Tech Support Forum banner
Status
Not open for further replies.
1 - 5 of 5 Posts

· Registered
Joined
·
102 Posts
Discussion Starter · #1 ·
A little while ago I noticed that my print spooler service kept getting disabled. Not sure if that has anything to do with my current problem. But anyways, just today when I try to open Internet Explorer it tells me it cannot locate iexplore.exe and I try to locate myself but cannot find. Also, when I look at the HJT log, which I am sure you'll notice also, there are a few svchost.exe files in places I don't think they should be. Let me know what you think. I downloaded Firefox so that I can get onto the internet in the meantime.

Main.txt

Deckard's System Scanner v20071014.68
Run by Administrator on 2007-11-05 09:41:55
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
74: 2007-11-05 14:42:04 UTC - RP219 - Deckard's System Scanner Restore Point
73: 2007-11-05 00:52:42 UTC - RP218 - Installed Adobe Reader 8.1.0
72: 2007-11-05 00:52:30 UTC - RP217 - Removed Adobe Reader 7.0.9
71: 2007-11-04 00:25:34 UTC - RP216 - System Checkpoint
70: 2007-11-03 00:25:29 UTC - RP215 - System Checkpoint


-- First Restore Point --
1: 2007-08-26 00:22:33 UTC - RP146 - System Checkpoint


Performed disk cleanup.



-- HijackThis (run as Administrator.exe) ---------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-05 09:45:56
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.0.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\securessl.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\netdde\netdde.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\Corel\Suite8\Programs\DAD8.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\administrator.GLF.000\Desktop\dss.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Corel Desktop Application Director 8.LNK = C:\Corel\Suite8\Programs\DAD8.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html (file missing)
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html (file missing)
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html (file missing)
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (file missing)
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120187452421
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{E1FCFE35-3E82-46B4-A000-FC74BEC0AC8D}: NameServer = 192.168.1.100,209.244.0.3
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Application Lar Service (Appl) - Unknown owner - C:\WINDOWS\system32\Com\svchost.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: CCProxy - Unknown owner - C:\WINDOWS\system\svchost.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\dhcp\svchost.exe
O23 - Service: SavRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Secure SSL System (secure) - Unknown owner - C:\WINDOWS\system32\securessl.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Support - Unknown owner - C:\WINDOWS\Helpsvcs.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Event Managers - Unknown owner - C:\WINDOWS\sv.exe
O23 - Service: Windows Cron Service - Unknown owner - C:\WINDOWS\System32\crons.exe
O23 - Service: Windows_rejoice2007_51 - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\freesexmovie.exe
O23 - Service: WMI Adapter Server (WmiSrv) - Unknown owner - C:\WINDOWS\system32\wmiapsrv.exe


--
End of file - 8999 bytes

-- HijackThis Fixed Entries (C:\HJT\backups\) ----------------------------------

backup-20070604-124631-383 O23 - Service: Windows_rejoice2007_51 - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\freesexmovie.exe
backup-20070607-092642-211 O23 - Service: Security-Services (secure) - Secure Soft - C:\WINDOWS\system32\wins\winback.exe
backup-20070607-092642-431 O23 - Service: Messagerp - Unknown owner - c:\svchost.exe
backup-20070607-092642-576 O23 - Service: Messager - Unknown owner - c:\temp\svchost.exe
backup-20070607-092642-606 O23 - Service: Windows Cron Service - Unknown owner - C:\WINDOWS\System32\crons.exe
backup-20070607-094833-494 O23 - Service: Windowservices - Unknown owner - c:\msinfo.exe (file missing)
backup-20071105-092113-507 O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\dhcp\svchost.exe (file missing)
backup-20071105-092113-717 O23 - Service: Support - Unknown owner - C:\WINDOWS\Helpsvcs.exe
backup-20071105-092113-727 O23 - Service: CCProxy - Unknown owner - C:\WINDOWS\system\svchost.exe
backup-20071105-092113-902 O23 - Service: Secure SSL System (secure) - Unknown owner - C:\WINDOWS\system32\securessl.exe
backup-20071105-092113-951 O23 - Service: Application Lar Service (Appl) - Unknown owner - C:\WINDOWS\system32\com\svchost.exe

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S0 amsint - c:\windows\microsoft kernel dls synthes??
(file missing)
S2 yiuzvvgl - c:\windows\system32\drivers\msearh.sys (file missing)
S2 yzdpyorp - c:\windows\system32\drivers\xzdpyo.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Appl (Application Lar Service) - c:\windows\system32\com\svchost.exe
R2 regsvc (Registry Services) - c:\windows\system32\regsvc.exe <Not Verified; Microsoft; RegSvc>
R2 secure (Secure SSL System) - c:\windows\system32\securessl.exe

S2 r_server (Remote Administrator Service) - "c:\windows\system32\dhcp\svchost.exe" /service (file missing)
S2 Symantec Event Managers - c:\windows\sv.exe
S2 WmiSrv (WMI Adapter Server) - "c:\windows\system32\wmiapsrv.exe" /service
S4 Support - c:\windows\helpsvcs.exe
S4 Windows Cron Service - c:\windows\system32\crons.exe (file missing)
S4 Windows_rejoice2007_51 - c:\program files\common files\microsoft shared\msinfo\freesexmovie.exe (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2007-10-05 and 2007-11-05 -----------------------------

2007-11-05 09:42:51 0 d-------- C:\Program Files\Trend Micro
2007-11-05 09:36:19 0 d-------- C:\Documents and Settings\administrator.GLF.000\Application Data\Mozilla
2007-11-04 19:48:02 0 d-------- C:\WINDOWS\Downloaded Installations
2007-11-04 04:53:37 355840 -r-hs---- C:\WINDOWS\sv.exe
2007-11-04 04:50:04 0 d-------- C:\Documents and Settings\iisadmin\Application Data\Macromedia
2007-11-04 04:49:51 0 d-------- C:\Documents and Settings\iisadmin\Application Data\Google
2007-11-04 04:48:42 0 d--h----- C:\Documents and Settings\iisadmin\NetHood
2007-11-04 04:48:42 0 dr------- C:\Documents and Settings\iisadmin\My Documents
2007-11-04 04:48:42 0 d--h----- C:\Documents and Settings\iisadmin\Local Settings
2007-11-04 04:48:42 0 dr------- C:\Documents and Settings\iisadmin\Favorites
2007-11-04 04:48:42 0 d-------- C:\Documents and Settings\iisadmin\Desktop
2007-11-04 04:48:42 0 d---s---- C:\Documents and Settings\iisadmin\Cookies
2007-11-04 04:48:42 0 dr-h----- C:\Documents and Settings\iisadmin\Application Data
2007-11-04 04:48:42 0 d---s---- C:\Documents and Settings\iisadmin\Application Data\Microsoft
2007-11-04 04:48:42 0 d-------- C:\Documents and Settings\iisadmin\Application Data\Identities
2007-11-04 04:48:41 0 d-------- C:\Documents and Settings\iisadmin\WINDOWS
2007-11-04 04:48:41 0 d---s---- C:\Documents and Settings\iisadmin\UserData
2007-11-04 04:48:41 0 d--h----- C:\Documents and Settings\iisadmin\Templates
2007-11-04 04:48:41 0 dr------- C:\Documents and Settings\iisadmin\Start Menu
2007-11-04 04:48:41 0 dr-h----- C:\Documents and Settings\iisadmin\SendTo
2007-11-04 04:48:41 0 dr-h----- C:\Documents and Settings\iisadmin\Recent
2007-11-04 04:48:41 0 d--h----- C:\Documents and Settings\iisadmin\PrintHood
2007-11-04 04:48:41 786432 --ah----- C:\Documents and Settings\iisadmin\NTUSER.DAT
2007-10-15 23:04:47 0 d--hs---- C:\WINDOWS\system\web
2007-10-15 23:04:47 974848 --ahs---- C:\WINDOWS\system\svchost.exe <Not Verified; ; CCProxy Application>
2007-10-15 23:04:47 0 d--hs---- C:\WINDOWS\system\Log
2007-10-15 23:04:47 0 d--hs---- C:\WINDOWS\system\Language
2007-10-15 08:08:42 1159 --a------ C:\WINDOWS\system32\Down(11532976).bat
2007-10-15 08:07:55 1159 --a------ C:\WINDOWS\system32\Down(11532975).bat
2007-10-15 08:07:35 1159 --a------ C:\WINDOWS\system32\Down(11532974).bat
2007-10-11 02:58:25 1159 --a------ C:\WINDOWS\system32\Down(11532973).bat
2007-10-11 02:56:25 1159 --a------ C:\WINDOWS\system32\Down(11532972).bat
2007-10-10 12:07:34 87 --a------ C:\WINDOWS\system32\StatSrv.dat
2007-10-10 11:52:40 54272 --a------ C:\WINDOWS\system32\KTRstat.dll
2007-10-10 11:52:40 1090 --a------ C:\WINDOWS\system32\KTRchl.dll
2007-10-10 11:52:36 64000 --a------ C:\WINDOWS\system32\JAcheck.dll
2007-10-10 11:52:10 769536 --a------ C:\WINDOWS\system32\securessl.exe
2007-10-10 11:52:09 1466 --a------ C:\WINDOWS\system32\sslsecntwrk.dll
2007-10-10 02:26:06 1159 --a------ C:\WINDOWS\system32\Down(11532971).bat
2007-10-10 02:19:42 1159 --a------ C:\WINDOWS\system32\Down(11532970).bat
2007-10-08 07:08:16 1159 --a------ C:\WINDOWS\system32\Down(11532969).bat
2007-10-08 07:07:06 1159 --a------ C:\WINDOWS\system32\Down(11532968).bat


-- Find3M Report ---------------------------------------------------------------

2007-11-05 09:23:56 0 d-------- C:\Program Files\Symantec AntiVirus
2007-11-04 19:52:58 0 d-------- C:\Program Files\Common Files\Adobe
2007-10-01 21:53:57 1159 --a------ C:\WINDOWS\system32\Down(0).bat
2007-09-26 11:28:41 0 d-------- C:\Program Files\Logitech
2007-09-26 11:28:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-09-26 11:28:12 0 d-------- C:\Program Files\Common Files
2007-09-26 11:28:12 0 d-------- C:\Program Files\Common Files\Logitech
2007-09-26 02:36:53 0 d-------- C:\Program Files\Siber Systems
2007-09-06 09:13:57 234960 --a------ C:\WINDOWS\system32\wmiapsrv.exe
2007-08-11 08:14:12 168960 --a------ C:\WINDOWS\system32\Down(1).exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [08/19/2003 10:56 PM C:\WINDOWS\system32\VTTimer.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/13/2002 05:42 PM]
"PExpress Unattended"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [04/08/2005 02:52 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [04/17/2005 11:30 AM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 07:38 AM]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [03/04/2004 09:46 AM]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [02/18/2004 12:55 PM]
"SoundMan"="SOUNDMAN.EXE" [05/14/2003 12:20 AM C:\WINDOWS\SOUNDMAN.EXE]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/29/2007 03:21 PM]
"Logitech Utility"="Logi_MwX.Exe" [11/07/2003 04:50 AM C:\WINDOWS\LOGI_MWX.EXE]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [03/09/2007 11:09 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 06:24 PM]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [09/26/2007 11:28 AM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


-- End of Deckard's System Scanner: finished at 2007-11-05 09:46:23 ------------
 

Attachments

· Registered
Joined
·
102 Posts
Discussion Starter · #3 ·
Re: "Cannot find iexplore.exe" and random svchost.exe files throughout HJT log

Ok I am not sure if I did harm to my computer or the virus did but for some reason now I cannot get "Workstation" "Server" or "Computer Browser" service to start. I get the following error:

Could not start the Computer Browser service on Local Computer
Error 1068: The dependency service or group failed to start

Could not start the Workstation service on Local Computer
Error 1075: The dependency service does not exist or has been marked for deletion

And the same error for Server as Workstation

What I did was delete the services that looked bad "Application Lar Service (Appl), Remote Administrator Service (r_server), Secure SSL System (secure) and Symantec Event Managers : C:\WINDOWS\sv.exe. I then went ahead and deleted each of those files. That is all I have done.

The other weird thing I noticed is in the description for Computer Browser it says "ededededededededede list of computers on the network..."

Oh and another thing, when I try to open up a command prompt it says it has been disabled by an administrator. This was the case before I posted here as well but I had been able to access it before.

Here is the latest HJT log. I don't want to run Deckard's because I know it sets a new restore point and I don't want to delete any restore points in case I have to go back. Please help me ASAP on this. Thanks alot.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:06 PM, on 11/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\netdde\netdde.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Corel\Suite8\Programs\DAD8.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Corel Desktop Application Director 8.LNK = C:\Corel\Suite8\Programs\DAD8.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.q104.com
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120187452421
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1FCFE35-3E82-46B4-A000-FC74BEC0AC8D}: NameServer = 192.168.1.100,209.244.0.3
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WMI Adapter Server (WmiSrv) - Unknown owner - C:\WINDOWS\system32\wmiapsrv.exe

--
End of file - 9888 bytes
 

· Registered
Joined
·
102 Posts
Discussion Starter · #4 · (Edited)
Re: "Cannot find iexplore.exe" and random svchost.exe files throughout HJT log

Ok new update. I got regedit and command prompt to be enabled using a utility I found on the web. I still can't get workstation, server or computer browser service to start. There are a bunch of services that look suspicious. For example:

xzdpyo Microsoft.NET Framework TPM
Path to executable: C:\WINDOWS\System32\svchost.exe -k xzdpyo

Also, there is no Windows Firewall/Internet Connection Sharing service listed. I think my registry needs major editing and or complete restoration. Can someone please help ASAP so I can get my computer running again. Thanks.
 

· Registered
Joined
·
102 Posts
Discussion Starter · #5 ·
Re: "Cannot find iexplore.exe" and random svchost.exe files throughout HJT log

Ok another update. I really hope someone will actually help me with this because it seems to be a bad one.

Looking at the registry I noticed under lanmanserver and lanmanworkstation they both have a DependOnGroup (which is blank) and a DependOneService (with the data as "secure"). This is one of the bad services I had deleted so I guess when I deleted it, now I cannot get the workstation or server services to start. Can someone send me maybe a clean registry I can merge with mine or something? I really need to get this fixed and I haven't heard anything from you guys. Please help!
 
1 - 5 of 5 Posts
Status
Not open for further replies.
Top