LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: hayc59 on April 26, 2010, 11:50:42 PM

Title: Check up Please?
Post by: hayc59 on April 26, 2010, 11:50:42 PM
Numbers 22 in particular...since I dont not know what they are or how they got in my system
thank you
If i dont need anything in that log I want them gone ;)
**Acronis try and decide...need it??

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\BurnAware Home\NMSAccess32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Tall Emu\Online Armor\OAui.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AutoSizer\AutoSizer.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Gordon & Nancy\Desktop\JuNk\HiJack\HiJackThis.exe
C:\WINDOWS\System32\svchost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.my.msn.com/default.aspx?mypg=3
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\OAui.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [AutoSizer] "C:\Program Files\AutoSizer\AutoSizer.exe"
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\BurnAware Home\NMSAccess32.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\OAcat.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

--
End of file - 5170 bytes
Title: Re: Check up Please?
Post by: winchester73 on April 27, 2010, 12:34:17 AM
If memory serves, browseui.dll is a key component of IE, allowing Windows to talk to the browser interface.

I have Acronis on one box, and really like it, easy to use, simple to recover from.  My lappy has a built-in Lenovo application that does something similar, otherwise I'd have it on that as well.
Title: Re: Check up Please?
Post by: Aaron Hulett on April 27, 2010, 12:50:28 AM
Removing browseui.dll == unhappy PC:

Microsoft Knowledge Base Article 914222
Error message when you restart a Windows XP-based computer: "Explorer.exe unable to locate component"
When you restart a Microsoft Windows XP-based computer, you receive an error message that is similar to the following:
QuoteExplorer.exe unable to locate component
This application has failed to start because Browseui.dll was not found.
Re-installing the application may fix this problem.
Additionally, the following items are not displayed:
To resolve this issue, rename the Browseui.dll file, and then expand the Browseui.dll file from the Windows XP CD to the %Windir%\System32 folder.

More: http://support.microsoft.com/kb/914222
Title: Re: Check up Please?
Post by: hayc59 on April 27, 2010, 12:56:56 AM
ok cool and thanks winchester73 & Aaron!!
that stays ;)
what about 'try and decide' does that need to stay??
Title: Re: Check up Please?
Post by: winchester73 on April 27, 2010, 01:35:25 PM
Sorry, mate, I mis-read your question ... I thought you were asking for opinions about Acronis.

TrueImageTryStartService.exe is solely for the "Try & Decide" function, so if you're not going to use that function, it's safe to set the service to disabled or manual.  I don't think I'd remove it, as I have seen some BSOD issues if it is not properly removed.

"Try & Decide" sounds like some sort of "trial evaluation period", but for the benefit of others reading this thread, it's purpose is to let you experiment with your system by temporarily writing disk changes to the Secure Zone area instead of directly to your system drive.

QuoteTry&Decide feature. Performing potentially dangerous changes in the system, such as installing new software from the internet is sometime a risky operation as it may lead to system instability or even worse add Viruses or spyware to your computer. Thanks to Try and Decide in Acronis True Image 11 Home, you can now safely perform these potentially risky operations. When Try and decide is turned on, all the changes performed will be transparently recorded on a virtual disk automatically created in Acronis Secure Zone. At any time you can decide if you want to validate the changes you made or discard them and therefore revert the system back to its previous state.

http://kb.acronis.com/content/1692

Personally, I've left the service alone.
Title: Re: Check up Please?
Post by: hayc59 on April 28, 2010, 08:52:25 PM
Thanks and will leave well enough alone
it has bitten me in the arse before :)