Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malware and appcompat.txt error


  • Please log in to reply

#1
Elkid27

Elkid27

    New Member

  • Member
  • Pip
  • 1 posts
Im having a lot of trouble with popups and programs running in the background, ive tried uninstalling some, they reinstall themselves, and ive used taskmanager to end processes but they start back up again. Also when opening some programs i get the appcompat.txt error and it closes out.

Heres the log

Logfile of HijackThis v1.99.1
Scan saved at 1:28:52 PM, on 3/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ipjk.exe
C:\Program Files\Security iGuard\Security iGuard.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.exe
C:\windows\system32\cejv8q.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\ivpnvr.exe
C:\windows\system32\qtakmdfv.exe
C:\WINDOWS\IEXPLOR.EXE
C:\WINDOWS\system32\cdir.exe
C:\WINDOWS\system32\cdir.exe
C:\Program Files\Trillian\trillian.exe
C:\windows\system32\calc.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Dragon's Era\Dragon's Era.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cody\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\Program Files\SurfSideKick 2\SskBho.dll (file missing)
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: FlashEnhancer Extender - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - c:\Program Files\Flen\flen.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [cejv8q] C:\windows\system32\cejv8q.exe
O4 - HKLM\..\Run: [cdir.exe] c:\windows\system32\cdir.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\ivpnvr.exe
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitekeh32.exe
O4 - HKLM\..\Run: [FlenCPY] "C:\Program Files\Common Files\Java\flencpy.exe"
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [qtakmdfv] c:\windows\system32\qtakmdfv.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM\aim.exe
O9 - Extra button: Microsoft AntiSpyware helper - {03D62B00-BF55-48C4-B4B3-1A5C66A1A99F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {03D62B00-BF55-48C4-B4B3-1A5C66A1A99F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {064888C0-4C89-4CC3-8FDE-007D990AE7A0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {064888C0-4C89-4CC3-8FDE-007D990AE7A0} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {131A2F69-0C82-4D92-AF52-CDEBA86B2EC3} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {131A2F69-0C82-4D92-AF52-CDEBA86B2EC3} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1AA15A6B-F689-452C-A768-11A11A12022D} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1AA15A6B-F689-452C-A768-11A11A12022D} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {1D05CDBF-5DCC-4B65-A779-BF1D49470889} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {1D05CDBF-5DCC-4B65-A779-BF1D49470889} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {324FF428-E5BA-4AB3-9702-7F4C6B611A7E} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {324FF428-E5BA-4AB3-9702-7F4C6B611A7E} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {49AD4A63-5551-45EA-9D0D-96F13F65BB8F} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {49AD4A63-5551-45EA-9D0D-96F13F65BB8F} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {4A58B0B5-914E-4DB8-8D62-9ABE66E55FC6} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {4A58B0B5-914E-4DB8-8D62-9ABE66E55FC6} - (no file) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {728F44F9-DE73-449D-82AE-5697E4263721} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {728F44F9-DE73-449D-82AE-5697E4263721} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {848297C4-4922-4818-B44A-6773B92038ED} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {848297C4-4922-4818-B44A-6773B92038ED} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {9F679C4C-0C9E-4812-9F72-CF840EA7DD98} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {9F679C4C-0C9E-4812-9F72-CF840EA7DD98} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A58EF1ED-C6ED-4452-9889-0A274493E221} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A58EF1ED-C6ED-4452-9889-0A274493E221} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {B743E4A9-42A6-4B9E-A4D2-76515A13DB6A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B743E4A9-42A6-4B9E-A4D2-76515A13DB6A} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D12F8AF4-29D6-4C47-9768-13A164790BAA} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D12F8AF4-29D6-4C47-9768-13A164790BAA} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D2693A1E-CFCF-4DAD-857A-B6AC7A525146} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D2693A1E-CFCF-4DAD-857A-B6AC7A525146} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D9D71375-A733-4B3D-8EBA-5F3ED86F9681} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D9D71375-A733-4B3D-8EBA-5F3ED86F9681} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D9F376AB-38E5-4019-9BDB-A26973B197D8} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D9F376AB-38E5-4019-9BDB-A26973B197D8} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {FFF37B60-FFF6-43E8-9B47-FA44C1FB39D4} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FFF37B60-FFF6-43E8-9B47-FA44C1FB39D4} - (no file) (HKCU)
O16 - DPF: {539DA0E0-74A7-11D9-9669-0800200C9A66} - http://www.ouchvideo...viewer_ic13.cab
O16 - DPF: {B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4} - http://www.alwaysupd...ll/aun_0011.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 6Q'8) - Unknown owner - C:\WINDOWS\system32\ipjk.exe
  • 0

Advertisements


#2
ilago

ilago

    Visiting Staff

  • Visiting Consultant
  • 363 posts
Hi Elkid27

Sorry for the delay in response. The forum has been very busy lately.

Please carry out all the steps in this topic http://www.geekstogo..._Log-t2852.html
and post a new HijackThis log when you've completed them.

If you have already fixed your machine or received help elsewhere please post back and let us know.

Thank you
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP