Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old April 24th, 2005, 08:46 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
oddities with computer, inc HJT

Hello,

we have had some odd things happen with the machine the last couple of days. I think we had a trojan that was calling itself DrWatson32 which i seem to have got rid of. But it seems to randomly restart. not sure why.

I can't see anything in the log but if someone else could advise that would be appreciated.

Thanks


here is the log

Logfile of HijackThis v1.99.1
Scan saved at 14:43:08, on 24/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rmctrl.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\devldr32.exe
C:\Documents and Settings\Mum and Dad\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [Workflow] E:\Workflow.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.sc-server1.bt.com/broadband/MotivePreQual.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe



Thanks

Froggy

Reply With Quote
  #2  
Old April 26th, 2005, 06:40 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi RF!

Could you post a fresh log. The first one didn't look too bad.

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #3  
Old April 26th, 2005, 07:13 PM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Infernal Technomancer
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2005
Location: Centrally located far from everywhere
Posts: 950 Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Week 16 h 34 m 19 sec
Reputation Power: 92
Send a message via ICQ to Dngrsone Send a message via Yahoo to Dngrsone
DrWatson is a component of NT (therefore in WinXP) that is used for debugging. The fact that you see it means you have a software error serious enough to invoke the debugger yet not dangerous enough to crash the OS.

I see you switched from Norton AV to AVG... good move, though you still have a couple Symantic modules you should get rid of:

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

Go into System Properties and turn off Restart on Error and see what you get in the way of BSODs.

Reply With Quote
  #4  
Old April 27th, 2005, 07:49 AM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Quote:
Originally Posted by Dngrsone
I see you switched from Norton AV to AVG... good move, though you still have a couple Symantic modules loading on startup you should get rid of:

[size=1][color=Green]O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

Hi Dngrsone,

The 016's are not startup entries. The are ActiveX objects (downloaded program files) that were used when Norton was in use on this system. It's true they should be fixed, but they are not startups.

Tom

Reply With Quote
  #5  
Old April 27th, 2005, 10:56 AM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Infernal Technomancer
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2005
Location: Centrally located far from everywhere
Posts: 950 Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Week 16 h 34 m 19 sec
Reputation Power: 92
Send a message via ICQ to Dngrsone Send a message via Yahoo to Dngrsone
Thanks, Tom. Edited my statement appropriately.

Reply With Quote
  #6  
Old April 27th, 2005, 11:09 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
oh i see, i misread the symantec report on it.

ok, i will get rid of those. symantec doobries.

I can't post a new log right now as i am not at that machine. But i will when i am next there.

If i turn off the restart on error will i get BSOD's then? do i really want that as i have had some that i can't recover from....

thanks for your replies.

RF

Reply With Quote
  #7  
Old April 27th, 2005, 11:22 AM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Infernal Technomancer
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2005
Location: Centrally located far from everywhere
Posts: 950 Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Week 16 h 34 m 19 sec
Reputation Power: 92
Send a message via ICQ to Dngrsone Send a message via Yahoo to Dngrsone
I prefer to see the BSOD because it will generally tell me what program/module is having a fit... playing guessing games every time the computer restarts is not the most efficient way of doing business.

Reply With Quote
  #8  
Old April 27th, 2005, 11:32 AM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
sleeping guru
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Feb 2003
Location: under the stars
Posts: 2,444 RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)RadioactiveFrog User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1Folding Points: 158091 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 6 Days 6 h 18 m 28 sec
Reputation Power: 171
Send a message via MSN to RadioactiveFrog
Quote:
Originally Posted by Dngrsone
I prefer to see the BSOD because it will generally tell me what program/module is having a fit... playing guessing games every time the computer restarts is not the most efficient way of doing business.

mmmm, fair point. I will have a play when i am next at the machine and see if i can figure anything out. Is there any other way of knowing? ie is a log produced when it restarts?

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > oddities with computer, inc HJT


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |