7Priest7 Posted November 15, 2007 Report Share Posted November 15, 2007 http://www.walmart.com/catalog/product.do?product_id=5946677^ Specs of machineI am running Windows Vista Home BasicHere is a hijackthis log...Logfile of HijackThis v1.99.1Scan saved at 6:19:47 AM, on 11/15/2007Platform: Unknown Windows (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16386)Running processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Windows Defender\MSASCui.exeC:\Windows\System32\s3trayp.exeC:\Program Files\Apoint2K\Apoint.exeC:\Program Files\Motorola\SMSERIAL\sm56hlpr.exeC:\Program Files\COMODO\Firewall\cfp.exeC:\Program Files\Alwil Software\Avast4\ashDisp.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\tinySpell\tinyspell.exeC:\Program Files\CyberBuddy\CyberBud.exeC:\Users\Priest.Priests-PC\Documents\PopTray\PopTray.exeC:\Program Files\Palm\Hotsync.exeC:\Program Files\PeoplePC\ISP6200\Browser\Bartshel.exeC:\Program Files\OpenOffice.org 2.2\program\soffice.exeC:\Program Files\OpenOffice.org 2.2\program\soffice.BINC:\Program Files\Apoint2K\Apntex.exeC:\Program Files\PeoplePC\ISP6200\Browser\PPShared.exeC:\Program Files\Internet Explorer\ieuser.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Users\Priest.Priests-PC\AppData\Local\Temp\Temp1_hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/searchR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.everex.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/searchR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [s3Trayp] S3trayp.exeO4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VistaADeck\HDAudioCPL.exe 1O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exeO4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exeO4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -sO4 - HKLM\..\Run: [bart Station] C:\Program Files\PeoplePC\ISP6200\BIN\PPCOLink.exe -STATIONO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [tinySpell] C:\Program Files\tinySpell\tinyspell.exeO4 - Startup: HotSync Manager.lnk = ?O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exeO4 - Global Startup: CyberBuddy.lnk = C:\Program Files\CyberBuddy\CyberBud.exeO4 - Global Startup: PopTray.lnk = C:\Users\Priest.AlexanderLeonnS\Documents\PopTray\PopTray.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dllO11 - Options group: [iNTERNATIONAL] International*O13 - Gopher Prefix: O17 - HKLM\System\CCS\Services\Tcpip\..\{8C574CEC-6E73-46F7-A18F-0EF38AA8246E}: NameServer = 209.244.0.3 209.244.0.4O17 - HKLM\System\CS1\Services\Tcpip\..\{8C574CEC-6E73-46F7-A18F-0EF38AA8246E}: NameServer = 209.244.0.3 209.244.0.4O20 - AppInit_DLLs: C:\Windows\system32\guard32.dllO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exeO23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exeO23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)Now to exactley what happens...I run the updater program.It gets the updates.It restarts.It takes an hour or more to configure them :(Why does it take so long?Are there any fixes?Please and Thank YouAlex Link to comment Share on other sites More sharing options...
andsome Posted November 15, 2007 Report Share Posted November 15, 2007 No one on here reads Hijack This scans now.Best to register on this forum. Link to comment Share on other sites More sharing options...
7Priest7 Posted November 16, 2007 Author Report Share Posted November 16, 2007 No one on here reads Hijack This scans now.Best to register on this forum.Firstly it is NOT malware...It has to be Vista...The only reason I put the HiJackThis is, in case it is a program that does not like vista...I put the HiJackThis for people who are capable of responding intelligently!If you were intelligent enough to read my post you would see comodo.exe(firewall) teatimer.exe(shield to prevent malware) and ashdisp.exe(Virus shield)Now...Is there a fix to this Vista problem or not?Please and Thank YouAlexP.S. You are the reason I like to ask questions at the ubuntu forums...Linux users seem to be way more tech savvy Link to comment Share on other sites More sharing options...
mark2 Posted November 17, 2007 Report Share Posted November 17, 2007 7Priest7I run the updater program.It gets the updates.It restarts.It takes an hour or more to configure themWhich are classic symptoms of malware.You don't state which updater, I'm guessing windows update but you haven't been specific.You also have a number of lines with reference to files missing such asO23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)The only persons likely to know whether those lines are relevant to the problem, are those who do regularly check for malware and know how to correctly interpret a Hijackthis log, such as the experts at the malware forums. Link to comment Share on other sites More sharing options...
andsome Posted November 17, 2007 Report Share Posted November 17, 2007 No one on here reads Hijack This scans now.Best to register on this forum.Firstly it is NOT malware...It has to be Vista...The only reason I put the HiJackThis is, in case it is a program that does not like vista...I put the HiJackThis for people who are capable of responding intelligently!If you were intelligent enough to read my post you would see comodo.exe(firewall) teatimer.exe(shield to prevent malware) and ashdisp.exe(Virus shield)Now...Is there a fix to this Vista problem or not?Please and Thank YouAlexP.S. You are the reason I like to ask questions at the ubuntu forums...Linux users seem to be way more tech savvyThere is NO NEED whatsoever to come on the forum and be extremely rude. I saw the hijack this log and automatically directed you to a forum where people are qualified to read these logs. I don't think that you are going the right way about things if you expect people to help you. So, it seems that I am not intelligent enough for you, I would suggest that you are not intelligent enough to be polite to those who offer help. Why not visit one of these forums where everyone is so intelligent and tech savvy as you call it. All of us on here are intelligent and 'tech savvy' enough to know that a firewall and Anti Malware programs DO NOT guarantee freedom from Malware. These programs are only as effective as their latest update, and can easily fall behind the Malware writers. Link to comment Share on other sites More sharing options...
AlanHo Posted November 17, 2007 Report Share Posted November 17, 2007 andsome - I must congratulate you on your restraint. It beggars belief that people expect to be helped when they are so arrogant and rude. Link to comment Share on other sites More sharing options...
-pops- Posted November 17, 2007 Report Share Posted November 17, 2007 I'm closing this for obvious reasons. Link to comment Share on other sites More sharing options...
Recommended Posts