Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Lap Top Bogged Down


  • This topic is locked This topic is locked
1 reply to this topic

#1 eac705

eac705

    New Member

  • New Member
  • Pip
  • 2 posts

Posted 29 August 2007 - 07:44 PM

PC is slow as ever. I did disk cleanup, went into msconfig and turned off start up services that were trivial.

I have a hijack log and im still a little confused on how to do this, it is my first time. I am sorry If i seem noobish but i suppose this is the correct way in submitting for help.

Logfile of HijackThis v1.99.1
Scan saved at 8:26:03 PM, on 8/29/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\Program Files\PowerPanel\Program\PcfMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\eddy\Desktop\HijackThis1991.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - Global Startup: NETGEAR WG511v2 Wireless Assistant.lnk = ?
O4 - Global Startup: PowerPanel.lnk = ?
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1188178273053
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1188178248817
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)


Start up list;

StartupList report, 8/29/2007, 8:31:53 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\eddy\Desktop\HijackThis1991.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\Program Files\PowerPanel\Program\PcfMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\eddy\Desktop\HijackThis1991.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
NETGEAR WG511v2 Wireless Assistant.lnk = ?
PowerPanel.lnk = ?

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ezShieldProtector for Px = C:\WINDOWS\System32\ezSP_Px.exe
SigmaTel StacMon = C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Disk Cleanup.job
Registration reminder 1.job
Registration reminder 2.job
Registration reminder 3.job

--------------------------------------------------

Enumerating Download Program Files:

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://www.update.mi...b?1188178273053

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\muweb.dll
CODEBASE = http://www.update.mi...b?1188178248817

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 4,110 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

    Advertisements

Register to Remove


#2 eac705

eac705

    New Member

  • New Member
  • Pip
  • 2 posts

Posted 30 August 2007 - 05:29 PM

Dr. Web file list. This list was compiled by moving to the actions performed tab and i click moved because it couldnt cure or delete for some reason. mal.exe;C:\;Dialer.Riprova;Moved.; del.exe;C:\Program Files\Common Files\delsim;Dialer.Radius;Moved.; A0045909.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP81;BackDoor.IRC.Sdbot.905;Moved.; A0051769.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Splendo;Moved.; A0051770.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Radius;Moved.; A0051771.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Splendo;Moved.; A0051772.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Splendo;Moved.; A0051773.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Splendo;Moved.; A0051774.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Radius;Moved.; A0051775.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Radius;Moved.; A0058575.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Riprova;Moved.; A0058576.exe;C:\System Volume Information\_restore{8EC4936A-5899-49E8-B3EA-BE7C199DBAB2}\RP94;Dialer.Radius;Moved.; sql-smss.exe;C:\WINDOWS;Win32.HLLW.MyBot;Moved.; HTpatch.exe;C:\WINDOWS\Drivers\Chipset\AGP\htpatch;Tool.Htpatch;Incurable.Deleted.;

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users