UNSOLVED

karan4

updated

18 years ago

K

karan4

4 Posts

0

759

June 26th, 2008 17:00

hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:06:39, on 27-06-2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Users\fanta\TweakMASTER\TMTray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Mozilla Firefox1\firefox.exe
C:\Program Files\IObit\Advanced WindowsCare 3 Beta\AWC.exe
C:\Program Files\IObit\Advanced WindowsCare 3 Beta\Sup_DiskExplorer.exe
C:\Users\fanta\Desktop\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8088
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 212.143.22.36 reviews.speedbit.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\Users\fanta\TweakMASTER\TweakBHO.dll
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Users\fanta\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SpeedBitVideoAccelerator] "D:\SpeedBit Video Accelerator\VideoAccelerator.exe"
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-in/wlscctrl2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C126D07-7736-41EC-9EE8-B910892B7940}: NameServer = 202.56.250.5 202.56.250.6
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D1139E6-CF09-4917-8F23-918359F5B7FF}: NameServer = 202.56.250.5 202.56.250.6
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4711AAF-750D-4BA0-90FF-A50A6A39348E}: NameServer = 202.56.250.5 202.56.250.6
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - D:\SpeedBit Video Accelerator\VideoAcceleratorService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 4687 bytes

 

 

 

 

anything wrong ??

  • Bugbatter

    4 Apprentice

    20487 Posts

    394

    0

    Posted June 26th, 2008 23:00


    Welcome :) I do not see any active malware in your log.
    Download and scan each user profile with CCleaner:
    http://www.ccleaner.com/download/builds
    ** Select to download the SLIM version.

    **Because CCleaner removes everything in temp folders, if you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner.


    1. Before first use, select Options > Advanced and UNCHECK
    " Only delete files in Windows Temp folder older than 48 hours"
    2. Then select the items you wish to clean up.
    In the Windows Tab:
    • Clean all entries in the "Internet Explorer" section except Cookies (if you want to keep those).
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.
    In the Applications Tab:
    • Clean all except cookies (if you want to keep those) in the Firefox/Mozilla section if you use it.
    • Clean all in the Opera section if you use it.
    • Clean Sun Java in the Internet Section.
    • Clean any others that you choose.
    3. Click the " Run Cleaner" button.
    4. A pop up box will appear advising this process will permanently delete files from your system.
    5. Click " OK" and it will scan and clean your system.
    6. Click " exit" when done.
    REBOOT.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

    Updating Java:

    • Download the latest version of Java Runtime Environment (JRE) 6.
    • Scroll down to where it says "Java Runtime Environment (JRE) 6u6 allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement".
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each of the Java versions.

    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.

    Official JAVA Installation Instructions if needed.

    ** Be sure to keep your AVG Anti-Virus updated. Please refer to information on AVG v. 8 for installing the new version.
  • karan4

    4 Posts

    394

    0

    Posted June 27th, 2008 08:00

    Thank you very much for a quick reply

    I have been using CCleaner regularly and everytime approx 30-40mb is cleaned....

    I have downloaded java update as per instructions

    I have some more problems

    1. My computer when purchased(6 months ago) was quite fast....but now it is very slow

    2.Windows automatic update is not working

    3.When i did a System Health scan (windows tool)

    it gave warnings- a)System is experiencing excessive paging

    b) Avg. Disk Queue Length : mean - 8, minimum-2, total-16

     

    My computer information -

     

    OS Name    Microsoft® Windows Vista™ Home Basic
    Version    6.0.6000 Build 6000
    Other OS Description     Not Available
    OS Manufacturer    Microsoft Corporation
    System Name    WORKGROUP
    System Manufacturer    Dell Inc.
    System Model    Inspiron 1520
    System Type    X86-based PC
    Processor    Intel(R) Core(TM)2 Duo CPU     T5250  @ 1.50GHz, 1500 Mhz, 2 Core(s), 2 Logical Processor(s)
    BIOS Version/Date    Dell Inc. A03, 16-08-2007
    SMBIOS Version    2.4
    Windows Directory    C:\Windows
    System Directory    C:\Windows\system32
    Boot Device    \Device\HarddiskVolume3
    Locale    India
    Hardware Abstraction Layer    Version = "6.0.6000.16407"
    User Name    WORKGROUP\fanta
    Time Zone    India Standard Time
    Total Physical Memory    1,013.57 MB
    Available Physical Memory    140.35 MB
    Total Virtual Memory    2.22 GB
    Available Virtual Memory    796.14 MB
    Page File Space    1.28 GB
    Page File    C:\pagefile.sys
    OS Name    Microsoft® Windows Vista™ Home Basic
    Version    6.0.6000 Build 6000
    Other OS Description     Not Available
    OS Manufacturer    Microsoft Corporation
    System Name    WORKGROUP
    System Manufacturer    Dell Inc.
    System Model    Inspiron 1520
    System Type    X86-based PC
    Processor    Intel(R) Core(TM)2 Duo CPU     T5250  @ 1.50GHz, 1500 Mhz, 2 Core(s), 2 Logical Processor(s)
    BIOS Version/Date    Dell Inc. A03, 16-08-2007
    SMBIOS Version    2.4
    Windows Directory    C:\Windows
    System Directory    C:\Windows\system32
    Boot Device    \Device\HarddiskVolume3
    Locale    India
    Hardware Abstraction Layer    Version = "6.0.6000.16407"
    User Name    WORKGROUP\fanta
    Time Zone    India Standard Time
    Total Physical Memory    1,013.57 MB
    Available Physical Memory    140.35 MB
    Total Virtual Memory    2.22 GB
    Available Virtual Memory    796.14 MB
    Page File Space    1.28 GB
    Page File    C:\pagefile.sys

     

    I am very sorry If I'm posting my query in a wrong discussion(hijack this)

    But i don't know where else to post it ......................

     

  • Bugbatter

    4 Apprentice

    20487 Posts

    394

    0

    Posted June 27th, 2008 14:00

    Just to be sure some malware is not hiding, you might try a scan with Malwarebytes' Anti-Malware.
    Download to your desktop Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

    If you are having a problem with slowness, you may want to consider one of the other free anti-virus programs rather than AVG 8. There is a list at the top of the Virus  & Spyware Board in the "Free Ssecurity Software" announcement.

    If you are using Vista settings instead of Classic settings, try changing it back to Classic.

    You can disable some services from running at startup and in the background. Follow BlackViper's suggestions:
    http://www.blackviper.com/WinVista/servicecfg.htm

     

    In addition, please refer to this link for troubleshooting a slow computer:
    http://www.dellcommunity.com/supportforums/board/message?board.id=si_virus&thread.id=58687

    If all of the above do not help, perhaps the regulars on the Vista Board will have additional suggestions:
    http://www.dellcommunity.com/supportforums/board?board.id=vista