Posts Tagged ‘Hidden’

Regarding Yesterdays Question On Hidden Problem–here Is The Hijackthis Log?

Thursday, October 8th, 2009

Logfile of HijackThis v1.99.1
Scan saved at 7:38:08 AM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Desktop Calendar\Desktop Calendar.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Lisa\LOCALS~1\Temp\Tempora… Directory 2 for hijackthis.zip\HijackThis.exe
R1 – HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 – URLSearchHook: Yahoo! Toolbar BETA – {EF99BD32-C1FB-11D2-892F-0090271D4F88} – C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.d…
O1 – Hosts: 216.93.174.28 a.tribalfusion.com
O1 – Hosts: 207.44.240.65 rad.msn.com
O1 – Hosts: 216.93.174.28 view.atdmt.com
O1 – Hosts: 216.93.174.28 media.fastclick.net
O1 – Hosts: 216.93.174.28 ad.doubleclick.net
O1 – Hosts: 216.93.174.28 images.trafficmp.com
O1 – Hosts: 216.93.174.28 adfarm.mediaplex.com
O1 – Hosts: 216.93.174.28 media1.fastclick.net
O1 – Hosts: 216.93.174.28 media19.fastclick.net
O1 – Hosts: 216.93.174.28 media39.fastclick.net
O1 – Hosts: 216.93.174.28 count.exitexchange.com
O1 – Hosts: 216.93.174.28 leader.linkexchange.com
O1 – Hosts: 67.15.114.78 pagead2.googlesyndication.com
O1 – Hosts: 67.15.114.78 pagead.googlesyndication.com
O1 – Hosts: 216.93.174.28 ad.yieldmanager.com
O1 – Hosts: 67.15.114.78 ypn-js.overture.com
O1 – Hosts: 216.93.174.28 freeze.zedo.com
O2 – BHO: (no name) – 0@å – (no file)
O2 – BHO: &Yahoo! Toolbar Helper – {02478D38-C3F9-4EFB-9B51-7695ECA05670} – C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.d…
O2 – BHO: (no name) – °?å – (no file)
O2 – BHO: (no name) – à?å – (no file)
O3 – Toolbar: Yahoo! Toolbar BETA – {EF99BD32-C1FB-11D2-892F-0090271D4F88} – C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.d…
O4 – HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe”
O4 – HKLM\..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 – HKLM\..\Run: [HP Software Update] “c:\Program Files\HP\HP Software Update\HPWuSchd2.exe”
O4 – HKLM\..\Run: [HP Component Manager] “C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”
O4 – HKLM\..\Run: [!AVG Anti-Spyware] “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
O4 – HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 – Startup: PowerReg Scheduler V3.exe
O4 – Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 – Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 – Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 – Extra button: (no name) – {e2e2dd38-d088-4134-82b7-f2ba38496583} – %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 – Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 – {e2e2dd38-d088-4134-82b7-f2ba38496583} – %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O15 – Trusted Zone: *.adgate.info (HKLM)
O15 – Trusted Zone: *.dollarrevenue.com (HKLM)
O15 – Trusted Zone: *.elitemediagroup.net (HKLM)
O15 – Trusted Zone: *.errorsafe.com (HKLM)
O15 – Trusted Zone: *.imagesrvr.com (HKLM)
O15 – Trusted Zone: *.matcash.com (HKLM)
O15 – Trusted Zone: *.media-motor.com (HKLM)
O15 – Trusted Zone: *.media-motor.net (HKLM)
O15 – Trusted Zone: *.mediatickets.net (HKLM)
O15 – Trusted Zone: *.mt-download.com (HKLM)
O15 – Trusted Zone: *.snipernet.biz (HKLM)
O15 – Trusted Zone: *.systemdoctor.com (HKLM)
O15 – Trusted Zone: *.winantivirus.com (HKLM)
O15 – Trusted Zone: *.winfixer.com (HKLM)
O16 – DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) – http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
O16 – DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) – https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 – DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) – http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
O16 – DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) – http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
O16 – DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) – http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
O18 – Filter: text/html – {2AB289AE-4B90-4281-B2AE-1F4BB034B647} – (no file)
O20 – Winlogon Notify: artm_newreg – C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\artm_ne… (file missing)
O20 – Winlogon Notify: polymorphreg – C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\polymor… (file missing)
O20 – Winlogon Notify: WgaLogon – C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 – SSODL: CDRecorder009 – {A3BC5E20-0235-1ABF-9CE1-00AA00512009} – C:\WINDOWS\system32\xcskzh32.dll (file missing)
O23 – Service: AVG Anti-Spyware Guard – Anti-Malware Development a.s. – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 – Service: CAISafe – Computer Associates International, Inc. – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 – Service: PCTEL Speaker Phone (Pctspk) – PCtel, Inc. – C:\WINDOWS\system32\pctspk.exe
O23 – Service: Pml Driver HPZ12 – HP – C:\WINDOWS\system32\HPZipm12.exe
O23 – Service: ProtexisLicensing – Unknown owner – C:\WINDOWS\system32\PSIService.exe
O23 – Service: VET Message Service (VETMSGNT) – CA, Inc. – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

Does Anyone Know How To Delete A .dll Files That Are Hidden On Your Pc But Come Up In Anti Virus Scan Pls?

Wednesday, September 16th, 2009

I have 5 files that come up in my AVG Scan that I cannot find to remove. Are they a virus? When the scan is finished it says “changed” but they still come up. Please help if you can. Thanks.