Customer has Toshiba satellite notebook home xp.
Logfile of HijackThis v1.99.0
Scan saved at 2:38:02 PM, on 2/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
C:\WINDOWS\System32\CTSvcC
DA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSP
Sv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\00THot
key.exe
C:\toshiba\ivp\ism\pinger.
exe
C:\WINDOWS\System32\s3hotk
ey.exe
C:\WINDOWS\System32\S3Tray
2.exe
C:\WINDOWS\System32\TFNF5.
exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TouchED\Touc
hED.Exe
C:\WINDOWS\System32\TPWRTR
AY.EXE
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\kbdp1h
fm.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\Documents and Settings\Owner\Local Settings\temp\Temporary Directory 3 for hijackthis_199.zip\HijackT
his.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.toshiba.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
7DF180C71A
C} - C:\PROGRA~1\SPYWAR~1\tools
\iesdpb.dl
l
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THot
key.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.
exe /run
O4 - HKLM\..\Run: [S3Hotkey] s3hotkey.exe
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\Touc
hED.Exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [77ti39W] kbdp1hfm.exe
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
O4 - HKLM\..\RunServices: [NAV Auto Updates] navupdaters.exe
O4 - HKLM\..\RunServices: [Microsoft Registry Startup SCan] uhchfmi.exe
O4 - HKLM\..\RunServices: [Microsofts media] wingtp.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: PowerReg Scheduler.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
C56B4E14E8
4} - C:\PROGRA~1\SPYWAR~1\tools
\iesdpb.dl
l
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://www.toshiba.comO16 - DPF: Yahoo! NFL GameChannel StatTracker -
http://aud9.sports.sc5.yahoo.com/java/y/nflgcst1010_x.cabO23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcC
DA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMAN
T~1\SCRIPT
~1\SBServ.
exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
I have run stinger in safe mode. AVG free 7 in both safe and protected mode.
I have run ad-aware se free, counterspy, spyware doctor and spybot 1.3 all in both safe and protected modes. I have unchecked just about every thing in msconfig startup. I have installed free zonealarm. This HJT logfile is after about 6 hours of steady work. Please look at this and tell me am I clean yet. I have run analyse on the log at the german HJT web page. Thanx ......... I C U cq2