Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 10-04-2007, 09:59 PM   #1 (permalink)
 
True Techie

Join Date: Mar 2005

Posts: 158

stevedub is on a distinguished road

Default My dad's comp has a nasty bug

I'm having a rough time getting rid of this bug on my dad's comp. I thought I had it when I ran Vundofix, but I am still seeing problems. Here is a log from Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:22 PM, on 10/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rstodptv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Gary\Desktop\HiJackThis.exe

R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [MSConfig] "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe " /auto
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\agfaosad.dll",sitypnow
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (User 'Default user')
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://www.eversoft.co.kr/vmpinstall..._lns4695d.html
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/02e85b7f...p/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1165019679140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1165112353765
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...33/mcfscan.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6FFE8DDC-B8DC-457F-93CC-01B9A8DA6545}: NameServer = 127.0.0.1,64.119.60.5,64.119.60.9
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\rstodptv.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 6051 bytes
stevedub is offline  
Old 10-05-2007, 07:02 AM   #2 (permalink)
 
True Techie

Join Date: Mar 2005

Posts: 158

stevedub is on a distinguished road

Default Re: My dad's comp has a nasty bug

Also, when trying to install Spybot and other programs I get an error along the line of "floating point error", and Spysweeper won't run all the way through, it just shuts down. I'm starting to wonder if I'm going to have to reformat his hard drive for this one.
stevedub is offline  
Old 10-05-2007, 10:49 AM   #3 (permalink)
Nick's Avatar
 
Courtesy of Mak.

Join Date: Feb 2007

Location: Chichester, England

Posts: 3,998

Nick is on a distinguished road

Send a message via MSN to Nick
Default Re: My dad's comp has a nasty bug

download AVG free, do a scan, it usually cleans everything up
__________________
Every time I get Rep, I die inside.

Cisco Cert.
Nick is offline  
Old 10-06-2007, 10:42 AM   #4 (permalink)
 
True Techie

Join Date: Mar 2005

Posts: 158

stevedub is on a distinguished road

Default Re: My dad's comp has a nasty bug

We have tried AVG, and just about everything else I could find. This bug is nasty. I know its a trojan horse, but it keeps renaming itself and keeps getting burried further and further. I'm thinking reformat may be the only solution
stevedub is offline  
Old 10-06-2007, 11:06 AM   #5 (permalink)
 
Junior Techie

Join Date: Oct 2007

Location: Off the grid.

Posts: 92

ReikokuKo is on a distinguished road

Send a message via AIM to ReikokuKo
Default Re: My dad's comp has a nasty bug

That log looks pretty clean and legit except for
C:\WINDOWS\system32\rstodptv.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\rstodptv.exe

Can you find out what program that's associated with?
ReikokuKo is offline  
Old 10-07-2007, 05:21 PM   #6 (permalink)
jay_bo's Avatar
 
Ultra Techie

Join Date: Jul 2006

Posts: 898

jay_bo is on a distinguished road

Default Re: My dad's comp has a nasty bug

i reformat will prob be the safest bet and quickest.
__________________
jay_bo is offline  
Old 10-07-2007, 05:25 PM   #7 (permalink)
nu2duo's Avatar
 
Super Techie

Join Date: Feb 2007

Location: Neza

Posts: 423

nu2duo is on a distinguished road

Thumbs up Re: My dad's comp has a nasty bug

Quote:
Originally Posted by jay_bo View Post
i reformat will prob be the safest bet and quickest.
^
exactly.
Just backup anything important. I'd rather save time and headaches and just reformat and reinstall os.
__________________
e6600@3.1 24/7 w/stock cooling. 2g Transcend Memory
3 hd's, 80-XP Pro, 500 and 320-Apps,Pics, Music, Videos
ATI Radeon HD 3450 512MB-I DON'T GAME!
Ultra PS, Ultra Mid Tower Case
Lite-on internal DVD-R, Samsung Lite-Scribe Ext. DVD-R
2 Acer 19" widescreen LCD's. For HTPC Olevia 32" LCD
nu2duo is offline  
Old 10-08-2007, 02:58 PM   #8 (permalink)
 
True Techie

Join Date: Mar 2005

Posts: 158

stevedub is on a distinguished road

Default Re: My dad's comp has a nasty bug

Thanks for all the replies guys, I did decide to reformat. I tried for a couple days to nail this bug down, but it just kept getting worse. It's amazing how some of these viruses and trojans can really destroy your computer system. Do you guys have any recommendations on what I should install for my dad to help prevent this in the future? I think I may put AVG on his comp for virus protection, and maybe a couple of spyware programs.
stevedub is offline  
Old 10-08-2007, 03:01 PM   #9 (permalink)
Nick's Avatar
 
Courtesy of Mak.

Join Date: Feb 2007

Location: Chichester, England

Posts: 3,998

Nick is on a distinguished road

Send a message via MSN to Nick
Default Re: My dad's comp has a nasty bug

a good firewall, i would consider purchasing the full version of AVG
__________________
Every time I get Rep, I die inside.

Cisco Cert.
Nick is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
New comp doesnt turn on Gregz Hardware Troubleshooting 9 08-22-2007 07:07 PM
Comp won't shut off - weird clicking sound Haoming Hardware Troubleshooting 18 08-04-2007 06:58 AM
Comp won't shut off - weird clicking sound Haoming Virus - Spyware Protection / Detection 2 07-27-2007 01:02 AM
Help Building a CAD Comp =] GopherBallz Building, Buying, or Upgrading High Performance PC Systems 12 05-19-2007 03:45 PM
What to use to get video on comp? dario03 Building, Buying, or Upgrading High Performance PC Systems 4 05-15-2007 09:50 PM