Jump to content

Clean System Help?


Little

Recommended Posts

Hello,

I was wondering if someone could take a look at my logs and determine if I have a clean bill of health for my computer? Last night, I started experiencing uncontrollable popups on my browser. My system began to run rather sluggish, and even after rebooting it seemed as if the response time was not normal. I would open firefox, but would notice in the taskmanager that firefox got practically no cpu time. I tried to update my spybot s&d definitions, but I would get an error saying that I wasn't connected to the internet. Yet, I was

able to use the internet just fine.

Anyhow, after a rather long struggle I think my system is clean, but I'm not entirely sure. So, I was wondering if someone could take a look at the logs.

I finished updating, running spybot search and destroy, and immunizing my machine. So that's all done. I did a malwarebytes anti-malware scan, a pandascan, and a hijackthis scan. I'll post them in separate replies.

Here is the malwarebytes anti-malware log:

Malwarebytes' Anti-Malware 1.31

Database version: 1531

Windows 5.1.2600 Service Pack 3

12/22/2008 9:17:57 AM

mbam-log-2008-12-22 (09-17-57).txt

Scan type: Quick Scan

Objects scanned: 60107

Time elapsed: 11 minute(s), 21 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

After the malwarebytes anti-malware scan and fix, I did a pandascan. Here is the log. Sorry about the bad formatting, I just copied and pasted. :\

;*******************************************************************************

********************************************************************************

*

*******************

ANALYSIS: 2008-12-22 11:39:46

PROTECTIONS: 1

MALWARE: 8

SUSPECTS: 27

;*******************************************************************************

********************************************************************************

*

*******************

PROTECTIONS

Description Version Active Updated

;===============================================================================

================================================================================

=

===================

McAfee VirusScan Enterprise 8.5.0.781 No Yes

;===============================================================================

================================================================================

=

===================

MALWARE

Id Description Type Active Severity Disinfectable Disinfected Location

;===============================================================================

================================================================================

=

===================

00003428 adware/memorywatcher Adware No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\memorywatcher

00020937 adware/statblaster Adware No 0 Yes No hkey_local_machine\software\minigolf

00020942 adware/exact.bargainbuddy Adware No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy

00147824 Cookie/Clickbank TrackingCookie No 0 Yes No C:\Documents and Settings\Admin 2\Cookies\admin_2@clickbank[1].txt

00447834 Adware/Lop Adware No 0 Yes No C:\Program Files\Norton AntiVirus\Quarantine\3B9B23F0

00456116 Adware/Antivirus2009 Adware No 0 Yes No C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Content.IE5\CYV06KJH\freescan[2].htm

00456116 Adware/Antivirus2009 Adware No 0 Yes No C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Content.IE5\CYV06KJH\freescan[1].htm

00527204 Application/PRScheduler HackTools No 0 Yes No C:\Documents and Settings\Admin 2\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe

04384357 Adware/VirusRemover2008 Adware No 0 Yes No C:\Documents and Settings\Admin 2\Local Settings\Temporary Internet Files\Content.IE5\PC2W7L0J\winsinstall[1].exe

;===============================================================================

================================================================================

=

===================

SUSPECTS

Sent Location ҋ

;===============================================================================

================================================================================

=

===================

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-153127-975.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170733-668.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170751-726.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170801-230.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170812-133.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170820-663.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-170853-850.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-171605-617.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-171614-508.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-171928-558.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-172023-601.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-172750-391.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-221352-489.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-221510-807.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-221524-847.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-224108-537.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-225355-934.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-225624-873.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081221-225755-351.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081222-023126-980.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081222-024147-552.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081222-024211-959.dll ҋ

No C:\Documents and Settings\Admin 2\Desktop\backups\backup-20081222-024646-176.dll ҋ

No C:\WINDOWS\SYSTEM32\awtsPFxy.dll ҋ

No C:\WINDOWS\SYSTEM32\jjtfggno.dll ҋ

No C:\WINDOWS\SYSTEM32\jlcmjz.dll ҋ

No C:\WINDOWS\SYSTEM32\xxyawxxv.dll ҋ

;===============================================================================

================================================================================

=

===================

VULNERABILITIES

Id Severity Description ҋ

;===============================================================================

================================================================================

=

===================

;===============================================================================

================================================================================

=

===================

Link to post
Share on other sites

Finally, here is the hijackthis log. Any help is appreciated, thanks!

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:51:50 AM, on 12/22/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\BCMSMMSG.exe

C:\WINDOWS\System32\DSentry.exe

C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

C:\Program Files\Common Files\Dell\EUSW\Support.exe

C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

C:\Program Files\Microsoft Hardware\Mouse\point32.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\McAfee\Common Framework\UdaterUI.exe

C:\WINDOWS\vVX1000.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\McAfee\Common Framework\McTray.exe

C:\Program Files\PeerGuardian2\pg2.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe

C:\WINDOWS\System32\CTsvcCDA.EXE

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\McAfee\Common Framework\FrameworkService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe

C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe

C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Admin 2\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost

O2 - BHO: (no name) - {950D9F77-1276-4BBA-AE1D-8CAA36DA343E} - C:\WINDOWS\system32\tuvTKaXO.dll (file missing)

O4 - HKLM\..\Run: [bCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

O4 - HKLM\..\Run: [POINTER] point32.exe

O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Sureshot PopUp Killer Demo\popupkiller.exe" -minimized

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0

O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"

O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab

O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab

O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partner...lim/install.cab

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Apache2.2 - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe

O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe

O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--

End of file - 7463 bytes

Link to post
Share on other sites

  • 2 weeks later...
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.