Unsolved
This post is more than 5 years old
73 Posts
0
3159
August 8th, 2008 14:00
HIjackthis File - Remote Hacking of emails/passwords...keyloggers?
I have a Dell Inspiron 1720, Windows Vista Home premium, Service Pack 1, 4GB ram, T5750, 32 bit operating system. I have AVG antivirus, Zone Alarm Firewall, Spybot, Adware and Roboform. I ran trend micro and there was nothing significant. But when i ran bitdefender it caused my computer to crash..it said something about DUMP? Not sure, so I had to restart and its working fine now.
I dont know much about computers so please bear with me. My emails have been hacked into....Its been going on for a long time. I have changed my passwords numerous times. Recently I downloaded roboform to prevent keyloggers? This is a brand new computer and it froze like someone took over my computer and I couldnt get the task manager opened so the only way was to hold the power button down and shut it down. This happened NUMEROUS times with my OLD laptop but i figured it was old. But this laptop is only a week old, so I know its someone that I know who is trying to hack into my computer and emails. So please if you can help, I would appreciate it. This is my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:28 AM, on 8/8/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Palm\Hotsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Adware\aawservice.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10443 bytes


bamajim
10.4K Posts
0
August 11th, 2008 12:00
1. Go HERE and download File Lister.
Rt Click ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Open the File Lister Folder.
Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
As the program runs, it will appear that nothing is happening.
When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.
"The world is what you make of it"
jlu
73 Posts
0
August 11th, 2008 21:00
its not allowing me to past the rest of the msg..this is what it says:
The message body contains the following prohibited content: B F E & n b s p You must remove this content before submitting your post.jlu
73 Posts
0
August 11th, 2008 21:00
mHelp====== Running Processes ======
System Idle Process [0]
System [4]
smss.exe [444] \SystemRoot\System32\smss.exe
csrss.exe [584] C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe [628] wininit.exe
csrss.exe [640] C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
services.exe [688] C:\Windows\system32\services.exe
lsass.exe [780] C:\Windows\system32\lsass.exe
winlogon.exe [788] winlogon.exe
lsm.exe [800] C:\Windows\system32\lsm.exe
svchost.exe [948] C:\Windows\system32\svchost.exe -k DcomLaunch
svchost.exe [1008] C:\Windows\system32\svchost.exe -k rpcss
svchost.exe [1048] C:\Windows\System32\svchost.exe -k secsvcs
svchost.exe [1136] C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
svchost.exe [1188] C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
svchost.exe [1212] C:\Windows\system32\svchost.exe -k netsvcs
audiodg.exe [1300]
SLsvc.exe [1348] C:\Windows\system32\SLsvc.exe
svchost.exe [1380] C:\Windows\system32\svchost.exe -k LocalService
svchost.exe [1536] C:\Windows\system32\svchost.exe -k NetworkService
vsmon.exe [1628] C:\Windows\System32\ZoneLabs\vsmon.exe -service
wlanext.exe [1792] C:\Windows\system32\WLANExt.exe 4127488
aawservice.exe [1936] C:\Adware\aawservice.exe
dwm.exe [12] "C:\Windows\system32\Dwm.exe"
explorer.exe [740] C:\Windows\Explorer.EXE
spoolsv.exe [1592] C:\Windows\System32\spoolsv.exe
svchost.exe [732] C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe [1692] taskeng.exe {5B568475-1328-477E-A31C-003CF0FDC432}
MSASCui.exe [2140] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
Apoint.exe [2160] "C:\Program Files\DellTPad\Apoint.exe"
taskeng.exe [2176] taskeng.exe {D10F63F7-7E35-47AB-85BF-A390ECE1ECD4}
OEM02Mon.exe [2208] "C:\Windows\OEM02Mon.exe"
sttray.exe [2264] "C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe"
hkcmd.exe [2300] "C:\Windows\System32\hkcmd.exe"
igfxsrvc.exe [2328] C:\Windows\system32\igfxsrvc.exe -Embedding
igfxpers.exe [2340] "C:\Windows\System32\igfxpers.exe"
DellWMgr.exe [2352] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
PCMService.exe [2384] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
avgtray.exe [2392] "C:\Program Files\AVG\AVG8\avgtray.exe"
zlclient.exe [2400] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
sprtcmd.exe [2408] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
ehtray.exe [2416] "C:\Windows\ehome\ehtray.exe"
wmpnscfg.exe [2440] "C:\Program Files\Windows Media Player\wmpnscfg.exe"
TeaTimer.exe [2472] "C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe"
robotaskbaricon.exe [2484] "C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe"
BTTray.exe [2496] "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
DLG.exe [2504] "C:\Program Files\Digital Line Detect\DLG.exe"
Hotsync.exe [2512] "C:\Program Files\Palm\Hotsync.exe"
ApMsgFwd.exe [2548] "C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
ehmsas.exe [2604] C:\Windows\ehome\ehmsas.exe -Embedding
ApntEx.exe [2704] "Apntex.exe"
hidfind.exe [2744] "C:\Program Files\DellTPad\HidFind.exe"
AEstSrv.exe [2808] C:\Windows\system32\aestsrv.exe
avgwdsvc.exe [2820] C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
svchost.exe [2832] C:\Windows\system32\svchost.exe -k bthsvcs
EvtEng.exe [2884] "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe"
MDM.EXE [2972] "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
svchost.exe [3072] C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
RegSrvc.exe [3168] "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe"
sprtsvc.exe [3284] "C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /p dellsupportcenter
stacsv.exe [3336] C:\Windows\system32\STacSV.exe
svchost.exe [3852] C:\Windows\system32\svchost.exe -k imgsvc
svchost.exe [3904] C:\Windows\System32\svchost.exe -k WerSvcGroup
SearchIndexer.exe [3936] C:\Windows\system32\SearchIndexer.exe /Embedding
XAudio.exe [4088] C:\Windows\system32\DRIVERS\xaudio.exe
SDWinSec.exe [1740] "C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe"
avgrsx.exe [3700] avgrsx.exe
BTStackServer.exe [3836] "c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
wmpnetwk.exe [3488] "C:\Program Files\Windows Media Player\wmpnetwk.exe"
firefox.exe [4756] "C:\Program Files\Mozilla Firefox\firefox.exe"
SearchProtocolHost.exe [1424] "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe23_ Global\UsGthrCtrlFltPipeMssGthrPipe23 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
SearchFilterHost.exe [5980] "C:\Windows\system32\SearchFilterHost.exe" 0 620 624 632 65536 628
wscript.exe [592] "C:\Windows\System32\WScript.exe" "C:\Users\JLukaMD\Desktop\FileLister.vbe"
WmiPrvSE.exe [5548] C:\Windows\system32\wbem\wmiprvse.exe
WmiPrvSE.exe [4960] C:\Windows\system32\wbem\wmiprvse.exe
====== Uninstall List From Registry ======
Panda ActiveScan 2.0
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Advanced Audio FX Engine
Advanced Video FX Engine
AVG Free 8.0
Conexant HDA D330 MDC V.92 Modem
Laptop Integrated Webcam Driver (1.04.01.1011)
Dell Webcam Center
Dell Webcam Manager
DynaMed (Palm) v 11.27.0 by Skyscape
GoToAssist 8.0.0.514
HijackThis 2.0.2
LimeWire PRO 4.12.3
MedAlert (Palm) v 10.0.11 by Skyscape
Mozilla Firefox (3.0.1)
Intel(R) PROSet/Wireless Software
smARTupdate
WinRAR archiver
ZoneAlarm
Roxio Creator Data
Roxio Creator DE
Microsoft Works
Live! Cam Avatar v1.0
Roxio Creator Tools
Roxio Update Manager
Java(TM) 6 Update 5
NetWaiting
QuickSet
Dell DataSafe Online
Browser Address Error Redirector
mWMI
Live! Cam Avatar Creator
Roxio Express Labeler 3
EDocs
Microsoft Visual C++ 2005 Redistributable
Roxio Creator Audio
Dell Getting Started Guide
Product Documentation Launcher
mPfMgr
Microsoft Office Professional Edition 2003
Compatibility Pack for the 2007 Office system
Microsoft Office PowerPoint Viewer 2007 (English)
OutlookAddinSetup
MediaDirect
Dell Touchpad
WIDCOMM Bluetooth Software 6.0.1.3100
Adobe Reader 8.1.0
GoodSync
Spybot - Search & Destroy
Roxio Creator Copy
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
Broadcom Management Programs
Music, Photos & Videos Launcher
Ad-Aware
Dell Support Center
Digital Line Detect
Roxio Creator DE
mMHouse
mCore
Modem Diagnostic Tool
Palm Desktop by ACCESS
======== Other Info ========
TOTAL PHYSICAL RAM: 3747 MB
jlu
73 Posts
0
August 11th, 2008 21:00
Link-Layer Topology Discovery Mapper (lltdsvc) C:\Windows\System32\svchost.exe -k LocalService - Manual
Windows Media Center Extender Service (Mcx2Svc) C:\Windows\system32\svchost.exe -k LocalService - Disabled
Multimedia Class Scheduler (MMCSS) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Windows Firewall (MpsSvc) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - Auto
Microsoft iSCSI Initiator Service (MSiSCSI) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Network List Service (netprofm) C:\Windows\System32\svchost.exe -k LocalService - Auto
Network Location Awareness (NlaSvc) C:\Windows\System32\svchost.exe -k NetworkService - Auto
Peer Networking Identity Manager (p2pimsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Peer Networking Grouping (p2psvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Program Compatibility Assistant Service (PcaSvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
PNRP Machine Name Publication Service (PNRPAutoReg) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Peer Name Resolution Protocol (PNRPsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
User Profile Service (ProfSvc) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Quality Windows Audio Video Experience (QWAVE) C:\Windows\system32\svchost.exe -k LocalService - Manual
Intel(R) PROSet/Wireless Registry Service (RegSrvc) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - Auto
SBSD Security Center Service (SBSDWSCService) C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe - Auto
Smart Card Removal Policy (SCPolicySvc) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Windows Backup (SDRSVC) C:\Windows\system32\svchost.exe -k SDRSVC - Manual
Terminal Services Configuration (SessionEnv) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Software Licensing (slsvc) C:\Windows\system32\SLsvc.exe - Auto
SL UI Notification Service (SLUINotify) C:\Windows\system32\svchost.exe -k LocalService - Manual
SNMP Trap (SNMPTRAP) C:\Windows\System32\snmptrap.exe - Manual
SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter - Auto
SigmaTel Audio Service (STacSV) C:\Windows\system32\STacSV.exe - Auto
stllssvr (stllssvr) "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" - Manual
Superfetch (SysMain) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Tablet PC Input Service (TabletInputService) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
TPM Base Services (TBS) C:\Windows\System32\svchost.exe -k LocalService - Auto
Thread Ordering Server (THREADORDER) C:\Windows\system32\svchost.exe -k LocalService - Manual
Windows Modules Installer (TrustedInstaller) C:\Windows\servicing\TrustedInstaller.exe - Manual
Interactive Services Detection (UI0Detect) C:\Windows\system32\UI0Detect.exe - Manual
Desktop Window Manager Session Manager (UxSms) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Windows Connect Now - Config Registrar (wcncsvc) C:\Windows\System32\svchost.exe -k LocalService - Manual
Windows Color System (WcsPlugInService) C:\Windows\system32\svchost.exe -k wcssvc - Manual
Diagnostic Service Host (WdiServiceHost) C:\Windows\System32\svchost.exe -k wdisvc - Manual
Diagnostic System Host (WdiSystemHost) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Manual
Windows Event Collector (Wecsvc) C:\Windows\system32\svchost.exe -k NetworkService - Manual
Problem Reports and Solutions Control Panel Support (wercplsupport) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Windows Error Reporting Service (WerSvc) C:\Windows\System32\svchost.exe -k WerSvcGroup - Auto
Windows Defender (WinDefend) C:\Windows\System32\svchost.exe -k secsvcs - Auto
WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) C:\Windows\system32\svchost.exe -k LocalService - Manual
Windows Remote Management (WS-Management) (WinRM) C:\Windows\System32\svchost.exe -k NetworkService - Manual
WLAN AutoConfig (Wlansvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Parental Controls (WPCSvc) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Portable Device Enumerator Service (WPDBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Windows Search (WSearch) C:\Windows\system32\SearchIndexer.exe /Embedding - Auto
XAudioService (XAudioService) C:\Windows\system32\DRIVERS\xaudio.exe - Auto
jlu
73 Posts
0
August 11th, 2008 21:00
====== Files under "\Administrator\Startup" Last 30 Days======
====== Files under "\All Users\Startup" Last 30 Days======
====== Folders under "\Program Files" Last 30 Days======
8/7/2008 12:14:37 AM 24687645 C:\Program Files\Mozilla Firefox
8/7/2008 12:14:37 AM 6070205 C:\Program Files\Mozilla Firefox\chrome
8/7/2008 12:14:37 AM 2330882 C:\Program Files\Mozilla Firefox\components
8/7/2008 12:14:37 AM 53894 C:\Program Files\Mozilla Firefox\defaults
8/7/2008 12:14:39 AM 7383 C:\Program Files\Mozilla Firefox\defaults\autoconfig
8/7/2008 12:14:39 AM 36775 C:\Program Files\Mozilla Firefox\defaults\pref
8/7/2008 12:14:41 AM 9736 C:\Program Files\Mozilla Firefox\defaults\profile
8/7/2008 12:14:41 AM 1741 C:\Program Files\Mozilla Firefox\defaults\profile\chrome
8/7/2008 12:14:41 AM 612845 C:\Program Files\Mozilla Firefox\dictionaries
8/7/2008 12:14:37 AM 1390 C:\Program Files\Mozilla Firefox\extensions
8/7/2008 12:14:39 AM 1390 C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
8/7/2008 12:14:37 AM 76011 C:\Program Files\Mozilla Firefox\greprefs
8/7/2008 12:14:37 AM 185990 C:\Program Files\Mozilla Firefox\modules
8/7/2008 12:14:37 AM 65536 C:\Program Files\Mozilla Firefox\plugins
8/7/2008 12:14:37 AM 368828 C:\Program Files\Mozilla Firefox\res
8/7/2008 12:14:38 AM 72215 C:\Program Files\Mozilla Firefox\res\dtd
8/7/2008 12:14:38 AM 80646 C:\Program Files\Mozilla Firefox\res\entityTables
8/7/2008 12:14:38 AM 79512 C:\Program Files\Mozilla Firefox\res\fonts
8/7/2008 12:14:38 AM 619 C:\Program Files\Mozilla Firefox\res\html
8/7/2008 12:14:41 AM 11439 C:\Program Files\Mozilla Firefox\searchplugins
8/7/2008 12:14:37 AM 514364 C:\Program Files\Mozilla Firefox\uninstall
7/14/2008 10:41:15 PM 0 C:\Program Files\MSXML 4.0
7/18/2008 10:20:35 PM 6358 C:\Program Files\Musicmatch
7/18/2008 10:20:35 PM 6358 C:\Program Files\Musicmatch\Musicmatch Jukebox
8/11/2008 8:03:44 AM 73994032 C:\Program Files\Panda Security
8/11/2008 8:03:44 AM 73994032 C:\Program Files\Panda Security\ActiveScan 2.0
8/11/2008 8:04:26 AM 2104716 C:\Program Files\Panda Security\ActiveScan 2.0\psqstore
8/6/2008 12:04:26 AM 13826030 C:\Program Files\Siber Systems
8/6/2008 12:04:26 AM 10897200 C:\Program Files\Siber Systems\AI RoboForm
8/7/2008 1:14:54 AM 1097736 C:\Program Files\Siber Systems\AI RoboForm\Firefox
8/7/2008 1:14:54 AM 23792 C:\Program Files\Siber Systems\AI RoboForm\Firefox\chrome
8/7/2008 1:14:54 AM 1072410 C:\Program Files\Siber Systems\AI RoboForm\Firefox\components
8/7/2008 11:53:29 AM 2928830 C:\Program Files\Siber Systems\GoodSync
8/8/2008 11:34:56 AM 417178 C:\Program Files\Trend Micro
8/8/2008 11:34:56 AM 406733 C:\Program Files\Trend Micro\HijackThis
7/11/2008 8:37:26 PM 2686615 C:\Program Files\WinRAR
7/11/2008 8:37:27 PM 599040 C:\Program Files\WinRAR\Formats
7/13/2008 12:52:21 AM 8741794 C:\Program Files\Zone Labs
7/13/2008 12:52:21 AM 8741794 C:\Program Files\Zone Labs\ZoneAlarm
7/13/2008 7:39:52 AM 1009252 C:\Program Files\Zone Labs\ZoneAlarm\Help
7/13/2008 7:39:49 AM 14551 C:\Program Files\Zone Labs\ZoneAlarm\images
7/13/2008 7:39:34 AM 2174408 C:\Program Files\Zone Labs\ZoneAlarm\repair
====== Files under "\System32\Drivers" Last 30 Days======
7/12/2008 12:01:16 PM 0 34 C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
8/11/2008 8:04:24 AM 28544 32 C:\Windows\System32\drivers\pavboot.sys
7/13/2008 7:39:13 AM 352615 34 C:\Windows\System32\drivers\vsconfig.xml
7/13/2008 7:39:13 AM 279440 0 C:\Windows\System32\drivers\vsdatant.sys
7/12/2008 11:40:58 PM 279440 32 C:\Windows\System32\drivers\~GLH0014.TMP
7/13/2008 7:39:33 AM 279440 32 C:\Windows\System32\drivers\~GLH0015.TMP
====== Files under "\User\Local Settings\Temp" Last 30 Days======
====== Files and Folders under "All Users\Application Data" Last 30 Days======
====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======
jlu
73 Posts
0
August 11th, 2008 21:00
thank you for replying. I dont know if this matters but I think the person that is doing this is an IT software consultant. I cant prove it. This is the file listerlog, it wont allow me to paste over 20,000 characters so I will have to break it up. let me know what to do next.
+++++++++++++++++++++++++++++++++
+
+ File Lister
+
+ Version 1.0.4
+
+ By bamajim / bamajim.com
+
+++++++++++++++++++++++++++++++++
Report ran on --->>> 8/11/2008 6:25:58 PM
====== Values under HKLM\~\Run ======
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
65,20,2d,68,69,64,65,00
"Apoint"="C:\\Program Files\\DellTPad\\Apoint.exe"
"OEM02Mon.exe"="C:\\Windows\\OEM02Mon.exe"
"SigmatelSysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,53,69,\
67,6d,61,54,65,6c,5c,43,2d,4d,61,6a,6f,72,20,41,75,64,69,6f,5c,57,44,4d,5c,\
73,74,74,72,61,79,2e,65,78,65,00
"IgfxTray"="C:\\Windows\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\Windows\\system32\\hkcmd.exe"
"Persistence"="C:\\Windows\\system32\\igfxpers.exe"
"DELL Webcam Manager"="\"C:\\Program Files\\Dell\\Dell Webcam Manager\\DellWMgr.exe\" /s"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"PCMService"="\"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe\""
"HotSync"="\"C:\\Program Files\\PalmSource\\Desktop\\HotSync.exe\" -AllUsers"
"AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""
====== Values under HKCU\~\Run ======
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"SpybotSD TeaTimer"="C:\\Spybot\\Spybot - Search & Destroy\\TeaTimer.exe"
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
====== Folders and Files from "%\" and "%\Windows" Created Last 30 Days ======
8/6/2008 12:41:00 AM 19618003 C:\Adware
8/6/2008 1:00:05 AM 2146934 C:\Adware\Help
8/6/2008 1:00:05 AM 709483 C:\Adware\Lang
8/6/2008 1:00:06 AM 3498834 C:\Adware\Skin
8/11/2008 8:21:58 AM 686630 C:\deckers
8/7/2008 12:13:35 AM 7499056 C:\firefox
8/11/2008 8:07:33 AM 322518 C:\IESpyad
8/11/2008 1:49:36 AM 53248 C:\JD2
8/11/2008 1:38:03 AM 15537 C:\JP2
7/18/2008 10:10:09 PM 0 C:\Music Match
7/11/2008 8:39:10 PM 50339065 C:\Palm Medical
7/11/2008 9:17:00 PM 0 C:\Palm Medical\Palm
7/11/2008 9:17:00 PM 0 C:\Palm Medical\Palm\Palm_User_Files
8/11/2008 8:03:19 AM 175648 C:\Panda
8/5/2008 11:48:26 PM 10814410 C:\Roboform
8/7/2008 12:09:05 PM 741 C:\Roboform\Documents
8/7/2008 12:09:05 PM 0 C:\Roboform\Documents\CruzerSyncData
8/7/2008 12:09:05 PM 0 C:\Roboform\Documents\Downloads
8/7/2008 12:09:05 PM 0 C:\Roboform\Documents\Music
8/7/2008 12:09:05 PM 741 C:\Roboform\Documents\My RoboForm Data
8/7/2008 12:09:05 PM 741 C:\Roboform\Documents\My RoboForm Data\Default Profile
8/7/2008 12:09:06 PM 0 C:\Roboform\Documents\Pictures
8/7/2008 12:09:06 PM 0 C:\Roboform\Documents\Videos
8/7/2008 12:07:24 PM 4175 C:\Roboform\_gsdata_
7/16/2008 9:35:16 PM 55687766 C:\Skyscape
7/16/2008 9:35:16 PM 53801242 C:\Skyscape\DynaMed
7/16/2008 9:35:16 PM 53801242 C:\Skyscape\DynaMed\11.27.0
7/16/2008 9:35:17 PM 53184722 C:\Skyscape\DynaMed\11.27.0\Palm Install Files
7/16/2008 11:52:34 PM 1886524 C:\Skyscape\smARTalerts
7/16/2008 11:52:34 PM 1826830 C:\Skyscape\smARTalerts\Palm Install Files
8/6/2008 12:59:17 AM 66176242 C:\Spybot
8/6/2008 1:03:57 AM 51092722 C:\Spybot\Spybot - Search & Destroy
8/6/2008 1:03:59 AM 55992 C:\Spybot\Spybot - Search & Destroy\Dummies
8/6/2008 1:04:02 AM 573029 C:\Spybot\Spybot - Search & Destroy\Help
8/6/2008 1:03:59 AM 13612954 C:\Spybot\Spybot - Search & Destroy\Includes
8/6/2008 1:04:01 AM 4261934 C:\Spybot\Spybot - Search & Destroy\Languages
8/6/2008 1:03:59 AM 2424432 C:\Spybot\Spybot - Search & Destroy\Plugins
8/6/2008 1:04:02 AM 49349 C:\Spybot\Spybot - Search & Destroy\Skins
8/6/2008 1:04:02 AM 3932925 C:\Spybot\Spybot - Search & Destroy\Updates
8/11/2008 8:07:07 AM 2869536 C:\SpywareBlaster
7/12/2008 5:07:11 PM 6793206 C:\WidescreenWallpaper
8/11/2008 6:25:58 PM 4974 32 C:\Files.txt
8/6/2008 10:54:19 PM 22874365 C:\Windows\BDOSCAN8
8/6/2008 10:54:54 PM 21583086 C:\Windows\BDOSCAN8\plugins
7/12/2008 11:36:58 PM 11679711 C:\Windows\Internet Logs
7/14/2008 10:34:06 PM 417528 C:\Windows\Minidump
7/18/2008 7:27:18 PM 2941 C:\Windows\pss
7/16/2008 9:35:17 PM 471552 C:\Windows\Skyscape
7/16/2008 9:35:17 PM 471552 C:\Windows\Skyscape\DynaMed_Palm
7/16/2008 9:35:17 PM 471552 C:\Windows\Skyscape\DynaMed_Palm\11.27.0
7/20/2008 5:21:58 PM 0 C:\Windows\Sun
7/20/2008 5:21:58 PM 0 C:\Windows\Sun\Java
7/20/2008 5:21:58 PM 0 C:\Windows\Sun\Java\Deployment
7/11/2008 8:46:03 PM 118849 32 C:\Windows\ctpu.exe
7/16/2008 9:35:30 PM 724992 32 C:\Windows\iun6002.exe
7/14/2008 10:33:27 PM 461864415 32 C:\Windows\MEMORY.DMP
7/14/2008 10:41:07 PM 262518 32 C:\Windows\msxml4-KB936181-enu.LOG
7/18/2008 11:31:57 PM 261010 32 C:\Windows\msxml4-KB941833-enu.LOG
8/7/2008 12:28:08 AM 0 32 C:\Windows\nsreg.dat
7/11/2008 8:44:47 PM 57344 32 C:\Windows\ResENU.dll
7/13/2008 7:39:13 AM 29273220 C:\Windows\System32\ZoneLabs
7/13/2008 7:39:36 AM 2391824 C:\Windows\System32\ZoneLabs\lib
7/13/2008 7:39:36 AM 437680 C:\Windows\System32\ZoneLabs\lib\pyd
7/13/2008 7:39:37 AM 60640 C:\Windows\System32\ZoneLabs\plugins
7/13/2008 7:39:37 AM 30290 C:\Windows\System32\ZoneLabs\plugins\rpc_server
7/13/2008 7:39:37 AM 30350 C:\Windows\System32\ZoneLabs\plugins\vsmon_plugin
7/13/2008 7:39:51 AM 6364 C:\Windows\System32\ZoneLabs\Updates
8/4/2008 11:36:17 PM 1671680 32 C:\Windows\System32\chsbrkr.dll
8/4/2008 11:36:17 PM 6103040 32 C:\Windows\System32\chtbrkr.dll
8/5/2008 9:57:19 PM 10752 32 C:\Windows\System32\gcmd5query.dll
8/4/2008 11:36:18 PM 143872 32 C:\Windows\System32\korwbrkr.dll
8/4/2008 11:36:17 PM 11967524 32 C:\Windows\System32\korwbrkr.lex
8/4/2008 11:36:17 PM 40448 32 C:\Windows\System32\mimefilt.dll
8/4/2008 11:36:19 PM 34816 32 C:\Windows\System32\msscb.dll
8/4/2008 11:36:17 PM 60416 32 C:\Windows\System32\msscntrs.dll
8/4/2008 11:36:19 PM 11776 32 C:\Windows\System32\msshooks.dll
8/4/2008 11:36:18 PM 231936 32 C:\Windows\System32\msshsq.dll
8/4/2008 11:36:18 PM 87552 32 C:\Windows\System32\mssitlb.dll
8/4/2008 11:36:16 PM 350208 32 C:\Windows\System32\mssph.dll
8/4/2008 11:36:16 PM 203776 32 C:\Windows\System32\mssphtb.dll
8/4/2008 11:36:18 PM 32768 32 C:\Windows\System32\mssprxy.dll
8/4/2008 11:36:16 PM 1418240 32 C:\Windows\System32\mssrch.dll
8/4/2008 11:36:18 PM 44032 32 C:\Windows\System32\msstrc.dll
8/4/2008 11:36:16 PM 670208 32 C:\Windows\System32\mssvp.dll
8/4/2008 11:36:17 PM 136704 32 C:\Windows\System32\nlhtml.dll
8/4/2008 11:36:17 PM 194560 32 C:\Windows\System32\offfilt.dll
8/4/2008 11:36:18 PM 71680 32 C:\Windows\System32\propdefs.dll
8/4/2008 11:36:18 PM 754176 32 C:\Windows\System32\propsys.dll
8/4/2008 11:36:17 PM 38400 32 C:\Windows\System32\rtffilt.dll
8/4/2008 11:36:18 PM 87552 32 C:\Windows\System32\SearchFilterHost.exe
8/4/2008 11:36:17 PM 439808 32 C:\Windows\System32\SearchIndexer.exe
8/4/2008 11:36:17 PM 184832 32 C:\Windows\System32\SearchProtocolHost.exe
8/4/2008 11:36:18 PM 301568 32 C:\Windows\System32\srchadmin.dll
8/4/2008 11:36:19 PM 106605 32 C:\Windows\System32\StructuredQuerySchema.bin
8/4/2008 11:36:19 PM 18904 32 C:\Windows\System32\StructuredQuerySchemaTrivial.bin
8/4/2008 11:36:18 PM 313344 32 C:\Windows\System32\thawbrkr.dll
8/4/2008 11:36:16 PM 1582592 32 C:\Windows\System32\tquery.dll
7/13/2008 7:39:33 AM 95720 32 C:\Windows\System32\vsdata.dll
7/13/2008 7:38:34 AM 165352 32 C:\Windows\System32\vsinit.dll
7/13/2008 7:39:34 AM 103912 32 C:\Windows\System32\vsmonapi.dll
7/13/2008 7:39:34 AM 275944 32 C:\Windows\System32\vspubapi.dll
7/13/2008 7:39:48 AM 71144 32 C:\Windows\System32\vsregexp.dll
7/13/2008 7:38:34 AM 493032 32 C:\Windows\System32\vsutil.dll
7/13/2008 7:39:37 AM 46568 32 C:\Windows\System32\vswmi.dll
7/13/2008 7:39:35 AM 99816 32 C:\Windows\System32\vsxml.dll
8/4/2008 11:36:17 PM 29184 32 C:\Windows\System32\wsepno.dll
8/4/2008 11:36:17 PM 56320 32 C:\Windows\System32\xmlfilter.dll
7/13/2008 7:39:40 AM 83432 32 C:\Windows\System32\zlcomm.dll
7/13/2008 7:39:40 AM 71144 32 C:\Windows\System32\zlcommdb.dll
7/13/2008 7:39:35 AM 1086952 32 C:\Windows\System32\zpeng24.dll
jlu
73 Posts
0
August 11th, 2008 21:00
jlu
73 Posts
0
August 11th, 2008 21:00
====== Files and Folders under "All Users\Application Data" Last 30 Days======
====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
====== BHO's under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
WormRadar.com IESiteBlocker.NavFilter
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}
RoboForm
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}
Browser Address Error Redirector
jlu
73 Posts
0
August 12th, 2008 01:00
bamajim
10.4K Posts
0
August 12th, 2008 12:00
File Lister would have no affect on AVG. It doesn't remove anything, it only lists files and drivers.
The good news is I don't see any signs of a keylogger program. If your email account has been compromised, it hasn't gotten into your PC.
It does look like you have downloaded and installed quite a few programs in an effort to protect your PC. But you may have too many.
I have a couple of questions:
Does your version of Zone Alarm have the Anti Virus in it? OR is it only the Firewall?
Does your version of Ad Aware have the Anti Virus in it?
"The world is what you make of it"
jlu
73 Posts
0
August 12th, 2008 20:00
After shutting down my computer llike 5 times, Avg is working now...=) I have no idea why it did that. My Zone Alarm and Adware has no antivirus...their both the free version. So there is nothing on my hijackthis log or file lister? Someone has access to my computer and info and I have no idea how they are doing it. Noone uses my laptop.
-what program can I use to clean my temp files and folders? On my old computer I used cleanup but I cant use that on my new computer because it doesnt work with Vista.
-Which programs do you think I should take off my computer? I downloaded Iespyad and spywareblaster but havent installed it on my computer yet. I dont think adware and spybot really helps. In your opnion which ones should I keep?
-Roboform keeps the profile IDs and passwords for all my accunts under my documents. Isnt it possible for a hacker to easily access that under my folders?
-When I ran both Panda activescan and bit defender my computer crashed and when I did it for Panda activescan this is what it said:
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.768.3
Locale ID: 1033
Additional information about the problem:
BCCode: c2
BCP1: 00000007
BCP2: 0000110B
BCP3: 00000000
BCP4: CC7FF008
OS Version: 6_0_6001
Service Pack: 1_0
Product: 768_1
Files that help describe the problem:
C:\Windows\Minidump\Mini081108-01.dmp
C:\Users\JL\AppData\Local\Temp\WER-39764-0.sysdata.xml
C:\Users\JL\AppData\Local\Temp\WERD097.tmp.version.txt
Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409
bamajim
10.4K Posts
0
August 13th, 2008 12:00
There is nothing on your PC that would allow others to access it. If your email has been compromised by a Bot, that is not the same thing as controlling your PC. And without a remote desktop installed a hacker cannot gain access to your My Documents folder.
With Vista IE7, there is no need for ZoneAlarm. And of late there has been quite a number of problems with that software.
I would remove it as well as Iespyad and spywareblaster. There have been reported probelems with IEspyad and Vista as well.
Uninstall all of those and see is that stops some of your crashing.
To clean temp files use this
Download CCleaner from here to clean temp files from your computer.
"The world is what you make of it"
jlu
73 Posts
0
August 13th, 2008 21:00
bamajim
10.4K Posts
0
August 14th, 2008 12:00
If you continue to have problems then I would dump ZoneAlarm. The firewall in Vista is quite good.
A Bot is a computer or bank of computers that auto sends random email to random email addresses in the hopes that someone will open one of the emails to see what it is. Once that happens it contacts the Bot computer, copies or tries to copy your Email address book. It then continues to send junk mail to your address as well as everyone in your address book.
Trying to seek out the emailer responsable only makes matters worse. The best course of action is to ride out the storm, it will soon pass.
1. Most good AntiVirus companies programs scan email, if yours doesn't then get one that does.
2. Be careful what you open. If you do not recognize the sender, delete it. Don't let curiousity get the best of you.
3. Empty your Deleted Items folder in your email program. Most people think that hte email is gone once it's deleted from your inbox, that is not the case. It sends it to the deleted items folder. Empty that folder often
4. Never store or leave passwords in any email folder. Everybody forgets their passwords to certain sites on the Internet, so we contact those sites and request our password, and they send it by email. So we keep the email in case we forget it again or store it in an email folder. Never do that. Once you retreive the password, delete that email right then.
5. Clean out your temp and cookie files
I have never heard of a hacker gaining access to your favorites/bookmarks in IE. There would be no point.
Does this information answer your questions?
"The world is what you make of it"
jlu
73 Posts
0
August 14th, 2008 13:00