Jump to content

johnk

Members
  • Posts

    1
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Webroot says connection error, Malwarebytes just shows an hourglass for 10 seconds, superantisaver brings up an error, and spyhunter does not load. Here is the hijackthis- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:03:03 PM, on 2/13/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18241) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\slagent.exe C:\WINDOWS\system32\slClient.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Webroot\Client\SPYSWEEPER.EXE C:\DOCUME~1\jkavalia\LOCALS~1\Temp\ose00000.exe C:\Program Files\Webroot\Client\SpySweeperUI.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.merhomes.com:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://*.iconf.net;http://intrasmart.merhomes.com;http://intra.merhomes.com;http://nfuse.merhomes.com;http://exchange.merhomes.com;http://*.corporate.merhomes.com;https://*.corporate.merhomes.com;http://*.iconf.net;http://207.31.116.*;http://192.168.*;https://192.168.*;file://CORP-004304-SVR;https://*.postini.com;https://*.conformx.com;https://pivotal.corporate.merhomes.com;http://zip4.usps.com;http://*.usps.com;http://publicrecords.netronline.com;http://www.drhsub.com;http://www.mercedeshomes.com;http://*.merhomes.com;http://irish;<local> O1 - Hosts: PSL-004653-LTP O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll O3 - Toolbar: NVRIEbar.IEbar - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - C:\Program Files\Naturalsoft\NaturalReader66\NVRIEbar.dll O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [WebrootClientUI] "C:\Program Files\Webroot\Client\SpySweeperUI.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea...en/preview.html O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ProxyPal - {B0127AF2-316C-4f1d-BF35-3DE43971EEC5} - C:\WINDOWS\system32\proxypal.exe O9 - Extra 'Tools' menuitem: ProxyPal - {B0127AF2-316C-4f1d-BF35-3DE43971EEC5} - C:\WINDOWS\system32\proxypal.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} (CentraUpdaterAxCtl Class) - http://asp18.centra.com/SiteRoots/main/Ins...raUpdaterAx.cab O16 - DPF: {1B0375B5-1A57-4684-BDF5-4D2E68A7EF4A} (Pivotal ePower Lifecycle Engine (Version 5.9) - Platform Access (rdaclnt.dll)) - https://pivotal.corporate.merhomes.com/epow...cab/RDACLNT.CAB O16 - DPF: {28E4BE08-1C25-4CE4-A9AA-3495A9D08C8E} (Pivotal eRelationship Active Access (version 5.9) - Shortcut Handler (rshortcut.dll)) - https://pivotal.corporate.merhomes.com/epow...b/RSHORTCUT.CAB O16 - DPF: {2AEC967B-BE2B-4D88-BB4E-C25F26B96CB0} (Pivotal eRelationship Active Access (Version 5.9) - Smart Portal (rdaprtl.dll)) - https://pivotal.corporate.merhomes.com/epow...cab/RDAPRTL.CAB O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {3D7C60CF-3CA3-4EEF-8FDE-F3903709834B} (Pivotal eRelationship Active Access (Version 5.9) - Stealth Report Interface (rdaRprt.dll)) - https://pivotal.corporate.merhomes.com/epow...cab/RDARPRT.CAB O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-24-0.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {6B231775-289F-4869-9120-FD6BEF3FEE7F} (Pivotal eRelationship Active Access (Version 5.9) - Charting Class (rdachart.dll)) - http://eagle/epower/cab/RDACHART.CAB O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1188239233625 O16 - DPF: {876DEC9E-28E9-4FE0-8ACD-CE107F9ACD1E} (Pivotal eRelationship Active Access (Version 5.9) - Resources (rdares.dll)) - https://pivotal.corporate.merhomes.com/epower/cab/RDARES.CAB O16 - DPF: {8B777F7B-E3F0-496F-AEAC-EF9169C0A341} (Pivotal eRelationship Active Access (Version 5.9) - Email Connector (rdaemail.dll)) - https://pivotal.corporate.merhomes.com/epow...ab/RDAEMAIL.CAB O16 - DPF: {A4BD9732-328D-11D4-BB89-00A0C9843488} (Pivotal ePower Lifecycle Engine (Version 5.9) - EMail Class (rn1sendx.dll)) - https://pivotal.corporate.merhomes.com/epow...ab/RN1SENDX.CAB O16 - DPF: {A7977C3E-1450-4990-977D-9C5522B1E6DD} (Pivotal ePower Lifecycle Engine (Version 5.9) - Instantiator (rdaobjcreate.dll)) - https://pivotal.corporate.merhomes.com/epow...daObjCreate.cab O16 - DPF: {AE4F48D0-6A0A-11D3-9FB0-005004A79108} (Pivotal eRelationship Active Access (Version 5.9) - Plug-in Result Return Collection (dfoutils.dll)) - https://pivotal.corporate.merhomes.com/epow...ab/DFOUTILS.CAB O16 - DPF: {BB89F812-072A-45E9-BEB2-2781D468F4E0} (Pivotal eRelationship Active Access (Version 5.9) - Shared Object Library Interface (rdashare.dll)) - https://pivotal.corporate.merhomes.com/epow...ab/RDASHARE.CAB O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553555000} - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D2A79F4E-98D9-4B65-9858-A7A1A3DCF872} (Pivotal eRelationship Active Access (Version 5.9) - Portal Control Proxy (rdaui.dll)) - https://pivotal.corporate.merhomes.com/epower/cab/RdaUI.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://cdcsoftware.webex.com/client/T25L/webex/ieatgpc.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://livenj01.custhelp.com/8201-b499h/rnl/java/RntX.cab O16 - DPF: {FA081ACE-41E6-4BD7-9B47-817BAFE2C572} (Pivotal eRelationship Tree Control - rdaTree.ocx) - https://pivotal.corporate.merhomes.com/epow...TreeControl.CAB O16 - DPF: {FA91DF8D-53AB-455D-AB20-F2F023E498D3} (RSClientPrint Class) - http://bull/Reports/Reserved.ReportViewerW...OpType=PrintCab O16 - DPF: {FB5FBB7F-92B4-11D3-8332-00C04F8B209E} (Genesys Webtour Control) - http://content101.mc.iconf.net/gcc_install...rowserquery.cab O16 - DPF: {FBE37597-190E-4A06-978F-E39037999049} (Genesys Component Installer) - http://content101.mc.iconf.net/gcc_install...mcinstaller.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corporate.merhomes.com O17 - HKLM\Software\..\Telephony: DomainName = corporate.merhomes.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corporate.merhomes.com O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- End of file - 11963 bytes
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.