﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / HijackThis Log / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sat, 04 Jul 2009 18:48:30 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: HijackThis Log</title><link>http://tweaks.com/forum/Topic239304-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;[b]Viewpoint Manager[/b] is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". &lt;br&gt;Read this article: &lt;br&gt;[url]http://www.clickz.com/news/article.php/3561546[/url]&lt;br&gt;You are well advised to remove the program now. &lt;br&gt;Go to Start &gt; Settings &gt; Control Panel &gt; Add/Remove Programs and remove the following programs if present,then restart your pc:&lt;br&gt;[b]Viewpoint&lt;br&gt;Viewpoint Toolbar&lt;br&gt;Viewpoint Manager&lt;br&gt;Viewpoint Media Player[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Click on Start&gt;Control Panel&gt;Add/Remove Programs.&lt;br&gt;Uninstall/remove any of the following programs if listed:&lt;br&gt;[b]Messenger Plus! Live &amp; Sponsor (CiD)&lt;br&gt;Netpumper&lt;br&gt;Get-Torrent&lt;br&gt;Bitroll&lt;br&gt;Bitgrabber&lt;br&gt;Bitdownload&lt;br&gt;Torrent101&lt;br&gt;CiD Help / CiD Manager&lt;br&gt;Download Plugin for Internet Explorer&lt;br&gt;Search Plugin&lt;br&gt;W3player&lt;br&gt;WinZix&lt;br&gt;Zone Media[/b]&lt;br&gt;This is because they are often bundled with the malware you are dealing with.&lt;br&gt;Don't worry if none of them are present.&lt;br&gt;[b]If you removed any of them please restart your pc.[/b]&lt;br&gt;&lt;br&gt;Download [b][url=http://www.spywareedge.net/nolop/NoLop.exe][color="blue"]NoLop.exe[/color][/URL][/B] to your desktop.&lt;br&gt;* First close any other programs you have running as this will require a reboot.&lt;br&gt;* Double click [b]NoLop.exe[/b] to run it.&lt;br&gt;* Then click the button labelled "[b]Search and Destroy[/b]". &lt;br&gt;* When scanning is finished you will be prompted to reboot only if infected,click '[b]OK[/b]'.&lt;br&gt;* Now click the "[b]REBOOT[/b]" Button.&lt;br&gt;* A Message should popup from NoLop, if not,double click the program again and it will finish. &lt;br&gt;[b]Post the contents of C:\NoLop.log into your next reply,even if NoLop reports no infections found.[/b]&lt;br&gt;Note:&lt;br&gt;If you receive the error,that [b]mscomctl.ocx[/b] or one of its dependencies are not correctly registered, please download this file to your 'System32' folder then rerun the program: [url]http://www.boletrice.com/downloads/mscomctl.ocx[/url]&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Mon, 12 May 2008 14:39:51 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>HijackThis Log</title><link>http://tweaks.com/forum/Topic239304-29-1.aspx</link><description>I am trying to get rid of the CiD vius and here is the log.&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 12:14:59 AM, on 5/12/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\csrss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccProxy.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;C:\Program Files\Norton Internet Security\ISSVC.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe&lt;br&gt;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;br&gt;C:\WINDOWS\eHome\ehRecvr.exe&lt;br&gt;C:\WINDOWS\eHome\ehSched.exe&lt;br&gt;C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE&lt;br&gt;C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe&lt;br&gt;C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;br&gt;C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;br&gt;C:\WINDOWS\ehome\mcrdsvc.exe&lt;br&gt;C:\WINDOWS\system32\dllhost.exe&lt;br&gt;C:\WINDOWS\System32\alg.exe&lt;br&gt;C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\stsystra.exe&lt;br&gt;C:\Program Files\Common Files\Symantec Shared\ccApp.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br&gt;C:\Program Files\3M\PSNLite\PsnLite.exe&lt;br&gt;C:\PROGRA~1\3M\PSNLite\PSNGive.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\NoAdware5.0\NoAdware5.exe&lt;br&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;C:\WINDOWS\ehome\ehshell.exe&lt;br&gt;C:\WINDOWS\eHome\ehRec.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;C:\WINDOWS\system32\wbem\wmiprvse.exe&lt;br&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll&lt;br&gt;O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)&lt;br&gt;O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll&lt;br&gt;O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll&lt;br&gt;O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll&lt;br&gt;O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll&lt;br&gt;O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll&lt;br&gt;O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll&lt;br&gt;O3 - Toolbar: &amp;Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll&lt;br&gt;O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll&lt;br&gt;O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll&lt;br&gt;O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll&lt;br&gt;O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe&lt;br&gt;O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"&lt;br&gt;O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer&lt;br&gt;O4 - HKLM\..\Run: [MATH DOES FIRST MODE] C:\Documents and Settings\All Users\Application Data\live 64 math does\Cash One.exe&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe&lt;br&gt;O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe&lt;br&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br&gt;O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe&lt;br&gt;O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe&lt;br&gt;O8 - Extra context menu item: E&amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O15 - Trusted Zone: *.doginhispen.com&lt;br&gt;O15 - Trusted Zone: http://*.java.com&lt;br&gt;O15 - Trusted Zone: http://*.racestud.com&lt;br&gt;O15 - Trusted Zone: *.whataboutadog.com&lt;br&gt;O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab&lt;br&gt;O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab&lt;br&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;br&gt;O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab&lt;br&gt;O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab&lt;br&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;br&gt;O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab&lt;br&gt;O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx&lt;br&gt;O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe&lt;br&gt;O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe&lt;br&gt;O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe&lt;br&gt;O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe&lt;br&gt;O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe&lt;br&gt;O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe&lt;br&gt;O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe&lt;br&gt;O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe&lt;br&gt;O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe&lt;br&gt;O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE&lt;br&gt;O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe&lt;br&gt;O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe&lt;br&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;br&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;br&gt;O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe&lt;br&gt;O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe&lt;br&gt;O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe&lt;br&gt;O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe&lt;br&gt;O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe&lt;br&gt;O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 10807 bytes&lt;br&gt;</description><pubDate>Mon, 12 May 2008 08:28:46 GMT</pubDate><dc:creator>bsmith40</dc:creator></item></channel></rss>