The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    HiJackThis Log File - Has my sister been keylogged?

    Discussion in 'Security and Anti-Virus Software' started by Asmodan, Nov 29, 2008.

  1. Asmodan

    Asmodan Notebook Consultant

    Reputations:
    20
    Messages:
    137
    Likes Received:
    0
    Trophy Points:
    30
    All -

    My sister has claimed as of the past 2 days that her machine is running unusually slow, and the system appears to hang from time to time. I told her to run her anti-virus program, defrag her hard-drive, and to remove any unused programs she isnt using anymore.

    She still is experiencing the same symptoms and this is concern as she did click on a link that brought up an open window that was blank..

    Here is her log file - please tell me she is ok... but if a re-format is the solution, then so be it.

    ** TEXT START**

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:21:18 AM, on 11/29/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Notebook Hardware Control\nhc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mmo-champion.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 4029 bytes

    ** TEXT END **
     
  2. entropy.cz

    entropy.cz Notebook Evangelist

    Reputations:
    110
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    i cannot see anything suspicious (maybe someone else will), so just one security question - does your sitster use at least the windows firewall? there is no FW logged in the HJT log, so in case that she does not use any, definitely tell her to install some (or switch on the windows one). in case that a keylogger tries to communicate, a firewall can catch the attempt.
     
  3. Asmodan

    Asmodan Notebook Consultant

    Reputations:
    20
    Messages:
    137
    Likes Received:
    0
    Trophy Points:
    30
    I'll ask and report back to you.
     
  4. Asmodan

    Asmodan Notebook Consultant

    Reputations:
    20
    Messages:
    137
    Likes Received:
    0
    Trophy Points:
    30
    It was not - I told her to Turn the Built in Firewall on. It is enabled. Do you need anything else?
     
  5. entropy.cz

    entropy.cz Notebook Evangelist

    Reputations:
    110
    Messages:
    386
    Likes Received:
    0
    Trophy Points:
    30
    hopefully someone else will have more ideas about the HJT log. (it seems to me that the log is kinda short, not containing all information for some reason, but i'm not really sure.)

    but regarding the system slowdown... when she displays the task manager (ctrl+alt+del, or rightclick on the taskbar), switches to the processes tab, which processes eat most CPU? (you can sort the processes by clicking on the CPU column header)
     
  6. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Posting a HiJackThis log on a more appropriate forum like Bleepingcomputer or MajorGeeks will get you an answer sooner.
    My guess is, this is the culprit; R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file).
    Either you can mark it and remove it with HiJackthis if you know how to or await an answer on one of the mentioned fora.
    Use an online scanner like the ones from Eset or F-Secure for a 2nd opinion scan, you can find them through my signature link.
    Cheers.
     
  7. zfactor

    zfactor Mastershake

    Reputations:
    2,894
    Messages:
    11,134
    Likes Received:
    3
    Trophy Points:
    455
    i recc the dr web scanner called cure it. but i agree that looks like the only possible line i see as well though i could also be wrong.
     
  8. Asmodan

    Asmodan Notebook Consultant

    Reputations:
    20
    Messages:
    137
    Likes Received:
    0
    Trophy Points:
    30
    Cleaned and fixed! Sister's computer is running at smoothly as it did before.

    Very odd..