Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Not sure of infection?


  • Please log in to reply

#1
mjaspey

mjaspey

    New Member

  • Member
  • Pip
  • 1 posts
While sending/receiving e-mail with Outlook I get a noticing informing me my address book is being accessed, do I what to allow this? Not sure if this is infection or not. Thanks for any advice/help.
Logfile of HijackThis v1.99.1
Scan saved at 11:38:11, on 24/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
C:\PROGRA~1\VCOM\SYSTEM~1\mxtask.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
E:\Program Files\PDVDServ.exe
E:\Program Files\Microsoft Spyware\gcasServ.exe
E:\Program Files\Microsoft Spyware\gcasDtServ.exe
C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
E:\Program Files\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SETI@home\SETI@home.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\program files\ActiveSync\WCESCOMM.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
D:\edit\utilities\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.madasafish.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe
O4 - HKLM\..\Run: [RCScheduleCheck] C:\Program Files\VCOM\Recovery Commander\RCSCHED.EXE -CHECK
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\PDVDServ.exe"
O4 - HKLM\..\Run: [gcasServ] "E:\Program Files\Microsoft Spyware\gcasServ.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [WorksFUD] E:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] E:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] E:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\SETI@home.exe -min
O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\program files\ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Outlook 2002\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - e:\program files\ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - e:\program files\ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - e:\program files\ActiveSync\INETREPL.DLL
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1120073047078
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O18 - Protocol: bw+0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw+0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw-0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw-0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw00 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw00s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw10 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw10s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw20 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw20s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw30 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw30s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw40 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw40s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw50 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw50s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw60 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw60s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw70 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw70s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw80 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw80s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw90 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bw90s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwa0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwa0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwb0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwb0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwc0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwc0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwd0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwd0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwe0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwe0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwf0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwf0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - (no file)
O18 - Protocol: bwg0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwg0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwh0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwh0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwi0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwi0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwj0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwj0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwk0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwk0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwl0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwl0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwm0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwm0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwn0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwn0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwo0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwo0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwp0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwp0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwq0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwq0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwr0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwr0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bws0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bws0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwt0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwt0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwu0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwu0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwv0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwv0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bww0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bww0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwx0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwx0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwy0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwy0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwz0 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: bwz0s - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O18 - Protocol: offline-8876480 - {64C9F3EE-79F6-41BF-848A-652953EC6A0A} - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SystemSuite Task Manager - V Communications, Inc. - C:\PROGRA~1\VCOM\SYSTEM~1\MXTask.exe
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP