Happy Highjackthis log right here....kinda

Started by Mithrandirxx, April 12, 2007, 02:37:34 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Mithrandirxx

Problem mentioned here

Logfile of HijackThis v1.99.1
Scan saved at 7:53:54 PM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\NightmareSoul\Desktop\stng260.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\NightmareSoul\My Documents\Mithrandirxx\Installs\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NightmareSoul Inc.
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - http://www.crucial.com/controls/cpcScanner.cab
O18 - Protocol: IW - {F4CB1DC2-BF71-42F5-81AB-4606998A6B56} - C:\Program Files\Walker\ImageWalker220\ImageWalkerHtml.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: IUDD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1.001\LOCALS~1\Temp\IUDD.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindService.exe

"Those who are skilled in combat do not become angered, those who are skilled at winning do not become afraid. Thus the wise win before they fight, while the ignorant fight to win." Zhuge Liang

SpyDie

Hmmm.

I'm interested in this:
O23 - Service: IUDD - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1.001\LOCALS~1\Temp\IUDD.exe

HijackThis doesn't do terribly well when it comes to labelling things as "file missing", so could you do this to make sure the file does actually exist:

Download FileFind from Atribune.
Unzip the file and save it to your desktop.

To run FileFind, please do the following:

  • Click on FileFind.exe
  • In the box labeled "Directory"

    • Enter Drive eg.. C:\
  • In the box labeled "File"

    • Enter the file IUDD.exe
  • Now click on the "Search" button
  • Once the utility has found the files click on "Export"
  • A Notepad will open up.  Please copy the entire contents of the Notepad and paste them here.
  • NOTE: The notepad is saved on your C:\ drive as "Export.txt"
Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

Mithrandirxx

The whole text file from this File find program is as follows
Quote


C:\Documents and Settings\Administrator.MITHRANDIRXX.001\Local Settings\Temp\IUDD.exe - 491603 Bytes

So it does exist, however I cannot find any information on said execute file on google or Microsoft ( who owns Sysinternals)
"Those who are skilled in combat do not become angered, those who are skilled at winning do not become afraid. Thus the wise win before they fight, while the ignorant fight to win." Zhuge Liang

SpyDie

Could you upload at this site?

http://www.virustotal.com/en/indexf.html

Just copy/paste it's filepath into the 'Browse' box and hit Send. The service can get very busy at times, so give it as long as it needs. The service is simply to scan a certain file with several AntiVirus engines.

Copy/paste the results it gives after the scan.
Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

Mithrandirxx

Antivirus Version Update Result
AhnLab-V3 2007.4.14.0 04.13.2007  no virus found
AntiVir 7.3.1.50 04.13.2007  no virus found
Authentium 4.93.8 04.14.2007  no virus found
Avast 4.7.936.0 04.13.2007  no virus found
AVG 7.5.0.447 04.13.2007  no virus found
BitDefender 7.2 04.14.2007  no virus found
CAT-QuickHeal 9.00 04.13.2007  no virus found
ClamAV devel-20070312 04.13.2007  no virus found
DrWeb 4.33 04.13.2007  no virus found
eSafe 7.0.15.0 04.12.2007  no virus found
eTrust-Vet 30.7.3567 04.14.2007  no virus found
Ewido 4.0 04.13.2007  no virus found
FileAdvisor 1 04.14.2007  no virus found
Fortinet 2.85.0.0 04.14.2007  no virus found
F-Prot 4.3.2.48 04.13.2007  no virus found
F-Secure 6.70.13030.0 04.13.2007  no virus found
Ikarus T3.1.1.5 04.13.2007  no virus found
Kaspersky 4.0.2.24 04.14.2007  no virus found
McAfee 5009 04.13.2007  no virus found
Microsoft 1.2405 04.14.2007  no virus found
NOD32v2 2187 04.13.2007  no virus found
Norman 5.80.02 04.12.2007  no virus found
Panda 9.0.0.4 04.13.2007  no virus found
Prevx1 V2 04.14.2007  no virus found
Sophos 4.16.0 04.12.2007  no virus found
Sunbelt 2.2.907.0 04.14.2007  no virus found
Symantec 10 04.14.2007  no virus found
TheHacker 6.1.6.088 04.09.2007  no virus found
VBA32 3.11.3 04.13.2007  no virus found
VirusBuster 4.3.7:9 04.13.2007  no virus found
Webwasher-Gateway 6.0.1 04.13.2007 no virus found



Aditional Information
File size: 491603 bytes
MD5: 4e70ca362e9bb6bbfc4c810484e9c6d9
SHA1: f90c2a57dd337d3cc1ec16bb65ed74120ccb9925
packers: BINARYRES

"Those who are skilled in combat do not become angered, those who are skilled at winning do not become afraid. Thus the wise win before they fight, while the ignorant fight to win." Zhuge Liang

SpyDie

In which case, the logfile looks fine.

One thing I would try, is to remove the Ace Mega Codec's Pack completely and see if it helps.
Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'