Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

possible trojan causing svchost.exe to drop my connection


  • Please log in to reply

#1
pentroll

pentroll

    New Member

  • Member
  • Pip
  • 1 posts
Ok. I'm not a computing god by any means but I can usually fix it or find a way to fix thanks to the friendly internet. But this time I am totally confused.

The computer started to act strangly after avast! antivirus updated its scan engine. A message would pop up after connectin to the net (via Wan/miniport pppoe) informing me that Generic Host Process for Win32 services (svchost.exe) caused an error. My internet connection would drop after this point and quite often the system sound would be muted. A restart was required to reconnect to the internet.

Here is a small amount of information from the original error message that I recieved when this happened:

EventType : BEX P1 : svchost.exe P2 : 5.1.2600.2180 P3 : 41107ed6
P4 : netapi32.dll P5 : 5.1.2600.2180 P6 : 411096ac P7 : 0000a3c0
P8 : c0000409 P9 : 00000000

C:\DOCUME~1\Heather\LOCALS~1\Temp\WERfc2d.dir00\svchost.exe.mdmp
C:\DOCUME~1\Heather\LOCALS~1\Temp\WERfc2d.dir00\appcompat.txt

I in turn installed a firewall (sysgate personal firewall) and embarked on a aggravating search of the net to find an answer. I followed instructions found on here on how to possibly remove malware and in turn post for help if needed. I followed all steps, even going beyond in some steps, all to no avail. I still have svchost.exe attempting to connect and causing connection to be dropped. I understand that svchost.exe needs to connect at times to allow certain functions within windows to work. But a website and a little program http://www.firewalll...er.com/wwdc.htm and the program listed there regonized that there was something funny about the svchost.exe file and suggested that a trojan might be present.

Anyway enough ramblings here are my HJT and ewido log:

Logfile of HijackThis v1.99.1
Scan saved at 4:49:31 PM, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\HTJ\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1150998121662
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.t...ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC840FAB-56B4-468E-A906-6439D2120136}: NameServer = 209.128.1.4 142.163.255.4
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:12:26 PM 30/08/2006

+ Scan result:



:mozilla.42:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.55:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.6:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.7:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Heather\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.145:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.17:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.154:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.155:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.129:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Masterstats : No action taken.
:mozilla.135:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.136:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.61:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.62:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.92:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.93:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.94:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.103:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.117:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.115:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.116:C:\Documents and Settings\Heather\Application Data\Mozilla\Firefox\Profiles\esmcjpjb.default\cookies.txt -> TrackingCookie.Zedo : No action taken.


::Report end


Can anyone help figure what the heck is going on.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP