Have recently removed two vav.exe files, which seems to have eliminated the Vista Anti-virus problem I picked up yesterday but I now get pop-ups and weird behavior, such as adds occupying full Google Tabs, and asian characters covering Gmail messages. Does the following hijack this log tell anything?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:10:33 AM, on 7/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATMsg.exe
C:\WINDOWS\system32\cisvc.
exe
C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATSERVER.EXE
C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATSPOOL.EXE
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.e
xe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.ex
e
C:\PROGRA~1\McAfee\MANAGE~
1\VScan\Mc
Shield.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntf
y.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\X1\X1FileMonitor.exe
C:\Program Files\Meeting Center\Modules\Launcher\mc
Launcher.e
xe
C:\Program Files\Picasa2\PicasaMediaD
etector.ex
e
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\X1\X1.exe
C:\WINDOWS\System32\svchos
t.exe
C:\program files\x1\X1Systray.exe
C:\Program Files\X1\X1Service.exe
C:\PROGRA~1\MICROS~3\Offic
e10\OUTLOO
K.EXE
C:\Program Files\Meeting Center\Modules\Calendar\Ad
dInMon.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EX
E
C:\Program Files\Pluck Corporation\Pluck\PluckSvr
.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\WINDOWS\system32\cidaem
on.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://www.managingautomation.com/maonline/news/read/12868R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [Miramar Systems, Inc.] C:\Program Files\Miramar\PC MACLAN for Windows 2000\atmsg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanman
wrk.exe clean
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [880e9e6d] rundll32.exe "C:\WINDOWS\system32\ptcrd
hql.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [X1FileMonitor.exe] C:\Program Files\X1\X1FileMonitor.exe
O4 - HKCU\..\Run: [MeetingLauncher] "C:\Program Files\Meeting Center\Modules\Launcher\mc
Launcher.e
xe"
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD
etector.ex
e
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'Default user')
O4 - Startup: X1.lnk = C:\Program Files\X1\X1.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Pluck - {053017A8-53F7-4EA3-AA38-A
4CCAAF1F9E
7} - C:\Program Files\Pluck Corporation\Pluck\PluckExp
lorerBar.d
ll
O9 - Extra 'Tools' menuitem: Pluck - {053017A8-53F7-4EA3-AA38-A
4CCAAF1F9E
7} - C:\Program Files\Pluck Corporation\Pluck\PluckExp
lorerBar.d
ll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~3\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsth
elper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-4
76512BBC33
6} (UploadListView Class) -
http://picasaweb.google.com/s/v/34.03/uploader2.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111683571281O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153403416787O16 - DPF: {975F9329-0F5F-48D2-ADF8-A
EFB19DEFB5
F} (ZohoMeeting Control) -
http://meeting.zoho.com/login/Agent.jspO16 - DPF: {BC0E239B-6C7E-4812-B766-2
A50300E189
5} (RTC_20061001.RTC) -
http://www.buyautomation.com/RTC/Install/invRTC.CABO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://xo.webex.com/client/v_mywebex-t20/webex/ieatgpc.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{E
C6E1D82-3C
C7-43F3-8D
02-95F5BC7
9F2A2}: NameServer = 65.106.1.196,65.106.7.196
O18 - Protocol: pluck - {A5DD5FEC-8239-4A12-B791-4
B6067F85CC
C} - C:\Program Files\Pluck Corporation\Pluck\PluckExp
lorerBar.d
ll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sg
ag.exe
O23 - Service: AppleTalk Messenger (ATMsg) - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATMsg.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Journyx Timesheet (journyxtimesheet) - Unknown owner - C:\PROGRA~1\Journyx\jwt\ti
mesheet\Ti
mesheetSer
vice.exe (file missing)
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~
1\VScan\Mc
Shield.exe
O23 - Service: Miramar AppleTalk File Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATSERVER.EXE
O23 - Service: Miramar AppleTalk Print Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN for Windows 2000\ATSPOOL.EXE
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.e
xe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\
DRIVERS\W3
2X86\3\HPZ
ipm12.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.ex
e
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/JOHNNE
~1/LOCALS~
1/Temp/mso
html1/01/c
lip_image0
02.jpg
--
End of file - 8714 bytes
Start Free Trial