Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

LSP [RESOLVED]


  • This topic is locked This topic is locked

#1
spread

spread

    New Member

  • Member
  • Pip
  • 3 posts
In my Temp folder I have a file called KomodiaSLP which consists of the following sample text:

04/02/2008 00:49:16 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Loaded LSP V1.11 in module: C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE
04/02/2008 00:49:16 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Requesting proxy information
04/02/2008 00:49:16 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - No reply about our process
04/02/2008 00:49:16 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Requesting proxy information
04/02/2008 00:49:16 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - No reply about our process
04/02/2008 00:49:17 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Requesting proxy information
04/02/2008 00:49:17 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - No reply about our process
04/02/2008 00:49:18 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Requesting proxy information
04/02/2008 00:49:18 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - No reply about our process
04/02/2008 00:49:18 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - Requesting proxy information
04/02/2008 00:49:18 C:\PROGRA~1\GRISOFT\AVG7\AVGINET.EXE:3020 - No reply about our process
04/02/2008 00:50:19 C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE:4000 - Loaded LSP V1.11 in module: C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE
04/02/2008 00:50:19 C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE:4000 - Requesting proxy information
04/02/2008 00:50:19 C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE:4000 - No reply about our process
04/02/2008 00:50:20 C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE:4000 - Requesting proxy information
04/02/2008 00:50:20 C:\PROGRAMAS\OUTLOOK EXPRESS\MSIMN.EXE:4000 - No reply about our process
04/02/2008 00:50:44 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Loaded LSP V1.11 in module: C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE
04/02/2008 00:50:44 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:50:44 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:50:45 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:50:45 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:50:46 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:00 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:00 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:01 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:02 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:02 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:02 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information
04/02/2008 00:51:02 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - No reply about our process
04/02/2008 00:51:03 C:\PROGRAMAS\INTERNET EXPLORER\IEXPLORE.EXE:328 - Requesting proxy information etc etc etc



I have made the following Hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:07:34, on 07-02-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\UPHClean\uphclean.exe
C:\Programas\Network Associates\Common Framework\UpdaterUI.exe
C:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Programas\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\Programas\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Ficheiros comuns\Ahead\Lib\NMBgMonitor.exe
C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
C:\Programas\Hide My IP 2007\SecureSrv.exe
C:\Programas\Trend Micro\HijackThis\HijackThis.exe
C:\Programas\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Programas\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Programas\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Programas\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Programas\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programas\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ATIPTA] C:\Programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Atalho para a Página de Propriedades do High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1163430529093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163680965875
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Programas\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: SecureSrv - Unknown owner - C:\Programas\Hide My IP 2007\SecureSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8396 bytes


Is this some sort of malware?? Can you please help.
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
These entries in your LSP chain

O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll

Are from

Part of Hide My IP 2007, an anonymous surfing program


It is a legitimate program so I would not worry.


Are you having any problems ?
  • 0

#3
spread

spread

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts

These entries in your LSP chain

O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll

Are from

Part of Hide My IP 2007, an anonymous surfing program


It is a legitimate program so I would not worry.


Are you having any problems ?



Hi Rorschach, any relation to the famous "Rorschach test"??? :) :)

Thank you so much for your prompt reply. As a matter of fact I downloaded and installed an update for Zone alarm and since then my computer is slower booting up and shutting down. When I close an internet page it goes blank for a while and only closes a few seconds later. I have defragmented my disc and there are no viruses on my computer (at least known ones!). That is the main reason why I have been looking more closely for "strange files" and the like but I don't think I'm having any serious problems!

Thank you again and regards
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
I wouldn't worry

Few things you should do

You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here


Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com.../readstep2.html



This link has lots of ways to speed up your PC

http://users.telenet...owcomputer.html


Let me know how that goes and if you have any questions
  • 0

#5
spread

spread

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Hi,

Have done what you recommended and had a look at the link you sent ... there is a lot of useful information.

Thank you and I have no more problems

Best wishes
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP