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Control

s/en/x86/client/muweb_site.cab?1124686139768
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto

Upload Manager Class) -

http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/a

xofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}

(HouseCall Control) -

http://a840.g.akamai.net/7/840/537/2004061001/housecall.

trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103}

(WScanCtl Class) -

http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613}

(NMInstall Control) -

http://a14.g.akamai.net/f/14/7141/1d/www.nielsennetpanel

.com/netmeter4_6/NetMeter_preinstaller_activex_en_4.60.3

8.0_MEGAPANEL_USA.cab
O16 - DPF: {944713E8-1F29-42D9-ABD5-557728B9AC97}

(PtClickLoanWF Control) -

https://ilnet.wellsfargo.com/ilonline/crs/hmupload/ptcli

ckloanwf.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C}

(cpbrkpie Control) -

http://a19.g.akamai.net/7/19/7125/4051/ftp.coupons.com/r

3302/cpbrkpie.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}

(ActiveScan Installer Class) -

http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}

(Get_ActiveX Control) -

https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownlo

adManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}

(ZoneIntro Class) -

http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}

(ASquaredScanForm Element) -

http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {BCF9A64D-1440-4404-863C-F5DF2B99F798} (Catan

Online Game) -

http://zone.msn.com/bingame/zpagames/zpa_catan.cab36900.

cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7}

(SproutLauncherCtrl Class) -

http://zone.msn.com/bingame/feed/default/SproutLauncher.

cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41}

(TikGames Online Control) -

http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937}

(StadiumProxy Class) -

http://zone.msn.com/binframework/v10/StProxy.cab35645.ca

b
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}

(PopCapLoader Object) -

http://zone.msn.com/bingame/dim2/default/popcaploader_v6

.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822}

(HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D}

(QDiagHUpdateObj Class) -

http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {FD5A684E-B2FE-4039-9068-48CF8B740E14}

(LOSInterface.LOSIface) -

https://www.novastaris.com/export/LOSInterface.CAB
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo

Auto-Import Utility) -

https://www.plaxo.com/activex/plx_upldr-2k-xp.cab
O23 - Service: CAISafe - Computer Associates

International, Inc. - C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido

networks - C:\Program Files\ewido\security

suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido

networks - C:\Program Files\ewido\security

suite\ewidoguard.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer

Associates International, Inc. - C:\Program

Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
Hmm, well the defrag helped a bit. At this point I would have to say that your problem is most likely not caused by spyware or other malware, so further help would be outside of the realm of this forum. We have other forums on this site that address hardware/software issues.
Sorry we couldn't do more. This Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
an email with the address of the thread. This applies only to the original topic starter. Any emails without the subject "Reopen" will be deleted without being looked at.

Everyone else please begin a New Topic.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI