Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Keeza

Pages: [1]
1
Tech Clinic / coolwwwsearch leftover (again) ;(
« on: March 11, 2005, 05:12:19 AM »
ok thankx..
here is DLLCompare log:


*    DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

O^E says: "There were no files found http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />"
________________________________________________

1,249 items found:  1,249 files, 0 directories.
Total of file sizes:  246,301,550 bytes    234.89 M

Administrator Account =  True

--------------------End log---------------------



i guess thats good ... here is StartDreck Log:

StartDreck (build 2.1.7 public stable) - 2005-03-11 @ 11:08:03 (GMT +01:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 1)
Internet Explorer: 6.0.2800.1106
Logged in as HH

»Registry
 »Run Keys
  »Current User
   »Run
    *CTFMON.EXE=C:\WINDOWS\System32\ctfmon.exe
    *MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
   »RunOnce
  »Default User
   »Run
    *CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
   »RunOnce
  »Local Machine
   »Run
    *NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
    *C-Media Mixer=Mixer.exe /startup
    *APVXDWIN="D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
    *QuickTime Task="D:\movie stuff\QuickTime\qttask.exe" -atboottime
    *EPSON Stylus CX3200=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
    *zafit=C:\WINDOWS\zafit.exe
    *SunJavaUpdateSched=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    *WinFoxV2=C:\WINDOWS\System32\WF2K.EXE Initial
    *WinFast2KLoadDefault=rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
    *SoundMan=SOUNDMAN.EXE
    *nwiz=nwiz.exe /install
    *NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    *NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    *sp=rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
    +OptionalComponents
     +MSFS
      *Installed=1
     +MAPI
      *Installed=1
      *NoChange=1
     +MAPI
      *Installed=1
      *NoChange=1
   »RunOnce
   »RunServices
   »RunServicesOnce
   »RunOnceEx
   »RunServicesOnceEx
 »Browser Helper Objects (LM)
  *{4613BB30-5B2F-40FD-AC33-E6661DB18062}
   `InprocServer32=C:\WINDOWS\System32\colg.dll
»Files
»System/Drivers
 »Running Processes
  +0=<idle>
  +4=<system>
  +600=\SystemRoot\System32\smss.exe
  +672=\??\C:\WINDOWS\system32\csrss.exe
  +696=\??\C:\WINDOWS\system32\winlogon.exe
  +740=C:\WINDOWS\system32\services.exe
  +752=C:\WINDOWS\system32\lsass.exe
  +936=C:\WINDOWS\system32\svchost.exe
  +1024=C:\WINDOWS\System32\svchost.exe
  +1140=C:\WINDOWS\System32\svchost.exe
  +1216=C:\WINDOWS\System32\svchost.exe
  +1416=C:\WINDOWS\system32\spoolsv.exe
  +1428=C:\WINDOWS\Explorer.EXE
  +1560=C:\WINDOWS\Mixer.exe
  +1628=D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
  +1660=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
  +1668=C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
  +1684=C:\WINDOWS\System32\WF2K.EXE
  +1712=C:\WINDOWS\SOUNDMAN.EXE
  +1732=C:\WINDOWS\System32\RUNDLL32.EXE
  +1764=C:\WINDOWS\System32\rundll32.exe
  +1772=C:\WINDOWS\System32\ctfmon.exe
  +1992=C:\WINDOWS\System32\alg.exe
  +2008=D:\Maya 6\docs\Wrapper.exe
  +2028=C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
  +2040=C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
  +224=C:\WINDOWS\System32\nvsvc32.exe
  +228=C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
  +408=D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
  +872=D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
  +976=C:\WINDOWS\System32\svchost.exe
  +1000=C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
  +1280=D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
  +1324=D:\Maya 6\docs\jre\bin\java.exe
  +2412=D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
  +1832=D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
  +2328=C:\WINDOWS\regedit.exe
  +2348=C:\Program Files\Internet Explorer\iexplore.exe
  +3508=C:\Documents and Settings\Henrik & Hilde\Desktop\eugen\startdreck\StartDreck.exe
»Application specific


and here is the hijackthis log i got afterwards...

Logfile of HijackThis v1.99.1
Scan saved at 11:09:21, on 11-03-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\WF2K.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Maya 6\docs\Wrapper.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Misc Apps\Panda Anti-Virus\AVENGINE.EXE
D:\Maya 6\docs\jre\bin\java.exe
D:\Misc Apps\Panda Anti-Virus\WebProxy.exe
D:\Misc Apps\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Henrik & Hilde\Local Settings\Temp\Temporary Directory 3 for hijackthis_199.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {4613BB30-5B2F-40FD-AC33-E6661DB18062} - C:\WINDOWS\System32\colg.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [APVXDWIN] "D:\Misc Apps\Panda Anti-Virus\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "D:\movie stuff\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [zafit] C:\WINDOWS\zafit.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinFoxV2] C:\WINDOWS\System32\WF2K.EXE Initial
O4 - HKLM\..\Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\HENRIK~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft\Office XP\Office10\OSA.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O18 - Filter: text/html - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O18 - Filter: text/plain - {DE0003E3-BD1E-48ED-92D8-E429CE14996A} - C:\WINDOWS\System32\colg.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Maya 6\docs\Wrapper.exe" -s "D:\Maya 6\docs/Wrapper.conf (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Misc Apps\Panda Anti-Virus\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Misc Apps\Panda Anti-Virus\PsImSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe




thank you so much for your help....
Looking forward to your answer..

Keeza

Pages: [1]