| | | New Member
         
Group: Forum Members Last Login: 12/14/2003 11:11 PM Posts: 1, Visits: 1 |
| Hi All, i just registered today Dec 15, should really be studying for my final right now, but it's just that my computer keeps shutting off by itself, sometimes reboot, sometimes sleep mode... i read some of the posts from this website and downloaded myself Hijackthis program... but i really don't know what the scan result says... could someone who understands the language please help me diagnose my computer for me? the following is the log:
Logfile of HijackThis v1.97.7 Scan saved at 12:01:23 AM, on 12/15/2003 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\sm56hlpr.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\system32\crypserv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\Program Files\Common Files\Symantec Shared\NMain.exe C:\PROGRA~1\NORTON~1\navw32.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\KenC\LOCALS~1\Temp\Rar$EX60.875\HijackThis.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 2\LMonitor.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Save Web Page (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst3_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab O16 - DPF: {6F7864F9-DB33-11D3-8166-0060B0F885E6} (VSPTA Class) - https://www.applyforproducts.cibc.com/certenroll/VSApps/vspta3.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37969.8586921296 O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4302/mcfscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{81B1CB2E-804E-4E1D-80E1-0254B6CE9A5F}: NameServer = 206.47.244.133 207.236.176.27
i know it's alot of complicated readings... i am really sorry to bother you guys with my problems... however, i really do appreciate if someone could help me!
if you'd like, you could email me at kenthecatmanATsympatico.ca (replace AT with @) ,<edited by BD>and let me know of your analysis result, Thank you! |
| | | | 
Senior Forum Advisor
         
Group: Senior Advisor Last Login: 12/4/2005 12:31 AM Posts: 4,743, Visits: 5 |
| Log looks fine.
you need to get the machine to stop restarting on errors so that you can get a BSOD and error message. Go to system properties (right click MyComputer > properties) > Advanced tab > under startup and recovery click settings > under System failure make sure "Write an event to the system log" is checked AND that "Automatically restart" is UNchecked. Click "OK" and reboot.
When you get your next BSOD, write down the entire STOP message. You can post it here for help and/or check it at this resource. http://aumha.org/win5/kbestop.htm
Cheers
|
| | | | 
Junior Member
         
Group: Forum Members Last Login: 9/2/2006 3:10 PM Posts: 183, Visits: 3 |
| Hi,Bulldog I been studying this highjack thread trying to learn from you how to read hijack logs ,very compulated ,I don't know how you can remember everything ,anyway i did a search on this C:\WINDOWS\System32\devldr32.exe from the above log and this is what i found ,http://www.sysinfo.org/startuplist.php?filter=devldr32.exe&count=100&type= ,not trying to be smart just learning ,was wondering if the same .EXE cam mean different things i know the log doesent say any thing about the Divie codex as startup name .Thanks sorry to bothere you and to butin to the post .Just wondering !!
Take The Long Way Home It's More Fun ! |
| | | | 
Senior Forum Advisor
         
Group: Senior Advisor Last Login: 12/4/2005 12:31 AM Posts: 4,743, Visits: 5 |
| Hi Caperjack, not a problem. I am doing a lot of these logs and you get used to seeing the bad ones. I help moderate with TonyKlien at a couple other security sites and am involved in the expert section at SpywareInfo/TomCoyote sites. There is an ongoing classroom for people interested in learning how to read these logs and help out fixing them. There have been a couple members from here join up, lots of newbies and experts alike are involved. If interested I can forwrd you instructions and links.
As for the devldr32.exe file... yes it can be a nastie, although in this case we do not see a startup entry for it. The page/link you referenced , points out that the startup would show as Divx4 codec.
If you were to check this link and look up that process.. http://www.answersthatwork.com/Tasklist_pages/tasklist_d.htm you will see it is associated with Creative Labs/soundblaster. And from the above log we can see that the poster has that hardware installed. This startup also indicates so: O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
So, to the point . If it was viral, it would have an associated startup entry. mainly.. O4 - HKLM\..\Run: [Divx4 codec] <path to file>\devldr32.exe
Cheers.
Cheers
|
| | | | 
Junior Member
         
Group: Forum Members Last Login: 9/2/2006 3:10 PM Posts: 183, Visits: 3 |
| Thank you ,don't have time for any serious learning ,will just keep reading and learning in here.
Take The Long Way Home It's More Fun ! |
| |
|
|