Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 02-17-2008, 01:24 PM   #11 (permalink)
 
Junior Techie

Join Date: Oct 2007

Posts: 68

Jophess is on a distinguished road

Default Re: clusap.dll/trojan horse

Here is the new HijackThis log after following all of the steps posted:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:23:12 PM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RivaTuner v2.06\RivaTuner.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /S
O4 - HKLM\..\Run: [RivaTuner] "C:\Program Files\RivaTuner v2.06\RivaTuner.exe" /T
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 2925 bytes
Jophess is offline  
Old 02-17-2008, 04:00 PM   #12 (permalink)
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: clusap.dll/trojan horse

Much Better
ECTech is offline  
Old 02-17-2008, 04:28 PM   #13 (permalink)
 
Junior Techie

Join Date: Oct 2007

Posts: 68

Jophess is on a distinguished road

Default Re: clusap.dll/trojan horse

So, the virus is completely gone now?
Jophess is offline  
Old 02-17-2008, 06:02 PM   #14 (permalink)
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: clusap.dll/trojan horse

based on the new log you posted, it seems to be gone.
ECTech is offline  
Old 02-17-2008, 06:11 PM   #15 (permalink)
 
Junior Techie

Join Date: Oct 2007

Posts: 68

Jophess is on a distinguished road

Default Re: clusap.dll/trojan horse

Alright, thanks a lot for the help. I have run an AVG virus test and it is no longer finding the virus, so I think everything is ok now.
Jophess is offline  
Old 02-18-2008, 01:39 AM   #16 (permalink)
Redmo0n's Avatar
 
Techalicious

Join Date: Aug 2007

Location: Perth, Australia

Posts: 1,573

Redmo0n is on a distinguished road

Send a message via MSN to Redmo0n
Default Re: clusap.dll/trojan horse

Yep all good, also your computer should be running a bit quick
__________________
Back to stay?
Redmo0n is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
think i have a Trojan horse dale1 Virus - Spyware Protection / Detection 14 12-18-2007 08:08 PM
Trojan Horse lop.BK Havoc1212 Virus - Spyware Protection / Detection 4 04-01-2007 12:08 PM