This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Potential Trojan?

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 08:32:20, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
H:\windows\System32\smss.exe
H:\windows\system32\winlogon.exe
H:\windows\system32\services.exe
H:\windows\system32\lsass.exe
H:\windows\system32\svchost.exe
H:\windows\System32\svchost.exe
H:\windows\system32\spoolsv.exe
H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
H:\Program Files\Comodo\Firewall\cmdagent.exe
H:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
H:\windows\System32\svchost.exe
H:\windows\System32\svchost.exe
H:\windows\Explorer.EXE
H:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
H:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Handset.exe
H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Control.exe
H:\Program Files\D-Link\AirPlus G\AirGCFG.exe
H:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
H:\Program Files\Comodo\Firewall\CPF.exe
H:\Program Files\Skype\Phone\Skype.exe
H:\Program Files\Kalender\Kalender.exe
H:\windows\system32\ctfmon.exe
H:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
H:\Program Files\Google\Google Updater\GoogleUpdater.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
H:\Program Files\Skype\Plugin Manager\SkypePM.exe
H:\windows\system32\wuauclt.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\windows\Explorer.EXE
H:\Documents and Settings\Steve Lythgoe\My Documents\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - H:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - H:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AVG7_CC] H:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinPatrol] H:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [VoipSkype] "H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Handset.exe"
O4 - HKLM\..\Run: [VoipSkypeVolCtrl] "H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Control.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] H:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] H:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 H:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [COMODO Firewall Pro] "H:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [Skype] "H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Kalender] H:\Program Files\Kalender\Kalender.exe
O4 - HKCU\..\Run: [ctfmon.exe] H:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "H:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\RunOnce: [FFTI] H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles/gh0wmu7r.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - Global Startup: Google Updater.lnk = H:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Customize Menu - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1137725340750
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: H:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - H:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - H:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device - - H:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MSCSPTISRV - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ServiceLayer - Nokia. - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Hi happyspider. I can't see any sign of malware in your HijackThis log. What makes you think that you may have a trojan? Please could you let me know as much detail as possible.
Hi beynac - firstly many thanks for your time. I have had my PayPal account compromised - I have been told by PayPal that someone has accessed my account and my first fear was that I had a Trojan. I just wanted to make sure - I like to think that I am fairly security conscious - I use Spyware Blaster, Spybot, Adaware, AVG Spyware and Anti-Virus and Comodo Firewall. I kjeep these up to date and run weekly scans. I must admit my PC is a bit sluggish though and seems to take some time to boot. I also lose my wireless connection from time to time but I think that may be my D-Link router. Thank you for putting my mind at rest about the Trojan but if you have any other suggestions I would be most grateful.
Hi happyspider.

I think that AVG AntiSpyware should have picked up any trojans, but it would be worth running an online scan to double-check.

—————————————————————

Download CCleaner from here.

This will remove temporary files and unwanted cookies and should make the scan, and your computer, run a bit faster.

NOTE: CCleaner installs the Yahoo Toolbar as an option which is checkmarked by default during the installation. If you do NOT want it, REMOVE the checkmark when provided with the option.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Make sure that all browser windows are closed
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click on the Options block on the left, then choose Cookies.
    • Under Cookies to Delete, highlight any cookies you would like to retain permanently
    • Click the right arrow > to move them to the Cookies to Keep pane.
  • Go into Options > Advanced deselect\uncheck 'Only delete files in Windows Temp folders older than 48 hours'
  • Click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the 'Issues' feature unless you are very familiar with the registry.
  • After CCleaner has completed its process, click Exit.
——————————————————–

Kaspersky Online Scanner

Using Internet Explorer, go to: http://www.kaspersky.com/virusscanner
  • Click on Kaspersky Online Scanner
  • Click the Accept button
  • Follow the prompts to download and install the ActiveX component(s) and other software
    • If a yellow information bar appears at the top of the browser window, click on it and select Install ActiveX Control
    • If a message box appears, click on OK or Run as appropriate
  • Click Accept again (see the note below if using IE7)
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click 'Next'.
  • Now click on 'Scan Settings'
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
    • Scan Options: 'Scan Archives' and 'Scan Mail Bases'
  • Click 'OK'
  • Now under 'Select a target to scan' select 'My Computer'
  • The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
  • Now click on the Save as… button:
  • Save the report to your desktop (Save as type: Text document (txt))
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

——————————————————-

Please post the Kaspersky report and a new HijackThis log.
Hi beynac,

Should have mentioned that I use CCleaner already but performed a clean as requested. Please find below Kaspersky and HJT logs. Once again, many thanks for your assistance

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, February 10, 2007 8:37:17 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 10/02/2007
Kaspersky Anti-Virus database records: 266733
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
Z:\

Scan Statistics:
Total number of scanned objects: 54342
Number of viruses found: 1
Number of infected objects: 2 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:00:17

Infected Object Name / Virus Name / Last Action
H:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\cert8.db Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\formhistory.dat Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\history.dat Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\key3.db Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\parent.lock Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\search.sqlite Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\urlclassifier2.sqlite Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\cert8.db Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\key3.db Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\Local Folders\Inbox.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\Local Folders\Junk.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\Local Folders\Templates.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\Local Folders\Trash.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\pop.tiscali.co.uk\Inbox.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\pop.tiscali.co.uk\Junk.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\Mail\pop.tiscali.co.uk\Trash.msf Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\panacea.dat Object is locked skipped
H:\Documents and Settings\Dawn\Application Data\Thunderbird\Profiles\zt0u3hrr.default\parent.lock Object is locked skipped
H:\Documents and Settings\Dawn\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\Cache\_CACHE_001_ Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\Cache\_CACHE_002_ Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\Cache\_CACHE_003_ Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Application Data\Mozilla\Firefox\Profiles\vreknfcv.default\Cache\_CACHE_MAP_ Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Temp\~DFB759.tmp Object is locked skipped
H:\Documents and Settings\Dawn\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Dawn\ntuser.dat Object is locked skipped
H:\Documents and Settings\Dawn\ntuser.dat.LOG Object is locked skipped
H:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
H:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
H:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\cert8.db Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\formhistory.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\history.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\key3.db Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\parent.lock Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\search.sqlite Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\urlclassifier2.sqlite Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\call256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\callmember256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\chat512.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\chatmember256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\chatmsg256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\chatmsg512.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\contactgroup256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\dyncontent\bundle.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\index2.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\profile4096.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\sms256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\sms512.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\user1024.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\user16384.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\user256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Application Data\Skype\steve.lythgoe\voicemail256.dbb Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbc2e.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbdam Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbdao Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbeam Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbeao Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbm Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbu2d.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbvm.cf1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\dbvmh.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\fii.cf1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\fiih.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\hp Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\hpt2i.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\rpm.cf1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\rpm1m.cf1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\rpm1mh.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Google\Google Desktop\3b31d0e20e7f\rpmh.ht1 Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\Cache\_CACHE_001_ Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\Cache\_CACHE_002_ Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\Cache\_CACHE_003_ Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\Cache\_CACHE_MAP_ Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\History\History.IE5\MSHist012007021020070211\index.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temp\~DF30DD.tmp Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temp\~DF53AA.tmp Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temp\~DF7163.tmp Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temp\~DF8EE7.tmp Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\ntuser.dat Object is locked skipped
H:\Documents and Settings\Steve Lythgoe\ntuser.dat.LOG Object is locked skipped
H:\Program Files\LogMeIn\update\2-30-555.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{00F5A1A5-8B77-4777-BA74-9B9FDA3E70C6}\RP478\A0080334.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
H:\System Volume Information\_restore{00F5A1A5-8B77-4777-BA74-9B9FDA3E70C6}\RP478\change.log Object is locked skipped
H:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
H:\WINDOWS\SchedLgU.Txt Object is locked skipped
H:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
H:\WINDOWS\Sti_Trace.log Object is locked skipped
H:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
H:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
H:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
H:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\default Object is locked skipped
H:\WINDOWS\system32\config\default.LOG Object is locked skipped
H:\WINDOWS\system32\config\Internet.evt Object is locked skipped
H:\WINDOWS\system32\config\SAM Object is locked skipped
H:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
H:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\SECURITY Object is locked skipped
H:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
H:\WINDOWS\system32\config\software Object is locked skipped
H:\WINDOWS\system32\config\software.LOG Object is locked skipped
H:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\system Object is locked skipped
H:\WINDOWS\system32\config\system.LOG Object is locked skipped
H:\WINDOWS\system32\h323log.txt Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
H:\WINDOWS\wiadebug.log Object is locked skipped
H:\WINDOWS\wiaservc.log Object is locked skipped
H:\WINDOWS\WindowsUpdate.log Object is locked skipped
Z:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 20:38:38, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
H:\windows\System32\smss.exe
H:\windows\system32\winlogon.exe
H:\windows\system32\services.exe
H:\windows\system32\lsass.exe
H:\windows\system32\svchost.exe
H:\windows\System32\svchost.exe
H:\windows\system32\spoolsv.exe
H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
H:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
H:\Program Files\Comodo\Firewall\cmdagent.exe
H:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
H:\windows\System32\svchost.exe
H:\windows\System32\svchost.exe
H:\windows\Explorer.EXE
H:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
H:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Handset.exe
H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Control.exe
H:\Program Files\D-Link\AirPlus G\AirGCFG.exe
H:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
H:\Program Files\Comodo\Firewall\CPF.exe
H:\Program Files\Skype\Phone\Skype.exe
H:\Program Files\Kalender\Kalender.exe
H:\windows\system32\ctfmon.exe
H:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
H:\Program Files\Google\Google Updater\GoogleUpdater.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
H:\Program Files\Skype\Plugin Manager\SkypePM.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\windows\system32\winlogon.exe
H:\windows\system32\wuauclt.exe
H:\WINDOWS\system32\lxcgcoms.exe
H:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\windows\Explorer.EXE
H:\Documents and Settings\Steve Lythgoe\My Documents\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - H:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - H:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [AVG7_CC] H:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinPatrol] H:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [VoipSkype] "H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Handset.exe"
O4 - HKLM\..\Run: [VoipSkypeVolCtrl] "H:\Program Files\Ikino Handset\Voice200\Ikino Voice 200 Control.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] H:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] H:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 H:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [COMODO Firewall Pro] "H:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [Skype] "H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Kalender] H:\Program Files\Kalender\Kalender.exe
O4 - HKCU\..\Run: [ctfmon.exe] H:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "H:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\RunOnce: [FFTI] H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles\gh0wmu7r.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="H:\Documents and Settings\Steve Lythgoe\Application Data\Mozilla\Firefox\Profiles/gh0wmu7r.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - Global Startup: Google Updater.lnk = H:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Customize Menu - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://H:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1137725340750
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: H:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - H:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - H:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcg_device - - H:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MSCSPTISRV - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ServiceLayer - Nokia. - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - H:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
Hi happyspider.

The only relevant items in the Kaspersky report relate to LogMeIn remote access software. Did you install this? If so, does this give access to your computer from others? Please let me know how it is used.

Other than that, everything looks fine.
Hi beynac The Logmein program was used for me to access other pc's remotely (my mother's mainly). Although I uninstalled it a while ago. Once again thanks for your assistance in this matter - you have put my mind at rest!
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI