Tech Support Forum banner

HijackThis log analyzed with KRC HT analyzer

1239 Views 2 Replies 2 Participants Last post by  Coaster
hey,
i just wanted to know if there's anything wrong with my pc. i ran spybot, ad-aware and trend virus scan and apparently everything's clean. i just sense some problems with the start-up. i have one or two progs that don't run at startup, even though they are set to.
don't be hasty about this one. i just want to rest assured, so i'm not in a hurry. :smile:


====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 17:24:55, on 24-08-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Programas\Sygate\SPF\smc.exe
C:\Programas\Microsoft IntelliPoint\point32.exe
C:\Programas\Java\jre1.5.0_04\bin\jusched.exe
C:\Programas\Netcount\Netcount.exe
C:\Programas\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
D:\Programas\eMule\eMule.exe
D:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Programas\MSN Messenger\msnmsgr.exe
C:\Programas\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iol.pt/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - (no file)
O2 - BHO: Toolbar Helper - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\WINDOWS\system32\s1928.dll
O3 - Toolbar: Stumble&Upon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1928.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programas\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [KAV50] "C:\Programas\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Netcount] C:\Programas\Netcount\Netcount.exe 0
O4 - HKCU\..\Run: [AWMON] "C:\Programas\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: eMule.lnk = D:\Programas\eMule\eMule.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\WINDOWS\system32\s1928.dll/blogimage
O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {82F2D6B2-6C58-4404-A930-9DB0FD90D4B1} (Driver_Detective_v43_Non_Member.DD_v43) - http://www.drivershq.com/cab/prod/Driver_Detective_v43_Non_Member.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.7) - http://gameadvisor.futuremark.com/global/msc37.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: kavsvc - Kaspersky Lab - C:\Programas\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Programas\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Programas\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programas\Sygate\SPF\smc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe


End of KRC HijackThis Analyzer Log.
====================================================================
See less See more
Status
Not open for further replies.
1 - 3 of 3 Posts
Hello Coaster,

I'm not seeing anything in this log. What programs are not loading at startup?

I understand that you've already run a virus scan, but let's get a 'second opinion' :smile:

Perform an online scan with Internet Explorer with Panda ActiveScan - requires Internet Explorer

  1. Click on the Scan your PC button & a 'pop up' window shall appear. * ensure that your pop up blocker doesn't block it
  2. Click On 'Scan Now'
  3. Enter your e-mail address & click 'Scan Now' ...begins downloading Panda's ActiveX controls.- 8MB
  4. Begin the scan by selecting My Computer
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
  5. If it finds any malware, it will offer you a report. Click on see report
  6. Then click Save report
  7. Post the contents of the report in your next reply

* Turn off the real time scanner of any existing antivirus program while performing the online scan
See less See more
here is the report:

-------------------------


Incident Status Location

Adware:adware/wupd No disinfected Windows Registry
Possible Virus. No disinfected C:\Programas\Maxthon\Maxthon.exe
Possible Virus. No disinfected C:\WINDOWS\Temp\ASHeuristic\Maxthon.exe.vir
Possible Virus. No disinfected J:\DIKO_-_Utilidades_Pro64_setup_1.2.0.0_pt_en_es.exe[FreeEnc_O.exe]
Possible Virus. No disinfected J:\Programas\DIKO\DIKOGUI.exe
Possible Virus. No disinfected J:\Programas\DIKO\FreeEnc\FreeEnc.exe
Possible Virus. No disinfected J:\Programas\DIKO\FreeEnc\FreeEnc_O.exe
Possible Virus. No disinfected J:\Programas\FreeEnc044\FreeEnc.exe ----------------------------------
See less See more
1 - 3 of 3 Posts
Status
Not open for further replies.
Top