Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished) » friends really bad log..needs some major help here.
 
Old 12-06-2007, 06:00 PM   #11 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: friends really bad log..needs some major help here.

Vundo takes forever to scan. hahah.
Vundo found nothing though. Thats a good thing right?

Virtumundo Be Gone found nothing also.

Ran Cleanup again (did last night too).
Ran CCleaner

Ran AVG and AVG spyware.
AVG AV found 4 entries:
http://i5.photobucket.com/albums/y17...me/screen3.png


AVG SW found about 45.

The background is able to change now (when you tried changing before, it would just change back as soon as a warning from the right hand corner would pop up.)
Those are gone now and the background is the same.

Comboscan's page isn't found...?
so no CS log.

New HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:56 PM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

Last edited by Static_11; 12-06-2007 at 06:03 PM.
Static_11 is offline  
Old 12-06-2007, 06:04 PM   #12 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: friends really bad log..needs some major help here.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = AOL.com - Welcome to AOL
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo!
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\lpcywinp.exe,C:\WINDO WS\system32\userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [VAIO Update 3] "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardware ResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O24 - Desktop Component 0: (no name) - http://images.google.com/images?q=tb...eybusiness.jpg
O24 - Desktop Component 1: (no name) - http://images.google.com/images?q=tb...just_balls.jpg
O24 - Desktop Component 10: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+059
O24 - Desktop Component 11: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+001
O24 - Desktop Component 12: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+009
O24 - Desktop Component 13: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+112
O24 - Desktop Component 14: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+142
O24 - Desktop Component 15: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+065
O24 - Desktop Component 16: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+006
O24 - Desktop Component 17: (no name) - http://a929.ac-images.myspacecdn.com...2f527a8d08.jpg
O24 - Desktop Component 18: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod2.jpg
O24 - Desktop Component 19: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod3.jpg
O24 - Desktop Component 2: (no name) - http://images.google.com/images?q=tb...nteen_days.jpg
O24 - Desktop Component 20: (no name) - http://tbn0.google.com/images?q=tbn:...ollywood10.jpg
O24 - Desktop Component 21: (no name) - http://photos-318.ak.facebook.com/ph...96318_6741.jpg
O24 - Desktop Component 22: (no name) - http://photos-302.ak.facebook.com/ph...96302_9477.jpg
O24 - Desktop Component 23: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 24: (no name) - http://photos-307.ak.facebook.com/ph...096307_647.jpg
O24 - Desktop Component 25: (no name) - http://photos-300.ak.facebook.com/ph...96300_9003.jpg
O24 - Desktop Component 26: (no name) - http://photos-313.ak.facebook.com/ph...96313_2064.jpg
O24 - Desktop Component 27: (no name) - http://photos-308.ak.facebook.com/ph...096308_883.jpg
O24 - Desktop Component 28: (no name) - http://photos-310.ak.facebook.com/ph...96310_1350.jpg
O24 - Desktop Component 29: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 3: (no name) - http://images.google.com/images?q=tb..._movealong.jpg
O24 - Desktop Component 30: (no name) - http://www.rickey.org/wp-content/upl...2007-03-23.jpg
O24 - Desktop Component 31: (no name) - http://i10.tinypic.com/53hsklw.jpg
O24 - Desktop Component 32: (no name) - http://tbn0.google.com/images?q=tbn:...toxicstyle.jpg
O24 - Desktop Component 33: (no name) - http://a325.ac-images.myspacecdn.com...242eb3630c.jpg
O24 - Desktop Component 34: (no name) - http://a398.ac-images.myspacecdn.com...8954f3dfc5.jpg
O24 - Desktop Component 35: (no name) - http://tbn0.google.com/images?q=tbn:...ars-poster.jpg
O24 - Desktop Component 4: (no name) - http://images.google.com/images?q=tb...2520coverV.jpg
O24 - Desktop Component 5: (no name) - http://images.google.com/images?q=tb...falloutboy.jpg
O24 - Desktop Component 6: (no name) - http://images.google.com/images?q=tb...2876634612.jpg
O24 - Desktop Component 7: (no name) - http://images.google.com/images?q=tb...lbum-cover.jpg
O24 - Desktop Component 8: (no name) - http://images.google.com/images?q=tb...file/MMHMM.jpg
O24 - Desktop Component 9: (no name) - http://images.google.com/images?q=tb...ientKMmhmm.jpg
Static_11 is offline  
Old 12-06-2007, 06:06 PM   #13 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: friends really bad log..needs some major help here.

sorry for double post - internet messed up.

Last edited by Static_11; 12-06-2007 at 06:12 PM.
Static_11 is offline  
Old 12-06-2007, 07:03 PM   #14 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,141

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: friends really bad log..needs some major help here.

Remove these entries

R3 - URLSearchHook: (no name) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\lpcywinp.exe,C:\WINDO WS\system32\userinit.exe


Open msconfig, go to startup, and make sure only AVG is running, reboot

and post a new log
__________________
Osiris is online now  
Old 12-06-2007, 10:44 PM   #15 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: friends really bad log..needs some major help here.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:07 PM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wscntfy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = AOL.com - Welcome to AOL
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo!
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardware ResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O24 - Desktop Component 0: (no name) - http://images.google.com/images?q=tb...eybusiness.jpg
O24 - Desktop Component 1: (no name) - http://images.google.com/images?q=tb...just_balls.jpg
O24 - Desktop Component 10: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+059
O24 - Desktop Component 11: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+001
O24 - Desktop Component 12: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+009
O24 - Desktop Component 13: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+112
O24 - Desktop Component 14: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+142
O24 - Desktop Component 15: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+065
O24 - Desktop Component 16: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+006
O24 - Desktop Component 17: (no name) - http://a929.ac-images.myspacecdn.com...2f527a8d08.jpg
O24 - Desktop Component 18: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod2.jpg
O24 - Desktop Component 19: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod3.jpg
O24 - Desktop Component 2: (no name) - http://images.google.com/images?q=tb...nteen_days.jpg
O24 - Desktop Component 20: (no name) - http://tbn0.google.com/images?q=tbn:...ollywood10.jpg
O24 - Desktop Component 21: (no name) - http://photos-318.ak.facebook.com/ph...96318_6741.jpg
O24 - Desktop Component 22: (no name) - http://photos-302.ak.facebook.com/ph...96302_9477.jpg
O24 - Desktop Component 23: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 24: (no name) - http://photos-307.ak.facebook.com/ph...096307_647.jpg
O24 - Desktop Component 25: (no name) - http://photos-300.ak.facebook.com/ph...96300_9003.jpg
O24 - Desktop Component 26: (no name) - http://photos-313.ak.facebook.com/ph...96313_2064.jpg
O24 - Desktop Component 27: (no name) - http://photos-308.ak.facebook.com/ph...096308_883.jpg
O24 - Desktop Component 28: (no name) - http://photos-310.ak.facebook.com/ph...96310_1350.jpg
O24 - Desktop Component 29: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 3: (no name) - http://images.google.com/images?q=tb..._movealong.jpg
O24 - Desktop Component 30: (no name) - http://www.rickey.org/wp-content/upl...2007-03-23.jpg
O24 - Desktop Component 31: (no name) - http://i10.tinypic.com/53hsklw.jpg
O24 - Desktop Component 32: (no name) - http://tbn0.google.com/images?q=tbn:...toxicstyle.jpg
O24 - Desktop Component 33: (no name) - http://a325.ac-images.myspacecdn.com...242eb3630c.jpg
O24 - Desktop Component 34: (no name) - http://a398.ac-images.myspacecdn.com...8954f3dfc5.jpg
O24 - Desktop Component 35: (no name) - http://tbn0.google.com/images?q=tbn:...ars-poster.jpg
O24 - Desktop Component 4: (no name) - http://images.google.com/images?q=tb...2520coverV.jpg
O24 - Desktop Component 5: (no name) - http://images.google.com/images?q=tb...falloutboy.jpg
O24 - Desktop Component 6: (no name) - http://images.google.com/images?q=tb...2876634612.jpg
O24 - Desktop Component 7: (no name) - http://images.google.com/images?q=tb...lbum-cover.jpg
O24 - Desktop Component 8: (no name) - http://images.google.com/images?q=tb...file/MMHMM.jpg
O24 - Desktop Component 9: (no name) - http://images.google.com/images?q=tb...ientKMmhmm.jpg

--
End of file - 15103 bytes
Static_11 is offline  
Old 12-06-2007, 11:32 PM   #16 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,141

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: friends really bad log..needs some major help here.

Did your friend configure an active desktop with all these below? If not then remove then, if he did, leave them alone. Is his computer fine now? Log looks better. Any other issues?

O24 - Desktop Component 0: (no name) - http://images.google.com/images?q=tb...eybusiness.jpg
O24 - Desktop Component 1: (no name) - http://images.google.com/images?q=tb...just_balls.jpg
O24 - Desktop Component 10: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+059
O24 - Desktop Component 11: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+001
O24 - Desktop Component 12: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+009
O24 - Desktop Component 13: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+112
O24 - Desktop Component 14: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+142
O24 - Desktop Component 15: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+065
O24 - Desktop Component 16: (no name) - http://us.a2.yahoofs.com/users/_ISIX...=McKayla+-+006
O24 - Desktop Component 17: (no name) - http://a929.ac-images.myspacecdn.com...2f527a8d08.jpg
O24 - Desktop Component 18: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod2.jpg
O24 - Desktop Component 19: (no name) - http://tbn0.google.com/images?q=tbn:...a_s2-prod3.jpg
O24 - Desktop Component 2: (no name) - http://images.google.com/images?q=tb...nteen_days.jpg
O24 - Desktop Component 20: (no name) - http://tbn0.google.com/images?q=tbn:...ollywood10.jpg
O24 - Desktop Component 21: (no name) - http://photos-318.ak.facebook.com/ph...96318_6741.jpg
O24 - Desktop Component 22: (no name) - http://photos-302.ak.facebook.com/ph...96302_9477.jpg
O24 - Desktop Component 23: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 24: (no name) - http://photos-307.ak.facebook.com/ph...096307_647.jpg
O24 - Desktop Component 25: (no name) - http://photos-300.ak.facebook.com/ph...96300_9003.jpg
O24 - Desktop Component 26: (no name) - http://photos-313.ak.facebook.com/ph...96313_2064.jpg
O24 - Desktop Component 27: (no name) - http://photos-308.ak.facebook.com/ph...096308_883.jpg
O24 - Desktop Component 28: (no name) - http://photos-310.ak.facebook.com/ph...96310_1350.jpg
O24 - Desktop Component 29: (no name) - http://photos-303.ak.facebook.com/ph...96303_9705.jpg
O24 - Desktop Component 3: (no name) - http://images.google.com/images?q=tb..._movealong.jpg
O24 - Desktop Component 30: (no name) - http://www.rickey.org/wp-content/upl...2007-03-23.jpg
O24 - Desktop Component 31: (no name) - http://i10.tinypic.com/53hsklw.jpg
O24 - Desktop Component 32: (no name) - http://tbn0.google.com/images?q=tbn:...toxicstyle.jpg
O24 - Desktop Component 33: (no name) - http://a325.ac-images.myspacecdn.com...242eb3630c.jpg
O24 - Desktop Component 34: (no name) - http://a398.ac-images.myspacecdn.com...8954f3dfc5.jpg
O24 - Desktop Component 35: (no name) - http://tbn0.google.com/images?q=tbn:...ars-poster.jpg
O24 - Desktop Component 4: (no name) - http://images.google.com/images?q=tb...2520coverV.jpg
O24 - Desktop Component 5: (no name) - http://images.google.com/images?q=tb...falloutboy.jpg
O24 - Desktop Component 6: (no name) - http://images.google.com/images?q=tb...2876634612.jpg
O24 - Desktop Component 7: (no name) - http://images.google.com/images?q=tb...lbum-cover.jpg
O24 - Desktop Component 8: (no name) - http://images.google.com/images?q=tb...file/MMHMM.jpg
O24 - Desktop Component 9: (no name) - http://images.google.com/images?q=tb...ientKMmhmm.jpg
__________________
Osiris is online now  
Old 12-06-2007, 11:53 PM   #17 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: friends really bad log..needs some major help here.

not that im aware of. Her background before it changed was a picture of her and her boyfriend. So im guessing those are safe to trash?

Is there a reason why i still can't open the task manager is there a registry fix for that?

Oh, and yeah..the laptop is soo much better now. Im going to do normal maintence stuff to it tonight..its almost a year old... no spyware/av protection at all until the last few days.. i can bet its never been defragged as well. haha.

im also going to set up the scanners to do it when she's not around and the auto updates and stuff...

much easier to prevent this from happening than to try cleaning it when its already there..

also, downloading zonealarm as i type this.

thanks for the help dude. appreciate it a lot. haha i always come here when i get something like this. im kind of wanting to learn how to do it better than i do though. idk. maybe ill read some tut's or something. Thanks again.
Static_11 is offline  
Old 12-07-2007, 09:44 AM   #18 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,141

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: friends really bad log..needs some major help here.

Task Manager has been disabled by your administrator
__________________
Osiris is online now  
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
friends log Static_11 HijackThis Logs (finished) 11 11-25-2007 10:27 PM
iifecca.dll - can't remove it, NOD32 says its bad? Akumajin Virus - Spyware Protection / Detection 3 10-05-2007 04:41 AM
Friend's PC need log checked ASAP superdave1984 HijackThis Logs (finished) 4 09-23-2007 11:39 AM
Hard Drive Errors!!! Bad or Faulty HDD? mike4realz Hardware Troubleshooting 3 09-19-2007 01:56 AM