jorgecs Posted April 23, 2005 Report Share Posted April 23, 2005 HelloI have 3 machines on a network of about 30 running XP pro sp2 that behave oddly when a network connection is active. MS Office applications take forever to load, when called by oppening a document in the Windows Explorer view. Also, some aplications like Notepad hang when I print, or when I try to configure print settings. The printer selection dialog box doesn't pop-up, the application hangs and the machine desktop takes forever to restore. In Outlook or Word, if I print from the print button the document gets printed, but if I print from the file menu Print, the applicattion hangs.This only happens when a network connectio is active. If I unplug the network cable or deactivate the network connection the machine resumes normal operation.I'm running AdAware, SpySweeper and Viruscan an all systems, but the problem persists even when AdAwre and SpySweeper are removed.VirusScan is also running on every machine on the network. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted April 23, 2005 Report Share Posted April 23, 2005 This does indeed sound malware related. Could you please post a HijackThis log for review? Quote Link to comment Share on other sites More sharing options...
jorgecs Posted April 26, 2005 Author Report Share Posted April 26, 2005 OK, here it isLogfile of HijackThis v1.99.1Scan saved at 1:01:15, on 26-04-2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\Programas\Software WIDCOMM\Bluetooth\bin\btwdins.exeC:\PROGRA~1\Iomega\System32\AppServices.exeC:\Programas\Network Associates\Common Framework\FrameworkService.exeC:\Programas\Network Associates\VirusScan\Mcshield.exeC:\Programas\Network Associates\VirusScan\VsTskMgr.exeC:\Programas\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\AGRSMMSG.exeC:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Programas\Alcatel\SpeedTouch USB\Dragdiag.exeC:\Programas\Network Associates\VirusScan\SHSTAT.EXEC:\Programas\Network Associates\Common Framework\UpdaterUI.exeC:\Programas\Synaptics\SynTP\SynTPLpr.exeC:\Programas\Synaptics\SynTP\SynTPEnh.exeC:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\Programas\QuickTime\qttask.exeC:\Programas\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exeC:\Programas\Nokia\Nokia PC Suite 6\Launch Application 2.exeC:\PROGRA~1\FTPSER~1\FTPSER~1.EXEC:\Programas\Ficheiros comuns\Nokia\NCLTools\NclTray.exeC:\WINDOWS\system32\ZCfgSvc.exeC:\WINDOWS\system32\ctfmon.exeC:\Programas\Microsoft ActiveSync\WCESCOMM.EXEC:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exeC:\Programas\Messenger\msmsgs.exeC:\PROGRA~1\FICHEI~1\PCSuite\DATALA~1\DATALA~1.EXEC:\Programas\Software WIDCOMM\Bluetooth\BTTray.exeC:\Programas\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exeC:\Programas\Nokia\PC Suite for Nokia 7650\connmngmntbox.exeC:\Programas\Nokia\PC Suite for Nokia 7650\ectaskscheduler.exeC:\Programas\WinZip\WZQKPICK.EXEC:\PROGRA~1\FICHEI~1\Nokia\MPAPI\MPAPI3s.exeC:\PROGRA~1\FICHEI~1\PCSuite\Services\SERVIC~1.EXEC:\PROGRA~1\Nokia\PCSUIT~2\Elogerr.exeC:\Programas\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exeC:\PROGRA~1\SOFTWA~1\BLUETO~1\BTSTAC~1.EXEC:\WINDOWS\System32\svchost.exeC:\PROGRA~1\Nokia\PCSUIT~2\BROADC~1.EXEC:\PROGRA~1\Nokia\PCSUIT~2\SCRFS.exeC:\WINDOWS\system32\wuauclt.exeC:\PROGRA~1\WINZIP\winzip32.exeC:\Documents and Settings\Eng. Dias da Costa\Definições locais\Temp\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.pt/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:9090 ftp=localhost:9093 https=localhost:9092 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost; 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = HiperligaçõesO1 - Hosts: 172.22.216.10 CibercaRO1 - Hosts: 200.54.87.10 aurecomO1 - Hosts: 172.22.217.11 serverntO1 - Hosts: 172.22.216.11 serversbsO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exeO4 - HKLM\..\Run: [Cpqset] C:\Programas\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -dO4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exeO4 - HKLM\..\Run: [ATIPTA] C:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Programas\Ficheiros comuns\Nokia\NCLTools\NCLConf.exe"O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Programas\Alcatel\SpeedTouch USB\Dragdiag.exe" /iconO4 - HKLM\..\Run: [shStatEXE] "C:\Programas\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programas\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exeO4 - HKLM\..\Run: [synTPLpr] C:\Programas\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Programas\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [WheelMouse] C:\WHEELM~1\wh_exec.exeO4 - HKLM\..\Run: [HP Lamp] "C:\Programas\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programas\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytrayO4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FICHEI~1\PCSuite\DATALA~1\DATALA~1.EXEO4 - HKLM\..\Run: [FTP Server] C:\PROGRA~1\FTPSER~1\FTPSER~1.EXEO4 - HKLM\..\Run: [Nokia Tray Application] C:\Programas\Ficheiros comuns\Nokia\NCLTools\NclTray.exeO4 - HKLM\..\Run: [iomega Automatic Backup 1.0.1] C:\Programas\Iomega\Iomega Automatic Backup\ibackup.exeO4 - HKLM\..\Run: [ZCfgSvc.exe] c:\WINDOWS\system32\ZCfgSvc.exeO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programas\Microsoft ActiveSync\WCESCOMM.EXE"O4 - HKCU\..\Run: [PcSync] C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialogO4 - HKCU\..\Run: [MSMSGS] "C:\Programas\Messenger\msmsgs.exe" /backgroundO4 - Startup: Iomega Product Registration.lnk = C:\Programas\Iomega\Registration\Register.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programas\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: BTTray.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet g series) - 1.lnk = C:\Programas\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: PCSuiteForNokia7650 Detect.lnk = ?O4 - Global Startup: PCSuiteForNokia7650 TS.lnk = ?O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXEO8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O8 - Extra context menu item: Enviar para &Bluetooth - C:\Programas\Software WIDCOMM\Bluetooth\btsendto_ie_ctx.htmO9 - Extra button: Criar favorito móvel - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programas\Microsoft ActiveSync\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programas\Microsoft ActiveSync\INetRepl.dllO9 - Extra 'Tools' menuitem: Criar favorito móvel... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programas\Microsoft ActiveSync\INetRepl.dllO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programas\Software WIDCOMM\Bluetooth\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programas\Software WIDCOMM\Bluetooth\btsendto_ie.htmO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exeO16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cabO16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall...oducts/vmp.htmlO16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - http://down.plaxo.com/down/release/PlaxoInstall.cabO16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocxO17 - HKLM\System\CCS\Services\Tcpip\..\{08F5AF71-A96A-49FE-98A3-6E9235CDC4E9}: NameServer = 62.48.131.10,62.48.131.11O17 - HKLM\System\CS1\Services\Tcpip\..\{08F5AF71-A96A-49FE-98A3-6E9235CDC4E9}: NameServer = 62.48.131.10,62.48.131.11O17 - HKLM\System\CS2\Services\Tcpip\..\{08F5AF71-A96A-49FE-98A3-6E9235CDC4E9}: NameServer = 62.48.131.10,62.48.131.11O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dllO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exeO23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Programas\Software WIDCOMM\Bluetooth\bin\btwdins.exeO23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exeO23 - Service: Serviço McAfee Framework (McAfeeFramework) - Unknown owner - C:\Programas\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart (file missing)O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Programas\Network Associates\VirusScan\Mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Programas\Network Associates\VirusScan\VsTskMgr.exeO23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Programas\Intel\NCS\Sync\NetSvc.exeO23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exeO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programas\Analog Devices\SoundMAX\SMAgent.exe Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.