Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old October 30th, 2006, 11:42 AM
ran_dizolph's Avatar
ran_dizolph ran_dizolph is offline
from the lab...
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2004
Location: the land of wind and ghosts
Posts: 1,591 ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 38 m 19 sec
Reputation Power: 143
Windows 2000 acting up

hey all,

k, as of late my computer's been running a little strangely...just not running very smooth.

as of this morning, photoshop 7 won't open up. it was fine when i left here friday.

i ran a chkdsk repair from the recovery console, did an anti-virus scan in safemode (which didn't turn anything up), and ran some anti-spy/mal/ad ware scanners, which didn't show anything out of the ordinary.

so, i ran hijackthis, and here's what i got...if anyone could shed a little light on this, it'd be greatly appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 11:35:32 AM, on 10/30/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\mysql\bin\winmysqladmin.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HighJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.graphixplus.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {EEA8A033-84D3-4CA9-9C12-3697347D0FD3} (Web Conferencing Pro Application Sharing Control) - http://onsitepro.theconferencedepot.com/atc/signedshare-plugin_1,32,0,51.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O17 - HKLM\System\CS2\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)

Reply With Quote
  #2  
Old October 30th, 2006, 11:52 AM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
I've had a quick look over you log, and there a few items that could do with a tidy up, but nothing that would cause you many problems. What happens when you try to boot up Photoshop 7 ? Is your machine just running generally sluggish ? Have you checked your task manager to see if any processes are eating up the cpu?
__________________
The No Ma'am commandments:

1.) It is O.K. to call hooters 'knockers' and sometimes snack trays
2.) It is wrong to be French
3.) It is O.K. to put all bad people in a giant meat grinder
4.) Lawyers, see rule 3
5.) It is O.K. to drive a gas guzzler if it helps you get babes
6.) Everyone should car pool but me
7.) Bring back the word 'stewardesses'
8.) Synchronized swimming is not a sport
9.) Mud wrestling is a sport

Reply With Quote
  #3  
Old October 30th, 2006, 12:00 PM
ran_dizolph's Avatar
ran_dizolph ran_dizolph is offline
from the lab...
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2004
Location: the land of wind and ghosts
Posts: 1,591 ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 38 m 19 sec
Reputation Power: 143
Hey,

my computer's not really running slowly or anything...checked the task manager out, and nothing seems to be using the cpu.

photoshops opening screen comes up while it loads plugins etc., but then just disapeers.

other adobe applications are running fine.

Reply With Quote
  #4  
Old October 30th, 2006, 12:05 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
Can you reboot your machine and see if the application then loads ?

Just out of curiosity, how many printers do you have access to?

Reply With Quote
  #5  
Old October 30th, 2006, 12:10 PM
ran_dizolph's Avatar
ran_dizolph ran_dizolph is offline
from the lab...
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2004
Location: the land of wind and ghosts
Posts: 1,591 ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 38 m 19 sec
Reputation Power: 143
i rebooted right after i found the problem...then re-installed it after it didn't work.

same thing.

i've got 3 printers (Ricoh aficio, pdf factory pro (not actually a printer), and LAN-fax). they're all technically thru the ricoh tho.

thanks.

Reply With Quote
  #6  
Old October 30th, 2006, 12:49 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
Has your default printer changed ? If so, change it back.

Recently, I had an issue with machines where the default printer had changed and it wouldn't totally open up an application (namely Word).

Reply With Quote
  #7  
Old October 30th, 2006, 01:33 PM
ran_dizolph's Avatar
ran_dizolph ran_dizolph is offline
from the lab...
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2004
Location: the land of wind and ghosts
Posts: 1,591 ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 38 m 19 sec
Reputation Power: 143
nope, hasn't changed at all.

what items could use a tidying up on my list there?

thanks!

Reply With Quote
  #8  
Old October 30th, 2006, 01:45 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,549 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 11 h 6 m 9 sec
Reputation Power: 1953
Run HJT again, check the following items and then select 'Fix':

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)


Once you have done so, please re-boot your machine and post a fresh HJT log for us to look at. As I said before though, there wasn't much contained in your log and these are just a tidy-up.

When did you install Google Desktop Search ?

Reply With Quote
  #9  
Old October 30th, 2006, 01:59 PM
ran_dizolph's Avatar
ran_dizolph ran_dizolph is offline
from the lab...
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2004
Location: the land of wind and ghosts
Posts: 1,591 ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level)ran_dizolph User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 38 m 19 sec
Reputation Power: 143
k, did what you suggested (except for the apache one...will that not kill the server?)

here are the results;

Logfile of HijackThis v1.99.1
Scan saved at 1:53:43 PM, on 10/30/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\mysql\bin\winmysqladmin.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HighJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.graphixplus.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {EEA8A033-84D3-4CA9-9C12-3697347D0FD3} (Web Conferencing Pro Application Sharing Control) - http://onsitepro.theconferencedepot.com/atc/signedshare-plugin_1,32,0,51.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O17 - HKLM\System\CS2\Services\Tcpip\..\{0EED4D64-A50C-4093-9015-CC2225061AB1}: NameServer = 192.168.3.100,206.48.122.8
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)

i installed google desktop quite a while ago...'spose i could get rid of it.

thanks for the help thus far.

Reply With Quote
  #10  
Old October 30th, 2006, 02:07 PM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
It wont kill the server as its pointing to a file that doesnt exist any more (note the "file missing" at the end).

Did you update the antivirus and spyware tools before scanning?

Have a look in the event logs & see if anything relevant is coming up.

When you run photoshop and it stops halfway through loading, can you see the photoshop exe in the task manager?

Displeaser
__________________
Vi Veri Veniversum Vivus Vici.

Reply With Quote
  #11