We rebuilt a new pc for a user, since she recieved the PC she has been getting all kinds of pop up's I will attatch the Hijack this Log, any help would be great!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:05:13 PM, on 4/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070816R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.dell.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Search,Default_Pa
ge_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070816R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - (no file)
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
Service\is
uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [Track-It! Workstation Manager Service Monitor] C:\WINDOWS\TIREMOTE\TIServ
iceMonitor
.exe
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\UPSNA1Msgr.exe
O4 - HKLM\..\Run: [BM6b700228] Rundll32.exe "C:\WINDOWS\system32\tkfxc
rqr.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSC
lientMsiTr
ans\tscuin
st.vbs" (User 'Default user')
O4 - Startup: Microsoft Office Outlook 2003.lnk = ?
O4 - Startup: printnow.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\WSTDMessaging.
exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminde
r.exe
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_05\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_05\bin
\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI1933~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00134F72-5284-44F7-95A8-5
2A619F7075
1} (ObjWinNTCheck Class) -
https://tlc23.sbs2003.local:4343/officescan/console/ClientInstall/WinNTChk.cabO16 - DPF: {08D75BB0-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) -
https://tlc23.sbs2003.local:4343/officescan/console/ClientInstall/setupini.cabO16 - DPF: {08D75BC1-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
https://tlc23.sbs2003.local:4343/officescan/console/ClientInstall/setup.cabO16 - DPF: {35C3D91E-401A-4E45-88A5-F
3B32CD72DF
4} (Encrypt Class) -
https://tlc23.sbs2003.local:4343/SMB/console/html/root/AtxEnc.cabO16 - DPF: {5EFE8CB1-D095-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) -
https://tlc23.sbs2003.local:4343/officescan/console/ClientInstall/RemoveCtrl.cabO16 - DPF: {7DD62E58-5FA8-11D2-AFB7-0
0104B64F12
6} (Sview Control) -
https://www.digitaldocs.cc/GetDocs/cab/svinstall_a_green.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = SBS2003.local
O17 - HKLM\Software\..\Telephony
: DomainName = SBS2003.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = SBS2003.local
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Trend Micro Security Server Master Service (ofcservice) - Trend Micro Inc. - C:\Program Files\Trend Micro\Security Server\PCCSRV\web\service\
ofcservice
.exe
O23 - Service: Track-It! Workstation Manager (TIRmtSvc) - Numara Software, Inc. - C:\WINDOWS\TIREMOTE\TIRemo
teService.
exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4
.exe
--
End of file - 6503 bytes
Start Free Trial