Author Topic: hey quest could ya have a look  (Read 333 times)

Offline sheepmaster

  • Sr. Member
  • ****
  • Posts: 463
  • Karma: +0/-0
    • View Profile
hey quest could ya have a look
« on: December 12, 2008, 06:40:17 PM »
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:29:49 AM, on 1/8/1980
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LEXBCES.EXE
C:\Windows\system32\spoolsv.exe
C:\Windows\system32\LEXPPS.EXE
C:\Windows\System32\PackethSvc.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Windows\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Windows\system32\lxdccoms.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\System32\snmp.exe
C:\Windows\system32\mqsvc.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\mqtgsvc.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Windows\system32\atiptaxx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\javaw.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [SprintModemUpdate] javaw.exe -cp "C:\Program Files\Motive\FirmwareUpdater\lib\SprintModemUpdate.jar" com.motive.firmwareUpdater.client.SprintModemUpdate
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\Windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Qwest Live - {0E0A4DC9-4BDF-474D-93FF-CE6C692EFA2A} - http://qwest.live.com (file missing) (HKCU)
O9 - Extra button: Advisor - {FB602155-A965-424E-98C0-DABE71C066FF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {596AF4AC-40A0-474A-9F86-33F0A90F0FD6} (PictureItLauncher Class) - http://photos.msn.com/resources/neutral/co...ls/DigWebX2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?3471575220038
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://admin.pressplay.com/duet/registration/isetup.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v46/sol/sol.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://wwemail.support.hp.com/fd2/objects/SysQuery.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\Windows\System32\Ati2evxx.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Compaq Remote Diagnostics Enabling Agent (CpqDfwWebAgent) - Compaq Computer Corporation - C:\Windows\Cpqdiag\Cpqdfwag.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\system32\LEXBCES.EXE
O23 - Service: lxdc_device -   - C:\Windows\system32\lxdccoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\Windows\System32\PackethSvc.exe

--
End of file - 8992 bytes
[color=\"#ffa500\"]TRADES

[/color]

-trade 2 pure accs for a lvl 93 to~f tickle squeez~[color=\"#ff0000\"]unsuccessful[/color], it got hacked back a few days later



-traded an 86 main for a skiller and a 20 def pure to slingshot911~[color=\"#008000\"]successful[/color]



[color=\"#00ff00\"]FREEBIES

[/color]

-got a lvl 31 str pure from~str killz you~SUCCESSFUL! =p



[color=\"pink\"]MM's[/color]

[color=\"red\"]SCAMMERS[/color]



-azn





-f tickle squeez





[color=\"#0000ff\"]TRUSTED

[/color]

-nobody.





-



[color=\"#9932cc\"]vouches[/color][/size]





-slingshot911



-


Offline sheepmaster

  • Sr. Member
  • ****
  • Posts: 463
  • Karma: +0/-0
    • View Profile
hey quest could ya have a look
« Reply #1 on: December 13, 2008, 02:06:26 AM »
bump
[color=\"#ffa500\"]TRADES

[/color]

-trade 2 pure accs for a lvl 93 to~f tickle squeez~[color=\"#ff0000\"]unsuccessful[/color], it got hacked back a few days later



-traded an 86 main for a skiller and a 20 def pure to slingshot911~[color=\"#008000\"]successful[/color]



[color=\"#00ff00\"]FREEBIES

[/color]

-got a lvl 31 str pure from~str killz you~SUCCESSFUL! =p



[color=\"pink\"]MM's[/color]

[color=\"red\"]SCAMMERS[/color]



-azn





-f tickle squeez





[color=\"#0000ff\"]TRUSTED

[/color]

-nobody.





-



[color=\"#9932cc\"]vouches[/color][/size]





-slingshot911



-


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
hey quest could ya have a look
« Reply #2 on: December 13, 2008, 02:16:50 AM »
Looks good, any problems?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline sheepmaster

  • Sr. Member
  • ****
  • Posts: 463
  • Karma: +0/-0
    • View Profile
hey quest could ya have a look
« Reply #3 on: December 13, 2008, 12:46:52 PM »
i just put in new ram, the computer is starting up faster but it's still running slow, any suggestions?
[color=\"#ffa500\"]TRADES

[/color]

-trade 2 pure accs for a lvl 93 to~f tickle squeez~[color=\"#ff0000\"]unsuccessful[/color], it got hacked back a few days later



-traded an 86 main for a skiller and a 20 def pure to slingshot911~[color=\"#008000\"]successful[/color]



[color=\"#00ff00\"]FREEBIES

[/color]

-got a lvl 31 str pure from~str killz you~SUCCESSFUL! =p



[color=\"pink\"]MM's[/color]

[color=\"red\"]SCAMMERS[/color]



-azn





-f tickle squeez





[color=\"#0000ff\"]TRUSTED

[/color]

-nobody.





-



[color=\"#9932cc\"]vouches[/color][/size]





-slingshot911



-


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
hey quest could ya have a look
« Reply #4 on: December 13, 2008, 12:51:57 PM »
Did you add more Ram, or put the equivalent amount in?

There may be some items you can disable on startup, but nothing malicious

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline sheepmaster

  • Sr. Member
  • ****
  • Posts: 463
  • Karma: +0/-0
    • View Profile
hey quest could ya have a look
« Reply #5 on: December 13, 2008, 09:33:58 PM »
i added more ram, i dunno just seems a bit slow.
[color=\"#ffa500\"]TRADES

[/color]

-trade 2 pure accs for a lvl 93 to~f tickle squeez~[color=\"#ff0000\"]unsuccessful[/color], it got hacked back a few days later



-traded an 86 main for a skiller and a 20 def pure to slingshot911~[color=\"#008000\"]successful[/color]



[color=\"#00ff00\"]FREEBIES

[/color]

-got a lvl 31 str pure from~str killz you~SUCCESSFUL! =p



[color=\"pink\"]MM's[/color]

[color=\"red\"]SCAMMERS[/color]



-azn





-f tickle squeez





[color=\"#0000ff\"]TRUSTED

[/color]

-nobody.





-



[color=\"#9932cc\"]vouches[/color][/size]





-slingshot911



-


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
hey quest could ya have a look
« Reply #6 on: December 14, 2008, 03:07:47 AM »
Try the following, see if it helps a bit
Right click on MyComputer>>Select Properties
Click the ADVANCED tab>>Select SETTINGS under PERFORMANCE>>Again select ADVANCED
Click on CHANGE under VIRTUAL MEMORY
Select the Radio button>>"System Managed size"
Click on SET>>APPLY>>OK
Reboot the computer and see if it's any help

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here